The Defense Compliance ReportCMMC 2.0 & the Defense Industrial Base
DFARS 252.204-7019 & 7020

DFARS 252.204-7019 and 7020 Explained (2026): SPRS & CMMC

What these clauses required, what the 2026 class deviation changed, and what defense contractors must do now — with primary-source citation on every claim.

The Defense Compliance Report Editorial TeamIndependent CMMC and DIB compliance research
Published: Last reviewed:
Editorial research — not formally reviewed by a CMMC Subject Matter Advisor. Verify scope and applicability with a Registered Practitioner before acting.

Provider-matching forms on this site may generate referral or lead-routing compensation. This page does not currently contain named provider rankings, endorsements, or "best provider" awards. If named provider reviews are published later, sponsored, affiliate, partner, or referral relationships will be labeled on the relevant provider card or review. See our Methodology and Editorial & Advertising Policy for details.

By The Defense Compliance Report Editorial Team · · Clauses last verified against primary sources:

Educational research only — not legal, contractual, or compliance advice. Confirm scope and applicability with a CMMC Registered Practitioner (RP/RPO) or a qualified federal-contracts attorney. The contract clause and your CUI handling set your level, not a checklist. Do not submit CUI, drawings, export-controlled data, or sensitive contract details through any form on this page.

DFARS 252.204-7019 and 7020, explained in one line: they were the provision-and-clause pair that turned NIST SP 800-171 from a paper promise into a scored, government-verifiable requirement. DFARS 252.204-7019 was a solicitation provision: have a current NIST SP 800-171 assessment score in SPRS — the Department of Defense’s Supplier Performance Risk System — before you could win the award. DFARS 252.204-7020 was the contract clause: the government’s right to conduct its own assessments, post the results in SPRS, and require subcontractor flow-down.

Here’s the part almost nobody explains correctly: as of February 1, 2026, a Revolutionary FAR Overhaul class deviation removed 7019 and renumbered 7020 to DFARS 252.240-7997 — but it did it by deviation, not by rulemaking. The official Code of Federal Regulations still shows 7019 and 7020 today, older contracts still cite them, and solicitations issued under the new deviation use the new number. Both are in play right now.

So the honest answer to “are 7019 and 7020 still required?” is: it depends which clause is in your specific document — and that single fact changes what you have to do next.

Start here: the clause you’re looking at, and the first move it triggers

The clause in your documentWhat it is, in plain EnglishThe first thing to do
DFARS 252.204-7012The foundation: protect Covered Defense Information and report cyber incidents within 72 hoursConfirm whether you store, process, or transmit Covered Defense Information (DoD CUI) on a covered system. If FCI-only, look to FAR 52.204-21 / FAR 52.240-93 and CMMC Level 1 instead
DFARS 252.204-7019Legacy/codified pre-award notice: have a current NIST SP 800-171 assessment score in SPRS to be eligibleCheck whether a current SPRS score exists — and whether your document is old, a stale prime template, or deviation-based
DFARS 252.204-7020Legacy/codified contract clause: government assessment access, SPRS posting, subcontractor flow-downBe ready for a possible government Medium/High assessment and verify your flow-down to subs
DFARS 252.240-7997The 2026 deviation number that now carries the assessment requirementsTreat this as the current Medium/High assessment clause for deviation-based solicitations
DFARS 252.204-7021The CMMC contract clauseIdentify the CMMC level and assessment type your contracting officer inserted, and your status/affirmation obligation
DFARS 252.204-7025The CMMC solicitation noticeConfirm the required CMMC level, your CMMC UID, and your affirmation before you bid
A prime’s email or PO note onlyNot enough by itself to act onAsk for the actual clause, level, assessment type, FCI/CUI scope, and the deadline

One honest caveat before we go deeper: a clause number alone cannot tell you whether to hire a readiness consultant, a managed security provider, a compliance-software vendor, an enclave provider, or a certified assessor. Your required level, your FCI/CUI scope, your system boundary, your environment, and your timeline decide that — not the clause number.

Map your clause, level, scope, and timeline to the right provider category

The Defense Compliance Report’s Find My CMMC Path tool returns your likely clause path, whether the request points to a NIST SPRS score or a CMMC status, the evidence to gather before you respond, and the provider category to evaluate next. It never needs CUI, drawings, or sensitive contract details.

Find My CMMC Path →

Disclosure: provider matching may generate compensation for qualified introductions, sponsorships, or partner referrals when disclosed. Compensation does not control our regulatory analysis, provider-category recommendations, or Cyber AB status verification.

DFARS 252.204-7019 and 7020 explained in plain English

DFARS — the Defense Federal Acquisition Regulation Supplement — is the set of contract rules that applies on top of the standard Federal Acquisition Regulation for Department of Defense work. DFARS 252.204-7019 was the pre-award notice telling offerors they needed a current NIST SP 800-171 assessment in SPRS when the standard applied. DFARS 252.204-7020 was the contract clause that let the government conduct its own assessments, post the results in SPRS, and require subcontractor flow-down.

The two didn’t appear out of nowhere. They came from the DoD’s November 2020 interim rule (DFARS Case 2019-D041), which created three at once — 7019, 7020, and the CMMC clause 7021 — to fix a problem the government had quietly tolerated for years. DFARS 7012 had required contractors to implement NIST SP 800-171 on covered systems no later than December 31, 2017, but it had no real verification mechanism. Contractors checked a box. Nobody checked the contractors. The 2020 rule added the teeth.

Two terms you’ll see throughout, defined once:

7012 = protect CUI and report incidents. 7019= the pre-award “show me your score” notice. 7020= the government’s assessment-access and flow-down clause. 7021 / 7025 = the CMMC certification and status path. 252.240-7997 = the 2026 deviation number now carrying the assessment-requirements language.

Are DFARS 7019 and 7020 still in effect, or were they replaced by 252.240-7997?

Both answers are true at the same time, and that’s not a dodge — it’s the actual state of the regulations. For solicitations and contracts issued under the 2026 Revolutionary FAR Overhaul class deviation, the NIST SP 800-171 assessment requirements now appear under DFARS 252.240-7997, and the standalone 7019 provision was dropped. But the deviation was issued withoutformal rulemaking, so 7019 and 7020 still sit in the codified Code of Federal Regulations, older contracts still cite them, and prime templates haven’t all been updated.

What the Revolutionary FAR Overhaul actually did

In late 2025, the government launched the Revolutionary FAR Overhaul (RFO) — a sweeping effort to rewrite federal acquisition regulations in plainer language and consolidate scattered requirements. On February 1, 2026, a batch of FAR and DFARS class deviations took effect to implement the first phase.

DARS Tracking Number 2026-O0025 — DFARS Part 240 Class Deviation

The relevant class deviation stood up a new DFARS Part 240 for cybersecurity, supply-chain, and information-security clauses. Under it, DFARS 252.204-7019 was removed and DFARS 252.204-7020 became DFARS 252.240-7997.

View at acq.osd.mil

Under DARS Tracking Number 2026-O0025:

What did not change

This is where contractors over-correct. The deviation did not touch:

Removing 7019 did not remove your obligation to implement NIST SP 800-171, maintain a System Security Plan, report incidents, or hold the CMMC status your contract requires. It reorganized where the assessment lives, not whether you owe one.

Why you’re seeing two different clause numbers

Because the change rides on a class deviation, the legacy clauses remain on the books. When we checked the eCFR on June 17, 2026, Title 48 was current as of June 2, 2026 (last amended May 7, 2026), and both 252.204-7019 and 7020 were still right there in the regulation text. Comply with whichever clause appears in your specific document.

The 2026 DFARS cyber-clause crosswalk

TopicLegacy clause (still in the CFR)Post-Feb-1-2026 deviation clauseWhat changedPrimary source
Pre-award NIST 800-171 assessment notice (solicitation provision)DFARS 252.204-7019Removed — no successor provisionThe standalone “post a Basic self-assessment to SPRS to be eligible” provision is gone from deviation-based solicitations; the function shifts to the CMMC patheCFR §252.204-7019; Class Deviation 2026-O0025
NIST 800-171 DoD assessment requirements (contract clause)DFARS 252.204-7020DFARS 252.240-7997Renumbered and modified: “Basic” self-assessment removed; only government-run Medium and High assessments defined; methodology referenced at 32 CFR 170.24Acquisition.gov 7020; Class Deviation 2026-O0025
Basic safeguarding of FCI (15 requirements)FAR 52.204-21FAR 52.240-93Renumbered only — same title, text, and 15 requirementsRFO FAR Part 40 deviation
Safeguarding CDI + 72-hour incident reportingDFARS 252.204-7012UnchangedNo change; still the foundational safeguarding clauseAcquisition.gov 7012
CMMC requirements (contract clause)DFARS 252.204-7021UnchangedNo change; still the vehicle that puts CMMC level requirements in contracts32 CFR Part 170
CMMC solicitation provisionDFARS 252.204-7025UnchangedNo change32 CFR Part 170 / DFARS

What we actually verified for this table. On June 17, 2026 we confirmed on the eCFR that 48 CFR 252.204-7019 and 252.204-7020 are still codified (Title 48 current as of June 2, 2026; last amended May 7, 2026). We read DoD Class Deviation 2026-O0025 (Revolutionary FAR Overhaul, DFARS Part 240), which directs contracting officers to use DFARS 252.240-7997 and removes the standalone 252.204-7019 provision in deviation-based solicitations.

→ Not sure whether your document is on the legacy path or the deviation path? Find My CMMC Path walks you through the clauses you actually have and maps them to your next step — no CUI required.

What did DFARS 252.204-7019 require before award?

DFARS 252.204-7019 required an offeror that had to implement NIST SP 800-171 to have a current assessment — generally not more than three years old — verifiable in SPRS for each relevant system before it could be considered for award. (DFARS 252.204-7019, Acquisition.gov)

NIST SP 800-171, Revision 2, is the standard at the center of all of this: 110 security requirements organized into 14 control families. The 7019 provision didn’t ask you to attach a full report. It asked you to confirm a summary-level score was in SPRS. Here’s the full field set — what each field actually requires and where contractors go wrong.

7019 fieldWhat it meansWhere it lives internallyA common bad answerVerify before you send it to a prime
Standard assessedWhich NIST SP 800-171 version you scored againstYour assessment recordNaming a version you didn’t actually assessIt matches what your contract or CMMC requires (Rev. 2 for CMMC)
Conducting organizationWho ran it — you, or the governmentYour assessment recordCalling a vendor gap analysis a “DoD assessment”Self vs. government is labeled correctly
CAGE code(s)The Commercial and Government Entity codes for the scored systemSAM.gov / your recordsListing a CAGE the assessment didn’t coverThe CAGE matches the assessed boundary
SSP architectureA short description of the system boundaryYour System Security Plan (SSP)“We’ll write the SSP later”The SSP exists and reflects reality
Assessment dateWhen you scored itYour assessment recordA date already older than three yearsIt’s current
Summary scoreYour number out of 110SPRSAn aspirational score, not your real oneIt reflects controls actually implemented
Date you’ll reach 110Your POA&M completion dateYour POA&MA date you can’t defendIt’s realistic and backed by a real POA&M

That last field matters and is widely misunderstood. 7019 did not require a perfect 110 to win an award. It required you to post your real score and, if you were below 110, to state when your Plan of Action and Milestones (POA&M) would close the gap. The point was honesty about where you stood — not a pass/fail gate at 110. The temptation buried in that design — post a flattering number and sort it out later — is precisely what put one contractor into a multimillion-dollar settlement. We’ll get to that.

What did DFARS 252.204-7020 require — and what does 252.240-7997 require now?

DFARS 252.204-7020 required contractors to give the government access to their facilities, systems, and personnel for a Medium or High NIST SP 800-171 assessment when necessary, to keep summary scores posted in SPRS, and to flow the requirement down to subcontractors. Its 2026 successor, DFARS 252.240-7997, keeps the government Medium and High assessments and drops the “Basic” self-assessment concept entirely. (DFARS 252.204-7020, Acquisition.gov)

Where 7019 was about getting in the door (be eligible), 7020 was about what happens after you’re in (oversight and accountability). Three obligations sat at its core: assessment access, SPRS posting, and subcontractor flow-down.

Basic, Medium, and High are not the same thing as “my self-score”

There are three assessment tiers, and they differ by who runs them and how much the government trusts the result.

AssessmentWho performs itStandard usedConfidence levelStatus after Feb 2026
BasicThe contractor (self-assessment)NIST SP 800-171 DoD Assessment MethodologyLow (self-generated)Removed from the assessment clause. If your contract requires CMMC Level 2 (Self), self-assessment runs through the CMMC path under 32 CFR Part 170
MediumGovernment personnel (in practice, DCMA’s DIBCAC)NIST SP 800-171AMediumRetained in 252.240-7997
HighGovernment personnel (in practice, DCMA’s DIBCAC), on-siteNIST SP 800-171A, with SSP validationHighRetained in 252.240-7997

DCMA is the Defense Contract Management Agency; DIBCAC is its Defense Industrial Base Cybersecurity Assessment Center — the team that conducts government assessments in practice. A High assessment isn’t a paperwork review. It’s a verification, examination, and demonstration that your real-world implementation matches what your SSP claims. A Medium assessment can be escalated to a High at the government’s discretion. The practical takeaway: if the government has assessment authority over your contract, your controls need to be demonstrable, not aspirational.

How the score is actually calculated

The NIST SP 800-171 DoD Assessment Methodology is the scoring system behind every SPRS number. It’s worth understanding, because it explains how a contractor can end up deeply negative.

ElementDetail
Requirements scored110 (NIST SP 800-171 Rev. 2, across 14 families)
Point weightsEach requirement is worth 1, 3, or 5 points, weighted by risk
The mathYou start at 110and subtract the weighted value of every requirement you haven’t fully implemented
Possible range−203 to +110 — yes, scores can go far below zero
If you’re below 110Document a POA&M with the date you’ll reach 110
What gets postedThe summary-level score only, not your per-requirement detail

The rebuttal window and the flow-down

Two operational details survive into 252.240-7997. First, there’s a built-in 14-business-day rebuttal window — contractors get 14 business days to provide additional evidence or challenge questioned findings before the government posts the summary score to SPRS. Second, the flow-down: the contractor must insert the substance of the clause into subcontracts and other contractual instruments, excluding commercially available off-the-shelf items.

If a government Medium or High assessment is a realistic prospect and your evidence isn’t organized, that’s a readiness problem, not an assessment problem. Compare provider categories with Find My CMMC Path to see what kind of help that calls for.

How do these clauses connect to DFARS 252.204-7012?

DFARS 252.204-7012 is the foundation: it requires you to safeguard Covered Defense Information by implementing NIST SP 800-171 and to report cyber incidents to the DoD within 72 hours. 7019, 7020, and 252.240-7997 are the proof mechanisms layered on top. (DFARS 252.204-7012, Acquisition.gov)

One 7012 detail catches contractors off guard: if you use an external cloud service provider to store, process, or transmit Covered Defense Information, that provider must meet security requirements equivalent to the FedRAMP Moderate baseline.A commercial email or file-sharing service that hasn’t met that bar can quietly put you out of compliance with 7012 no matter what your self-score says. This is exactly what happened in the enforcement case below.

Here’s the information-type trigger map — and what not to assume:

Information typeLikely safeguarding clauseControl baselineAssessment / status pathDon’t assume
FCI (Federal Contract Information)FAR 52.204-21 (FAR 52.240-93 under the deviation)15 basic safeguardsCMMC Level 1 (Self)That FCI-only work pulls in the full NIST SP 800-171 / 7012 stack
CUI / Covered Defense InformationDFARS 252.204-7012NIST SP 800-171 Rev. 2 (110 requirements)NIST assessment via 252.240-7997 (legacy 7019/7020); CMMC Level 2 (Self or C3PAO)That a NIST SPRS score equals a CMMC status
Highest-priority CUI (critical programs)DFARS 252.204-7012 + program directionNIST SP 800-171 Rev. 2 + selected NIST SP 800-172CMMC Level 3 (DIBCAC)That you can self-assess your way to Level 3

For the full control set, see our NIST 800-171 requirements checklist — the 110 Rev. 2 requirements mapped to the evidence that proves each one.

How do 7019, 7020, and 7997 relate to CMMC (DFARS 252.204-7021 and 7025)?

DFARS 252.204-7021 is the CMMC contract clause that requires you to hold and maintain the CMMC level and status your contracting officer inserts. DFARS 252.204-7025 is the solicitation notice that makes that status a pre-award eligibility issue. A NIST SP 800-171 SPRS score and a CMMC status are related but are not the same thing. (32 CFR Part 170)

CMMC adds a formal status-and-affirmation requirement. Depending on the solicitation, that status is Level 1 (Self), Level 2 (Self), Level 2 (C3PAO certification), or Level 3 (DIBCAC). The CMMC Program Rule at 32 CFR Part 170 became effective December 16, 2024.

NIST SP 800-171 SPRS scoreCMMC status
What it provesYour assessment score against the 110 NIST SP 800-171 requirementsYour CMMC level and status, tied to a defined scope and a CMMC UID
Where it lives in SPRSThe NIST SP 800-171 Assessments areaThe CMMC Assessments area
Who creates itYou (Basic/self) or the government (Medium/High)You (self-assessment path), a C3PAO (Level 2 certification), or DIBCAC (Level 3)
Ongoing dutyKeep it current (generally within three years for a NIST assessment record)Maintain status plus a current annual affirmation
What it does not proveA CMMC status by itselfThat every unrelated system or subcontract is in scope

SPRS keeps separate areas for NIST SP 800-171 assessments and for CMMC assessments (SPRS Software User’s Guide for Awardees/Contractors). So when a prime says “send me your SPRS score,” the right first question is which one — a NIST assessment record, or a CMMC status with a CMMC UID and affirmation?

For the level-by-level picture, see our explainer on CMMC Level 2 self-assessment vs. C3PAO, and for the SPRS mechanics, how to verify a company’s CMMC status in SPRS.

Do you still need an SPRS score or a CMMC entry right now?

Probably — but what kind depends entirely on which clauses are in your document. A legacy 7019/7020 path points to a NIST SP 800-171 assessment record in SPRS. A CMMC 7021/7025 path points to a CMMC status, CMMC UID, and annual affirmation in SPRS. Many contractors now have reasons to maintain both, and a prime email alone tells you neither.

  1. Does your document include DFARS 252.204-7025?If yes, find the required CMMC level and assessment type — and remember it’s a pre-awardeligibility requirement, so don’t plan to solve it after award.
  2. Does it include DFARS 252.204-7021? If yes, current CMMC status and a current annual affirmation are contract obligations you must maintain.
  3. Does it include DFARS 252.240-7997?If yes, you’re on the deviation path — prepare for the possibility of a government Medium or High NIST SP 800-171 assessment.
  4. Does it include legacy 7019 or 7020? If yes, confirm whether the document is older, codified, or a stale prime template — then verify the right NIST assessment record is current in SPRS.
  5. Does it include only 7012? If yes, your first job is implementing NIST SP 800-171 and meeting any contract-specific proof requirement.
  6. Is it just a prime’s email or a PO note? Then your first move isn’t to post anything — it’s to ask for the exact clause, level, scope, and deadline.

Run your actual clauses through the decoder

Tell it which clauses you see — 7012, 7019, 7020, 252.240-7997, 7021, 7025 — plus your FCI/CUI scope, environment, and timeline, and it maps you to the provider category to evaluate next, with the evidence checklist for your situation. It never needs CUI, drawings, or sensitive contract details.

Find My CMMC Path →

What exactly should you verify in SPRS before you respond?

Before you answer a prime or contracting officer, confirm whether the request points to the NIST SP 800-171 assessment area or the CMMC assessment area of SPRS — they’re different records. For a NIST record, check the assessment date, score, scope, CAGE codes, SSP name and version, confidence level, and POA&M completion date where applicable. For a CMMC record, check the level, status, CMMC UID, scope, and the annual affirmation date.

If a prime or CO asks for…Check this SPRS areaVerify these fieldsDon’t do this
“Your SPRS score” / NIST 800-171 scoreNIST SP 800-171 AssessmentsAssessment date, summary score, scope and CAGE codes, SSP name/version, confidence level, POA&M dateSend a CMMC status when they wanted the NIST score
“Your CMMC status” / CMMC levelCMMC AssessmentsCMMC level, status, CMMC UID, scope, annual affirmation dateSend a NIST score and call it a CMMC certification
“Proof you’re current” (unclear)Ask which one firstGuess and send a screenshot of the wrong record

The single most common avoidable mistake: a stale or expired annual affirmation on a CMMC record. Your status can be real and still read as non-current if the affirmation has lapsed — so calendar it. For the SPRS mechanics, see our guide to SPRS scores and CMMC affirmations.

Is DFARS 7020 the same as CMMC?

No. DFARS 252.204-7020 (now 252.240-7997) governs NIST SP 800-171 assessmentmechanics — especially the government’s right to conduct Medium and High assessments. CMMC governs certification status, through DFARS 252.204-7021 and 252.204-7025 and the program rule at 32 CFR Part 170. They overlap on NIST SP 800-171 and on SPRS, but they answer different questions.

7020 / 7997 asks: Can the government assess your NIST SP 800-171 implementation, and is your score posted?

7021 / 7025 asks: Do you hold the CMMC status and affirmation your contract requires to be eligible and to perform?

A contractor can be perfectly fine on one and exposed on the other. Treating a NIST SPRS score as a CMMC certificate — or assuming a 7020/7997 clause means you need a third-party assessment when your scope only involves FCI — is a common and expensive misread. See our CMMC levels explainer for the full level-by-level picture.

What should a subcontractor verify when a prime flows down 7019, 7020, 7997, or CMMC?

Don’t treat a prime’s email as the full requirement. Ask for the actual clause text and the specifics around it, because the wrong assumption here can cost you a subcontract or push you into spending you didn’t need.

Before you respond to a prime, a contracting officer, or an assessor, get answers to these:

For the full picture, see our guide to CMMC flow-down requirements for primes and subcontractors.

The $4.6 million lesson: why an inaccurate SPRS score is now a legal liability

The biggest mistake contractors make with 7019/7020 isn’t misunderstanding the clauses — it’s posting a score that doesn’t reflect reality. In March 2025, that exact mistake led to a $4.6 million False Claims Act settlement.

On March 26, 2025, the Department of Justice announced a $4.6 million settlement with MORSECORP, Inc. (MORSE), a Cambridge, Massachusetts contractor serving the Army and Air Force. The case came from a qui tamwhistleblower complaint filed by MORSE’s own Head of Security and Facility Security Officer — alleging the company failed to satisfy DFARS 252.204-7008, 7012, 7019, and 7020. The whistleblower received roughly $851,000 of the settlement. (U.S. Department of Justice, Office of Public Affairs)

The numbers are what make it stick. MORSE posted a NIST SP 800-171 self-assessment summary score of 104 in SPRS in January 2021. After a third-party gap analysis, the real picture emerged: it had implemented roughly 22% of the controls, and its actual summary score was −142. MORSE did not update its score until June 2023 — months after the government had served it with a subpoena.

What the DOJ stated / MORSE admittedThe operational failureDFARS clause the conduct relates to
Used a third-party email host without ensuring FedRAMP Moderate-equivalent securityThe cloud service didn’t meet the cloud-security bar252.204-7012
Had not fully implemented all NIST SP 800-171 controlsThe 110 requirements weren’t actually in place252.204-7012 / NIST SP 800-171
Lacked a consolidated written security planNo single accurate SSPNIST SP 800-171 (SSP requirement)
Posted a 104 score; real score was −142; updated only in June 2023An inflated self-reported score7019 / 7020 (assessment + SPRS posting)

The settlement resolved allegations; the whistleblower complaint alleged violations of DFARS 252.204-7008, 7012, 7019, and 7020. The facts above are drawn from the DOJ announcement and settlement agreement.

We’re not citing this to scare you — we’re citing it because it’s the most concrete public proof of a point that’s easy to wave away: a SPRS score is a representation to the federal government, and an inflated one is a legal exposure, not just a technical gap. The gap between 104 and −142 is the gap between “we think we’re basically there” and “we’ve implemented about a fifth of this.”

If this produced a small knot in your stomach about your own score, that instinct is worth acting on. If you’re not ready to talk to anyone yet, work through the NIST 800-171 requirements checklist and compare your evidence against the 110 Rev. 2 requirements before you touch SPRS. When you are ready: Get matched to the provider category that fits your situation — and keep readiness work and formal assessment separate, which the C3PAO independence rules require.

What provider category fits this problem?

The right category depends on what you actually need: implementation and readiness, managed security operations, evidence and workflow software, a scoped CUI enclave, or a formal assessment. The clause in your contract, your FCI/CUI scope, your environment, and your timeline decide it.

Vocabulary, defined once:

On that last one, a rule worth stating plainly: a C3PAO cannot both prepare you and certify you. Under the CMMC Assessment Process and the Cyber AB Code of Professional Conduct, a C3PAO is barred from conducting your Level 2 certification assessment if it provided you CMMC consulting or implementation services, generally within the prior three years. Treat any assessor who offers to remediate and then certify the same work as a red flag.

The table below is editorial routing guidance from The CMMC Path Framework — it maps your situation to a provider category, not a named provider, and it is not a regulatory requirement, a certification guarantee, or a ranking.

Your situationUsually evaluate firstWhyDon’t ask this category to
No SSP or no defensible scope yetRPO/RP or readiness consultantScope and evidence have to be mapped before any formal assessmentIssue you a CMMC certification
CUI spread across Microsoft 365 / commercial ITMSSP or GCC High implementation providerThe architecture itself may need remediationAct as your independent assessor on the same work
You need to shrink your assessment scopeCUI enclave providerAn enclave can limit where CUI lives, and what gets assessedReplace the control implementation work entirely
Controls exist but your evidence is a messGRC / evidence platformOrganizes SSP, POA&M, artifacts, owners, and affirmation supportStand in for actually implementing the 110 requirements
Your contract requires Level 2 C3PAO and you’re readyC3PAOThe formal certification path — only when you’re assessment-readyAlso remediate or consult on the work it will certify
You see Level 3 languageDIBCAC readiness plus qualified advisory supportLevel 3 is a separate DIBCAC path that follows Level 2 certificationSelf-assess your way to Level 3

For the full provider-category picture, see our guide to which CMMC provider category to hire first.

Your situation changes the answer

Find My CMMC Path

The right CMMC provider isn't the same for every contractor. The category you need — a C3PAO, an RPO, an MSSP, a GRC platform, or a CUI enclave — depends on your required CMMC level, whether you handle FCI or CUI, your assessment type, your cloud and IT environment, and your contract timeline. (The contract clause sets your level, not a checklist.) Because a general answer can't resolve those for you, use The Defense Compliance Report's Find My CMMC Path tool to map your situation to the right provider category before you request quotes.

  • What it asks: your required CMMC level, FCI vs CUI handling, assessment type, IT/cloud environment, and contract timeline
  • What you get: the provider category that fits your situation and the readiness steps to get there, with the questions to ask before requesting quotes
  • Educational triage only: free · 2-minute assessment · no obligation · do not submit CUI, drawings, or sensitive contract details
Find My CMMC Path →

Frequently asked questions

What is DFARS 252.204-7019?

DFARS 252.204-7019 was a DoD solicitation provision titled “Notice of NIST SP 800-171 DoD Assessment Requirements.” It required an offeror that had to implement NIST SP 800-171 to have a current assessment — generally not more than three years old — posted in SPRS before being considered for award. As of February 1, 2026, a class deviation removed the standalone provision for deviation-based solicitations, though it still appears in the codified CFR and older contracts.

What is DFARS 252.204-7020?

DFARS 252.204-7020 was the DoD contract clause titled “NIST SP 800-171 DoD Assessment Requirements.” It required contractors to give the government access for Medium or High assessments, keep summary scores posted in SPRS, and flow the requirement down to subcontractors. In 2026 it was renumbered to DFARS 252.240-7997 and modified to define only government-run Medium and High assessments.

What is DFARS 252.240-7997?

DFARS 252.240-7997 carries the NIST SP 800-171 DoD assessment requirements under the 2026 Revolutionary FAR Overhaul class deviation (DARS Tracking Number 2026-O0025). It defines government-run Medium and High assessments using NIST SP 800-171A, references the methodology at 32 CFR 170.24, and removes the “Basic” self-assessment concept that lived in the old 7019/7020 framework.

Did DFARS 7019 and 7020 go away in 2026?

For solicitations issued under the 2026 class deviation, the standalone 7019 provision is gone and 7020’s mechanics moved to 252.240-7997. But the change was made by deviation, not rulemaking, so 7019 and 7020 still appear in the codified Code of Federal Regulations and in pre-February-2026 contracts. We confirmed both were still in the eCFR on June 17, 2026. Comply with whichever clause your specific contract cites.

Do I still need a NIST 800-171 self-assessment and SPRS score?

Likely yes, but the form depends on your clauses. If your contract specifies CMMC Level 2 (Self), you still perform a self-assessment against the 110 NIST SP 800-171 Rev. 2 requirements, post your score in SPRS, and keep an annual affirmation current. The assessment obligation moved into the CMMC framework rather than disappearing.

Is an SPRS score the same as a CMMC status?

No. A NIST SP 800-171 SPRS score reflects your assessment against the 110 requirements and lives in the NIST assessments area of SPRS. A CMMC status reflects your CMMC level, ties to a CMMC UID and scope, lives in the CMMC assessments area of SPRS, and requires an annual affirmation. A prime asking for “your SPRS score” should be asked which one they mean.

Is DFARS 7020 the same as CMMC?

No. DFARS 7020, now 252.240-7997, governs NIST SP 800-171 assessment access and SPRS posting. CMMC governs certification status through DFARS 252.204-7021, 252.204-7025, and 32 CFR Part 170. They share NIST SP 800-171 and SPRS but answer different questions: assessment authority versus certification status.

What is the difference between DFARS 7012, 7019, 7020, and 7021?

DFARS 7012 requires protecting CUI via NIST SP 800-171 and 72-hour incident reporting. DFARS 7019 was the pre-award notice to have a current SPRS assessment. DFARS 7020, now 252.240-7997, gave the government assessment access and required flow-down. DFARS 7021 is the CMMC clause requiring the CMMC status your contract specifies.

Does a subcontractor have to comply with 7019/7020 or 252.240-7997?

It depends on the flow-down and whether your subcontract involves covered systems and FCI or CUI. The prime is required to insert the substance of the assessment clause into qualifying subcontracts, excluding commercially available off-the-shelf items. Before responding, get the exact clause, the FCI/CUI scope, the required level and assessment type, and the deadline from your prime.

Should I hire a C3PAO just because I see DFARS 7020?

Not necessarily. A 7020 or 252.240-7997 clause concerns government NIST SP 800-171 assessments, not automatically a CMMC Level 2 certification. Whether you need a C3PAO depends on the CMMC level and assessment type your contract specifies — and readiness work must stay separate from formal assessment, since a C3PAO generally cannot certify an organization it has consulted for within the prior three years.

Can I submit CUI through the matching form?

No. Do not submit CUI, drawings, export-controlled data, or sensitive contract details through any form on this page. The matching process only needs your required level, scope, environment, and timeline to point you to the right provider category.

What we verified for this article

We treat regulatory facts as the kind of claims that have to be right. Here’s what we checked and when.

Verified itemSourceLast verified
7019 still codified; clause texteCFR / Acquisition.gov DFARS 252.204-7019
7020 still codified; clause textAcquisition.gov DFARS 252.204-7020
252.240-7997 + Part 240 deviationDoD Class Deviation 2026-O0025
7012 safeguarding + incident reportingAcquisition.gov DFARS 252.204-7012
CMMC program structure; Level 2 = NIST 800-171 Rev. 232 CFR Part 170 (eCFR)
CMMC phase timing (Phase 1 / Phase 2)DoD CIO — About CMMC
SPRS NIST vs. CMMC assessment areasSPRS Software User’s Guide for Awardees/Contractors
MORSECORP $4.6M settlement + score timelineU.S. DOJ press release

How we report this. Every regulatory claim on this page links to a primary source — Acquisition.gov, the eCFR, the DoD class-deviation memo, 32 CFR Part 170, the DoD CIO, SPRS, and the Department of Justice — and we re-verify these items on a monthly cadence during the FAR Overhaul transition. See our editorial standards and corrections policy.

Limitations, stated plainly. We are not your contracting officer, and this is not legal advice. The exact clause in your specific solicitation, contract, or flow-down controls — older contracts and prime terms may still carry the legacy numbers, and the class deviation remains in effect until it is rescinded or folded into formal rulemaking. The Defense Compliance Report is an independent trade publication on CMMC 2.0 and DIB compliance, and is not affiliated with the Cyber AB, the Department of Defense, DCMA DIBCAC, NIST, SPRS, or any U.S. government agency.

Next decision pages

Or keep going at your own pace: CMMC levels explained · what CMMC Level 2 actually costs · which CMMC provider category to hire first · Find My CMMC Path.

The Defense Compliance Report is the independent CMMC decision layer for defense contractors. Clause first, provider second.

Your situation changes the answer

Find My CMMC Path

The right provider category — a C3PAO, an RPO, an MSSP, a GRC platform, or a CUI enclave — depends on your required CMMC level, FCI vs CUI handling, assessment type, IT/cloud environment, and contract timeline. Use The Defense Compliance Report's Find My CMMC Path tool to map your situation to the right provider category before you request quotes. Educational triage only: free · 2-minute assessment · no obligation · do not submit CUI, drawings, or sensitive contract details.

Find My CMMC Path →