By The Defense Compliance Report Editorial Team
Bottom line: CMMC vs DFARS is not a choice between two versions of the same requirement. The CMMC status specified in a solicitation addresses DFARS 252.204-7021. It does not separately prove performance of every incident-reporting, cloud, evidence-preservation, government-access, and subcontractor duty in DFARS 252.204-7012.
Implementation status verified August 24, 2026: Phase 1 began November 10, 2025. Under the original schedule, it ran through November 9, 2026 and Phase 2 would have begun November 10, 2026. DoD suspended the move to Phase 2 and later phases in July 2026; Phase 1 requirements remain active, and the action did not remove existing DFARS 252.204-7012 contract duties. DoD CMMC implementation updates
Independent educational resource: The Defense Compliance Report is not affiliated with or endorsed by the U.S. Department of Defense or The Cyber AB. This article is educational and is not legal, contractual, or compliance advice. Sponsored, affiliate, or referral relationships are labeled where they appear.
Controlling CMMC version: CMMC Level 2 currently uses all 110 requirements in NIST SP 800-171 Rev. 2 across 14 families. NIST SP 800-171 Rev. 3 does not become the CMMC-controlling version unless DoD amends the governing requirements. CMMC Level 3 adds 24 selected requirements from NIST SP 800-172.
CMMC vs DFARS: which clause does what?
| Clause | What it controls | The proof a contractor should retain |
|---|---|---|
| DFARS 252.204-7012 | Operational safeguarding, cyber-incident reporting, evidence preservation, external-cloud, government-access, and subcontract duties when the clause applies | Procedures plus event-by-event records showing the duty was performed |
| DFARS 252.204-7019 | Pre-award verification that a current NIST SP 800-171 DoD Assessment summary score is posted in SPRS when required | Current SPRS assessment record for each covered contractor information system subject to the clause |
| DFARS 252.204-7020 | DoD assessment access and specified subcontractor assessment/flowdown conditions | Assessment access, required SPRS records, and subcontract administration evidence |
| DFARS 252.204-7021 | The CMMC level/status, continuing maintenance, affirmation, and flowdown required by the solicitation or contract | Current CMMC status and required affirmations |
An SPRS score is not a CMMC status. A CMMC status is not a DIBNet incident report. Neither replaces the operating evidence DFARS 252.204-7012 creates when an incident, cloud decision, government request, or subcontract action occurs.
CMMC vs DFARS 7012: What Each One Actually Requires
By The Defense Compliance Report Editorial Team Last reviewed: August 2026 · Clause text verified August 24, 2026
CMMC and DFARS 7012 are not two names for the same requirement, and they are not alternatives. DFARS 252.204-7012 is the contract clause that creates the obligations. CMMC is the program that verifies one of them. The clause runs from paragraph (a) to paragraph (m). A CMMC assessment scores the security-controls paragraph. That's it.
Here's the part that should make you sit up: we read every operative paragraph of the live clause on Acquisition.gov and mapped it against what a CMMC assessment actually examines. Ten separate duties in DFARS 252.204-7012 are not NIST SP 800-171 requirements and are not separately scored as a DFARS 252.204-7012 contractual duty in a CMMC assessment — the 72-hour reporting clock, the malware submission to the DoD Cyber Crime Center, the 90-day forensic evidence hold, the unaltered flow-down, and six more. If your company "did CMMC" and closed the file, you almost certainly have uncovered contractual exposure sitting in an active contract right now.
We'll show you all ten in a table you can check against the clause yourself. We'll also show you four places where the clause text on Acquisition.gov and the regulation that actually governs say different things — including one that could be costing you about $175 a year for a credential the government stopped requiring in 2024.
What changes the answer for you specifically: whether your contract contains 7012, 7021, 7025, all of them, or none; whether you handle Federal Contract Information (FCI) or Controlled Unclassified Information (CUI); and whether a post-July-13 modification has actually issued against your award. The clause in your contract governs. A press release does not.
The four-layer stack, on one screen
Most explainers give you two boxes: "DFARS is the rulebook, CMMC is the referee." That's directionally fine and operationally useless, because it hides two of the four authorities that can create a duty for you. Here is the whole stack.
The DoD cybersecurity authority stack — verified August 24, 2026
| Layer Authority What it creates Did July 13, 2026 change it? | |||
|---|---|---|---|
| 1. The operational duties | DFARS 252.204-7012 — "Safeguarding Covered Defense Information and Cyber Incident Reporting," clause version MAY 2024 | Safeguard Covered Defense Information (CDI), implement NIST SP 800-171, report incidents within 72 hours, submit malware, preserve evidence, cooperate with forensics, flow it down | No. Untouched. |
| 2. The reporting procedures | 32 CFR Part 236 — DoD DIB Cybersecurity Activities | How mandatory incident reporting actually works: the account you need, who may file on your behalf, and which agreement types the duty reaches | No. Untouched — and almost nobody covers this layer. |
| 3. The verification program | 32 CFR Part 170 — the CMMC Program Rule, effective December 16, 2024 | The three CMMC levels, assessment types, scoring, POA&M rules, statuses, and affirmations | No. The rule was not amended. |
| 4. The contract implementation | DFARS 252.204-7025 (solicitation provision) and DFARS 252.204-7021 (contract clause), effective November 10, 2025 | Which CMMC level you must hold before award, and the duty to maintain that status during performance | Yes. New designations are presently limited to Level 1 (Self) and Level 2 (Self). |
Read that table twice. Layer 1 and Layer 2 have not moved since 2017 and 2024 respectively. Layer 4 is the one that got paused. Almost every "is CMMC dead?" conversation happening in the DIB right now is a conversation about Layer 4 that people mistakenly believe is about Layer 1.
Who this page is for — and who should leave
We'd rather lose you now than waste twenty minutes of your time.
| Read this if you… Skip this if you… | |
|---|---|
| Found both terms in the same solicitation and can't tell how they relate | Want the clause explained paragraph by paragraph — that's our DFARS 252.204-7012 explainer, and it's more detailed than this page |
| Have a CMMC status and want to know what it does not cover | Need Level 2 pricing — see the CMMC Level 2 cost guide |
| Are deciding what to keep funding after the July 2026 pause | Are already assessment-ready and shopping for an assessor — see self-assessment vs C3PAO |
| Are a subcontractor holding a prime's flow-down and want to know which one it is | Handle only FCI and never touch CUI. Almost nothing here applies to you. Go to the CMMC Level 1 walkthrough instead. |
The Defense Compliance Report is the independent trade publication and decision resource for CMMC and Defense Industrial Base compliance — explaining the CMMC Final Rule with primary-source citation on every claim and mapping a contractor's level, CUI scope, assessment type, and timeline to the right provider category, so DIB contractors choose the right CMMC path before they spend six figures.
We are not affiliated with the Cyber AB, the Department of Defense, DCMA DIBCAC, NIST, or any U.S. government agency.
What is the difference between CMMC and DFARS 7012?
Answer capsule: DFARS 252.204-7012 is a Department of Defense contract clause that requires contractors to safeguard Covered Defense Information using NIST SP 800-171 and to report cyber incidents to DoD within 72 hours of discovery. CMMC is a separate assessment program, codified at 32 CFR Part 170, that verifies implementation of applicable FCI or CUI safeguards and reaches contracts through DFARS 252.204-7025 and 252.204-7021. Neither replaces the other.
The clean way to hold it in your head: 7012 is a duty. CMMC is a check on part of that duty.
DFARS stands for the Defense Federal Acquisition Regulation Supplement — DoD's add-on to the government-wide Federal Acquisition Regulation. When a contracting officer inserts 252.204-7012 into your contract, every obligation in it becomes binding the day you sign. No assessment required, no certificate involved, no phase-in. The clause has been standard in DoD contracts since the mid-2010s, and full NIST SP 800-171 implementation was due by December 31, 2017.
CMMC — the Cybersecurity Maturity Model Certification — arrived much later and does a narrower job. Under 32 CFR § 170.5, the CMMC Program does not alter existing FCI or CUI protection requirements. It provides a mechanism to verify them. The rule's own framing is the whole point: CMMC didn't invent new security rules. It put a check on old ones.
That distinction has been academic for most of CMMC's life. On July 13, 2026, it stopped being academic, because the check got paused and the duty didn't.
The mnemonic everyone repeats, and why it's incomplete
You've seen this on five different vendor blogs: "DFARS tells you what to do, NIST tells you how, and CMMC proves you did it."
It's a decent starter. It's also incomplete in a way that costs money, because it implies CMMC proves you did all of it. It doesn't. It proves you implemented the 110 security requirements in NIST SP 800-171 Revision 2 — organized into 14 control families — within a defined assessment scope. The other ten duties in the clause are operational, they sit outside the control set, and no assessor at any level is looking at them.
That's the next section, and it's the reason this page exists.
Which DFARS 7012 duties does a CMMC assessment actually verify?
Answer capsule: A CMMC Level 2 assessment scores the 110 NIST SP 800-171 Revision 2 security requirements against the assessment objectives in NIST SP 800-171A. Ten operative duties in DFARS 252.204-7012 — including the 72-hour incident report to DIBNet, malware submission to the DoD Cyber Crime Center, a 90-day evidence preservation window, and unaltered subcontract flow-down — are not NIST SP 800-171 requirements and are not scored at any CMMC level.
This is our original analysis, and we want you to be able to check it rather than take our word for it. We read the live clause at Acquisition.gov on August 24, 2026 (version MAY 2024, current under DFARS Change 5/7/2026), pulled every operative duty, and asked one question of each: does a CMMC assessment look at this?
To answer that fairly you have to know what a CMMC assessment examines. Under 32 CFR Part 170, a Level 2 assessment evaluates the 110 requirements in NIST SP 800-171 Revision 2. The Incident Response family contains exactly three of them:
- 3.6.1 — establish an operational incident-handling capability covering preparation, detection, analysis, containment, recovery, and user response.
- 3.6.2 — track, document, and report incidents to designated officials and authorities, internal and external.
- 3.6.3 — test the incident response capability.
Read 3.6.2 carefully. It says report to authorities. It does not say 72 hours. It does not say DIBNet. It does not name the DoD Cyber Crime Center. It sets no evidence-retention floor. That gap between "have a reporting capability" and "can execute this specific contractual chain under a hard clock" is where the exposure lives.
The DFARS 7012 Coverage Map
Verified August 24, 2026 against DFARS 252.204-7012 (MAY 2024) and NIST SP 800-171 Rev. 2
| # The duty Clause In NIST SP 800-171 Rev. 2? Scored in a CMMC assessment? | ||||
|---|---|---|---|---|
| — | Implement NIST SP 800-171 on covered systems | (b)(2)(i) | Yes — this is the 110 | Yes. This is what CMMC Level 2 scores. |
| — | External cloud handling CDI must meet FedRAMP Moderate–equivalent security | (b)(2)(ii)(D) | No — clause-level, not a control | Partly. Cloud service providers enter CMMC scope under 32 CFR § 170.19. The pass-through obligation to comply with paragraphs (c)–(g) does not. |
| 1 | Review for evidence of compromise across affected and adjacent systems | (c)(1)(i) | Partly — 3.6.1 requires the capability | No. The capability is scored. This specific review scope is not. |
| 2 | Report to DIBNet within 72 hours of discovery | (c)(1)(ii) | No. Rev. 2 sets no clock and names no portal. | No |
| 3 | Report must contain DoD's required elements | (c)(2) | No | No |
| 4 | Hold the credential needed to file the report | (c)(3) | No | No — and see the next section; the clause is out of date here |
| 5 | Submit isolated malicious software to the DoD Cyber Crime Center (DC3) — not to the contracting officer | (d) | No | No |
| 6 | Preserve system images and monitoring/packet-capture data for at least 90 days from report submission | (e) | No. No Rev. 2 requirement sets a forensic retention floor. | No |
| 7 | Provide DoD access to additional information or equipment for forensic analysis | (f) | No | No |
| 8 | Provide damage-assessment information if DoD elects to conduct one | (g) | No | No |
| 9 | Flow the clause down unaltered in subcontracts involving CDI or operationally critical support — including commercial products and services | (m)(1) | No — CMMC has a separate flow-down at DFARS 252.204-7021(f) | No |
| 10 | Require subcontractors to pass the DoD-assigned incident report number up the chain | (m)(2)(ii) | No | No |
Coverage assessment is our editorial analysis, derived from the clause text and the NIST SP 800-171 Rev. 2 control set. The clause and control citations are primary-source verified.
The honest nuance, because it matters
We're not going to overstate this. An assessor examining 3.6.2 will very likely ask who you report to externally, and a well-built System Security Plan will name DIBNet in that answer. So these duties get touched during an assessment.
Touched is not verified. A CMMC assessor is not testing whether you can file inside 72 hours, whether your PIEE access works, whether your log retention actually reaches 90 days, or whether the clause made it into your subcontracts unaltered. Passing an assessment is evidence that your controls exist. It is not evidence that your contract obligations are operational.
The practical translation: a Certificate of CMMC Status is not a defense to a 7012 failure. They're answering different questions.
Find out which of these ten duties has no owner at your company
Our DFARS 7012 Coverage Gap Check asks eight questions about your clause set, your logging, your cloud terms, and your subcontracts — then returns a dated, clause-cited memo naming every duty you currently can't demonstrate. Free, no email required, runs entirely in your browser.
[ Run the 7012 Coverage Gap Check → ]
Do not enter CUI, drawings, contract numbers, or system details.
The right provider isn't the same for every contractor
The right CMMC provider isn't the same for every contractor — the category you need (a C3PAO, an RPO, an MSSP, a GRC platform, or a CUI enclave) depends on your required CMMC level, whether you handle FCI or CUI, your assessment type, your cloud and IT environment, and your contract timeline. The contract clause sets your level, not a checklist. Because a general answer can't resolve those for you, use The Defense Compliance Report's Find My CMMC Path tool to map your situation to the right provider category before you request quotes — and do not submit CUI, drawings, or sensitive contract details.
For the record on vocabulary, since these get used loosely and the differences are expensive: a C3PAO is a CMMC Third-Party Assessment Organization, authorized to conduct official Level 2 certification assessments. An RPO is a Registered Provider Organization and an RP is a Registered Practitioner — the Cyber AB's categories for consultants who help you prepare. An MSSP is a Managed Security Service Provider. A GRC platform is governance, risk, and compliance software that manages evidence. A CUI enclave is a contained environment built to shrink what's in scope. They are not interchangeable, and the independence rules mean one firm generally cannot both remediate you and certify you.
Is DFARS 7012 still in effect after the CMMC Phase II suspension?
Answer capsule: Yes. On July 13, 2026, the Department of War suspended the CMMC Phase II transition and all later implementation milestones. The implementation guidance issued the same day states that DFARS 252.204-7012 requirements remain in effect. The suspension paused a verification milestone through policy memoranda; it did not amend 32 CFR Part 170, the DFARS, or any contract clause.
Here is what was actually suspended, and what wasn't. We read the implementation memorandum directly.
Suspended:
- The Phase II transition, originally scheduled for November 10, 2026, which would have made third-party certification by a C3PAO a condition of award on contracts involving CUI.
- All pending and future CMMC implementation milestones, which pulls Phases 3 and 4 in as well.
- New procurement designations of Level 2 (C3PAO) and Level 3 (DIBCAC). During the suspension, program managers may designate only CMMC Level 1 (Self) or CMMC Level 2 (Self).
Not suspended:
- DFARS 252.204-7012. Every duty in the Coverage Map above.
- Phase I Level 1 and Level 2 self-assessment requirements where they're already designated.
- NIST SP 800-171 Revision 2 as the Level 2 baseline.
- SPRS postings and annual affirmations.
- Select government-led assessments, which the memorandum expressly preserves.
- The CMMC Program Rule at 32 CFR Part 170, which was not amended.
A CMMC Reform Task Force was directed to report to the Department CIO within 60 days, putting its report in the mid-September 2026 window. As of August 24, 2026, no report and no replacement Phase II date have been published.
The distinction that decides your next move
A memorandum directs government contracting officers. A clause binds you.
The implementation guidance directs contracting activities to amend active solicitations and to remove paused assessment requirements from existing contracts through modification — before the next option exercise or during the next scheduled administrative modification. That is a direction to the government, on the government's timeline.
Until the modification actually issues, the clause on your contract is the clause on your contract. Do not treat a press release as a contract modification. And do not silently ignore a solicitation that still says Level 2 (C3PAO) — ask for the amendment in writing. We give you the letter further down.
For the full timeline, the memoranda, and what each one says, see our CMMC Phase II suspension analysis. This page keeps its lane.
The uncomfortable part, and we'll say it against our own interest
We route CMMC provider inquiries. This site makes money when readers ask to be matched with providers. So take this in that context:
If your contract contains DFARS 252.204-7012 but no CMMC clause, a CMMC certificate buys you nothing at award today. No contracting officer is checking for a status you weren't asked to hold. During the suspension, no new DoD requirement can even designate a C3PAO assessment. You would be paying five or six figures to verify a requirement nobody asked you to verify.
We are telling you not to buy that.
Here's the pivot, and it's the more useful half. What you do owe in that situation is everything in the Coverage Map — the reporting chain, the evidence hold, the cloud terms, the flow-down. That work is real, it's binding, it's been binding since 2017, and it is a fundamentally different and usually far cheaper project than a certification assessment. It's readiness and operations, not audit.
That's good news dressed as bad news. The expensive thing is paused. The necessary thing is smaller than you feared, and you can start it this week without a purchase order.
See exactly what the 110 requirements expect before you spend anything
Our NIST SP 800-171 Readiness Checklist maps all 110 requirements across the 14 control families to the evidence each one expects — plus the 7012 operational items that sit outside the control set entirely. It's the artifact we'd want on the table before any vendor conversation.
[ Open the readiness checklist → ]
Four places where the clause text and the rule disagree
Answer capsule: The text of DFARS 252.204-7012 on Acquisition.gov is not, by itself, a complete statement of what governs a contractor today. In four specific areas — the NIST revision, the credential required to file an incident report, who may file it, and which agreement types the reporting duty reaches — a class deviation or 32 CFR Part 236 controls instead. Reading the clause alone produces wrong answers in all four.
This is the section we could not find anywhere else, and it explains most of the bad advice circulating on this topic. The clause is the starting point, not the finish line.
Verified August 24, 2026
| What the clause text says What actually governs today Primary source | ||
|---|---|---|
| The NIST version. Paragraph (b)(2)(i) points to the version of NIST SP 800-171 in effect when the solicitation was issued, or as the contracting officer authorizes. | Revision 2 is pinned. A DoD class deviation issued May 2, 2024 requires NIST SP 800-171 Revision 2 rather than the version in effect at solicitation, and adds a FedRAMP Moderate requirement. It remains in effect until rescinded. CMMC Level 2 is separately mapped to Revision 2 at 32 CFR § 170.14. | Class Deviation 2024-O0013 Rev. 1, DoD Defense Pricing and Contracting; 32 CFR § 170.14 |
| The reporting credential. Paragraph (c)(3) says the contractor or subcontractor must have or acquire a DoD-approved medium assurance certificate to report cyber incidents. | A PIEE account is the requirement. 32 CFR § 236.4(e) requires a Procurement Integrated Enterprise Environment account to access dibnet.dod.mil. In the final rule adopting that change, DoD stated it was removing the medium assurance certificate requirement and replacing it with PIEE registration — expressly to eliminate a cost DoD put at roughly $175 annually. Certificates are still accepted. Effective April 11, 2024. | 32 CFR § 236.4(e); 89 FR 17741 (March 12, 2024) |
| Who may file. The clause is silent on delegation. | Your service provider can file for you. 32 CFR § 236.4(f) provides that a contractor using a third-party service provider for information system security services may authorize that provider to report cyber incidents on the contractor's behalf. | 32 CFR § 236.4(f) |
| How far the duty reaches. The clause rides in contracts and flows down through subcontracts. | The reporting duty reaches every agreement type. 32 CFR § 236.4(a) requires the reporting requirement in all forms of agreement between the government and the contractor — contracts, grants, cooperative agreements, other transaction agreements, technology investment agreements, and any other legal instrument — where CDI resides on covered systems or the contractor provides operationally critical support. | 32 CFR § 236.4(a) |
Two more moving parts, for completeness. First, the neighboring clause numbers changed on February 1, 2026 under DoD Class Deviation 2026-O0025: DFARS 252.204-7019 is no longer used in new deviation-path solicitations, 252.204-7020's mechanics carry forward as DFARS 252.240-7997, and FAR 52.204-21 was renumbered to FAR 52.240-93. DFARS 252.204-7012, 252.204-7008, 252.204-7021, and 252.204-7025 were left unchanged. Second, the clause itself is under active amendment. DFARS Case 2023-D024, "Updates to the Safeguarding Covered Defense Information and Cyber Incident Reporting Clause," would amend 7012 to incorporate references to NIST SP 800-172, harmonize terminology, address international agreements, and streamline the vendor identification process. Its report due date was extended to August 12, 2026, and it remained open on the July 31, 2026 case list.
Why this matters more than it sounds
Two of the most confident, well-trafficked guides on this topic currently tell readers that DFARS 7012 requires NIST SP 800-171 Revision 3. That's what you get when you read paragraph (b)(2)(i) and stop. It is the wrong target, and building a compliance program to Revision 3 right now is a months-long, budget-burning detour away from the standard CMMC actually assesses.
The medium assurance certificate divergence is the one with a dollar figure attached. If your incident response plan still says "obtain an ECA certificate before an incident," you may be renewing a credential the government replaced more than two years ago. Provision PIEE. Keep the certificate if you already have one — DoD still accepts it — but don't buy a new one on the strength of clause text that hasn't been conformed to the rule.
Our editorial read, labeled as such: DFARS Case 2023-D024's "streamline the vendor identification process" language is a plausible fit for exactly this conforming change. We can't confirm that, because the proposed rule hasn't published. Watch the case.
For the full revision picture — every instrument that can obligate a version and what would change it — see our NIST 800-171 Rev. 2 vs Rev. 3 comparison.
What is the 72-hour rule, and does a CMMC status cover it?
Answer capsule: DFARS 252.204-7012 defines "rapidly report" as within 72 hours of discovering a cyber incident, and the report goes to DoD at dibnet.dod.mil — not to the contracting officer. The clock runs from discovery, not from root-cause determination or the end of an investigation. Holding a CMMC status does not satisfy, replace, or excuse this obligation.
Of everything on this page, the 72-hour chain is the duty most likely to catch a well-run compliance program flat-footed. Not because it's hard. Because it's operational, and compliance programs tend to be documentary.
The chain, in the order it actually happens:
- You discover a cyber incident. The clause defines it broadly — actions through computer networks producing a compromise or an actual or potentially adverse effect on a system or the information on it. That word "potentially" is doing real work. You don't wait for confirmed exfiltration.
- You review for evidence of compromise. Paragraph (c)(1)(i) requires you to identify compromised computers, servers, specific data, and user accounts — and to analyze not just the systems in the incident but other systems on your network that may have been reached through it.
- You report within 72 hours at dibnet.dod.mil, with the elements DoD requires.
- You file using a PIEE account — see the divergence table above. Provision it now, while nothing is on fire. The 72 hours does not pause while you complete identity proofing.
- You preserve evidence for at least 90 days from the date you submit the report: images of affected systems, plus relevant monitoring and packet-capture data.
- You submit isolated malware to DC3 — the DoD Cyber Crime Center — per its instructions. The clause is explicit that it does not go to the contracting officer.
- You support forensic access and a damage assessment if DoD asks.
Three things almost nobody tells you
Your MSSP can file for you — but authorize it in writing. 32 CFR § 236.4(f) permits a contractor using a third-party service provider for information system security services to authorize that provider to report on its behalf. Most managed security agreements we've seen don't mention it. If you outsource detection and response, this belongs in the contract, and it's a legitimate buying criterion when you're comparing MSSPs.
Ninety days is not your backup retention. The preservation window covers system images and monitoring or packet-capture data. If your log retention is 30 days — a very common default — paragraph (e) is a gap on your network today regardless of your SPRS score. This is a logging architecture question, not a paperwork question.
Subcontractors report directly. Under 32 CFR § 236.4(a), subcontractors report cyber incidents directly to DoD at dibnet.dod.mil and to the prime, including providing the DoD-assigned incident report number to the next higher tier as soon as practicable. A sub does not route its report through you and wait.
The DoD CIO adjudication that CMMC gives you credit for
Answer capsule: DFARS 252.204-7012 permits a contractor to request, in writing through the contracting officer, that the DoD Chief Information Officer adjudicate a security requirement as not applicable or accept an alternative measure as equally effective. Under 32 CFR § 170.24, a favorable DoD CIO adjudication is assessed as MET in a CMMC assessment — but only if the adjudication is documented in the System Security Plan and the environment has not changed.
Here's the flip side of everything above, and it's the reason we say these two regimes are wired together rather than merely adjacent.
Most contractors treat 7012 as pure obligation and CMMC as pure cost. But 7012 contains a flexibility mechanism, and the CMMC rule expressly imports it.
How the mechanism works. Paragraphs (b)(2)(ii)(B) and (C) let you submit a variance request in writing to the contracting officer for consideration by the DoD CIO. If the CIO adjudicates that a requirement is not applicable to you, or that an alternative security measure you've implemented is equally effective, you need not implement the original requirement. The procedure is documented: under DFARS PGI 204.7303-2, the contracting officer forwards the offeror's explanation of the proposed variance to the DoD CIO for adjudication.
Why it's worth money. 32 CFR § 170.24 provides that where an organization previously received a favorable DoD CIO adjudication under DFARS 252.204-7008 or 252.204-7012 indicating that a requirement is not applicable or that an alternative measure is equally effective, that adjudication must be included in the System Security Plan to receive consideration during an assessment — and a requirement with measures adjudicated equally effective is assessed as MET if there have been no changes in the environment.
Read that again if you have an old adjudication sitting in a folder. A ruling you obtained years ago under the 7012 clause converts directly into assessment credit — if it's in your current SSP. If it's not in the SSP, it does nothing. That's a documentation task, not a remediation project, and we'd start there before spending a dollar on controls.
The limits, stated plainly. This is not a general waiver. It is a per-requirement adjudication, it must be requested through the contracting officer, it must live in the SSP, and it holds only while the environment stays the same. It also does not touch the ten operational duties in the Coverage Map — you cannot get a variance from the 72-hour clock.
Our editorial judgment: this is the single most underused flexibility in the entire DoD cybersecurity regime, and it is a live reason to keep your 7012 documentation current even while third-party verification is suspended.
Does DFARS 7012 require an SPRS score or a CMMC status?
Answer capsule: Not by itself. The text of DFARS 252.204-7012 creates safeguarding and incident-reporting duties; it does not direct a contractor to post a score in the Supplier Performance Risk System or to obtain a CMMC status. Those requirements arise from separate assessment and CMMC provisions — historically DFARS 252.204-7019 and -7020, now DFARS 252.240-7997 where it applies, and CMMC status and annual affirmation duties under 32 CFR Part 170 and DFARS 252.204-7021 and -7025.
These three things travel together in DoD contracts, which is exactly why people collapse them. They are not the same.
What SPRS is: the Supplier Performance Risk System, DoD's system of record for supplier data — including NIST SP 800-171 assessment scores and CMMC statuses. It stores the record. It doesn't create the duty.
Three records people blur, and the distinction matters at award:
- A NIST SP 800-171 self-assessment score is a number computed under the DoD Assessment Methodology. It lives in SPRS.
- A CMMC status is the formal result of a CMMC assessment — Final Level 1 (Self), Conditional or Final Level 2 (Self), Conditional or Final Level 2 (C3PAO), or the Level 3 equivalents.
- An affirmation is a senior official's attestation of continuing compliance, submitted at assessment and annually thereafter.
A posted score is not a status. A status without a current affirmation can lapse. And none of the three is created by 7012.
The practical implication: even though 7012 says nothing about posting, if your contract carries the assessment or CMMC provisions, your SPRS record is what a contracting officer checks. Keep it current, and — this is the part with teeth — keep it true. Full mechanics in our SPRS score guide.
The enforcement point, in one paragraph
We're not going to rebuild the enforcement case list here; our DFARS 252.204-7012 explainer already documents four named DOJ settlements against the specific 7012 paragraphs at issue. One data point belongs on this page, though, because it speaks directly to the suspension question. In June 2026, DOJ announced a $507,144 False Claims Act settlement with LOGZONE Inc. resolving allegations concerning Navy contracts. The company had self-scored 110 — a perfect NIST SP 800-171 result. A later DCMA DIBCAC assessment produced a score of -170. The settlement resolved allegations; there was no determination of liability, and the company did not admit liability.
Both numbers were computed against the same Revision 2 standard. The scale wasn't the problem. The evidence was. That is the whole argument for why self-assessment discipline matters more, not less, now that the third-party layer is paused.
How do CMMC and DFARS 7012 flow down to subcontractors?
Answer capsule: The two flow-downs have different triggers and are not interchangeable. DFARS 252.204-7012 paragraph (m) requires the clause to be included, unaltered except to identify the parties, in subcontracts involving Covered Defense Information or operationally critical support — including subcontracts for commercial products and services. The CMMC flow-down operates separately through DFARS 252.204-7021 and turns on whether subcontract performance involves FCI or CUI.
If you take one thing from this section, take this: relief does not flow downhill.
The July 13 memoranda bind government contracting officers. They do not rewrite the terms of a purchase order your prime issued you in March. A prime's flow-down obligation comes from its own contract and its own risk posture, and plenty of primes are holding steady precisely because their contract risk didn't change on July 13.
Two flow-downs, side by side:
| DFARS 252.204-7012(m) DFARS 252.204-7021 flow-down | ||
|---|---|---|
| Trigger | Subcontract involves CDI or operationally critical support | Subcontract performance involves FCI or CUI |
| What flows | The clause itself, unaltered except to identify the parties | The substance of the CMMC requirement |
| Reaches commercial items? | Yes — expressly including subcontracts for commercial products and services | Per the clause's own terms |
| Changed by July 13, 2026? | No | The designations available to the government changed; your subcontract terms did not change automatically |
| Special duty on the sub | Report incidents directly to DoD and pass the DoD-assigned incident report number up the chain | Hold and maintain the applicable CMMC status |
If you're the sub, ask for four things in writing before you spend anything: the exact clause text being flowed, the required CMMC level and assessment type, identification of whether the information you'll receive is FCI, CUI, or CDI, and confirmation of whether any post-July-13 amendment has issued. A questionnaire is not a clause. We've put the letter below.
Full supply-chain treatment lives in our CMMC flow-down guide and our subcontractor guide.
Does DFARS 7012 reach grants, OTAs, and cooperative agreements?
Answer capsule: The DFARS 252.204-7012 clause itself is a contract clause. The underlying cyber incident reporting requirement is broader: 32 CFR § 236.4(a) requires the reporting obligation to be included in all forms of agreement between the government and a contractor — including grants, cooperative agreements, other transaction agreements, and technology investment agreements — where Covered Defense Information resides on covered contractor information systems or the contractor provides operationally critical support.
Almost nobody covers this, and it's the section that matters most if you're an R&D shop, an SBIR performer, a university-affiliated lab, or a member of an OTA consortium.
The distinction is clean. CMMC is implemented through DFARS clauses. A DFARS clause reaches a DFARS contract. If your instrument isn't a contract, the CMMC clause may never appear in it.
The reporting duty is not limited that way. 32 CFR Part 236 governs mandatory cyber incident reporting as a regulation, and § 236.4(a) directs that the requirement be included in all forms of agreement — with the further instruction that those requirements be identical to the ones in the regulation, whether incorporated by reference or set out expressly.
So the trap is specific and real: an organization performing under an OTA or a cooperative agreement can reasonably conclude that CMMC doesn't apply to it — and be right — while still carrying a mandatory incident reporting obligation it never noticed, because it went looking for a DFARS clause number and the duty didn't arrive as one.
One more primary-source line worth putting on your wall. In the same rulemaking, DoD estimated the maximum number of defense contractors subject to mandatory cyber incident reporting under DFARS 252.204-7012 at 80,000 — and stated plainly that the presence of the clause in a contract does not establish that covered defense information is shared.
That second half is the most useful scoping sentence in federal cyber policy, and we've never seen a competitor quote it. Finding 7012 in your contract is the beginning of a scoping analysis, not the end of one. Document your data-flow reasoning, then get written confirmation from the prime or contracting officer about whether performance actually involves CDI. That email is cheap. Guessing is not.
Which clauses are actually in your contract?
Answer capsule: A contractor's obligations are determined by the clauses incorporated into its specific solicitation, contract, order, or subcontract — not by general guidance. Searching the document set for six clause numbers, and then requesting written clarification on anything ambiguous, resolves the question faster and more defensibly than any checklist.
Stop reading guidance. Open the PDF. Search for six strings.
| Search string If you find it What it means | ||
|---|---|---|
252.204-7012 | The safeguarding and incident-reporting clause is in your contract | Every duty in the Coverage Map applies where CDI is in play |
252.204-7008 | The companion solicitation provision | You represented compliance with the 7012 controls when you offered |
252.204-7021 | The CMMC contract clause | You must hold and maintain a CMMC status during performance |
252.204-7025 | The CMMC solicitation provision | A CMMC level is a condition of award — check which one is inserted |
252.240-7997 | The post–February 2026 government assessment clause | Medium and High assessments, government-performed |
52.240-93 (or 52.204-21) | Basic safeguarding of FCI | The 15 requirements behind CMMC Level 1 |
Then check the places clauses hide: Section I of the contract, incorporation-by-reference lists, solicitation provisions, attachments, task and delivery orders, every modification, and — if you're a sub — the flow-down matrix attached to the purchase order.
Letter 1 — to your contracting officer
Subject: Request for confirmation of cybersecurity clause requirements — [Contract/Solicitation No.]
Reference is made to [contract/solicitation number]. So that we may accurately scope our safeguarding and reporting obligations, we respectfully request written confirmation of the following as of today's date:
- Which cybersecurity provisions and clauses are incorporated into this instrument, specifically DFARS 252.204-7008, 252.204-7012, 252.204-7021, 252.204-7025, and 252.240-7997.
- The CMMC level and assessment type, if any, currently required.
- Whether contract performance is expected to involve Federal Contract Information, Controlled Unclassified Information, or Covered Defense Information, and any applicable marking or handling instructions.
- Whether any amendment or modification has issued, or is planned, following the July 13, 2026 suspension of the CMMC Phase II transition, with respect to any Level 2 (C3PAO) or Level 3 (DIBCAC) requirement identified in this instrument.
We are prepared to proceed on the requirements as written and are seeking confirmation solely to align our compliance scope. Thank you.
Letter 2 — to your prime
Subject: Clarification of cybersecurity flow-down — [Subcontract/PO No.]
To support accurate scoping of our cybersecurity obligations under [subcontract/PO number], we request written confirmation of the following:
- Whether DFARS 252.204-7012 is flowed to this subcontract, and the exact clause text incorporated.
- Whether a CMMC requirement is flowed, the specific level and assessment type, and the clause or contractual provision creating it.
- What information will be furnished to or generated by us in performance, and whether it constitutes FCI, CUI, or Covered Defense Information, including applicable markings.
- Whether your position on any Level 2 (C3PAO) or Level 3 requirement has changed following the July 13, 2026 suspension of the CMMC Phase II transition.
- The date by which any required status must be in place, and the consequence under the subcontract if it is not.
We are not asking to reduce a requirement — we are asking to scope it correctly so we can meet it.
Copy them, change the brackets, send them. That's the fastest, cheapest risk reduction available to you today, and it costs nothing.
Which requirement applies to me right now?
Answer capsule: The answer depends on which clauses appear in the live document set and what information the work actually involves. DFARS 252.204-7012 creates its own safeguarding and reporting duties wherever it appears and CDI is in play. A CMMC status requirement arises separately through DFARS 252.204-7025 before award and DFARS 252.204-7021 during performance.
Verified against the clause set as of August 24, 2026
| What you find What it means Your next move | ||
|---|---|---|
| 7012 present, CDI in play | Safeguarding, reporting, preservation, and flow-down duties are active now | Work the Coverage Map. Confirm PIEE access and log retention first — they're the fastest gaps to close. |
| 7012 present, no CDI expected | Scope question, not a compliance project | Document your data-flow reasoning and send Letter 1. Don't ignore the clause; don't invent CUI either. |
| 7025 present, Level 1 (Self) | FCI-only pathway | Confirm the 15 basic safeguarding requirements and your SPRS record. Start at our Level 1 checklist. |
| 7025 present, Level 2 (Self) | The 110 Revision 2 requirements, self-assessed | Confirm scope, score, status, and affirmation. Readiness help, not an assessor. |
| Level 2 (C3PAO) or Level 3 in a post-July-13 solicitation | Conflicts with current implementation guidance | Send Letter 1 and request the amendment. Do not assume it's void; do not assume it stands. |
| Level 2 (C3PAO) in an existing contract | Guidance directs removal by modification, on the government's schedule | Request the modification in writing. Until it issues, the clause stands. |
| Prime questionnaire, no clause located | A questionnaire is not a contractual requirement | Send Letter 2. Ask which clause creates the ask. |
| Grant, OTA, or cooperative agreement | CMMC may genuinely not apply — the reporting duty may still | Check 32 CFR § 236.4(a) against your instrument's terms |
| No documents in hand | No reliable answer exists yet | Get the documents. Everything else is guessing. |
Which provider category do you actually need?
Answer capsule: The 110 security requirements are a readiness problem. The 72-hour reporting chain is an operations problem. Subcontract flow-down is a contracts problem. These map to different provider categories, and purchasing a certification assessment does not resolve either of the other two.
This is where the money gets wasted, and it's almost always a sequencing error rather than a vendor-quality error.
| Your situation Category to look at first What it is not the right first move for | ||
|---|---|---|
| You don't know your CDI/CUI scope or which clauses bind you | RP/RPO (Registered Practitioner / Registered Provider Organization), or a vCISO | Hiring a C3PAO |
| You know the scope; the controls and evidence aren't there | RPO or readiness provider, paired with implementation | Buying GRC software and calling it done |
| Your systems can't support the controls; detection and response are thin | MSSP or a CMMC-focused managed IT provider | Assuming your general-purpose IT vendor understands 7012 |
| You need to shrink scope by containing CUI | CUI enclave or secure collaboration implementation | Spreading CUI across consumer-grade tools |
| You have evidence but no workflow to maintain it | GRC platform — a supporting layer | Treating software alone as compliance |
| The reporting chain, log retention, or forensic hold is the gap | MSSP with 7012-specific incident terms, authorized in writing under 32 CFR § 236.4(f) | A GRC platform. This is an operations problem. |
| A contract genuinely requires Level 2 certification and you're ready | An authorized C3PAO | Using your readiness firm as your assessor |
| The question is what the contract means or what you must disclose | Government contracts counsel | Asking your MSP for a legal conclusion |
The independence rule, because it's an accreditation requirement and not a preference. Under the Cyber AB's conflict-of-interest and professional conduct rules, and 32 CFR § 170.9, the firm that prepares you and the C3PAO that certifies you must be separate. A C3PAO generally cannot assess an organization it provided CMMC consulting to within the previous three years. If a vendor offers to fix you and certify you in one engagement, ask exactly how they handle that boundary — and get the answer in writing before you sign anything.
Why there are no provider names on this page. We maintain a research priority list of readiness, enclave, GRC, and assessment firms. None of them appear here, deliberately. This page answers a regulatory question, and we don't have documented compensation status, current Cyber AB verification, and last-verified dates for named firms in this context — so publishing a list would violate our own standard and undercut the argument the page just made. When we do publish named providers, the provider category, status check, services reviewed, compensation relationship, evaluation depth, last-verified date, and what we couldn't verify appear on the page. Not before.
Three different obligations. Three different provider categories. Get matched to the right one before you request a quote.
Tell The Defense Compliance Report's Find My CMMC Path tool your required level, FCI/CUI scope, assessment type, cloud environment, and timeline. It maps your situation to a category — C3PAO, RPO/RP, MSSP, GRC platform, or CUI enclave — and to source-checked provider options within it. It does not rank vendors and it is not compliance advice.
[ Get matched with source-checked provider options → ]
Disclosure: The Defense Compliance Report is an independent trade publication on CMMC 2.0 and DIB compliance. We may receive compensation for qualified introductions, sponsorships, or partner referrals when disclosed. Compensation does not control our regulatory analysis, provider-category recommendations, or Cyber AB status verification.
Do not submit CUI, drawings, export-controlled content, or sensitive contract details. This intake is for provider-category routing only.
The most expensive CMMC-versus-7012 mistakes
Answer capsule: The costliest errors on this topic are sequencing and scope errors rather than technical ones: treating the July 2026 CMMC suspension as relief from DFARS 252.204-7012, assuming a CMMC status covers the clause's incident and preservation duties, building to NIST SP 800-171 Revision 3 based on the clause's uncorrected version language, and buying a certification assessment before confirming the contract requires one.
"Phase II is paused, so we can stop." Separate the deferred assessment expense from the active duties. The first is genuinely deferrable right now. The second never was.
"We have a CMMC status, so 7012 is handled." Ten duties say otherwise. Start with log retention and PIEE access; those are the two gaps we'd expect to find first in almost any program.
"Our SPRS score proves we're compliant with the clause." A score measures the 110 requirements. It says nothing about your cloud terms, your reporting chain, or your subcontracts. LOGZONE self-scored 110.
"The clause says the current version, so we're building to Rev. 3." The class deviation pins Revision 2. CMMC Level 2 assesses Revision 2. Building to Revision 3 right now is an expensive detour.
"We need an ECA certificate before an incident." You need a PIEE account. DoD replaced the certificate requirement effective April 11, 2024.
"Every subcontractor needs Level 2." Two different flow-downs with two different triggers. Determine what information each subcontract actually involves.
"We'll hire a C3PAO to tell us what's broken." That inverts the sequence and burns the independence boundary. Readiness first, assessment when a contract requires it and your evidence is mature.
What we actually verified
Answer capsule: Every regulatory claim on this page was checked against the issuing authority's own published material on August 24, 2026. Where a source could not be independently confirmed, we say so rather than publishing it.
We don't ask you to take our word for any of it.
| Source What it supports Verified | ||
|---|---|---|
| Acquisition.gov — DFARS 252.204-7012, clause version MAY 2024, current under DFARS Change 5/7/2026 | Every duty in the Coverage Map; the 72-hour definition; the malware, preservation, forensic, damage-assessment, and flow-down paragraphs | Aug 24, 2026 |
| 32 CFR § 236.4 (eCFR) | PIEE account requirement; third-party service provider reporting authorization; the all-forms-of-agreement reach; direct subcontractor reporting | Aug 24, 2026 |
| 89 FR 17741 (March 12, 2024), effective April 11, 2024 | DoD's removal of the medium assurance certificate requirement; the \~$175 annual cost cited; the 80,000-contractor estimate; the "presence of the clause does not establish that CDI is shared" statement | Aug 24, 2026 |
| 32 CFR Part 170 §§ 170.5, 170.14, 170.19, 170.24 (eCFR) | CMMC does not alter separately applicable requirements; Level 2 mapped to NIST SP 800-171 Rev. 2; CSP scope; DoD CIO adjudication assessed as MET | Aug 24, 2026 |
| NIST SP 800-171 Rev. 2, §3.6 | The three Incident Response requirements and what they do not specify | Aug 24, 2026 |
| DoD Class Deviation 2026-O0025, Defense Acquisition Regulations System | The February 1, 2026 clause renumbering; 7012, 7008, 7021, 7025 unchanged | Aug 24, 2026 |
| DFARS PGI 204.7303-2 | The variance adjudication route through the contracting officer to the DoD CIO | Aug 24, 2026 |
| Open DFARS Cases list (July 31, 2026) | DFARS Case 2023-D024 open; report due date extended to August 12, 2026 | Aug 24, 2026 |
| DoW CMMC Phase II suspension memoranda, July 13, 2026 | What was suspended, what remains in force, and the direction to amend and modify | Aug 24, 2026 |
| U.S. Department of Justice, June 2026 announcement | LOGZONE Inc. settlement amount and the 110 versus -170 score gap | Aug 24, 2026 |
What we could not establish, and won't pretend to:
- A restart date for CMMC Phase II. None has been announced.
- What DFARS Case 2023-D024 will change. The proposed rule has not published.
- Which CMMC status your contract requires. Only your document set answers that.
- Whether the information in your performance is CDI. That requires your contract, your markings, and usually a written confirmation from your prime or contracting officer.
This page is educational research produced by The Defense Compliance Report Editorial Team. It is not legal, contractual, or compliance advice. Confirm scope and applicability with a CMMC Registered Practitioner (RP/RPO) or a qualified federal-contracts attorney before making decisions about your contracts.
Frequently asked questions: CMMC vs DFARS 7012
Does CMMC replace DFARS 252.204-7012? No. 32 CFR § 170.5 provides that the CMMC Program does not alter existing FCI or CUI protection requirements — it provides a mechanism to verify them. A CMMC status verifies implementation of the applicable security requirements. It does not discharge the separate operational duties written into the 7012 clause.
Is DFARS 7012 still required after the CMMC pause? Yes. The July 13, 2026 implementation guidance states that DFARS 252.204-7012 requirements remain in effect. The suspension paused the Phase II transition to third-party assessment. It did not amend the clause, the DFARS, or 32 CFR Part 170.
What is the difference between DFARS 7012 and DFARS 7021? DFARS 252.204-7012 creates safeguarding and cyber incident reporting duties for Covered Defense Information. DFARS 252.204-7021 requires the contractor to have and maintain the CMMC status identified in the contract, including annual affirmation. Different clauses, different obligations.
What is the difference between DFARS 7021 and 7025? DFARS 252.204-7025 is the solicitation provision that tells offerors which CMMC level is required before award. DFARS 252.204-7021 is the resulting contract clause requiring that status to be maintained during performance.
Does DFARS 7012 require a C3PAO assessment? No. The clause creates no assessment requirement of any kind. A C3PAO requirement can arise only through the CMMC provisions in your specific procurement — and during the current suspension, new requirements may designate only Level 1 (Self) or Level 2 (Self).
Does DFARS 7012 require an SPRS score? Not by itself. The clause creates safeguarding and reporting duties. Posting a score in SPRS is tied to the assessment and CMMC provisions — historically DFARS 252.204-7019 and -7020, now DFARS 252.240-7997 where it applies, and CMMC status and affirmation duties under 32 CFR Part 170 and DFARS 252.204-7021 and -7025.
If we have a CMMC status, do we still have to report within 72 hours? Yes, wherever DFARS 252.204-7012 applies and the incident meets the clause's trigger. The 72-hour reporting duty is a contract obligation. A CMMC assessment does not verify it, and a CMMC status does not satisfy it.
Do I still need a medium assurance certificate to file a DIBNet report? 32 CFR § 236.4(e) requires a PIEE account to access dibnet.dod.mil. DoD removed the medium assurance certificate requirement effective April 11, 2024 and replaced it with PIEE registration, expressly to eliminate the cost. Certificates are still accepted. Note that the text of DFARS 252.204-7012(c)(3) has not been conformed to that change.
Can our MSSP report a cyber incident on our behalf? Yes, if you authorize it. 32 CFR § 236.4(f) provides that a contractor using a third-party service provider for information system security services may authorize that provider to report on the contractor's behalf. Put the authorization in the service agreement.
Which NIST SP 800-171 revision applies? CMMC Level 2 is mapped to Revision 2 under 32 CFR § 170.14. A DoD class deviation issued May 2, 2024 pins the 7012 requirement to Revision 2 rather than the version in effect at solicitation. Verify the version named in your specific solicitation before scoping work.
Can a contractor have 7012 duties with no CMMC requirement? Yes, and it's common. The obligations come from different authorities and different contract provisions. Search your document set for both.
Can a contractor have CMMC Level 1 with no 7012 duties? Potentially. CMMC Level 1 addresses Federal Contract Information and the 15 basic safeguarding requirements. DFARS 252.204-7012 is directed at Covered Defense Information on covered contractor information systems. Your contract and the information you actually handle control the answer.
Does DFARS 7012 apply to grants, OTAs, or cooperative agreements? The clause is a contract clause. The underlying reporting duty is broader: 32 CFR § 236.4(a) requires it in all forms of agreement between the government and a contractor where Covered Defense Information resides on covered systems or the contractor provides operationally critical support.
Does DFARS 7012 flow down to commercial-item subcontracts? Yes. Paragraph (m)(1) expressly includes subcontracts for commercial products and commercial services where performance involves Covered Defense Information or operationally critical support, and requires the clause be included without alteration except to identify the parties.
What if my solicitation still says Level 2 (C3PAO) after July 13, 2026? Request the amendment in writing. Implementation guidance directs contracting activities to amend active solicitations, but until an amendment issues, the solicitation text is the solicitation text. Send Letter 1 above.
Does a CMMC Level 2 certificate prove DFARS 7012 compliance? No. It is evidence that the 110 security requirements were assessed as implemented within a defined scope. Ten operative duties in the clause are not part of that assessment.
Can one firm prepare us for assessment and then certify us? Generally no. Under the Cyber AB's conflict-of-interest and professional conduct rules and 32 CFR § 170.9, readiness and formal certification assessment must be kept separate, with a three-year separation between consulting for an organization and conducting its Level 2 certification assessment.
Need help deciding what type of CMMC provider you need?
Tell us your level, scope, and timeline, and we'll match you with source-checked CMMC provider options.
[ Find My CMMC Path → ]
Already know exactly what you need? Request a quote directly.
Do not submit CUI, drawings, export-controlled content, or sensitive contract details. This intake is for provider-category routing only. Provider matching may generate referral or lead-routing compensation, disclosed at the point of recommendation.
The Defense Compliance Report is the independent CMMC decision layer for defense contractors. Choose the right CMMC path before you hire.
Last reviewed: August 2026. CMMC regulatory developments are tracked continuously; material changes trigger a re-review. Found an error? See our Corrections policy — we publish them.
CMMC vs DFARS: the 10 contract-duty crosswalk
How to read this crosswalk: “Not separately scored” does not mean “technically unrelated to CMMC.” CMMC practices overlap with several technical subjects below. The narrower point is contractual: a CMMC result does not independently certify performance of each reporting, preservation, notification, access, cloud-contract, and flowdown duty imposed by DFARS 252.204-7012.
| DFARS 252.204-7012 duty | Clause location | Where CMMC may overlap | What the CMMC result does not independently prove | Evidence to retain |
|---|---|---|---|---|
| Review affected systems, data, and accounts for evidence of compromise after discovering a cyber incident | 252.204-7012(c) | Incident-response and system-integrity evidence | That the required incident-specific review was completed | Incident ticket, scope notes, affected-system list, account review, analyst conclusion |
| Rapidly report a covered cyber incident to DoD through DIBNet—defined by the clause as within 72 hours of discovery | 252.204-7012(c) and the definition of “rapidly report” | Incident escalation and reporting procedures | That the DIBNet report was submitted through the required channel within the deadline | DIBNet receipt, report number, discovery timestamp, approval trail |
| Submit discovered malicious software to DoD when required and instructed | 252.204-7012(d) | Malware and incident-response handling | That the clause-specific submission was made and tracked | DoD instructions, chain of custody, submission confirmation |
| Preserve and protect images of affected systems and relevant monitoring/packet-capture data for at least 90 days after the report | 252.204-7012(e) | Media-protection and incident-response procedures | That the required artifacts were preserved for the required incident and period | Preservation log, storage location, retention lock, deletion date, custodian |
| Provide DoD access to additional information or equipment needed for forensic analysis | 252.204-7012(f) | Governed access-control evidence | That a specific DoD forensic-access request was fulfilled | Request, authorization, access log, transfer record, response correspondence |
| Support DoD cyber-incident damage-assessment activities | 252.204-7012(g) | Incident-response roles and escalation | That the requested assistance, information, and cooperation were supplied | Government correspondence, task log, data package, completion notice |
| When an external cloud service provider stores, processes, or transmits covered defense information, impose the applicable FedRAMP Moderate-equivalent and 7012(c)–(g) obligations and secure required access | 252.204-7012(b)(2)(ii)(D) | CMMC scope and evidence can examine the CSP and FedRAMP-equivalency basis | That the CSP contract and operating model carry every 7012 reporting, preservation, and access duty | CSP agreement, responsibility matrix, equivalency package, incident-notice and access terms |
| Flow the substance of 252.204-7012 to covered subcontracts and make the contract-specific information determination | 252.204-7012(m)(1) | A subcontractor may have its own required CMMC status; supplier processes may be examined | That the correct clause was inserted in every covered subcontract and the data determination was documented | Subcontract clause, information determination, supplier register, review record |
| Require a covered subcontractor to notify the prime or next higher tier when it submits a request to vary from a NIST SP 800-171 security requirement | 252.204-7012(m)(2) | Risk and configuration governance may overlap | That the higher-tier notice obligation was written into the subcontract and executed | Subcontract term, variance request, higher-tier notice, contracting-officer correspondence |
| Require a covered subcontractor to provide its DoD incident-report number to the prime or next higher tier as soon as practicable | 252.204-7012(m)(3) | Supplier incident-escalation procedures | That the report number was transmitted through the contractual chain | Supplier notice, report number, timestamp, higher-tier acknowledgment |
Original verification method: This map was rechecked on August 24, 2026, clause paragraph by clause paragraph. A row appears here only when 252.204-7012 creates a contract-performance, reporting, preservation, access, cloud, or subcontract-administration obligation that a CMMC result does not independently prove. Technical overlap is shown rather than erased.
Primary sources
- DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting — Acquisition.gov
- DFARS 252.204-7021, CMMC Level Requirements — Acquisition.gov
- DFARS 252.204-7008, Compliance with Safeguarding Covered Defense Information Controls — Acquisition.gov
- DFARS PGI 204.7303-2, Safeguarding controls and requirements — Acquisition.gov
- 32 CFR Part 236, DoD Defense Industrial Base Cybersecurity Activities — eCFR
- 89 FR 17741 (March 12, 2024), DIB Cybersecurity Activities final rule — govinfo.gov
- 32 CFR Part 170, CMMC Program — eCFR
- CMMC Program Rule, Federal Register, October 15, 2024 — federalregister.gov
- CMMC DFARS acquisition rule, Federal Register, September 10, 2025 — federalregister.gov
- DoD Class Deviation 2026-O0025, Revolutionary FAR Overhaul — Defense Acquisition Regulations System
- DoD Class Deviation 2024-O0013 Rev. 1 — Defense Pricing and Contracting policy vault
- Open DFARS Cases (Case 2023-D024) — acq.osd.mil
- NIST SP 800-171 Rev. 2 — NIST CSRC
- DoW CMMC Phase II suspension implementation memorandum, July 13, 2026 — dowcio.war.gov
- DoD CIO CMMC — dodcio.defense.gov/cmmc
- DIBNet cyber incident reporting portal — dibnet.dod.mil · PIEE — piee.eb.mil
- U.S. Department of Justice, LOGZONE Inc. settlement, June 18, 2026 — justice.gov
