Skip to main content
Federal statuteDFARS 252.204-7021

CMMC Acquisition Rule

CMMC Acquisition Rule Short Answer DFARS 252.204-7021 is the DoD contract clause that places CMMC requirements into solicitations, contracts, and covered subcontracts.

Last reviewedJune 27, 2026Version v1

# CMMC Acquisition Rule

Short Answer

DFARS 252.204-7021 is the DoD contract clause that places CMMC requirements into solicitations, contracts, and covered subcontracts. It matters because the CMMC status identified for the work becomes an award, performance, annual-affirmation, and flowdown requirement.

Why this matters for government contractors

32 C.F.R. Part 170 establishes the CMMC Program. DFARS 252.204-7021 is the acquisition mechanism that makes the required CMMC status contractually binding. A contractor that handles only Federal Contract Information may face Level 1 requirements. A contractor that handles CUI may face Level 2, and certain high-risk work may require Level 3.

The key legal question is whether the solicitation or contract requires a specific CMMC status for the contractor information system that will process, store, or transmit FCI or CUI.

What the clause does

The clause requires the contractor to have and maintain the CMMC status stated in the contract for the relevant system. It requires annual affirmations of continuing compliance in SPRS. It addresses Conditional and Final CMMC Status, the use and closure of POA&Ms, unique identifiers, subcontractor flowdown, and requirements to verify covered subcontractor status before award.

The clause should be read together with the 32 C.F.R. Part 170 program rule. The program rule explains the assessment levels, self-assessment and third-party assessment rules, Level 3 government assessment structure, POA&M limits, affirmation requirements, and phased implementation.

How it reaches contractors

DFARS 252.204-7021 reaches contractors only when the clause is included in DoD procurement instruments. The CMMC Program rule has broad program significance, but contract obligations become concrete when the solicitation or contract identifies a required CMMC status. The flowdown piece is critical because prime contractors must push the appropriate requirement to covered subcontractors and verify status before subcontract award.

Procurement and cybersecurity significance

The clause affects go/no-go decisions for DoD opportunities. Contractors should identify the required level early, map the level to the actual system boundary, confirm assessment type, track affirmation deadlines, and evaluate whether POA&M use is allowed. Proposals should avoid loose statements such as “CMMC compliant” without identifying the level, status, system boundary, assessment date, and scope.

DFARS 252.204-7021 connects to 32 C.F.R. Part 170, FAR 52.204-21, NIST SP 800-171, selected NIST SP 800-172 requirements, DFARS 252.204-7012, DFARS 252.204-7019/7020, and SPRS. It should link to the framework page for control-level explanations and avoid duplicating the CMMC framework content.

What contractors should do

  • Check the solicitation for the required CMMC level and status.
  • Identify the systems that will process, store, or transmit FCI or CUI.
  • Determine whether self-assessment, C3PAO assessment, or government assessment is required.
  • Confirm whether Conditional status is allowed and whether POA&M limitations are met.
  • Submit and maintain required SPRS affirmations.
  • Flow the requirement to covered subcontractors and verify status before award.
  • Keep proposal, SPRS, SSP, assessment, and contract records consistent.

Current status

Current DFARS clause effective for CMMC acquisition implementation. The page should distinguish DFARS 252.204-7021 from the 32 C.F.R. Part 170 program rule and from older pre-final CMMC descriptions.

Primary citations

  • DFARS 252.204-7021.
  • 48 C.F.R. § 252.204-7021.
  • 32 C.F.R. Part 170.
  • 90 Fed. Reg. 43575 (Sept. 10, 2025), effective Nov. 10, 2025.

---

Source type: acquisition_clause. Implementation status: in_force.