Independent DIB implementation resource — not affiliated with or endorsed by the U.S. Department of WarView the official DoW campaign ↗
KNOWLEDGE BASECompliance FrameworksEDITOR REVIEWED

The Foundation Clauses — FAR 52.204-21 and the DFARS 7012 Family

Five clauses do most of the work in defense cybersecurity compliance. Here is what each one actually triggers, obligates, and flows down — plus the fourth gate almost nobody builds for.

TL;DR

FAR 52.204-21 protects FCI with 15 basic safeguards. DFARS 252.204-7012 is the workhorse: it triggers on CDI and requires adequate security, NIST SP 800-171 Rev 2, a 72-hour incident report, 90-day media preservation, FedRAMP-Moderate-equivalent cloud protection, and flowdown. -7019 requires a current SPRS score before award (generally not more than three years old). -7020 gives the government assessment access, defines the Basic/Medium/High confidence levels, and restricts subcontract award without a current Basic Assessment. -7021 makes a specified CMMC status a condition of award, with annual affirmations and up to 180 days of conditional status. Underneath all of it runs a separate gate — source allowability — where a technology that satisfies every one of these can still be excluded from a covered contract.

Read the clause, not the summary

The summaries below describe the operative function of each clause. Applicability must always be verified against your actual solicitation, contract, order, and flowdowns — this is educational analysis, not legal advice or contract review.

The five-clause map

Almost all defense cybersecurity obligation flows from five clauses. Teams that can state each clause's trigger, obligation, and flowdown from memory make dramatically better scoping decisions than teams that treat “compliance” as one undifferentiated blob.

FAR 52.204-21 — Basic Safeguarding

Trigger. A contractor or subcontractor information system may have FCI residing in or transiting through it. The substance flows down when a subcontractor may handle FCI, including commercial-product and commercial-service subcontracts other than COTS items.

Obligation. Apply 15 basic safeguarding requirements, covering access limitation, authentication, external-system controls, media sanitization, physical protection, boundary protection, flaw remediation, malicious-code protection, and system scanning.

Leadership impact

This is the government-wide floor for contractor systems handling FCI. CMMC Level 1 uses the same 15 requirements and adds an annual self-assessment and affirmation when the acquisition requires that CMMC status. If you do federal work of any kind, this is your baseline — not an advanced goal.

DFARS 252.204-7012 — Safeguarding CDI and Cyber Incident Reporting

Trigger. A covered contractor information system processes, stores, or transmits CDI, or the contractor provides operationally critical support identified in the contract.

Obligations. This is the densest clause in the stack:

  • Provide adequate security, implementing the 110 requirements of NIST SP 800-171 Rev 2 for applicable covered systems.
  • Document the implementation in a System Security Plan (SSP).
  • Rapidly report qualifying cyber incidents within 72 hours.
  • Preserve and protect system images and relevant monitoring data for at least 90 days.
  • Submit malicious software when requested, and support Department forensic and damage-assessment activities.
  • Flow the clause down to qualifying subcontractors.

Cloud. If an external cloud service provider stores, processes, or transmits CDI in contract performance, the contractor must require and ensure that the CSP meets security requirements equivalent to the FedRAMP Moderate baseline, and complies with the clause's incident, malicious-software, preservation, forensic-access, and damage-assessment provisions.

Cloud precision

DFARS 7012 does not name GCC High and does not prohibit every commercial offering. The determination is offering-specific: validate FedRAMP authorization or documented equivalency, the additional paragraphs, contract terms, CMMC scope, export controls, and support-personnel access before selecting the service. See GCC High vs. Commercial Microsoft 365.

DFARS 252.204-7019 — Pre-Award Assessment Notice

An offeror required to implement NIST SP 800-171 must verify that current summary-level scores are posted in SPRS for every covered contractor information system relevant to the offer.

“Current” generally means not more than three years old, unless the solicitation specifies a shorter period. If no current score exists, the offeror may conduct and submit a Basic Assessment for posting.

In practice this clause is a quiet eligibility gate: a missing or stale score can remove you from consideration before anyone evaluates your technical proposal. If you are unsure how the number is produced, start with Your SPRS Score, Explained.

DFARS 252.204-7020 — Government Assessment and Supply-Chain Verification

The contractor must provide access to facilities, systems, and personnel needed for a government Medium or High NIST SP 800-171 DoD Assessment. The clause establishes the Basic, Medium and High assessment confidence levels, provides a rebuttal process for government assessments, and restricts subcontract award when an applicable subcontractor lacks a current Basic Assessment.

Leadership impact

A self-generated SPRS score is a low-confidence score — it is not a certification. Maintain the SSP, the score worksheet, objective-level evidence, and POA&M history so the posted result can survive government review. A Medium or High assessment can overwrite your number.

DFARS 252.204-7021 — CMMC Contract Requirement

When the clause and a specified CMMC status are included, the contractor must hold the required status — or a higher eligible status — for each contractor information system that will process, store, or transmit FCI or CUI in performance; maintain that status; complete annual affirmations; identify applicable CMMC UIDs; and flow the appropriate status to subcontractors and suppliers.

The clause permits Level 2 and Level 3 conditional status for no more than 180 days when the applicable POA&M criteria are satisfied. Award may occur with an eligible conditional status; Level 1 requires a final status.

Current implementation overlay (July 2026)

During the CMMC Phase II suspension, requiring activities may use only Level 1 (Self) or Level 2 (Self). They may not designate Level 2 (C3PAO) or Level 3 (DIBCAC) requirements; active solicitations containing those designations are to be amended, and existing contracts modified as directed. The clause itself is unchanged — what is paused is which assessment types may be designated.

Clause relationships at a glance

AuthorityPrimary jobAssessment / recordFlowdown
FAR 52.204-21Protect FCI systems15 safeguards; no FAR scoreQualifying FCI subcontracts
DFARS 7012Protect CDI and report incidentsSSP, NIST 800-171 implementation, incident evidenceQualifying CDI subcontracts
DFARS 7019Pre-award SPRS noticeCurrent summary-level scoreOperates with the 7012 / 7020 structure
DFARS 7020Government assessment authorityBasic, Medium or High assessmentSubcontract assessment eligibility
DFARS 7021CMMC award and performance conditionCMMC status, UID and annual affirmationAppropriate level by information flowed down

The four gates — and the one most programs skip

Alongside the cybersecurity clauses runs an independent acquisition gate. Under 10 U.S.C. §3252 and DFARS Subpart 239.73, authorized officials may exclude a source, withhold consent to subcontract with a source, or direct source exclusion in a covered procurement after a required determination and notification process. DFARS 252.239-7018 separately requires the contractor to mitigate supply-chain risk in supplies and services furnished to the government.

The independent-gate principle

A technology can satisfy CMMC, NIST SP 800-171, FedRAMP authorization or equivalency, export-control and data-security requirements — and still be prohibited on a particular defense contract because the source has been excluded or ordered removed.

Reading every technology decision through four gates makes that risk visible before it becomes an emergency migration:

GateThe questionTypical evidenceFailure consequence
1 · Data authorityWhat information is involved — FCI, CUI, CDI, export-controlled, classified?Contract, CUI markings, data inventory, export classificationWrong protection, release or authorization model
2 · Cybersecurity baselineWhich FAR, DFARS, NIST and CMMC duties apply?SSP, assessment results, SPRS score, control evidenceControl or contract noncompliance
3 · Offering qualificationDoes the exact service meet cloud, incident, forensic, location and scope requirements?Authorization package, equivalency evidence, shared-responsibility matrixOffering is unsuitable even if the vendor is generally approved
4 · Source allowabilityIs the vendor, model, API and material subprocessor permitted for this contract and mission?Contract clauses, modifications, contracting-officer direction, source-risk decisionExclude, replace or remove the source

Every gate must pass independently. Passing three of four is a failure. Most programs are well built for gates 2 and 3, assume gate 1, and have no process at all for gate 4 — which is precisely the gate that produces short-notice removal work.

Practical mitigations: keep an AI/ICT dependency register (an AIBOM/SBOM covering models, APIs, hosting platforms, agents, libraries, data sources, integrations, subprocessors and downstream consumers); require contract, program, supply-chain and legal review before a new source enters a defense workflow; and design for portability so a source restriction becomes a migration rather than an outage.

If you ever do have to remove a source

Confirm scope with the contracting officer; preserve incident and audit evidence before decommissioning; export only authorized records; revoke keys and service accounts; address vendor retention and backups; validate deletion; and reassess the replacement as a new external service. A rushed migration can create a fresh CUI exposure while closing an old one.

Key takeaways

  • FAR 52.204-21 is the floor — 15 safeguards wherever FCI lives, plus flowdown.
  • DFARS 7012 is the workhorse — CDI trigger, 110 Rev 2 requirements, SSP, 72-hour report, 90-day preservation, FedRAMP-Moderate-equivalent cloud, flowdown.
  • 7019 and 7020 are about the record — a current SPRS score (generally ≤3 years) and the government's authority to assess and overwrite it.
  • 7021 is the award condition — required CMMC status, UIDs, annual affirmation, flowdown, and up to 180 days of conditional status.
  • Source allowability is a fourth, independent gate. Compliance is not approval — inventory dependencies and design for portability.

Sources

Cloud consoles and federal guidance change; confirm control text and clause language against the official publication that applies to your contract. This article is independent education and does not by itself establish compliance or confer CMMC certification.

← Back to the knowledge base