FAR vs DFARS vs CMMC vs NIST

Who protects what, and how they fit together.

A handful of acronyms decide who protects what in a defense contract, and they stack in a specific order. This is the short version: what each one covers, and how it points to the next. 

At a Glance

Term

What it is

Type

Governs/References

Applies to 

FCI

Federal Contract Information 

Data
category 

FAR 52.204-21 

All Federal Contractors 

CUI

Controlled Unclassified Information 

Data
category 

DFARS 252.204-7012, NIST SP 800-171 

Contractors that handle CUI (DoW via DFARS 7012) 

FAR

Federal Acquisition Regulation 

Regulation 

Includes 52.204-21 

All Federal Contractors 

DFARS

Defense FAR Supplement 

Regulation 

252.204-7012, 7019, 7020, 7021 

Department of War Contractors 

NIST SP 800-171 

Standard defining security requirements for CUI 

Security standard 

Required by DFARS 7012 

Any contractor handling CUI 

CMMC 

Cybersecurity Maturity Model Certification 

Cert. Program 

NIST SP 800-171 + added requirements 

Department of War Contractors 

How do FAR, DFARS, NIST, and CMMC relate? 

These acronyms govern how sensitive but unclassified information is protected across the federal contracting environment, and especially in the Department of War supply chain. Each one plays a specific role. Here is what each covers and what it points to. 

What does each acronym mean? 

The process of granting or denying specific requests to obtain and use information and related information processing services; and/or entry to specific physical facilities (e.g., Federal buildings, military establishments, or border crossing entrances), as defined in FIPS PUB 201-3 Jan2002 (incorporated by reference, see § 170.2).

FCI: Federal Contract Information

Not intended for public release, provided or generated under a contract. Type: Data category Governs / references: FAR 52.204-21 Applies to: All federal contractors 

CUI: Controlled Unclassified Information

Sensitive but unclassified information that requires safeguarding. Type: Data category Governs / references: DFARS 252.204-7012, NIST SP 800-171 Applies to: Contractors that handle CUI (in DoW, through DFARS 7012)

FAR: Federal Acquisition Regulation

Government-wide rules for federal acquisition, including basic safeguarding of FCI. Type: Regulation Governs / references: Includes 52.204-21 Applies to: All federal contractors

DFARS: Defense FAR Supplement

DoW-specific rules layered on top of the FAR, including the requirement to protect CUI. Type: Regulation Governs / references: 252.204-7012, 7019, 7020, 7021 Applies to: Department of War contractors

NIST SP 800-171

The standard that defines the security requirements for protecting CUI in non-federal systems. Type: Security standard Governs / references: Required by DFARS 7012 Applies to: Any contractor that handles CUI Current baseline: Revision 2, 110 requirements. A move to Revision 3 is anticipated through future rulemaking, so the count may change.

CMMC: Cybersecurity Maturity Model Certification

 The DoW program that verifies a contractor meets NIST SP 800-171, with added requirements at higher levels. Type: Certification program Governs / references: NIST SP 800-171 plus added requirements Applies to: Department of War contractors (in contracts since 2025)

How do they fit together? 

  • FAR governs the protection of FCI: basic safeguarding, 15 requirements (FAR 52.204-21). 
  • DFARS governs the protection of CUI: requires NIST SP 800-171, 110 requirements. 
  • CMMC is the DoWD program that verifies it, by self-assessment or third-party assessment. 
  • CUI is protected under DFARS 252.204-7012, which points to NIST SP 800-171. 
  • CMMC Level 1 covers FCI, and matches FAR 52.204-21. 
  • CMMC Level 2 covers CUI, and matches NIST SP 800-171. 

Which rules apply to me? 

Scenario 1

You process payment or scheduling data for a federal contract (FCI). Applicable rules: FAR 52.204-21, CMMC Level 1.

FAR 52.204-21, CMMC Level 1

Scenario 2

You develop software containing DoW mission data (CUI). Applicable rules: DFARS 252.204-7012, NIST SP 800-171, CMMC Level 2.

DFARS 252.204-7012, NIST SP 800-171. CMMC Level 2

Scenario 3

You are bidding on a DoW contract, either directly with the Department or with another contractor, that requires CMMC. Applicable rules: CMMC. The level depends on the sensitivity of the data you will handle.

CMMC. The level depends on the sensitivity of the data you will handle

The Right License is A Compliance Decision

The CMMC level you have to meet decides which Microsoft cloud instance and licensing you need, and GCC High changes the math. Agile IT maps the instance and the license to your contract, so you are not paying for capability you cannot use or missing one the contract requires. 

Frequently Asked Questions

What is the difference between FAR and DFARS?

The FAR is the government-wide acquisition rulebook and covers basic safeguarding of FCI. DFARS is the Department of War supplement layered on top, and it adds the requirement to protect CUI through DFARS 252.204-7012. Every DoD contractor follows both. 

FCI is information generated under a federal contract that is not for public release. CUI is sensitive but unclassified information that requires safeguarding under specific rules. FCI maps to FAR 52.204-21 and CMMC Level 1; CUI maps to NIST SP 800-171 and CMMC Level 2. 

NIST SP 800-171 is the standard: 110 security requirements for protecting CUI. CMMC is the DoW program that verifies you meet that standard, by self-assessment or third-party assessment. One is the rulebook; the other is the check. 

If you handle FCI but not CUI, you are in CMMC Level 1 territory, which matches the 15 basic safeguarding requirements of FAR 52.204-21 and is met by self-assessment. Handling CUI raises you to Level 2. 

No. DFARS is the Department of War supplement, so it applies to DoW contracts, either with the Department or with Department contractors. The government-wide FAR applies to all federal contractors. 

The current CMMC baseline is Revision 2, with 110 security requirements. A move to Revision 3 is anticipated through future rulemaking, so that number may change. 

It depends on the data you handle. FCI puts you at Level 1. CUI puts you at Level 2. Higher-sensitivity programs can require Level 3. The contract and the data sensitivity set the level.

Let’s review your environment and determine what allignment looks like, before and assessment forces the conversation.