If you cannot find information about a compliance topic, please contact us for free support.
-
Policies & Procedures
- How to Submit Your SPRS Score: PIEE Step-by-Step Guide [2026 Update]
- CMMC Policies and Procedures: What Documentation You Need
- How to Write a System Security Plan: The Owner's Guide to the One Document That Gates Everything
- Creating a Plan of Action and Milestones for CMMC
- Documenting Evidence for CMMC Assessment
-
SPRS & Self-Assessment
-
CMMC Fundamentals
-
Contract Clauses & Flowdown
- DFARS and FAR Cybersecurity Clauses: What Each One Actually Requires
- What DFARS 252.204-7012 Requires, in Plain English
- DFARS 252.204-7019 vs 7020 vs 7021: What Each Clause Triggers
- FAR 52.204-21 and FCI: The 15 Basic Safeguarding Requirements
- DFARS flowdown requirements: Which Clauses You Must Pass to Your Subcontractors
- Flowdown: Which Clauses You Must Pass to Your Subcontractors
- Who Is Exempt from CMMC, and Why "We Only Make Parts" Usually Isn't
- What to Do When a DFARS Clause Appears in a Contract You Already Signed
- FAR 52.204-21 and FCI: The 15 Basic Safeguarding Requirements
-
Trigger Events & Urgent Situations
- Cybersecurity Questionnaire From Your Prime? Do This
- CUI Marked Drawings You Were Not Expecting? Do This
- Expired SPRS Score and a Bid Due? Fix It This Week
- Dropped Without CMMC? What a Prime Can Actually Do
- 90 Days to CMMC Compliance: What Is Really Possible
- DFARS 7021 Clause Found After Award? Read This First
- CMMC Compliant MSP? How to Verify What Yours Claims
- CUI in Commercial Microsoft 365: What to Do Now
- CMMC Level 2 Certification an RFP Wants? Bid Anyway
- CMMC Trigger Events: A Triage Guide for Contractors
-
CMMC Levels & Requirements
-
The 14 Control Families
- Access Control (AC)
- Awareness and Training (AT)
- Audit and Accountability (AU)
- Configuration Management (CM)
- Identification and Authentication (IA)
- CMMC Incident Response (IR)
- Maintenance (MA)
- Media Protection (MP)
- Personnel Security (PS)
- Physical Protection (PE)
- Risk Assessment (RA)
- Security Assessment (CA)
- System and Communications Protection (SC)
- System and Information Integrity (SI)
-
Implementation Roadmaps
-
Industry-Specific Guides
-
CMMC Documentation & Evidence
-
CMMC Costs & Budgeting
-
Technology & Tools
-
CMMC Training & Awareness
-
Supply Chain & Third-Party Risk
-
Incident Response & Breach Reporting
-
Common Mistakes & Failures
-
Advanced Topics & Level 2
-
Updates & Regulatory Changes
-
Artificial Intelligence (AI)
-
Comparisons & Alternatives
- GCC High vs GCC vs Commercial Microsoft 365 for CUI
- CMMC Compliance Options: Enclave, Environment or Service
- Enclave vs Full Remediation: Which CMMC Path Fits
- PreVeil vs GCC High for Small Defense Contractors
- CMMC Platform vs Consultant vs Doing It In House
- RPO vs C3PAO vs Consultant: Who Does What in CMMC
- CMMC Compliance Software for Small Manufacturers
- Azure Government vs AWS GovCloud for CUI Workloads
- Virtual Desktop Enclave vs Managed Laptops for CUI
- Free NIST 800-171 Tools vs Paid Platforms: The Gaps
- Build vs Buy Enclave: What In House Actually Costs
DFARS 7021 Clause Found After Award? Read This First
The award came through, somebody in contracts finally read the whole document, and a DFARS 7021 clause is sitting in section I. Now there is a question nobody wants to be the one to ask: did we just sign up for something we cannot deliver.
Take the temperature down first. A DFARS 7021 clause in an executed contract is a fact, not an emergency, and the sequence for handling it is well established. What you must not do is quietly hope it goes unnoticed, because the obligations in that clause are ongoing and they carry an affirmation attached to your name. This article belongs to Something Just Happened and You Need CMMC: A Triage Guide.
Read the whole contract before you react to the DFARS 7021 clause
A DFARS 7021 clause rarely travels alone, and the clauses around it tell you more about your real obligations than 7021 does by itself. Pull the contract and find every one of these:
| Clause | What it puts on you |
|---|---|
| FAR 52.204-21 | Fifteen basic safeguarding requirements for federal contract information. The floor, and it applies very broadly. |
| DFARS 252.204-7012 | Safeguarding covered defense information to NIST SP 800-171, cloud service provider conditions, and 72 hour incident reporting. This is the clause with real operational teeth. |
| DFARS 252.204-7019 | You must have a current assessment posted in SPRS, not more than three years old, to be considered for award. |
| DFARS 252.204-7020 | Access for DoD assessments, and flowdown to subcontractors handling covered defense information. |
| DFARS 252.204-7021 | The CMMC level stated in the contract, maintained for the life of the contract, and flowed down. |
Also find the statement of work and the contract data requirements list. If the contract genuinely involves no controlled unclassified information, the practical burden of 7012 and 7021 is very different from a contract that ships you a technical data package on day one. A side by side of the three assessment clauses is in DFARS 252.204-7019 vs 7020 vs 7021: What Each Clause Triggers.
Identify the required level, in writing, from the contract itself
7021 is not self executing. It points to a level, and the level should be stated in the solicitation or the contract. Level 1 covers federal contract information and is a self assessment against fifteen requirements. Level 2 covers controlled unclassified information and is measured against all 110 requirements of NIST SP 800-171.
If you are seeing the same ambiguity on the bid side rather than after award, an RFP requires a Level 2 certification you don’t have covers how to read and answer it. If the contract includes 7021 but never states a level, you have a contract defect, and identifying it is your job because nobody else will. Raise it with the contracting officer now, while the relationship is new and cooperative, rather than at closeout.
What the suspension changed and what it did not
CMMC Phase 2 certification assessments were suspended on July 13, 2026. That removed the ability to obtain a new third party certificate. It removed nothing else.
DFARS 252.204-7012 remains in force. NIST SP 800-171 remains the standard. The SPRS score requirement under 7019 remains. The annual affirmation by a named senior official remains. So the answer to “do we still have to do this” is yes for everything except the assessment you currently cannot schedule.
This is useful when you talk to your contracting officer. You are not asking to be relieved of a security obligation. You are asking how the government wants performance demonstrated during a period when one specific verification mechanism is unavailable.
The message to your contracting officer
Send it in writing, through the channel the contract specifies, and keep it factual. Contracting officers deal with this weekly and they respond well to a contractor who arrives with specifics rather than anxiety.
- State what you found. Contract number, clause, and the level stated or the fact that no level is stated.
- State your current posture honestly. Your SPRS score, its assessment date, and whether a System Security Plan and Plan of Action and Milestones exist.
- Ask the operative question. Given that CMMC Phase 2 assessments are suspended, what does the government expect the contractor to demonstrate during performance.
- Ask whether controlled unclassified information will be provided or generated under this contract, and if so, how it will be transmitted to you.
- Propose something. A compliance schedule with dates, or a modification if you believe the clause was included in error for this scope of work.
Do not ask to have the clause removed as your opening position. Ask what compliance looks like. If removal is appropriate, the conversation will get there on its own and it will get there faster if you did not lead with it.
What not to sign once you find a DFARS 7021 clause
Three specific cautions, each of which has cost companies real money.
Do not sign a modification that adds new obligations without pricing them. If the government proposes a bilateral modification that clarifies the CMMC level upward, that is a change, and changes have cost and schedule consequences you are entitled to raise.
Do not certify to a score you cannot evidence. The annual affirmation is a statement to the federal government in connection with a contract. The Department of Justice Civil Cyber-Fraud Initiative has settled multiple cases against contractors whose reported cybersecurity posture did not match reality, and those cases usually start with an employee who knew.
Do not accept controlled information you are not ready to hold. If the contracting officer confirms CUI is coming, tell them how you want it transmitted and where it will live before it arrives. Data that shows up in a commercial email inbox becomes a spillage conversation instead of a planning conversation, which is the situation described in your CUI is sitting in commercial Microsoft 365.
Flowing it down before you forget
7021 and 7020 both require flowdown. If any part of this work goes to a subcontractor who will touch covered defense information, the clause has to appear in their subcontract, and their SPRS posture becomes your exposure. Handle it while you are drafting subcontracts rather than after. The mechanics are covered in Flowdown: Which Clauses You Must Pass to Your Subcontractors.
If the contract was signed some time ago and you are only discovering this now, the situation is common enough to have its own playbook. See What to Do When a DFARS Clause Appears in a Contract You Already Signed.
Frequently asked
Questions about this topic
Can we get a DFARS 7021 clause removed from an awarded contract?
Do we have to comply if CMMC assessments are suspended?
What level applies if the contract does not say?
Could we be terminated over this?
Should we tell the contracting officer our score is low?
Does 7021 apply to our subcontractors?
Keep reading
More in Trigger Events & Urgent Situations
- 90 Days to CMMC Compliance: What Is Really Possible →
- CMMC Compliant MSP? How to Verify What Yours Claims →
- CMMC Level 2 Certification an RFP Wants? Bid Anyway →
- CMMC Trigger Events: A Triage Guide for Contractors →
- CUI in Commercial Microsoft 365: What to Do Now →
- CUI Marked Drawings You Were Not Expecting? Do This →
- Cybersecurity Questionnaire From Your Prime? Do This →
- Dropped Without CMMC? What a Prime Can Actually Do →
- Expired SPRS Score and a Bid Due? Fix It This Week →
Free tools
Get to an honest number faster
You will run this more than once: after any material change to your environment, and again before every annual affirmation. Both are free, and both are yours to keep.
Neither is a certified assessment, and neither pretends to be.
Official sources
The audit is gone. The liability isn't.
Greypike runs the environment your CUI lives in and owns the compliance outcome that proves it's protected. If you are not certain your environment supports the score sitting in SPRS next to your CAGE code, that is the conversation to have.
Talk to Greypike about SPRS Attestation AssuranceGreypike Inc.
SBA-certified Veteran-Owned Small Business
Cyber AB Registered Practitioner (RP) and Registered Practitioner Advanced (RPA) on staff
CAGE 9WVS6 · UEI N6CJNGDARFM5