Manufacturing operations face intense competitive pressures, increasingly complex supply chains, and strict compliance requirements like CMMC and ITAR...
Healthcare providers face mounting pressures from ever-evolving technology...
Accounting firms handle sensitive financial data—from tax filings to audit...
Law firms operate under strict confidentiality obligations and face evolving...
Auto dealerships handle a wealth of customer information, from financing details...
In Oil & Gas, uptime, safety, and data integrity are paramount. Whether you’re managing offshore rigs,...
Financial institutions bear a heavy responsibility: they hold sensitive client information and manage...
In the insurance sector, safeguarding sensitive policyholder information is essential—not just to meet...
Auto dealerships handle a wealth of customer information, from financing details...
Small and medium-sized businesses are the backbone of our economy, but they often face...
Manufacturing operations face intense competitive pressures, increasingly complex supply chains, and strict compliance requirements like CMMC and ITAR...
Healthcare providers face mounting pressures from ever-evolving technology...
Accounting firms handle sensitive financial data—from tax filings to audit...
Law firms operate under strict confidentiality obligations and face evolving...
Auto dealerships handle a wealth of customer information, from financing details...
In Oil & Gas, uptime, safety, and data integrity are paramount. Whether you’re managing offshore rigs,...
Financial institutions bear a heavy responsibility: they hold sensitive client information and manage...
In the insurance sector, safeguarding sensitive policyholder information is essential—not just to meet...
Auto dealerships handle a wealth of customer information, from financing details...
Small and medium-sized businesses are the backbone of our economy, but they often face...
DFARS 252.204-7019 and 252.204-7020 are separate from and often confused with DFARS 252.204-7012. Where 7012 creates the underlying obligation to protect covered defense information on your covered contractor information system, 7019 requires you to actually assess your NIST SP 800-171 compliance and report a score to the Supplier Performance Risk System (SPRS) tied to your company’s CAGE code (Commercial and Government Entity code) and 7020 requires you to give the DoD access to verify that assessment and flows the same requirement down to your subcontractors.
Here’s what that actually means in practice, and why the score you submit matters more than a lot of contractors realize.
DFARS 252.204-7019 requires contractors to have a current NIST SP 800-171 DoD Assessment on record before contract award specifically, a summary-level score submitted to SPRS, based on the DoD’s Assessment Methodology, and no more than three years old unless a shorter time is specified in the solicitation. In plain terms: before the DoD can award you a contract requiring NIST 800-171 compliance, they want to see a documented, current score showing where you actually stand.
That score can range from a perfect score of 110 (full implementation of all 110 controls) down into negative territory we’ve seen real client starting scores as low as 7 out of 110, and in one case, an initial score of negative 145. Negative scores happen because the DoD Assessment Methodology doesn’t just fail to award points for unmet controls in certain categories it actively subtracts points for some of them, which is why a company with almost no controls in place can end up well below zero rather than just at zero.
Related Topic: CMMC Compliance Timeline: How Long Does It Take?
DFARS 252.204-7020 does two things. First, it requires you to provide the DoD with access to your facilities, systems, and personnel if needed to verify your NIST 800-171 assessment your self-reported score isn’t just taken at face value forever. Second, it flows the same assessment requirement down through your supply chain: if you’re a prime or higher-tier subcontractor, you’re generally required to confirm that your own subcontractors who handle covered defense information have a current assessment on file too, not just verify your own.
That second part is where a lot of contractors get caught off guard. Protect your organization by ensuring subcontractors handling CUI meet the same security and compliance requirements you follow internally.
Related Topic: How to Meet CUI Marking Requirements: A Guide for the Defense Industrial Base
The NIST SP 800-171 DoD Assessment Methodology defines three assessment types, and knowing which one applies to you matters:
Basic Assessment — a self-assessment you conduct and submit yourself, based on your own review against the 110 controls. This is the minimum requirement for most contractors under 7019.
Medium Assessment — conducted by the DoD, involving a review of your Basic Assessment plus additional documentation, without an on-site visit.
High Assessment — the most rigorous level, involving DoD personnel reviewing your system security plan and conducting interviews and verification, sometimes on-site. High Assessment scores also carry more weight and a longer validity period in some circumstances.
Most contractors follow Basic Assessment requirements unless specific contracts or sensitive information require a higher assessment level instead.
Related Topic: CMMC Compliance for Manufacturers: What You Need to Know
This is worth taking seriously: a self-assessment score submitted to SPRS isn’t just a number you’re allowed to estimate favorably. Support your score with evidence, documentation, and a system security plan that withstands DoD verification under DFARS 7020. Submitting an unsupported SPRS score creates DFARS exposure and potential False Claims Act liability if auditors later prove inaccuracies.
This has practical implications right now, too. Contractors must maintain accurate, current, defensible SPRS scores under DFARS 7019 despite CMMC Phase 2’s current suspension status. We cover how the broader CMMC timeline has shifted in our CMMC compliance timeline guide.
Related Topic: How to Determine if Your Product Is on the U.S. Munitions List?
Think of it this way: 7012 tells you what to protect and how to respond to an incident. 7019 tells you to measure and report how well you’re actually doing it.
7020 tells you that report is subject to verification, and that your subcontractors need to do the same measuring. All three clauses typically show up together in the same contracts, and all three trace back to the same underlying NIST SP 800-171 control set. We cover the foundational obligation in detail in our guide to DFARS 252.204-7012, and the mechanics of the score itself in our SPRS score guide.
Verify your SPRS score and subcontractor assessments before a prime contractor or the DoD requests proof during review. Our team works with manufacturers navigating exactly this kind of CMMC compliance work.
👉 Schedule a free consultation with our team to talk through where your SPRS score actually stands.
Related Topic: Is Your Key Control Policy Actually Working?
DFARS stands for Defense Federal Acquisition Regulation Supplement, which adds Department of Defense contracting rules to the FAR.
The DoD uses this standardized methodology to score NIST SP 800-171 implementation and record assessment results in SPRS.
A DFARS 7019 assessment generally remains valid for three years unless the solicitation or contract requires earlier reassessment.
No. DFARS 7020 covers assessment verification and subcontractor flow-down, while DFARS 7021 establishes separate CMMC contract requirements instead.
DFARS 252.204-7019 and 252.204-7020 are separate from and often confused with DFARS 252.204-7012. Where…
Supply chain cybersecurity covers three related but distinct risks: software supply chain attacks, where…
A deemed export happens when controlled technology or technical data is released to a…