Recognize these on sight
The five DFARS clauses that trigger your cybersecurity obligations
A single contract can include several at once. Your job: read the contract, identify which clauses are present, and map each to its specific obligations.
252.204-7012
Safeguarding Covered Defense Information & Cyber Incident Reporting
The big one. Three core obligations: implement all 110 NIST SP 800-171 controls on any system handling CUI; report cyber incidents to DoD within 72 hours via the DIBNet portal and preserve forensic images; and flow the clause down to subcontractors who may handle covered defense information.
Flowdown · Mandatory
252.204-7019
Notice of NIST SP 800-171 DoD Assessment
Requires a current 800-171 self-assessment score on record in SPRS (scale −203 to 110) before award. No current score, no eligibility.
Pre-award gate
252.204-7020
NIST SP 800-171 DoD Assessment Requirements
Gives DoD the right to conduct a government-led Medium or High assessment of your implementation — and requires your cooperation. Almost always paired with 7019.
Government assessment
252.204-7021
CMMC Requirements
The CMMC clause itself. Specifies the required level (1, 2, or 3). Most CUI handlers need Level 2, mapping to the 110 controls and requiring a C3PAO third-party assessment. Carries a flowdown requirement.
Flowdown · C3PAO
252.239-7010
Cloud Computing Services
If you or your subs use cloud to process DoD data, providers must meet FedRAMP Moderate (or equivalent). Direct impact on how you scope your boundary and document services in your SSP.
Scope · SSP
STACK ↯
These don't work in isolation — they stack. A single contract can carry 7012, 7019, 7020, and 7021 simultaneously. The full guide maps every clause to its obligations, flowdowns, and the evidence artifacts each one drives.