Cybersecurity rules in this supplement
DFARS adds the defense cybersecurity clauses that drive most contractor security obligations across the federal market. The key rules:
DFARS Subpart 204.73 / clause 252.204-7012 — Safeguarding Covered Defense Information and Cyber Incident Reporting. Requires you to protect Covered Defense Information (CDI) on your systems by implementing the 110 controls of NIST SP 800-171 (Revision 2 remains the required version), and to report cyber incidents to DoD at dibnet.dod.mil within 72 hours.
DFARS 252.204-7019 / 252.204-7020 — NIST SP 800-171 DoD Assessment Requirements. You must complete a NIST SP 800-171 self-assessment and post your score in the Supplier Performance Risk System (SPRS) before award, and keep it current (within 3 years).
DFARS Subpart 204.75 / clause 252.204-7021 — Cybersecurity Maturity Model Certification (CMMC). Under the CMMC final rule (effective November 10, 2025), contracts handling Federal Contract Information (FCI) or CDI require a specific CMMC level. Provision 252.204-7025 gives notice of the level; the rollout is phased, with Level 2 third-party (C3PAO) certification phasing in from November 10, 2026.
DFARS 252.204-7008 — Compliance with Safeguarding Covered Defense Information Controls. A representation that you will meet the 7012 controls; included in covered solicitations.
DFARS 252.204-7012 telecom companion 252.204-7018 — Prohibition on Covered Defense Telecommunications Equipment or Services. Bars covered telecom equipment in the defense supply chain.
DFARS 252.204-7000 / 252.204-7009 — Disclosure of Information; Limits on use of third-party reported incident information. Controls disclosure of unclassified-but-sensitive information and protects incident data shared with DoD.
DFARS Subparts 239.71, 239.73, and 239.76 — Security for computer systems, supply-chain risk, and cloud computing. Add IT-security, supply-chain, and FedRAMP-aligned cloud requirements for DoD information systems.
In plain terms
If you contract with DoD and touch defense information, three rules do most of the work: 7012 makes you secure that information to NIST SP 800-171; 7019/7020 make you prove it by posting an SPRS score; and 7021 (CMMC) makes you hold a verified certification at the level your contract names. The other clauses fill in disclosure limits, banned telecom gear, and cloud/supply-chain rules.
Who it applies to
Any contractor or subcontractor doing business with DoD or its components whose work involves Federal Contract Information or Covered Defense Information — which covers most of the defense supply chain, including subcontractors at all tiers.
What it requires
Meet the FAR baseline, then: implement NIST SP 800-171 Rev 2, post and maintain an SPRS assessment score, hold the CMMC level your contract requires, report cyber incidents within 72 hours, and follow the cloud, supply-chain, and covered-telecom prohibitions.
Why it matters
DFARS is where the defense supply chain's cybersecurity duties live. Falling short can cost you eligibility for award, and — because compliance is something you certify — misrepresenting your security posture is a leading source of False Claims Act exposure in government contracting.
Citation
Defense Federal Acquisition Regulation Supplement (DFARS), codified at 48 C.F.R. Chapter 2.