DFARS (Defense Federal Acquisition Regulation Supplement) is the Department of Defense supplement to the Federal Acquisition Regulation - the set of contract clauses that carry cybersecurity and contracting obligations into defense contracts.
DFARS is not guidance and not optional. If your organization does business with the DoD, or supports a prime contractor, DFARS requirements are legally binding contract terms. Failure to comply can mean contract termination, loss of eligibility, and legal exposure. /* ⚖️ COUNSEL - FCA framing verified as plausible but sourced outside the citation map; see whyItMattersRisk */
From a cybersecurity standpoint, DFARS is the foundation that CMMC is built on. The clauses came first; the certification program checks them.
Four clauses drive most defense cybersecurity obligations:
One correction worth pinning down: FCI safeguarding is not a DFARS requirement. The 15 basic safeguarding requirements for Federal Contract Information come from FAR 52.204-21, a FAR clause. DFARS 252.204-7012 protects covered defense information - CUI. CMMC, applied through 252.204-7021, enforces both.
DFARS cyber clauses apply to:
Company size does not matter. If your contracts include DFARS clauses, you are responsible for compliance - even if IT is outsourced. Responsibility does not transfer with the invoice.
The DFARS cyber clauses center on covered defense information - Controlled Unclassified Information (CUI) provided under or generated in performance of a defense contract. That includes:
Federal Contract Information (FCI) is governed separately: its baseline safeguarding comes from FAR 52.204-21, and it enters the DFARS picture through 252.204-7021, which scopes CMMC levels to systems processing FCI or CUI.
From an IT perspective, CUI commonly lives across email, file storage, endpoints, cloud platforms, and vendor systems. Scoping it accurately is the first real compliance task.
The relationship is a chain, and DFARS is the link that makes it contractual:
CUI is the what. NIST defines the how. DFARS and CMMC enforce it. Or shorter still: DFARS is the obligation. CMMC is the enforcement mechanism.
Even with CMMC Phase II suspended, DFARS compliance is mandatory today. That line has always been true; since July 2026 it carries even more weight, because self-attested 800-171 compliance under 7012 and 7019 is what DoD is actively relying on.
DFARS cybersecurity requirements are technical, operational, and evidence-driven:
Failure to comply with DFARS can result in:
The common failures are consistent: poor scoping of CUI, incomplete NIST SP 800-171 implementation, missing documentation, weak MFA or access controls, and over-reliance on vendors to handle compliance.
DFARS aligns closely with the NIST Cybersecurity Framework, NIST SP 800-171 and 800-53, ISO 27001, and SOC 2.
Organizations that implement DFARS well typically see significant improvements in overall security posture, not just contract compliance. The controls that satisfy the clause are the controls that shorten incidents.
Here is the key takeaway: DFARS compliance is not about intent. It is about enforceable contractual obligations.
Most requirements are known cybersecurity practices, technically achievable, and already expected under CMMC. What creates risk is misunderstanding the clauses, poor documentation, and false assumptions about who is handling what.
Our Cyber Risk & Compliance Gap Assessment helps organizations:
Our assessment scopes your covered defense information and tests the controls behind your SPRS score before DoD does.
Confirm which clauses apply, which contracts are affected, and whether CMMC requirements are included through 252.204-7021. Check your subcontracts too - flow-down means the clauses may reach you without a direct DoD contract.
Document the systems handling covered data, the data flows between them, and the users and vendors with access. Remember the split: FCI baseline safeguarding is FAR 52.204-21; CUI protection is DFARS 252.204-7012.
Evaluate control implementation, technical gaps, documentation gaps, and evidence availability. This step prevents failed audits, inaccurate SPRS scores, and the legal exposure that follows them.
Focus on MFA and access management, secure configurations, endpoint and email security, logging and monitoring, and incident response readiness - including the ability to actually report within 72 hours.
Prepare System Security Plans, POA&Ms, incident response procedures, and vendor flow-down documentation. The clause requires proof, not intentions.
Confirm your SPRS score is accurate and less than three years old, your evidence supports every claim in it, staff understand their obligations, and vendors meet their flowed-down requirements.
Almost certainly, if covered data reaches you. Clauses 252.204-7012, 7020, and 7021 all require primes to flow the requirements down to subcontractors handling covered defense information. The obligations travel with the data, not the contract tier.
DFARS is the contractual obligation; CMMC is the verification program. DFARS 252.204-7012 has required NIST SP 800-171 protection of CUI for years. CMMC, applied through DFARS 252.204-7021, checks whether you actually did it. Even with CMMC Phase II suspended, every other DFARS obligation stands.
Within 72 hours of discovery. DFARS 252.204-7012 requires rapid reporting to DoD through its designated portal, plus preservation of affected system images and monitoring data for at least 90 days after the report. If your response plan cannot hit those numbers, it is not DFARS-ready.
The Supplier Performance Risk System is where your NIST SP 800-171 self-assessment score is posted, as required by 252.204-7019. The scoring methodology starts at 110 and subtracts for unimplemented requirements. There is no published passing score - but the score is a representation to the government, and it must be accurate and no more than three years old.
The FAR. Basic safeguarding of Federal Contract Information comes from FAR 52.204-21, which sets 15 baseline requirements. DFARS 252.204-7012 covers the more sensitive tier - covered defense information, which is CUI. CMMC Level 1 verifies the FAR baseline; Level 2 verifies the CUI tier.
Yes. The clauses bind the contractor, not the IT vendor. You can delegate the work; you cannot delegate the responsibility. Your MSP or cloud provider becomes part of your compliance scope, which is why vendor oversight and flow-down documentation are DFARS requirements in their own right.
It depends on your CUI footprint and how much of NIST SP 800-171 you already meet. We publish no pricing - you get a firm quote before any work begins, and the conversation costs nothing. Scoping first keeps you from buying controls you do not need.
Read your contracts and find the clauses, then find your CUI. From there, a NIST SP 800-171 gap assessment tells you where you actually stand before your SPRS score claims otherwise. Our Cyber Risk & Compliance Gap Assessment covers exactly that ground.
Official source: Defense Acquisition Regulations System, Acquisition.gov
Secondary source: eCFR, DFARS 252.204-7012
Source verified 2026-07-24
By Joshua Nelson, CXO & Compliance Coach · Last reviewed 2026-07-25