Status: CMMC status note: third-party certification requirements applied through DFARS 252.204-7021 are paused with CMMC Phase II (suspended July 13, 2026, per DoD CIO); every other DFARS cyber obligation, including NIST SP 800-171 protection of CUI under 252.204-7012, remains fully in effect.

What Is DFARS and Why It Matters

DFARS (Defense Federal Acquisition Regulation Supplement) is the Department of Defense supplement to the Federal Acquisition Regulation - the set of contract clauses that carry cybersecurity and contracting obligations into defense contracts.

DFARS is not guidance and not optional. If your organization does business with the DoD, or supports a prime contractor, DFARS requirements are legally binding contract terms. Failure to comply can mean contract termination, loss of eligibility, and legal exposure. /* ⚖️ COUNSEL - FCA framing verified as plausible but sourced outside the citation map; see whyItMattersRisk */

From a cybersecurity standpoint, DFARS is the foundation that CMMC is built on. The clauses came first; the certification program checks them.

What It Is

Four clauses drive most defense cybersecurity obligations:

  • **252.204-7012 - Safeguarding Covered Defense Information and Cyber Incident Reporting:** requires protecting covered defense information (CUI) with the NIST SP 800-171 controls, rapidly reporting cyber incidents to DoD within 72 hours of discovery, preserving images of affected systems and monitoring data for at least 90 days from the report, and flowing the clause down to subcontractors. This is the most commonly cited DFARS cyber clause.
  • **252.204-7019 - Notice of NIST SP 800-171 DoD Assessment Requirements:** requires a current NIST SP 800-171 self-assessment - not more than three years old - with the score posted in the Supplier Performance Risk System (SPRS) as a condition of award.
  • **252.204-7020 - NIST SP 800-171 DoD Assessment Requirements:** requires contractors to give DoD access to conduct its own higher-level assessments when required, and to flow the requirement down.
  • **252.204-7021 - Contractor Compliance With the CMMC Level Requirements:** requires achieving and maintaining the CMMC status the contract specifies, with annual affirmations in SPRS and subcontractor flow-down.

One correction worth pinning down: FCI safeguarding is not a DFARS requirement. The 15 basic safeguarding requirements for Federal Contract Information come from FAR 52.204-21, a FAR clause. DFARS 252.204-7012 protects covered defense information - CUI. CMMC, applied through 252.204-7021, enforces both.

Who It Applies To

DFARS cyber clauses apply to:

  • Prime defense contractors: the clauses appear in their contracts directly.
  • Subcontractors and suppliers: 7012, 7020, and 7021 all require flow-down, so the obligations travel with the data.
  • Manufacturers and engineering firms: the typical holders of covered technical data.
  • IT, MSP, and cloud providers supporting DoD work: service providers inherit obligations for the systems they run.
  • Professional services firms handling defense-related data: scope follows the information, not the industry label.

Company size does not matter. If your contracts include DFARS clauses, you are responsible for compliance - even if IT is outsourced. Responsibility does not transfer with the invoice.

What Information Is Regulated

The DFARS cyber clauses center on covered defense information - Controlled Unclassified Information (CUI) provided under or generated in performance of a defense contract. That includes:

  • Technical drawings and specifications: the core of controlled technical information.
  • Export-controlled data: technical data also regulated under ITAR or EAR.
  • Defense-related intellectual property: designs, processes, and research tied to DoD programs.
  • Operational and logistics data: schedules, quantities, and movement information.
  • Certain personal and financial data: where tied to defense programs.

Federal Contract Information (FCI) is governed separately: its baseline safeguarding comes from FAR 52.204-21, and it enters the DFARS picture through 252.204-7021, which scopes CMMC levels to systems processing FCI or CUI.

From an IT perspective, CUI commonly lives across email, file storage, endpoints, cloud platforms, and vendor systems. Scoping it accurately is the first real compliance task.

Relation to Other Frameworks

The relationship is a chain, and DFARS is the link that makes it contractual:

  • **CUI Program:** defines what data is sensitive and requires protection.
  • NIST SP 800-171: defines the controls.
  • DFARS: establishes the cybersecurity requirements contractually.
  • **CMMC:** verifies compliance through assessment and affirmation.

CUI is the what. NIST defines the how. DFARS and CMMC enforce it. Or shorter still: DFARS is the obligation. CMMC is the enforcement mechanism.

Even with CMMC Phase II suspended, DFARS compliance is mandatory today. That line has always been true; since July 2026 it carries even more weight, because self-attested 800-171 compliance under 7012 and 7019 is what DoD is actively relying on.

IT Requirements

DFARS cybersecurity requirements are technical, operational, and evidence-driven:

  • Access control and identity: role-based access, least-privilege permissions, multi-factor authentication, secure remote access, and account monitoring and reviews.
  • System and endpoint security: secure configurations, malware protection, patch and vulnerability management, and endpoint hardening.
  • Data protection: CUI protected at rest and in transit, secure file storage and sharing, controlled data transfers, and backup protections.
  • Logging, monitoring, and incident response: audit logging, monitoring for cyber events, and a response plan that can hit the clause deadlines - report to DoD within 72 hours of discovering a cyber incident, then preserve system images and monitoring data for at least 90 days (252.204-7012). Incident response failures are a major DFARS risk area.
  • Configuration and change management: baseline configurations, controlled changes, and documented modifications.
  • Vendor and subcontractor risk: flow-down of requirements, oversight of vendors handling CUI, and accountability for third-party failures. You are responsible for your supply chain.
  • Documentation and evidence: System Security Plans (SSPs), policies and procedures, evidence of control implementation, and POA&Ms for open gaps. Controls must exist and be demonstrable, and the SPRS score built on them must be current - not more than three years old under 252.204-7019.

Why It Matters

Failure to comply with DFARS can result in:

  • Loss of contracts and contract termination: the clauses are conditions of the deal.
  • Suspension or debarment: exclusion from federal contracting entirely.
  • False Claims Act liability: inaccurate SPRS scores and compliance representations create legal risk, and false or inflated reporting is the pattern enforcement actions target. /* ⚖️ COUNSEL - FCA exposure is legally plausible and widely enforced but not verifiable from the mapped sources; consider adding 31 U.S.C. 3729 (uscode.house.gov) as a qualifying source before publish */
  • Reputational damage across the defense supply chain: primes drop subs who create risk.

The common failures are consistent: poor scoping of CUI, incomplete NIST SP 800-171 implementation, missing documentation, weak MFA or access controls, and over-reliance on vendors to handle compliance.

How It Fits Into Cyber Risk Management

DFARS aligns closely with the NIST Cybersecurity Framework, NIST SP 800-171 and 800-53, ISO 27001, and SOC 2.

Organizations that implement DFARS well typically see significant improvements in overall security posture, not just contract compliance. The controls that satisfy the clause are the controls that shorten incidents.

How We Help With DFARS Compliance

Our Cyber Risk & Compliance Gap Assessment helps organizations:

  • Comprehensive Compliance & Security Review: evaluate your environment against the requirements that apply to you
  • Plain-Language Gap Analysis & Roadmap: see exactly where you stand and what to fix first
  • Corrective Action Plan & Progress Tracker (CART): turn findings into tracked, prioritized work
  • POA&M (Plan of Action & Milestones): the documented remediation record auditors and contract officers expect

Our assessment scopes your covered defense information and tests the controls behind your SPRS score before DoD does.

How to Prepare

  1. 01Identify the DFARS clauses in your contracts

    Confirm which clauses apply, which contracts are affected, and whether CMMC requirements are included through 252.204-7021. Check your subcontracts too - flow-down means the clauses may reach you without a direct DoD contract.

  2. 02Identify your FCI and CUI scope

    Document the systems handling covered data, the data flows between them, and the users and vendors with access. Remember the split: FCI baseline safeguarding is FAR 52.204-21; CUI protection is DFARS 252.204-7012.

  3. 03Perform a NIST SP 800-171 gap assessment

    Evaluate control implementation, technical gaps, documentation gaps, and evidence availability. This step prevents failed audits, inaccurate SPRS scores, and the legal exposure that follows them.

  4. 04Implement and harden required controls

    Focus on MFA and access management, secure configurations, endpoint and email security, logging and monitoring, and incident response readiness - including the ability to actually report within 72 hours.

  5. 05Build documentation and evidence

    Prepare System Security Plans, POA&Ms, incident response procedures, and vendor flow-down documentation. The clause requires proof, not intentions.

  6. 06Prepare for reporting and assessments

    Confirm your SPRS score is accurate and less than three years old, your evidence supports every claim in it, staff understand their obligations, and vendors meet their flowed-down requirements.

Frequently Asked Questions

Does DFARS apply to us if we are only a subcontractor?

Almost certainly, if covered data reaches you. Clauses 252.204-7012, 7020, and 7021 all require primes to flow the requirements down to subcontractors handling covered defense information. The obligations travel with the data, not the contract tier.

What is the difference between DFARS and CMMC?

DFARS is the contractual obligation; CMMC is the verification program. DFARS 252.204-7012 has required NIST SP 800-171 protection of CUI for years. CMMC, applied through DFARS 252.204-7021, checks whether you actually did it. Even with CMMC Phase II suspended, every other DFARS obligation stands.

How fast do we have to report a cyber incident?

Within 72 hours of discovery. DFARS 252.204-7012 requires rapid reporting to DoD through its designated portal, plus preservation of affected system images and monitoring data for at least 90 days after the report. If your response plan cannot hit those numbers, it is not DFARS-ready.

What is SPRS and what score do we need?

The Supplier Performance Risk System is where your NIST SP 800-171 self-assessment score is posted, as required by 252.204-7019. The scoring methodology starts at 110 and subtracts for unimplemented requirements. There is no published passing score - but the score is a representation to the government, and it must be accurate and no more than three years old.

If DFARS covers CUI, who covers FCI?

The FAR. Basic safeguarding of Federal Contract Information comes from FAR 52.204-21, which sets 15 baseline requirements. DFARS 252.204-7012 covers the more sensitive tier - covered defense information, which is CUI. CMMC Level 1 verifies the FAR baseline; Level 2 verifies the CUI tier.

Our IT is outsourced. Are we still responsible?

Yes. The clauses bind the contractor, not the IT vendor. You can delegate the work; you cannot delegate the responsibility. Your MSP or cloud provider becomes part of your compliance scope, which is why vendor oversight and flow-down documentation are DFARS requirements in their own right.

What does DFARS compliance cost?

It depends on your CUI footprint and how much of NIST SP 800-171 you already meet. We publish no pricing - you get a firm quote before any work begins, and the conversation costs nothing. Scoping first keeps you from buying controls you do not need.

Where do we start?

Read your contracts and find the clauses, then find your CUI. From there, a NIST SP 800-171 gap assessment tells you where you actually stand before your SPRS score claims otherwise. Our Cyber Risk & Compliance Gap Assessment covers exactly that ground.

Official source

Official source: Defense Acquisition Regulations System, Acquisition.gov

Secondary source: eCFR, DFARS 252.204-7012

Source verified 2026-07-24

By Joshua Nelson, CXO & Compliance Coach · Last reviewed 2026-07-25