Every Department of Defense contractor that touches sensitive unclassified information lives under a family of four DFARS clauses, and confusing them is one of the most common compliance mistakes in the defense industrial base. The anchor is DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting, which sets the substantive security bar. Clauses 252.204-7019 and 252.204-7020 added a scoring and verification layer on top of it, and 252.204-7021 now ties contract eligibility to the Cybersecurity Maturity Model Certification (CMMC) program. Each does a different job, each flows down differently, and — as a string of False Claims Act settlements shows — each can become an enforcement problem if a contractor signs for compliance it does not have.

252.204-7012: The Substantive Baseline

Clause 7012 (current version May 2024) requires contractors to provide "adequate security" for covered defense information — unclassified controlled technical information or other CUI that is either provided by DoD or collected and developed in performance of the contract. For most covered contractor systems, adequate security means implementing NIST SP 800-171, a requirement that has been mandatory since December 31, 2017.

The clause's second half is incident response. Contractors must "rapidly report" — defined as within 72 hours of discovery — any cyber incident affecting covered defense information or operationally critical support, through DoD's DIBNet portal. Reporting requires a DoD-approved medium assurance certificate, which contractors should obtain before an incident, not during one. The clause flows down verbatim: primes must include it in subcontracts involving covered defense information or operationally critical support, and subcontractors must pass DoD-assigned incident report numbers up the chain.

7019 and 7020: The Scoring Layer — Reshaped in 2026

Clause 7012 told contractors what to implement; the 2020-era companions told DoD how to check. Provision 252.204-7019 required offerors to have a NIST SP 800-171 DoD Assessment score — not more than three years old — posted in the Supplier Performance Risk System (SPRS) to be considered for award. The Basic assessment is a self-assessment scored against the DoD methodology, reported as a summary figure (for example, 95 out of a maximum 110). Clause 252.204-7020 backed that up: contractors must give the government access to facilities, systems, and personnel for Medium or High assessments conducted by DCMA's DIBCAC, get 14 business days to rebut findings, and may not award a subcontract unless the subcontractor has a current Basic assessment on file.

The FAR Overhaul changed this architecture. Under DoD class deviations effective February 1, 2026 — issued for 31 DFARS parts, as Wiley Rein's overhaul tracker details — cybersecurity requirements moved from DFARS Part 204 to a new Part 240, mirroring the FAR's move of information security into Part 40. Clause 7020's requirements were relocated to a renumbered clause, 252.240-7997, while 7012 and 7021 kept their numbering. Industry analyses note the deviations dropped the standalone Basic self-assessment machinery, since CMMC now performs that gatekeeping. The official DFARS text still carries 7019 and 7020, and legacy contracts still contain them, so contractors should read each award's actual clause set rather than assume.

252.204-7021: The CMMC Clause

Revised in November 2025 to implement the CMMC acquisition rule, clause 7021 makes cybersecurity a condition of award. Contractors must achieve and maintain, for the duration of the contract, a current CMMC status at the required level: Level 1 (Self), Level 2 (Self), Level 2 (C3PAO), or Level 3 (DIBCAC). "Current" is defined precisely — a conditional Level 2 status is valid only 180 days; a final Level 1 self-assessment lasts one year; final Level 2 and Level 3 statuses last three years, but only with an affirmation of continuous compliance, not older than one year, entered in SPRS by the company's affirming official.

That affirmation is the legal pivot between self-assessment and certification. Level 1 and some Level 2 contracts accept a self-assessment; higher-sensitivity CUI work requires a third-party C3PAO certification. Either way, a senior official personally attests to continuous compliance annually — the exact kind of representation the Justice Department builds cases on. Under DFARS subpart 204.75, contracting officers apply CMMC requirements when the program office requires them during the phase-in; on or after November 10, 2028, inclusion becomes mandatory wherever contractor systems process, store, or transmit FCI or CUI. The clause flows down to subcontractors at the level appropriate to the information they handle. GovConFeed's CMMC levels and phase-in guide walks through the timeline in detail.

The Enforcement Backdrop

These clauses are now a False Claims Act priority. As GovConFeed has reported, DOJ's Civil Cyber-Fraud Initiative treats false SPRS scores and unimplemented controls as fraud. Mayer Brown's review of FY2025 counts more than $52 million across nine cybersecurity FCA settlements — including Raytheon and Nightwing's $8.4 million settlement over DFARS 7012 and FAR 52.204-21 failures, MorseCorp's $4.6 million, and a $421,234 settlement with an Illinois precision-machining supplier over technical drawings. As DOJ's Brenna Jenny put it, these cases are "not about data breaches" — they are "premised on misrepresentations."

What It Means for Contractors

Map your obligations clause by clause. If you hold covered defense information, 7012 applies now: implement NIST SP 800-171, stand up 72-hour reporting, and get the medium assurance certificate. Check whether your contracts carry 7019/7020 or the overhauled 252.240-7997, and keep your SPRS score honest — an inflated score is the fact pattern behind nearly every cyber FCA settlement. For new work, treat CMMC as a bid-eligibility issue: know the level your contracts will demand, schedule C3PAO assessments early, and put a named affirming official through a real review before each annual affirmation. Finally, manage flowdown actively — primes are responsible for verifying subcontractor status before award, and a subcontractor's false score can become the prime's problem.

Sources