Framework Defense, Supply Chain & NIST Catalogue
DFARS
The Defense Federal Acquisition Regulation Supplement is the Department of Defense's supplement to the Federal Acquisition Regulation. In compliance conversations "DFARS" almost always means the 252.204-70xx cybersecurity clauses.
DFARS 252.204-7012 requires contractors that handle covered defense information to implement the 110 requirements of NIST SP 800-171, report cyber incidents to DoD within 72 hours, preserve images and logs, and flow the clause down to subcontractors.
DFARS 252.204-7019 and 7020 require a current NIST SP 800-171 self-assessment score posted in the Supplier Performance Risk System (SPRS) and allow DoD to conduct its own assessments. DFARS 252.204-7021, rewritten by the final rule published September 10, 2025 and effective November 10, 2025, ties contract eligibility to holding the CMMC level named in the solicitation.
In writing, a contractor needs a system security plan that describes how each NIST SP 800-171 requirement is met, plans of action and milestones for gaps, the SPRS score and its basis, incident response procedures aligned to the 72-hour reporting rule, subcontractor flow-down and verification records, and, under CMMC, the annual affirmation by a senior official.
The rule phases CMMC into contracts over three years; Phase 1 (self-assessments) began November 10, 2025, and the transition to Phase 2 third-party certification was paused by the Department in July 2026 pending a program review (verify current status).
Who has to comply
Any contractor or subcontractor whose DoD contract includes the clauses, which in practice means anyone that processes, stores, or transmits federal contract information or controlled unclassified information for DoD. Commercial off-the-shelf item suppliers are excluded. The clauses flow down through the supply chain.
What the assessor asks to see
System security plan; asset inventory and CUI data flow; SPRS score with scoring worksheet; POA&Ms; policies and procedures for each NIST SP 800-171 family; access control and multifactor authentication evidence; audit logs and monitoring; configuration baselines; vulnerability scans and patching; incident response plan and 72-hour reporting records; media protection and encryption (FIPS-validated); personnel screening and training; physical security; external service provider agreements and shared responsibility matrix; subcontractor flow-down records; senior official affirmations.
Where the requirement sits: DFARS 252.204-7012/7019/7020/7021
CMMC phase-in
The DFARS final rule (DFARS Case 2019-D041) was published September 10, 2025 and took effect November 10, 2025. Phase 1 introduced Level 1 and Level 2 self-assessments in new solicitations.
Phase 2 was scheduled to add Level 2 C3PAO certification requirements from November 10, 2026, but the Department announced a pause of the Phase 2 transition on July 13, 2026 during a program review; Phase 1 requirements remain in force. Check the DoD CIO CMMC page for the current schedule.
What AllyMatter does here
Same wording as CMMC.
AllyMatter publishes this site.
Assessors
Who assesses DFARS
Level 1 and some Level 2 requirements are self-assessed and affirmed. Level 2 certification assessments are performed by CMMC Third-Party Assessment Organizations (C3PAOs). Level 3 assessments are performed by the Defense Contract Management Agency's DIBCAC.
DoD may also conduct medium and high assessments under 7020. Accredited by The Cyber AB (CMMC Accreditation Body) accredits C3PAOs; individual assessors are certified through the CMMC Assessors and Instructors Certification Organization.
Public register of assessors: https://cyberab.org/Catalog
No firm has claimed a DFARS assessor listing yet. Claim yours →
Consultants
Who helps with DFARS
A very large ecosystem: registered practitioner organizations, managed service providers offering enclave environments, and consultancies that write system security plans and run readiness assessments.
Typical engagement is a gap assessment against NIST SP 800-171, remediation, SSP and POA&M drafting, and mock assessment, running six to eighteen months for a first-time Level 2 effort.
Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.
No firm has claimed a DFARS consultant listing yet. Claim yours →
Software
Tools for DFARS
Tools that name this framework in their own material.
Related reading
- Reassessing CMMC: DOD suspends CMMC Phase II, but core DFARS obligations endureExplains what the 2026 suspension did and did not change, and why the 7012 safeguarding clause still binds contractors.Arnold & Porter
- Department of War suspends CMMC Phase II requirements, but cybersecurity obligations remainSets out which assessment levels contracting officers may still impose during the suspension and what contractors should keep doing.Morgan Lewis
- CMMC regulations: key questions and answers for defense contractorsQ&A on how the DFARS clauses, CUI scoping and the NIST SP 800-171 requirements fit together in a contract.Holland & Knight
Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.
Need a hand implementing it?
Find a Consultant for DFARS
Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.
From the publisher
Run the Policy Side of DFARS in AllyMatter
Approve the policies DFARS asks for, keep every version, and record a named acknowledgment from each person who has to read them.