DFARS Compliance

DFARS is the set of defense-specific rules layered on top of the Federal Acquisition Regulation, and its cybersecurity clauses decide whether you can hold a Department of War contract. The core clause, 252.204-7012, requires you to protect Controlled Unclassified Information to the NIST SP 800-171 standard, report a cyber incident within 72 hours, and flow the requirement down to your subcontractors. 

3- Yr

Maximum Age of an SPRS Score Before Award

4

Core Clauses: 7012 · 7019 · 7020 · 7021

72 Hrs

Cyber Incident Reporting Window

110

NIST SP 800-171 Security Requirements

What is DFARS?

DFARS is the Defense Federal Acquisition Regulation Supplement. It is the Department of War’s addition to the government-wide FAR, and it carries the cybersecurity obligations that apply to defense contracts. The FAR sets the floor for all federal contractors. DFARS raises it for anyone in the defense supply chain.  

The clauses that matter most for cybersecurity are 252.204-7012, 7019, 7020, and 7021. Each one is covered below. 

Who has to comply with DFARS

Any organization with a Department of War contract or subcontract that involves Controlled Unclassified Information. That includes prime contractors and every subcontractor down the chain, because 7012 flows down. If your contract handles only Federal Contract Information and no CUI, your obligation is lighter, but the moment CUI enters your systems, the full weight of 7012 and NIST SP 800-171 applies. 

What is DFARS 252.204-7012?

DFARS 252.204-7012, “Safeguarding Covered Defense Information and Cyber Incident Reporting,” is the clause the rest of the framework hangs on. It requires four things:

  • Implement NIST SP 800-171. Provide “adequate security” on any covered contractor system by meeting the 110 security requirements in NIST SP 800-171.
  • Report incidents within 72 hours. Rapidly report any cyber incident affecting covered defense information to the Department of War within 72 hours of discovery, through DIBNet.
  • Use compliant cloud. Any external cloud service provider that stores or processes covered defense information must meet security requirements equivalent to the FedRAMP Moderate baseline.
  • Flow it down. Include the clause in subcontracts that involve covered defense information or operationally critical support.

What is Covered Defense Information?

Covered defense information (CDI) is unclassified controlled technical information or other information that requires safeguarding, either marked or identified in the contract, or collected and developed by the contractor during contract performance. In practice, CDI is the defense subset of Controlled Unclassified Information (CUI). If the government would not release it publicly and it touches a defense program, it is in scope.

For how CDI, CUI, and FCI relate, see our FAR vs DFARS vs CMMC vs NIST cheat sheet

What are DFARS 7019, 7020, and 7021?

A 2020 interim rule, effective November 30, 2020, added three clauses that put teeth behind 7012:

  • 252.204-7019 requires you to have a current NIST SP 800-171 self-assessment score, no more than three years old, posted before award in the Supplier Performance Risk System (SPRS), the government database that holds these scores.
  • 252.204-7020 sets the DoD assessment methodology (Basic, Medium, and High) and requires you to give the government access for higher-level assessments, and to confirm your subcontractors have current scores.
  • 252.204-7021 is the Cybersecurity Maturity Model Certification (CMMC) clause. It requires the CMMC level named in the solicitation. The 48 CFR final rule made this clause operative in contracts.

A suspended government mandate doesn’t suspend a prime’s own bar for its supply chain. 

What is SPRS, and what is the self-assessment score?

SPRS is the Supplier Performance Risk System, the government database where your NIST SP 800-171 assessment score lives. You score your own implementation against the 110 requirements using DoD’s methodology, starting at 110 and subtracting for each control not fully met. That number, and the date you assessed, must be current in SPRS before award under 7019. It is also a representation to the government, which matters in the enforcement section below.

How does DFARS relate to NIST SP 800-171?

DFARS 7012 does not write security controls. It points to NIST SP 800-171, which defines them: 110 security requirements across 14 families, covering access control, audit and accountability, configuration management, incident response, and more. The current baseline is Revision 2. A move to Revision 3 is anticipated through future rulemaking, so the requirement count may change.

For the full standard and how it maps to Microsoft controls, see our NIST 800-171 page

How does DFARS relate to CMMC

CMMC is the verification layer. NIST SP 800-171 says what to do, and until CMMC, contractors attested to it themselves. CMMC requires that attestation to be checked. Level 1 is a self-assessment. Level 2 is assessed one of two ways, depending on the contract: self-assessment for a limited set of programs, or a certification assessment by a third-party assessor, called a C3PAO, for most contracts that involve CUI. Level 3 goes further still. It adds a subset of the enhanced NIST SP 800-172 requirements, requires a Level 2 certification first, and is assessed by the government’s assessment center, DIBCAC, not a C3PAO.

Current status, August 2026: the 32 CFR program rule took effect in December 2024, and the 48 CFR rule brought CMMC into contracts, with Phase 1 self-assessment a condition of award since November 2025. A July 13, 2026 Department of War memo paused Phases 2 through 4 pending a review. The certification mechanism is on hold. NIST SP 800-171 and DFARS 252.204-7012 are not. The timeline moved. The obligation did not. 

What are the cyber incident reporting requirements?

Under 7012, you have 72 hours from discovering a cyber incident that affects covered defense information to report it to the Department of War through DIBNet, which requires a medium assurance certificate. The clause also requires you to preserve affected media for at least 90 days, submit malicious software if isolated, and give the government access for damage assessment. 

What about cloud services and GCC High?

If covered defense information lives in a cloud, 7012 requires that cloud to meet security equivalent to the FedRAMP Moderate baseline. For organizations built on Microsoft, that requirement, together with export-control rules like ITAR, is what points them toward Microsoft 365 GCC High, the government tenant, and Azure Government, the separate government cloud, rather than commercial Microsoft 365. 

 

Moving the whole organization is not the only option. A CMMC enclave draws a hard boundary around the systems that store, process, or transmit CUI, usually in a separate GCC High tenant, so only those systems fall inside the assessment. The rest of the organization can stay in commercial Microsoft 365. Fewer systems in scope means a lower cost to certify. 

 

Whichever path fits, where your data sits and whether that environment is configured to the controls is where most of the real work happens. See our CMMC enclave page, GCC High page, and Microsoft Security page. 

What happens if you are not compliant?

An inaccurate SPRS score or a false NIST SP 800-171 attestation is a representation to the government. Under the False Claims Act, the Department of Justice has settled cases through its Civil Cyber-Fraud Initiative against contractors who certified compliance they did not have, including settlements over misstated NIST SP 800-171 posture. That exposure predates CMMC and does not depend on it. 
 

That exposure is not only the company’s. Under the False Claims Act, an individual who knowingly certifies a false representation can be named personally, not just the organization. A knowingly false statement to the government is also a federal crime under 18 U.S.C. 1001, separate from any civil claim.  

The action that reduces the risk is the same one the contract already requires: an accurate assessment, and an environment configured and documented to match it. 

 

The action that reduces the risk is the same one the contract already requires: an accurate assessment, and an environment configured and documented to match it. 

How do you become DFARS compliant?

Not a single project that your IT manager or CTO is responsible for but is a companywide initiative. 

  1. Scope it. Identify where CUI and CDI live across your systems, and which contracts carry 7012. 
  2. Assess against NIST SP 800-171. Score all 110 requirements honestly, and put the current score in SPRS. 
  3. Close the gaps. Configure identity, logging, data protection, and endpoint controls to meet the requirements, in an environment that qualifies (for Microsoft, that usually means GCC High). 
  4. Document it. Write a System Security Plan that describes the environment that exists, and a Plan of Action and Milestones for anything open. 
  5. Keep it current. Re-assess as the environment and the rules change, and prepare for the CMMC assessment your contracts will require. 

Agile IT builds and validates this in Microsoft environments, from readiness through assessment. Learn More at AgileDefend

Frequently Asked Questions

What does DFARS stand for?

DFARS is the Defense Federal Acquisition Regulation Supplement, the Department of War’s addition to the government-wide FAR. Its cybersecurity clauses govern how defense contractors protect Controlled Unclassified Information.

DFARS 252.204-7012 is the contractual requirement. NIST SP 800-171 is the security standard it points to: 110 requirements for protecting CUI. DFARS makes the standard mandatory; NIST defines the controls. 

Phase 1 self-assessment, DFARS 252.204-7012, NIST SP 800-171 Rev 2 compliance, and SPRS score postings and annual affirmations continue without interruption.

DFARS 252.204-7021 requires CMMC at the level named in the solicitation. As of August 2026, Phase 1 self-assessment is a condition of award, and Phases 2 through 4 are paused under a July 2026 Department of War memo. DFARS 7012 and NIST SP 800-171 remain mandatory regardless. 

DFARS 252.204-7012 requires contractors to report a cyber incident affecting covered defense information to the Department of War within 72 hours of discovery, through DIBNet.

The task force is required to deliver a final report to the CIO within 60 days of July 13, 2026, putting a report on the CIO’s desk around mid-September.

Not by name, but if covered defense information lives in the cloud, that cloud must meet FedRAMP Moderate equivalent security, and export rules like ITAR often apply. For Microsoft environments, that combination is what pushes most defense contractors to GCC High rather than commercial Microsoft 365.

Yes. DFARS 252.204-7012 flows down to any subcontract that involves covered defense information or operationally critical support, regardless of tier.

An inaccurate score is a representation to the government. The Department of Justice has pursued False Claims Act settlements over misstated NIST SP 800-171 compliance through its Civil Cyber-Fraud Initiative. The exposure is real and predates CMMC.

DFARS compliance is not a certificate you earn once.

It is an environment configured to the NIST SP 800-171 requirements, with documentation that tells the truth about it.
Which of those two are you sure of today?