Manufacturing operations face intense competitive pressures, increasingly complex supply chains, and strict compliance requirements like CMMC and ITAR...
Healthcare providers face mounting pressures from ever-evolving technology...
Accounting firms handle sensitive financial data—from tax filings to audit...
Law firms operate under strict confidentiality obligations and face evolving...
Auto dealerships handle a wealth of customer information, from financing details...
In Oil & Gas, uptime, safety, and data integrity are paramount. Whether you’re managing offshore rigs,...
Financial institutions bear a heavy responsibility: they hold sensitive client information and manage...
In the insurance sector, safeguarding sensitive policyholder information is essential—not just to meet...
Auto dealerships handle a wealth of customer information, from financing details...
Small and medium-sized businesses are the backbone of our economy, but they often face...
Manufacturing operations face intense competitive pressures, increasingly complex supply chains, and strict compliance requirements like CMMC and ITAR...
Healthcare providers face mounting pressures from ever-evolving technology...
Accounting firms handle sensitive financial data—from tax filings to audit...
Law firms operate under strict confidentiality obligations and face evolving...
Auto dealerships handle a wealth of customer information, from financing details...
In Oil & Gas, uptime, safety, and data integrity are paramount. Whether you’re managing offshore rigs,...
Financial institutions bear a heavy responsibility: they hold sensitive client information and manage...
In the insurance sector, safeguarding sensitive policyholder information is essential—not just to meet...
Auto dealerships handle a wealth of customer information, from financing details...
Small and medium-sized businesses are the backbone of our economy, but they often face...
DFARS cybersecurity compliance means meeting the specific clauses the Department of Defense (DoD) embeds in a contract through the Defense Federal Acquisition Regulation Supplement primarily DFARS 252.204-7012, which requires implementing NIST SP 800-171, safeguarding covered defense information, and reporting cyber incidents within 72 hours. If your customer’s purchase order references DFARS clauses, these are not suggestions. They are contract terms, and they apply whether or not you ever signed anything directly with the DoD.
A lot of shop owners hear “DFARS” and assume it’s paperwork for somebody else the big prime, the company with the government contracts officer on staff. Then a customer sends over a supplier questionnaire, or a purchase order shows up with a clause number nobody in the office recognizes, and suddenly it’s not somebody else’s paperwork anymore.
Related Topic: What Is a POA&M? Complete Guide for Defense Contractors
The Defense Federal Acquisition Regulation Supplement is the DoD’s own add-on to the Federal Acquisition Regulation the standard rulebook every federal agency uses to buy goods and services. DFARS clauses get written into a prime contractor’s agreement with the DoD. From there, the prime is required to flow those same obligations down to its subcontractors and those subcontractors flow them down again. That’s how these requirements reach every tier of the defense industrial base, not just the companies with a contracts officer on staff. By the time it reaches a 30-person machine shop three tiers removed from the Pentagon, it doesn’t look like a government requirement. It looks like a line item buried in a customer’s terms and conditions.
That’s the part that catches people off guard. You never had to apply for anything. You never signed a DoD contract. But the moment a customer’s purchase order includes DFARS language and you accept the work, you’ve accepted the requirement that comes with it.
Related Topic: FCI vs. CUI: What Every Defense Subcontractor Needs to Know
Everything else in the DFARS cybersecurity conversation sits underneath this one clause. It requires three things:
“Covered defense information” is broader than most owners expect. If a customer’s drawings, technical specs, or program data land in your email inbox, your shared drive, or your ERP system as part of a defense contract, there’s a real chance this clause already applies to you — whether or not anyone ever used the word “CUI” out loud.
Federal Contract Information Is Not the Same Thing as CUI And the Difference Changes Everything You Have to Do
This is where a lot of confusion starts, and it’s worth being precise about it because the practical burden is completely different depending on which one you’re dealing with.
Level 1 under the Cybersecurity Maturity Model Certification (CMMC) program. Roughly half of those controls are about physical security: locked doors, visitor logs, that kind of thing. FCI can travel through your standard business email. It can sit in a normal cloud storage account. It doesn’t require a specialized government-cloud environment. Handling Federal Contract Information under a purchase order like this is often closer to what a shop is already doing than owners expect — a shop running standard business-grade tools with reasonable access control is often most of the way there.
It’s protected by the full 110 requirements in NIST SP 800-171 — officially titled “Protecting Controlled Unclassified Information in Nonfederal Information Systems and Organizations” the same 110 requirements DFARS 252.204-7012 points back to. CUI generally can’t sit in a standard cloud environment. It needs a government-community cloud, tighter access controls, and a documented system security plan behind it.
The practical question isn’t “do we have cybersecurity.” It’s “which one of these are we actually handling, and does our environment match what that one requires.”
Related Topic: Why Passing CMMC Starts With Finding the Gaps First?
Here’s a situation that comes up constantly: a shop is DFARS-compliant and has FCI clearance sorted out, but needs to send technical plans to a subcontractor who isn’t. Maybe it’s a small specialty vendor who’s never heard of CMMC. There’s no public directory to check whether a supplier meets Level 1 — you either take their word for it, ask them to send their self-attestation confirmation, or find another way to share the information without technically handing it over.
One approach that actually works and still satisfies the intent of the DFARS flow-down clause: the requirement to flow down controls is triggered by transferring *ownership* of the document, not by someone simply viewing it. If you share a file through OneDrive or SharePoint with view-only permissions no download, no re-sharing, an expiration date on the link the subcontractor can see what they need to do their part of the job without ever taking ownership of the file. You’re not avoiding the requirement. You’re meeting the actual intent of it: the information never leaves your controlled environment, and you can prove that.
It’s not a workaround you invent on the fly during an audit. It’s a documented decision you make ahead of time, with the reasoning written down, so it holds up if a customer or an assessor ever asks how you handled it.
Related Topic: CMMC Enclave vs. Enterprise: Which Compliance Model Works Best?
DFARS 252.204-7019 requires SPRS assessment submissions, while DFARS 252.204-7020 requires prime contractors to ensure subcontractor compliance before awards.
Here’s what that looks like in practice, and it’s not what most owners picture. The SPRS score range runs from a perfect 110 down to negative 203. Plenty of shops start deep in negative territory — a starting score in the negative hundreds is common, not alarming, for a shop that’s early in the process. The requirement isn’t that you show up with a perfect score. The requirement is that a current, honest score is in the system, and that you can show a real plan — a Plan of Action and Milestones (POA&M) — for closing what’s left.
That’s an important distinction, especially right now. CMMC Phase II third-party certification has been temporarily suspended, but DFARS 7019’s requirement to submit a current NIST 800-171 self-assessment score was never part of that pause. It’s a standing DFARS obligation that exists independent of where CMMC certification stands. Contractors who read the Phase II suspension as “compliance is on hold” are working from the wrong assumption.
Related Topic: Why Every Business Needs an IT Risk Assessment?
Submitting an inaccurate SPRS score, or attesting to security controls you haven’t actually implemented, isn’t a paperwork slip it’s cybersecurity misrepresentation, and the Department of Justice has pursued exactly these cases under the False Claims Act.
In December 2025, an Illinois precision machining supplier agreed to pay $421,234 to resolve allegations that it failed to provide adequate cybersecurity for technical drawings it supplied to DoD prime contractors — a DFARS 252.204-7012 case in the exact same trade as a lot of the shops reading this, brought forward by a former quality-control manager under the whistleblower provisions of the False Claims Act. The annual affirmation of compliance tied to CMMC self-assessments means a specific person at your company is personally on the hook for that attestation being accurate.
This is exactly why a negative starting score isn’t the problem. Non-compliance with DFARS in the form of an inaccurate score is. If your environment doesn’t match what you’ve told the government, that gap is where real legal exposure lives — regardless of whether Phase II certification is active, paused, or years away for your business.
Related Topic: Why Your Small Business Network Setup Matters More Than You Think?
DFARS 252.204-7021 is the clause that makes CMMC certification a contractual requirement rather than an aspiration. When a contract includes 7021, achieving and maintaining the applicable CMMC level becomes a condition of doing the work not a nice-to-have.
Understanding how these clauses connect matters more than memorizing any one of them. 7012 sets the underlying obligation. 7019 and 7020 require you to prove where you stand. 7021 is the mechanism that turns CMMC into a contract term. Treating these as four separate compliance conversations is how shops end up with gaps between what they’ve done and what their contract actually requires.
If defense-related drawings, technical data, or contract information already come through your shop, the question isn’t whether DFARS cybersecurity requirements apply. It’s whether your current environment actually meets them and whether what you’ve told the government about your environment is accurate.
Start with a conversation, not a project plan. A CMMC-certified team can walk through what you’re actually handling, where your current setup stands against it, and what to fix first without assuming you need to rebuild everything at once.
Related Topic: Windows 10 ESU Cost: What Delaying Your Upgrade Will Really Cost
DFARS 252.204-7012 requires contractors to implement NIST SP 800-171, report cyber incidents within 72 hours, and preserve system evidence.
DFARS 7019 requires SPRS assessment submissions, while DFARS 7020 requires prime contractors to verify subcontractor compliance before contract awards.
No. Contractors must still maintain SPRS scores, implement NIST SP 800-171 controls, and meet DFARS incident-reporting requirements.
No. DFARS establishes cybersecurity requirements, while CMMC verifies contractor compliance through formal assessments and certification.
FCI requires basic safeguards, while CUI demands all 110 NIST SP 800-171 controls and stronger security protections.
DFARS cybersecurity compliance means meeting the specific clauses the Department of Defense (DoD) embeds…
A POA&M — Plan of Action and Milestones — is the document that lists…
FCI vs. CUI: What the Difference Actually Means for Your Subcontractors Federal Contract Information (FCI)…