DFARS Cybersecurity Clause Recognition Guide | Xact Cybersecurity
DFARS · NIST 800-171 · CMMC Level 2

Know exactly which DFARS clauses you signed — and what they obligate you to do.

If your contract includes 252.204-7012 and your systems touch CUI, you're already on the hook for 110 controls, 72-hour breach reporting, and mandatory flowdowns. Read the clauses correctly before an assessor — or a breach — does it for you.

FREE DOWNLOAD · Clause-by-clause breakdown · Obligations · Flowdowns · Evidence
DFARS Cybersecurity Clause Recognition Guide
The clause was there the whole time

DFARS clauses aren't boilerplate. They're enforceable obligations.

DoD uses DFARS clauses to push cybersecurity requirements down through the supply chain. When one appears in your contract — or gets flowed down from a prime — you've accepted the obligation, whether you read it or not.

  • 7012Adequate security, now. Not a future goal. The moment you sign and your system touches covered defense information, the 110 NIST 800-171 controls are required.
  • FCAFalse Claims Act exposure. Certifying compliance you don't actually have carries real civil liability — not just a compliance gap.
  • SUBSubcontractors inherit it. When a prime flows a clause down, you accept the same obligations — often discovered mid-performance.
Recognize these on sight

The five DFARS clauses that trigger your cybersecurity obligations

A single contract can include several at once. Your job: read the contract, identify which clauses are present, and map each to its specific obligations.

252.204-7012
Safeguarding Covered Defense Information & Cyber Incident Reporting

The big one. Three core obligations: implement all 110 NIST SP 800-171 controls on any system handling CUI; report cyber incidents to DoD within 72 hours via the DIBNet portal and preserve forensic images; and flow the clause down to subcontractors who may handle covered defense information.

Flowdown · Mandatory
252.204-7019
Notice of NIST SP 800-171 DoD Assessment

Requires a current 800-171 self-assessment score on record in SPRS (scale −203 to 110) before award. No current score, no eligibility.

Pre-award gate
252.204-7020
NIST SP 800-171 DoD Assessment Requirements

Gives DoD the right to conduct a government-led Medium or High assessment of your implementation — and requires your cooperation. Almost always paired with 7019.

Government assessment
252.204-7021
CMMC Requirements

The CMMC clause itself. Specifies the required level (1, 2, or 3). Most CUI handlers need Level 2, mapping to the 110 controls and requiring a C3PAO third-party assessment. Carries a flowdown requirement.

Flowdown · C3PAO
252.239-7010
Cloud Computing Services

If you or your subs use cloud to process DoD data, providers must meet FedRAMP Moderate (or equivalent). Direct impact on how you scope your boundary and document services in your SSP.

Scope · SSP
STACK ↯

These don't work in isolation — they stack. A single contract can carry 7012, 7019, 7020, and 7021 simultaneously. The full guide maps every clause to its obligations, flowdowns, and the evidence artifacts each one drives.

Where contractors get it wrong

Five mistakes that turn into assessment findings

Each of these is common, avoidable, and exactly what a Medium or High assessor will look for.

Treating 7012 as a future obligation

The requirement is active the moment you sign and your system touches covered defense information. There's no grace period to "work toward."

Missing a flowed-down clause

Primes use their own templates. The clause may be paraphrased, incorporated by reference, or buried in an attachment. If CUI is involved, assume it applies — and verify.

An SPRS score with no documentation

A score without a dated self-assessment, SSP, and POA&M behind it is a significant finding waiting to happen under 7020.

Scoping the boundary wrong

Too broad pulls in systems that needn't carry 800-171 obligations. Too narrow leaves out systems that legitimately process CUI. Your scope must be documented and defensible.

Ignoring the 72-hour window

If your incident response plan doesn't name DIBNet, assign an owner, and define evidence preservation, you'll miss the reporting window under pressure.

Want the fixes for all five?

The guide pairs each clause with the documentation and evidence that keeps it from becoming a finding.

Get my free guide
The lead magnet

The DFARS Cybersecurity Clause Recognition Guide

A contract-by-clause breakdown of obligations, flowdowns, and evidence requirements — built for the people doing the actual contract work. Inside:

  • Every triggering clause — 7012, 7019, 7020, 7021, 7010 — with its short name and primary obligation
  • What each clause actually requires, in plain language
  • Flowdown rules so subcontractors know what they've inherited
  • The evidence artifacts each clause drives — SSP, POA&M, SPRS, incident response
  • A six-step compliance trigger map to run against your active contracts
Download the DFARS breakdown
Get your copy

Send me the Clause Recognition Guide

Drop your details and we'll send the full clause-by-clause breakdown straight to your inbox — obligations, flowdowns, and the evidence each clause requires.

NO SPAM · The guide, then occasional CMMC insights. Unsubscribe anytime.

Know what you signed. Implement what you owe.

Claim the guide

CMMC and DFARS guidance for the defense industrial base. Helping contractors and subcontractors read what they signed and implement what they owe.

Contact

© Xact Cybersecurity. All rights reserved. CMMC requirements and DFARS clause language evolve. Always verify specifics against current official DoD and CMMC Accreditation Body guidance before making compliance decisions.