DFARS Cybersecurity Requirements: Small Contractors

DFARS 101 for Small Contractors

Defense Federal Acquisition Regulation Supplement — DFARS — is the DoD’s overlay on top of the general Federal Acquisition Regulation (FAR). For any small business selling to the Department of Defense, DFARS clauses matter as much as FAR clauses. The most-discussed DFARS provisions today are the cybersecurity clauses that require contractors to protect Controlled Unclassified Information and demonstrate NIST SP 800-171 compliance — clauses that changed the compliance landscape for defense contracting starting in 2018 and continue evolving through the CMMC transition.

This guide walks through the four DFARS cybersecurity clauses that hit small contractors most, what each requires, how they interact, the SPRS score you need to know, and the practical compliance steps a small contractor takes. Companion coverage in our NIST 800-171 for small contractors guide and CMMC compliance pillar.

The Four Key DFARS Cyber Clauses

The DFARS cybersecurity clauses that matter most: 252.204-7008 (Compliance With Safeguarding Covered Defense Information Controls), 252.204-7012 (Safeguarding Covered Defense Information and Cyber Incident Reporting), 252.204-7019 (Notice of NIST SP 800-171 DoD Assessment Requirements), 252.204-7020 (NIST SP 800-171 DoD Assessment Requirements), and 252.204-7021 (Contractor Compliance with the CMMC Level Requirement). These clauses flow down to subcontractors on DoD contracts, meaning even sub-tier contractors handling defense information have to comply.

DFARS 252.204-7012: Safeguarding CDI

The foundational clause. Requires you to implement NIST SP 800-171 controls to protect Covered Defense Information (CDI) — a category that includes Controlled Unclassified Information (CUI). Also mandates cyber incident reporting to DoD within 72 hours of discovery. Applies to essentially all DoD contracts above the micropurchase threshold that involve covered defense information.

DFARS 252.204-7019: SPRS Assessment Notice

Notifies the contractor that DoD will require a NIST SP 800-171 self-assessment score to be posted to the Supplier Performance Risk System (SPRS) before award. This clause exists to alert contractors that a score is required; the actual scoring happens under 7020.

DFARS 252.204-7020: The Assessment Requirement

The active requirement. You must have a current NIST SP 800-171 basic (self) assessment score posted in SPRS at the time of contract award. Scores range from -203 (worst) to +110 (maximum). Higher-tier contracts require Medium or High assessments performed by DoD assessors, not just self-assessment.

DFARS 252.204-7021: CMMC

The Cybersecurity Maturity Model Certification clause is the ongoing transition from self-attestation to third-party certification. As CMMC 2.0 rolls out (Level 1 self-attestation, Level 2 third-party for most CUI contracts, Level 3 government-led for the most sensitive), this clause specifies the required CMMC level for the contract.

How These Clauses Interact

7012 requires the controls; 7019 warns you a score is needed; 7020 requires the score be current in SPRS; 7021 layers CMMC on top. In practice, a small DoD contractor: implements NIST SP 800-171 controls (7012), self-assesses using DoD’s official scoring methodology, posts the score to SPRS (7019/7020), and prepares for CMMC assessment as required by the contract (7021).

The 72-Hour Reporting Requirement

DFARS 7012 requires reporting cyber incidents affecting covered defense information within 72 hours of discovery. Reporting goes to DoD via dibnet.dod.mil. "Incident" is broadly defined — not just confirmed breaches but potentially any event that could compromise CDI. Establish your incident reporting workflow before you need it; discovering the reporting URL during an actual incident is too late.

Small Contractor Compliance Steps

Practical path for a small DoD contractor new to DFARS cyber requirements: (1) identify whether you handle CDI/CUI in your current or prospective contracts; (2) obtain a NIST SP 800-171 self-assessment tool (multiple free options; DoD publishes the scoring methodology); (3) perform your assessment honestly — inflated scores create audit risk; (4) create a System Security Plan (SSP) and Plan of Action and Milestones (POA&M) for the gaps; (5) post your score to SPRS; (6) prepare for CMMC assessment on any contract requiring it.

DFARS vs FAR Cyber Clauses

The FAR has its own cyber baseline (FAR 52.204-21, Basic Safeguarding of Covered Contractor Information Systems) which is broader but far less specific. DFARS clauses are the ones with real teeth for defense contractors. Some civilian agencies are adopting similar requirements — HHS, DHS — but DoD is still the leading edge.

SPRS Score Basics

SPRS scoring assigns positive or negative points for each of the 110 NIST SP 800-171 controls. Full implementation of all controls = +110. Each unimplemented control deducts specified points (1, 3, or 5 depending on the control’s weight). Contractors post the score, the date of assessment, and the date the score was last updated. Scores older than three years generally require refresh.

How DoD uses the score at award: the contracting officer verifies that a current SPRS score exists before award on any contract with the 7019/7020 clauses. A missing or expired score can delay or disqualify an award. Many contractors underestimate this — the score isn’t just a compliance artifact, it’s a gate on eligibility. If you’re bidding on DoD work and your SPRS score is negative, expect scrutiny even if your proposal is otherwise strong.

Flow-Down to Subcontractors

DFARS 252.204-7012 flows down to subcontractors handling covered defense information, meaning your primes will require you to demonstrate compliance and may audit you as part of their contract obligations. Conversely, if you’re a prime, you’re responsible for your subcontractors’ compliance on your contract — building a supplier due-diligence process is part of DoD contract management. Don’t assume subs are compliant just because they’ve been on prior DoD work; verify assessments and SPRS scores at contract start.

Get Help Interpreting the Clauses in Your Solicitation

If a solicitation you’re eyeing includes DFARS cybersecurity clauses and you’re not sure whether you’re compliant or how much investment closing the gap requires, Veteran Forge Strategies works with small businesses on GovCon cybersecurity readiness — including SPRS assessment prep and CMMC transition planning.

Key Takeaways

  • DFARS cybersecurity clauses flow down to subcontractors on DoD contracts.
  • Four clauses to know: 7008, 7012 (controls + incident reporting), 7019/7020 (SPRS score), 7021 (CMMC).
  • NIST SP 800-171 controls are the underlying compliance baseline; SPRS is where your score is posted.
  • 72-hour cyber incident reporting to DoD via dibnet.dod.mil is required — plan the workflow now.
  • CMMC transitions from self-attestation to third-party certification at Level 2+ over the next contracting cycles.

FAQ

Do DFARS cyber clauses apply to non-DoD federal contracts? No — DFARS is DoD-only. Civilian agencies use FAR clauses and may layer their own. Some civilian agencies are moving toward NIST 800-171-style requirements.

What’s the difference between DFARS 7012 and CMMC? DFARS 7012 requires you to implement NIST SP 800-171 controls (self-attestation). CMMC layers third-party certification of those controls on top for higher-tier contracts.

How do I know if my contract handles Controlled Unclassified Information? The solicitation should specify. If unclear, ask the contracting officer — it’s the CO’s job to identify CUI in the requirement.

What’s a good NIST 800-171 self-assessment score? The maximum is +110. Most small contractors can honestly reach +60 to +90 with focused effort. Higher scores require deeper technical investment.

Similar Posts