Manufacturing operations face intense competitive pressures, increasingly complex supply chains, and strict compliance requirements like CMMC and ITAR...
Healthcare providers face mounting pressures from ever-evolving technology...
Accounting firms handle sensitive financial data—from tax filings to audit...
Law firms operate under strict confidentiality obligations and face evolving...
Auto dealerships handle a wealth of customer information, from financing details...
In Oil & Gas, uptime, safety, and data integrity are paramount. Whether you’re managing offshore rigs,...
Financial institutions bear a heavy responsibility: they hold sensitive client information and manage...
In the insurance sector, safeguarding sensitive policyholder information is essential—not just to meet...
Auto dealerships handle a wealth of customer information, from financing details...
Small and medium-sized businesses are the backbone of our economy, but they often face...
Manufacturing operations face intense competitive pressures, increasingly complex supply chains, and strict compliance requirements like CMMC and ITAR...
Healthcare providers face mounting pressures from ever-evolving technology...
Accounting firms handle sensitive financial data—from tax filings to audit...
Law firms operate under strict confidentiality obligations and face evolving...
Auto dealerships handle a wealth of customer information, from financing details...
In Oil & Gas, uptime, safety, and data integrity are paramount. Whether you’re managing offshore rigs,...
Financial institutions bear a heavy responsibility: they hold sensitive client information and manage...
In the insurance sector, safeguarding sensitive policyholder information is essential—not just to meet...
Auto dealerships handle a wealth of customer information, from financing details...
Small and medium-sized businesses are the backbone of our economy, but they often face...
DFARS compliance means meeting the cybersecurity and reporting requirements the Defense Federal Acquisition Regulation Supplement writes into Department of Defense contracts. If your contract includes DFARS 252.204-7012 and you handle covered defense information, you have to protect it with the 110 security controls in NIST SP 800-171, report cyber incidents to the DoD within 72 hours, and be able to prove you did it.
A prime contractor sends over a supplier questionnaire. One line asks whether you are DFARS compliant. Suddenly the question is not whether your machines can hold tolerance. It is whether you can show you protect the information behind the parts.
That does not mean you need enterprise IT complexity. It means you need to know which clauses apply to you, where your sensitive data lives, and what to fix first.
One note on scope. “DFARS compliant” also gets used in the metals trade to mean something different. We cover that below. This guide is about the cybersecurity clauses.
Related Topic: Deemed Export Compliance and Technical Data
DFARS stands for the Defense Federal Acquisition Regulation Supplement. It is the Department of Defense’s supplement to the Federal Acquisition Regulation (FAR), the rulebook for how the federal government buys things. DFARS adds the rules specific to contracts with the Department of Defense, and those federal regulations cover everything from pricing to sourcing to cybersecurity. On the cybersecurity side, the goal is simple: safeguard the sensitive information DoD shares with the companies that build for it.
On the cybersecurity side, there are two layers. FAR 52.204-21 sets a baseline of 15 security requirements for federal contract information. DFARS 252.204-7012 goes further for covered defense information, which in practice means the Controlled Unclassified Information (CUI) tied to your contract. To protect Controlled Unclassified Information, DoD requires the 110 controls in NIST Special Publication (SP) 800-171, published by the National Institute of Standards and Technology for nonfederal information systems and organizations, meaning a contractor’s own IT environment, not a government-owned system. The controls focus on the confidentiality of CUI. GAO notes DoD has required those 110 requirements since 2016.
So DFARS compliance means four things: implement the controls, document how you did it, report incidents on time, and be ready to show an assessor.
Related Topic: ITAR vs EAR: Which Rules Apply to You?
Any DoD contractor or subcontractor whose contract includes the cybersecurity clause and who handles covered defense information. Contractors and subcontractors must implement the required controls whatever their size. Tier does not change that. What matters is the clause in your contract and the data you actually receive.
The requirement also flows down. Prime contractors must pass the clause along with any covered defense information they share with a subcontractor. That is how a shop three or four tiers down the defense supply chain ends up subject to it.
Scale matters here too. GAO’s March 2026 report says DoD relies on approximately 200,000 defense industrial base (DIB) companies, and roughly three-quarters of them are small businesses. The cybersecurity requirements apply to any of them that handle federal contract information or CUI, whether they are a large prime or a 20-person machine shop.
We recently spoke with a fabricator, a third- or fourth-tier shop, that wanted to know whether it was covered. The answer did not depend on its tier. It depended on whether the shop actually receives CUI under a contract that carries the clause. If it does not, the cybersecurity requirements are not the right starting point. If it does, they apply no matter how small the shop is.
One real exception: the clauses do not apply to contracts solely for commercial off-the-shelf (COTS) items.
A lot of good manufacturers are in this same spot. The requirement arrived as contract language, not as a letter, and plenty of shops are technically subject to it without realizing.
Related Topic: What Is DFARS 252.204-7012? Requirements, Compliance & CMMC?
None. DFARS is a set of acquisition regulations that apply to contractors and contracts, not to countries. Nobody holds a “DFARS compliant” status the way a company might hold a certification.
The question usually comes from a different part of DFARS: Part 225, on foreign acquisition. Its specialty metals clause (252.225-7009) requires specialty metals in delivered items to be melted or produced in the United States, its outlying areas, or a “qualifying country,” a term DFARS defines in section 225.003. That is why metals suppliers sometimes call a material “DFARS compliant.”
That is a sourcing and country-of-origin rule, and it is separate from the cybersecurity clauses in this guide. If sourcing is your question, read the regulation text for the current qualifying-country list rather than relying on a copied one. Lists like that go out of date.
Related Topic: ITAR Compliance: Requirements & Cybersecurity
The cybersecurity side of DFARS runs through four clauses that work in sequence: protect the data, score yourself, allow verification, and get certified.
DFARS 252.204-7012 (protect data)
The foundation. It requires adequate security for covered defense information. DoD contractors must implement NIST SP 800-171, report cyber incidents within 72 hours, and use cloud services that meet the required security standard. We cover the clause in detail in our guide to DFARS 252.204-7012.
DFARS 252.204-7019 (score yourself)
Before award, you need a current NIST SP 800-171 assessment on record, with a summary score posted in the DoD’s Supplier Performance Risk System (SPRS). This came in through an interim rule effective November 30, 2020.
DFARS 252.204-7020 (allow verification)
DoD can access your facilities, systems, and personnel to verify that assessment, and the requirement flows down to your subcontractors. Both of these clauses get a full breakdown in our guide to DFARS 7019 and 7020.
DFARS 252.204-7021 (get certified)
This is the clause that writes Cybersecurity Maturity Model Certification (CMMC) requirements into contracts. It took effect November 10, 2025.
People mix these up because both show up in the same conversations with primes. They are different rules from different agencies.
DFARS is a set of Department of Defense contract clauses. It applies to you because of what is written in your contract. ITAR, the International Traffic in Arms Regulations, is a State Department export control regime. It applies to you because of what you make or handle, whether or not a particular DoD contract mentions it.
| DFARS (cybersecurity clauses) | ITAR | |
| What it is | Department of Defense contract clauses | State Department export control regulations |
| Applies to you because of | The clauses in your contract | What you make, handle, or export |
| Main concern | Protecting covered defense information and reporting incidents | Controlling who can access defense articles and technical data |
| How you show compliance | NIST SP 800-171 implementation, an SPRS score, and increasingly CMMC | DDTC registration, licenses, and your own internal compliance program |
They overlap in one important place. ITAR technical data is generally also treated as CUI, so DFARS governs how you protect it on your systems, while ITAR adds limits on who may access it, including foreign persons. A shop handling both has to satisfy both. We break down the export control side in our guide to ITAR vs. EAR.
Related Topic: Is Your Business Ready for SOC 2? | What a Readiness Assessment Reveals
Becoming DFARS compliant is a sequence, not a single project. To meet DFARS requirements, you do not need to fix everything at once. You do need to know where you stand, what matters first, and a plan that does not disrupt production. In order:
Check each contract and flow-down for the cybersecurity clauses, and note which ones carry covered defense information.
Email, shared drives, CAD/CAM files, customer drawings, vendor portals, USB drives. You cannot protect what you have not mapped. Scoping is also a decision: one six-person defense contractor we have spoken with isolated its limited CUI in a separate cloud-based enclave, away from its commercial network, instead of securing everything. It is not right for every shop, but it shows that scope is something you can shrink.
A gap assessment shows which controls are in place, which are partial, and which are missing.
These document how you meet each control and how you will close the rest.
Start with the highest-impact ones: access control, multi-factor authentication, patching, and endpoint protection.
Make sure the score is one you can defend with evidence.
Build an incident response plan around the 72-hour clock, and confirm that whoever reports holds a DoD-approved medium assurance certificate, which is required to use the DoD’s incident reporting portal. In three separate recent engagements, that certificate turned out to be missing or unverified until someone checked. In one case it surfaced during a tabletop exercise, which is exactly when you want to find out.
Know which subcontractors receive CUI and who owns passing the clauses along. In a recent assessment, ownership of that flow-down was an open action item, and it is a common one.
Reassess on a schedule, update the SSP when the environment changes, and refresh your SPRS score before it expires.
If that feels like a lot for a small shop, there is free help. DoD’s Office of Small Business Programs runs Project Spectrum at no cost, and the NSA’s Cybersecurity Collaboration Center offers no-cost services to DoD contractors. Neither covers everything, but both can take a piece of the work off the table.
Related Topic: SOC 2 Requirements: What Your Business Needs to Know
DFARS 252.204-7012 has been a contract requirement for years. CMMC does not replace it. CMMC, through DFARS 252.204-7021, adds a verification layer on top. Under the streamlined CMMC 2.0 framework finalized in 32 CFR Part 170, NIST 800-171 compliance is the baseline for Level 2, but instead of relying only on self-reported scores, DoD requires proof, and for many contracts that proof comes from a third-party assessment.
The timing is where shops get confused. CMMC’s third-party assessment phase is currently paused. The DFARS obligations are not. Your contract clauses, your 110-control requirement, and your 72-hour reporting duty did not pause with it. We track where the rollout stands in our CMMC compliance timeline guide.
One more detail worth knowing: NIST published Revision 3 of SP 800-171 in 2024, but per GAO’s March 2026 report, DoD has not yet updated CMMC to use it. Build to Revision 2 today and keep an eye on the transition.
If you cannot say with confidence which clauses apply to you, where your CUI lives, and what your SPRS score would be today, that is the place to start. Our team works with manufacturers in the DoD supply chain on exactly this, and our DFARS compliance work starts with a clear picture of where you stand and what to fix first.
Schedule a free consultation with our team to find out where you stand against the DFARS requirements.
Related Topic: Build a Stronger Vulnerability Management Program
DFARS stands for the Defense Federal Acquisition Regulation Supplement. It is the Department of Defense’s supplement to the Federal Acquisition Regulation (FAR), adding the rules specific to defense contracts.
The FAR governs how all federal agencies buy goods and services. DFARS adds the Department of Defense’s own requirements on top. For cybersecurity, FAR 52.204-21 sets a 15-requirement baseline for federal contract information, while DFARS 252.204-7012 requires the 110 controls in NIST SP 800-171 for covered defense information.
Generally no. The cybersecurity clauses do not apply to contracts solely for commercial off-the-shelf items. If your contract involves anything beyond COTS and you handle covered defense information, assume the clauses apply until you have confirmed otherwise.
It depends on how much of the 110-control framework your business already satisfies, and on how much of your environment is in scope. The cost drivers overlap heavily with CMMC, so rather than a generic number, see our breakdown in How Much Does a CMMC Audit Actually Cost? A gap assessment against your actual environment is the only way to get an estimate that reflects your starting point.
Yes, and many do. The practical routes are shrinking the scope by isolating CUI in a dedicated environment, working with a managed IT and compliance provider, and using DoD’s no-cost small business resources. What matters is that every control has a named owner and evidence behind it.
DFARS compliance means meeting the cybersecurity and reporting requirements the Defense Federal Acquisition Regulation…
Vulnerability management is the continuous process of finding, prioritizing, fixing, and verifying the security…
A cybersecurity risk assessment is a systematic process of identifying what could go wrong,…