Skip to main content

Research

DFARS 252.204-7012 and CMMC

DFARS 252.204-7012 and CMMC are connected, but they are not the same thing. Contractors need to understand what each does, how they interact, and what remains required even after CMMC appears in solicitations and contracts.

Last reviewed: June 29, 2026

The relationship in one sentence

DFARS 252.204-7012 is the DoD contract clause that requires safeguarding covered defense information and reporting cyber incidents; CMMC is the DoD assessment and contract-eligibility framework used to verify implementation of required cybersecurity protections for FCI and CUI in applicable DoD contracts.

A contractor can misunderstand risk if it treats CMMC as a replacement for 7012. CMMC changes how DoD verifies cybersecurity implementation. It does not erase the underlying safeguarding, incident-reporting, flowdown, malicious-software, evidence-preservation, or damage-assessment obligations in 7012 when that clause applies.

What DFARS 252.204-7012 does

DFARS 252.204-7012 requires contractors to provide adequate security for covered contractor information systems. For covered defense information in nonfederal systems, the clause points to NIST SP 800-171 unless another requirement applies or an authorized variance is approved.

The clause also requires contractors to:

  • rapidly report cyber incidents to DoD;
  • submit malicious software when discovered and isolated in connection with a reported incident;
  • preserve and protect images and monitoring/packet-capture data for at least 90 days;
  • support DoD damage assessment activities;
  • use cloud services that meet specified requirements when cloud computing is used to store, process, or transmit covered defense information in performance of the contract; and
  • flow down the clause to subcontractors when required.

7012 is both a security clause and an incident-response clause.

How NIST SP 800-171 fits into 7012

NIST SP 800-171 provides security requirements for protecting the confidentiality of CUI in nonfederal systems and organizations. Under 7012, contractors handling covered defense information in covered contractor information systems generally must implement the applicable NIST SP 800-171 requirements.

Contractors should not treat 800-171 as a theoretical framework. They need a scoped environment, SSP, implemented controls, supporting procedures, evidence, and a remediation plan for gaps. The system boundary matters: over-scoping increases cost, under-scoping increases compliance risk.

SPRS, self-assessments, and DoD assessment clauses

DFARS 252.204-7019 and 252.204-7020 connect NIST SP 800-171 assessment results to DoD procurement through the Supplier Performance Risk System. Contractors subject to these clauses should ensure that submitted assessment scores are accurate and supported by evidence.

An unsupported score can create more than a technical issue. It may affect proposal eligibility, responsibility, contract administration, and enforcement risk. Contractors should update scores when material changes occur and maintain evidence for the score submitted.

What CMMC adds

CMMC adds a structured assessment and affirmation layer. The CMMC program is codified at 32 CFR part 170, and the DFARS acquisition rule/clauses provide the contract mechanism for including CMMC requirements in applicable DoD solicitations and contracts.

CMMC Level 1 addresses FCI safeguarding. CMMC Level 2 addresses CUI protection and is based on NIST SP 800-171 requirements under the CMMC program. CMMC Level 3 involves higher-level protection for certain programs and requires Level 2 as a prerequisite.

Depending on the contract and CMMC level, contractors may need a self-assessment, third-party assessment, government assessment, affirmation, and periodic reassessment.

Phase-in and contract clause relationship

DoD's CMMC implementation uses a phased approach. Under 32 CFR part 170, Phase 1 begins on the effective date of the complementary DFARS acquisition final rule, with CMMC requirements introduced into applicable solicitations and contracts according to the phase structure. The DFARS CMMC clause and notice provision are the contract tools that tell offerors and contractors what CMMC status is required.

Contractors should read the solicitation. CMMC status matters when the solicitation or contract requires it. Do not assume every DoD opportunity requires the same CMMC level at the same time.

Common misconceptions

Misconception: “CMMC replaces DFARS 7012.”
It does not. 7012 obligations can still apply, including incident reporting and flowdowns.

Misconception: “We only need CMMC when the assessor arrives.”
CMMC status is tied to contract eligibility when required. Contractors should prepare before the solicitation requires it.

Misconception: “A tool purchase equals compliance.”
Controls require implemented practices, documentation, evidence, governance, and operations.

Misconception: “The prime handles everything.”
Subcontractors may have direct obligations, including reporting obligations under 7012 when the clause applies.

Misconception: “No CUI markings means no CUI risk.”
Markings matter, but contractors should escalate unclear sensitive information rather than assume no protection is required.

Flowdowns

Prime contractors should identify which subcontractors will handle FCI, CUI, covered defense information, or covered contractor information systems. Flowdowns should not be generic. They should address the clause, data, system boundary, required CMMC level if applicable, assessment expectations, incident reporting, evidence cooperation, cloud services, and subcontractor-to-prime notice.

Subcontractors should not accept flowdowns without understanding what information and systems are actually in scope.

Practical compliance planning

Contractors should:

  1. Identify contracts and solicitations containing DFARS 7012, 7019, 7020, 7021, or 7025.
  2. Map FCI, CUI, covered defense information, systems, users, administrators, vendors, and subcontractors.
  3. Define the system boundary.
  4. Build or update the SSP.
  5. Assess implementation against required controls.
  6. Submit or update SPRS assessment information when required and supported.
  7. Remediate gaps with a real POA&M.
  8. Prepare CMMC evidence and affirmations.
  9. Test incident reporting and evidence preservation.
  10. Review subcontract flowdowns and supplier access.

Educational content only. This page provides general legal information for educational purposes. It does not constitute legal advice and does not create an attorney-client relationship. Contractors should consult qualified legal counsel for contract-specific DFARS and CMMC obligations.