Skip to main content
DFARSAgency supplement

Department of Defense

The Department of Defense's master add-on to the federal procurement rules — the source of the defense cybersecurity clauses most contractors must meet.

Last reviewedJune 9, 2026Version v1

Cybersecurity rules in this supplement

DFARS adds the defense cybersecurity clauses that drive most contractor security obligations across the federal market. The key rules:

DFARS Subpart 204.73 / clause 252.204-7012 — Safeguarding Covered Defense Information and Cyber Incident Reporting. Requires you to protect Covered Defense Information (CDI) on your systems by implementing the 110 controls of NIST SP 800-171 (Revision 2 remains the required version), and to report cyber incidents to DoD at dibnet.dod.mil within 72 hours.

DFARS 252.204-7019 / 252.204-7020 — NIST SP 800-171 DoD Assessment Requirements. You must complete a NIST SP 800-171 self-assessment and post your score in the Supplier Performance Risk System (SPRS) before award, and keep it current (within 3 years).

DFARS Subpart 204.75 / clause 252.204-7021 — Cybersecurity Maturity Model Certification (CMMC). Under the CMMC final rule (effective November 10, 2025), contracts handling Federal Contract Information (FCI) or CDI require a specific CMMC level. Provision 252.204-7025 gives notice of the level; the rollout is phased, with Level 2 third-party (C3PAO) certification phasing in from November 10, 2026.

DFARS 252.204-7008 — Compliance with Safeguarding Covered Defense Information Controls. A representation that you will meet the 7012 controls; included in covered solicitations.

DFARS 252.204-7012 telecom companion 252.204-7018 — Prohibition on Covered Defense Telecommunications Equipment or Services. Bars covered telecom equipment in the defense supply chain.

DFARS 252.204-7000 / 252.204-7009 — Disclosure of Information; Limits on use of third-party reported incident information. Controls disclosure of unclassified-but-sensitive information and protects incident data shared with DoD.

DFARS Subparts 239.71, 239.73, and 239.76 — Security for computer systems, supply-chain risk, and cloud computing. Add IT-security, supply-chain, and FedRAMP-aligned cloud requirements for DoD information systems.

In plain terms

If you contract with DoD and touch defense information, three rules do most of the work: 7012 makes you secure that information to NIST SP 800-171; 7019/7020 make you prove it by posting an SPRS score; and 7021 (CMMC) makes you hold a verified certification at the level your contract names. The other clauses fill in disclosure limits, banned telecom gear, and cloud/supply-chain rules.

Who it applies to

Any contractor or subcontractor doing business with DoD or its components whose work involves Federal Contract Information or Covered Defense Information — which covers most of the defense supply chain, including subcontractors at all tiers.

What it requires

Meet the FAR baseline, then: implement NIST SP 800-171 Rev 2, post and maintain an SPRS assessment score, hold the CMMC level your contract requires, report cyber incidents within 72 hours, and follow the cloud, supply-chain, and covered-telecom prohibitions.

Why it matters

DFARS is where the defense supply chain's cybersecurity duties live. Falling short can cost you eligibility for award, and — because compliance is something you certify — misrepresenting your security posture is a leading source of False Claims Act exposure in government contracting.

Citation

Defense Federal Acquisition Regulation Supplement (DFARS), codified at 48 C.F.R. Chapter 2.