# Assessing Contractor Implementation of Cybersecurity Requirements
Short Answer
Effective February 1, 2026, DoD deleted DFARS 252.204-7019 and renumbered DFARS 252.204-7020 to DFARS 252.240-7997, narrowing it to cover only government-performed Medium and High assessments. The clauses used to connect NIST SP 800-171 implementation to SPRS assessment records and government assessment access; that connection now runs primarily through CMMC (DFARS 252.204-7021), with SPRS still the system of record.
What changed, and when
As part of the Revolutionary FAR Overhaul, DoD issued a class deviation (DARS tracking no. 2026-O0025), effective February 1, 2026, that:
- Deleted DFARS 252.204-7019 outright — the solicitation-stage clause requiring offerors to have a current NIST SP 800-171 assessment score posted in SPRS.
- Renumbered DFARS 252.204-7020 to DFARS 252.240-7997, removing the "Basic" (contractor self-assessment) language and leaving only the requirement to support government-performed Medium and High DoD assessments.
The change took effect through a class deviation, not final rulemaking — the FAR Overhaul is being implemented in phases, so the codified DFARS text on Acquisition.gov/eCFR may still show 252.204-7019/-7020 until rulemaking catches up. What governs a given procurement is the clause language actually incorporated into the solicitation or contract.
What did not change
- DFARS 252.204-7012 is untouched — the safeguarding requirement and 72-hour incident-reporting clock are unchanged.
- The standard is still NIST SP 800-171 Revision 2 (110 controls) under the standing class deviation.
- SPRS remains the system of record for assessment scores.
- The underlying security-posture requirement did not change — only which clause creates and routes the obligation.
Why this matters for government contractors
The self-assessment/SPRS-posting pathway that 7019/7020 created was duplicative of CMMC, which verifies the same NIST SP 800-171 controls. DoD folded the contractor-facing obligation into CMMC under DFARS 252.204-7021 and let the standalone clauses go. Contractors should:
- Replace citations to DFARS 252.204-7019 and -7020 in templates, checklists, and subcontract flow-down language with the current structure (DFARS 252.204-7021 / CMMC, and DFARS 252.240-7997 where referencing government Medium/High assessments).
- Confirm the exact clause language incorporated into a given solicitation or contract before relying on any citation.
- Keep SPRS scores current and accurate — the obligation now flows through CMMC, but False Claims Act exposure for an inflated score is unchanged.
Relationship to other GovConCyber requirements
Connects to DFARS 252.204-7012, NIST SP 800-171, the DoD Assessment Methodology, SPRS, and CMMC (DFARS 252.204-7021 / 32 C.F.R. Part 170). CMMC does not erase the need for accurate assessment records; it adds a verification regime and affirmation structure where applicable.
Current status
Superseded via class deviation effective February 1, 2026 (DARS tracking no. 2026-O0025); codified DFARS text pending conforming rulemaking. Treat DFARS 252.204-7021 / CMMC as the current contractor-facing obligation and DFARS 252.240-7997 as the current government Medium/High assessment-access clause.
Primary citations
- FAR Overhaul class deviation, DARS tracking no. 2026-O0025 (effective Feb. 1, 2026).
- 48 C.F.R. § 252.240-7997 (formerly 48 C.F.R. § 252.204-7020).
- 48 C.F.R. § 252.204-7019 (deleted Feb. 1, 2026).
- NIST SP 800-171 DoD Assessment Methodology, Version 1.2.1.
- GovConCyber, "Where Did DFARS 7019 and 7020 Go? The FAR Overhaul's Quiet Cybersecurity Reshuffle" (/blog/dfars-7019-7020-deleted-far-overhaul-cmmc, published Feb. 1, 2026).
Source type: acquisition_clause. Implementation status: in_force.