Regulatory Guide

DFARS Cybersecurity Clauses: 7012, 7019, 7020, and 7021 Explained

Last updated: 2026-08-19

The Four Clauses at a Glance 252.204-7012 252.204-7019 252.204-7020 252.204-7021 Find Them in Your Contract

The Four Clauses at a Glance

If you handle Controlled Unclassified Information for the Department of Defense, four DFARS clauses in the 252.204-70xx family define your cybersecurity obligation. They are not interchangeable, and they do not all say the same thing. One requires you to secure your systems, one requires you to report a score, one lets the government check that score, and one requires a third-party certification. They travel together, so finding one tells you which of the others to expect.

This is a decoder for the family. For the full detail on the foundational clause, see the DFARS 252.204-7012 compliance guide; this page focuses on how the four clauses relate and what each one asks you to do.

DFARS 252.204-7012Safeguard CUI to the NIST SP 800-171 standard and report cyber incidents to the DoD within 72 hours. In force since December 2017. The foundation the other three build on.
DFARS 252.204-7019Self-assess against NIST SP 800-171 and post the score to SPRS before award. Your score has to be current, no more than three years old.
DFARS 252.204-7020Give the DoD the right to verify that your NIST SP 800-171 implementation matches the score you reported. The check on 7019.
DFARS 252.204-7021Achieve and maintain the required CMMC level as a condition of award. For most CUI work this is Level 2, which requires a C3PAO assessment instead of self-attestation.

252.204-7012: Safeguard CUI and Report Incidents

252.204-7012, "Safeguarding Covered Defense Information and Cyber Incident Reporting," is the foundational clause. It requires you to implement the 110 security requirements of NIST SP 800-171 on every system that processes, stores, or transmits CUI, to report cyber incidents affecting that information to the DoD within 72 hours of discovery, and to flow the same obligation down to subcontractors who handle CUI under your work.

The key thing to understand about 7012 is that it has been a contract term since 2017, well before CMMC. If this clause is in your contract, you are already required to be NIST SP 800-171 compliant today, independent of whether the CMMC clause has reached your contracts yet. The reporting and flow-down duties are covered in depth in the 7012 guide and the subcontractor flow-down article.

What 7012 obligates you to do
Implement all 110 NIST SP 800-171 requirements on CUI systems, stand up a documented 72-hour incident reporting process through the DIBNet portal, and include the substance of the clause in subcontracts where the subcontractor touches CUI.

252.204-7019: Submit Your SPRS Self-Assessment

252.204-7019 is the scoring clause. It requires you to assess your own NIST SP 800-171 implementation using the DoD Assessment Methodology and post the result to the Supplier Performance Risk System (SPRS) before a contract can be awarded. The methodology starts at 110 for full implementation and subtracts the weighted point value of each requirement you have not met, so scores can run negative.

Two details trip contractors up. First, the score has to be current: no more than three years old at time of award. Second, the score is not a private number. Contracting officers and primes read it as a supply-chain risk signal. An honest low score paired with an active plan is defensible; a score that overstates your posture is the exact fact pattern behind the government's False Claims Act cases. For how the number is built and how to keep it accurate, see the SPRS scoring guide, or calculate yours with the SPRS self-assessment tool.

252.204-7020: Let the Government Verify Your Score

252.204-7020 is the verification clause, and it is the reason a self-reported score is not the end of the story. It gives the DoD the right to conduct or commission a higher-level assessment of your NIST SP 800-171 implementation, to confirm that what you posted to SPRS reflects what you have actually built. It also obligates you to keep your assessment current and to flow the same access-for-verification requirement down to subcontractors handling CUI.

In practice, 7020 is what turns 7019 from an honor system into a checkable claim. It almost always appears alongside 7012 and 7019 in current CUI contracts, whether or not the CMMC clause has arrived yet.

252.204-7021: The CMMC Certification Requirement

252.204-7021 is the CMMC clause. Where 7019 lets you attest to your own score, 7021 makes an independently verified CMMC certification a condition of award. For the large majority of contracts that involve CUI, the required level is CMMC Level 2, which is assessed by an accredited C3PAO against the same 110 NIST SP 800-171 requirements. It adds no new technical controls; what it adds is the third-party assessment.

7021 is being phased into new solicitations on a rolling basis rather than appearing everywhere at once, which is why you may see 7012, 7019, and 7020 in a contract without 7021 yet. When 7021 is present, self-attestation is no longer sufficient for that award. For the certification itself, see what CMMC Level 2 is, and note that certification also brings an ongoing annual affirmation duty.

How the Four Clauses Chain Together

Read in order, the family tells one story. 7012 says protect the information and report incidents. 7019 says prove where you stand by posting a score. 7020 says the government can check that score. 7021 says an accredited assessor, not you, will confirm you meet the standard. Each clause closes a gap the previous one leaves open, which is why they are written to work as a set rather than as alternatives.

7012 alone (older contracts)You must implement NIST SP 800-171 and report incidents. Self-attestation, no posted score required by this clause on its own.
7012 + 7019 + 7020The current baseline for CUI contracts. Implement the controls, post a current SPRS score, and allow government verification of it. Self-attestation, but now scored and checkable.
7012 + 7019 + 7020 + 7021The full stack. Everything above, plus a valid CMMC certification from a C3PAO as a condition of award. Self-attestation is no longer sufficient.

The practical read: the presence of 7012 today means CMMC is coming to that work, and the presence of 7021 means it is already required. Neither one lets you defer NIST SP 800-171 implementation, because that obligation lives in 7012 and has since 2017.

How to Find These Clauses in Your Contract

You do not need to wait for someone to tell you these clauses apply. They are written into the contract, and you can find them yourself in a few minutes.

Section I, Contract ClausesFederal contracts list their clauses in Section I. Open it and scan for any entry beginning with 252.204-70. Clauses are often incorporated "by reference," so you may see only the number and title, not the full text.
Search the documentSearch the contract or solicitation PDF for 7012, 7019, 7020, and 7021, and for the phrase "Covered Defense Information." A hit on any of them means the family applies.
Section K, RepresentationsIn a solicitation, 7019 shows up here too: it requires you to represent that you have a current SPRS score on file. If you are being asked to confirm a score, 7019 is in play.
Ask your primeAs a subcontractor, your obligation can flow from the prime's contract even when your own paperwork is thin. If you receive CUI from a prime, assume the family applies and confirm in writing.
What to do when you find each one
Find 7012: confirm your CUI scope and stand up NIST SP 800-171 and a 72-hour reporting process. Find 7019: make sure a current, honest SPRS score is posted. Find 7020: be ready to show that your implementation matches that score. Find 7021: plan for a C3PAO assessment at the required level, and book early, because assessment slots are limited.

Frequently Asked Questions

What is DFARS 252.204-7019?

252.204-7019 requires you to perform a NIST SP 800-171 self-assessment using the DoD Assessment Methodology and post the resulting score to SPRS before award. The score has to be current, no more than three years old. It is the clause that turns your compliance posture into a number the government and your primes can see.

What is DFARS 252.204-7020?

252.204-7020 gives the DoD the right to verify that your NIST SP 800-171 implementation matches the score you posted under 7019. It also requires you to keep the score current and to extend the same verification right to subcontractors who handle CUI. It is the check that keeps the self-reported score honest.

What is DFARS 252.204-7021?

252.204-7021 is the CMMC clause. It makes a specific CMMC certification level a condition of award. For most CUI work that level is Level 2, which is assessed by a C3PAO rather than self-attested. It adds no new controls beyond NIST SP 800-171; it adds the independent assessment.

Do all four clauses appear together?

7012, 7019, and 7020 travel together in current CUI contracts. 7021 is being phased into new solicitations on a rolling basis, so you may see the first three without 7021 yet. Seeing 7012 is a strong signal that 7021 is coming to that work, because the underlying obligation is the same.

What is the difference between 252.204-7012 and 252.204-7021?

7012 requires you to implement NIST SP 800-171 and to self-attest; it has applied since 2017. 7021 requires an independently verified CMMC certification from a C3PAO for the same 110 requirements. 7021 does not replace 7012, it sits on top of it and adds third-party verification. See the 7012 guide for the foundational detail.

Where do I find these clauses in my contract?

Look in Section I (Contract Clauses) of the contract or solicitation, or search the document for 252.204-7012, 7019, 7020, and 7021, and for "Covered Defense Information." In a solicitation, also check the Section K representations, where 7019 asks you to confirm a current SPRS score.

Structure your posture.

1TEN provides the GRC framework defense manufacturers need to track, score, and evidence their CMMC Level 2 posture.

Request a Demo