What It Is

Four clauses drive most defense cybersecurity obligations:

  • **252.204-7012 - Safeguarding Covered Defense Information and Cyber Incident Reporting:** requires protecting covered defense information (CUI) with the NIST SP 800-171 controls, rapidly reporting cyber incidents to DoD within 72 hours of discovery, preserving images of affected systems and monitoring data for at least 90 days from the report, and flowing the clause down to subcontractors. This is the most commonly cited DFARS cyber clause.
  • **252.204-7019 - Notice of NIST SP 800-171 DoD Assessment Requirements:** requires a current NIST SP 800-171 self-assessment - not more than three years old - with the score posted in the Supplier Performance Risk System (SPRS) as a condition of award.
  • **252.204-7020 - NIST SP 800-171 DoD Assessment Requirements:** requires contractors to give DoD access to conduct its own higher-level assessments when required, and to flow the requirement down.
  • **252.204-7021 - Contractor Compliance With the CMMC Level Requirements:** requires achieving and maintaining the CMMC status the contract specifies, with annual affirmations in SPRS and subcontractor flow-down.

One correction worth pinning down: FCI safeguarding is not a DFARS requirement. The 15 basic safeguarding requirements for Federal Contract Information come from FAR 52.204-21, a FAR clause. DFARS 252.204-7012 protects covered defense information - CUI. CMMC, applied through 252.204-7021, enforces both.

What Information Is Regulated

The DFARS cyber clauses center on covered defense information - Controlled Unclassified Information (CUI) provided under or generated in performance of a defense contract. That includes:

  • Technical drawings and specifications: the core of controlled technical information.
  • Export-controlled data: technical data also regulated under ITAR or EAR.
  • Defense-related intellectual property: designs, processes, and research tied to DoD programs.
  • Operational and logistics data: schedules, quantities, and movement information.
  • Certain personal and financial data: where tied to defense programs.

Federal Contract Information (FCI) is governed separately: its baseline safeguarding comes from FAR 52.204-21, and it enters the DFARS picture through 252.204-7021, which scopes CMMC levels to systems processing FCI or CUI.

From an IT perspective, CUI commonly lives across email, file storage, endpoints, cloud platforms, and vendor systems. Scoping it accurately is the first real compliance task.

IT Requirements

DFARS cybersecurity requirements are technical, operational, and evidence-driven:

  • Access control and identity: role-based access, least-privilege permissions, multi-factor authentication, secure remote access, and account monitoring and reviews.
  • System and endpoint security: secure configurations, malware protection, patch and vulnerability management, and endpoint hardening.
  • Data protection: CUI protected at rest and in transit, secure file storage and sharing, controlled data transfers, and backup protections.
  • Logging, monitoring, and incident response: audit logging, monitoring for cyber events, and a response plan that can hit the clause deadlines - report to DoD within 72 hours of discovering a cyber incident, then preserve system images and monitoring data for at least 90 days (252.204-7012). Incident response failures are a major DFARS risk area.
  • Configuration and change management: baseline configurations, controlled changes, and documented modifications.
  • Vendor and subcontractor risk: flow-down of requirements, oversight of vendors handling CUI, and accountability for third-party failures. You are responsible for your supply chain.
  • Documentation and evidence: System Security Plans (SSPs), policies and procedures, evidence of control implementation, and POA&Ms for open gaps. Controls must exist and be demonstrable, and the SPRS score built on them must be current - not more than three years old under 252.204-7019.

How It Fits Into Cyber Risk Management

DFARS aligns closely with the NIST Cybersecurity Framework, NIST SP 800-171 and 800-53, ISO 27001, and SOC 2.

Organizations that implement DFARS well typically see significant improvements in overall security posture, not just contract compliance. The controls that satisfy the clause are the controls that shorten incidents.

How We Help With DFARS Compliance

Our Cyber Risk & Compliance Gap Assessment helps organizations:

  • Comprehensive Compliance & Security Review: evaluate your environment against the requirements that apply to you
  • Plain-Language Gap Analysis & Roadmap: see exactly where you stand and what to fix first
  • Corrective Action Plan & Progress Tracker (CART): turn findings into tracked, prioritized work
  • POA&M (Plan of Action & Milestones): the documented remediation record auditors and contract officers expect

Our assessment scopes your covered defense information and tests the controls behind your SPRS score before DoD does.

How to Prepare

  1. Identify the DFARS clauses in your contracts

    Confirm which clauses apply, which contracts are affected, and whether CMMC requirements are included through 252.204-7021. Check your subcontracts too - flow-down means the clauses may reach you without a direct DoD contract.

  2. Identify your FCI and CUI scope

    Document the systems handling covered data, the data flows between them, and the users and vendors with access. Remember the split: FCI baseline safeguarding is FAR 52.204-21; CUI protection is DFARS 252.204-7012.

  3. Perform a NIST SP 800-171 gap assessment

    Evaluate control implementation, technical gaps, documentation gaps, and evidence availability. This step prevents failed audits, inaccurate SPRS scores, and the legal exposure that follows them.

  4. Implement and harden required controls

    Focus on MFA and access management, secure configurations, endpoint and email security, logging and monitoring, and incident response readiness - including the ability to actually report within 72 hours.

  5. Build documentation and evidence

    Prepare System Security Plans, POA&Ms, incident response procedures, and vendor flow-down documentation. The clause requires proof, not intentions.

  6. Prepare for reporting and assessments

    Confirm your SPRS score is accurate and less than three years old, your evidence supports every claim in it, staff understand their obligations, and vendors meet their flowed-down requirements.

Official source

Official source: Defense Acquisition Regulations System, Acquisition.gov

Secondary source: eCFR, DFARS 252.204-7012

Source verified 2026-07-24

By Joshua Nelson, CXO & Compliance Coach · Last reviewed 2026-07-25