The Four Clauses at a Glance
If you handle Controlled Unclassified Information for the Department of Defense, four DFARS clauses in the 252.204-70xx family define your cybersecurity obligation. They are not interchangeable, and they do not all say the same thing. One requires you to secure your systems, one requires you to report a score, one lets the government check that score, and one requires a third-party certification. They travel together, so finding one tells you which of the others to expect.
This is a decoder for the family. For the full detail on the foundational clause, see the DFARS 252.204-7012 compliance guide; this page focuses on how the four clauses relate and what each one asks you to do.
| DFARS 252.204-7012 | Safeguard CUI to the NIST SP 800-171 standard and report cyber incidents to the DoD within 72 hours. In force since December 2017. The foundation the other three build on. |
| DFARS 252.204-7019 | Self-assess against NIST SP 800-171 and post the score to SPRS before award. Your score has to be current, no more than three years old. |
| DFARS 252.204-7020 | Give the DoD the right to verify that your NIST SP 800-171 implementation matches the score you reported. The check on 7019. |
| DFARS 252.204-7021 | Achieve and maintain the required CMMC level as a condition of award. For most CUI work this is Level 2, which requires a C3PAO assessment instead of self-attestation. |
252.204-7012: Safeguard CUI and Report Incidents
252.204-7012, "Safeguarding Covered Defense Information and Cyber Incident Reporting," is the foundational clause. It requires you to implement the 110 security requirements of NIST SP 800-171 on every system that processes, stores, or transmits CUI, to report cyber incidents affecting that information to the DoD within 72 hours of discovery, and to flow the same obligation down to subcontractors who handle CUI under your work.
The key thing to understand about 7012 is that it has been a contract term since 2017, well before CMMC. If this clause is in your contract, you are already required to be NIST SP 800-171 compliant today, independent of whether the CMMC clause has reached your contracts yet. The reporting and flow-down duties are covered in depth in the 7012 guide and the subcontractor flow-down article.
252.204-7019: Submit Your SPRS Self-Assessment
252.204-7019 is the scoring clause. It requires you to assess your own NIST SP 800-171 implementation using the DoD Assessment Methodology and post the result to the Supplier Performance Risk System (SPRS) before a contract can be awarded. The methodology starts at 110 for full implementation and subtracts the weighted point value of each requirement you have not met, so scores can run negative.
Two details trip contractors up. First, the score has to be current: no more than three years old at time of award. Second, the score is not a private number. Contracting officers and primes read it as a supply-chain risk signal. An honest low score paired with an active plan is defensible; a score that overstates your posture is the exact fact pattern behind the government's False Claims Act cases. For how the number is built and how to keep it accurate, see the SPRS scoring guide, or calculate yours with the SPRS self-assessment tool.
252.204-7020: Let the Government Verify Your Score
252.204-7020 is the verification clause, and it is the reason a self-reported score is not the end of the story. It gives the DoD the right to conduct or commission a higher-level assessment of your NIST SP 800-171 implementation, to confirm that what you posted to SPRS reflects what you have actually built. It also obligates you to keep your assessment current and to flow the same access-for-verification requirement down to subcontractors handling CUI.
In practice, 7020 is what turns 7019 from an honor system into a checkable claim. It almost always appears alongside 7012 and 7019 in current CUI contracts, whether or not the CMMC clause has arrived yet.
252.204-7021: The CMMC Certification Requirement
252.204-7021 is the CMMC clause. Where 7019 lets you attest to your own score, 7021 makes an independently verified CMMC certification a condition of award. For the large majority of contracts that involve CUI, the required level is CMMC Level 2, which is assessed by an accredited C3PAO against the same 110 NIST SP 800-171 requirements. It adds no new technical controls; what it adds is the third-party assessment.
7021 is being phased into new solicitations on a rolling basis rather than appearing everywhere at once, which is why you may see 7012, 7019, and 7020 in a contract without 7021 yet. When 7021 is present, self-attestation is no longer sufficient for that award. For the certification itself, see what CMMC Level 2 is, and note that certification also brings an ongoing annual affirmation duty.
How the Four Clauses Chain Together
Read in order, the family tells one story. 7012 says protect the information and report incidents. 7019 says prove where you stand by posting a score. 7020 says the government can check that score. 7021 says an accredited assessor, not you, will confirm you meet the standard. Each clause closes a gap the previous one leaves open, which is why they are written to work as a set rather than as alternatives.
| 7012 alone (older contracts) | You must implement NIST SP 800-171 and report incidents. Self-attestation, no posted score required by this clause on its own. |
| 7012 + 7019 + 7020 | The current baseline for CUI contracts. Implement the controls, post a current SPRS score, and allow government verification of it. Self-attestation, but now scored and checkable. |
| 7012 + 7019 + 7020 + 7021 | The full stack. Everything above, plus a valid CMMC certification from a C3PAO as a condition of award. Self-attestation is no longer sufficient. |
The practical read: the presence of 7012 today means CMMC is coming to that work, and the presence of 7021 means it is already required. Neither one lets you defer NIST SP 800-171 implementation, because that obligation lives in 7012 and has since 2017.
How to Find These Clauses in Your Contract
You do not need to wait for someone to tell you these clauses apply. They are written into the contract, and you can find them yourself in a few minutes.
| Section I, Contract Clauses | Federal contracts list their clauses in Section I. Open it and scan for any entry beginning with 252.204-70. Clauses are often incorporated "by reference," so you may see only the number and title, not the full text. |
| Search the document | Search the contract or solicitation PDF for 7012, 7019, 7020, and 7021, and for the phrase "Covered Defense Information." A hit on any of them means the family applies. |
| Section K, Representations | In a solicitation, 7019 shows up here too: it requires you to represent that you have a current SPRS score on file. If you are being asked to confirm a score, 7019 is in play. |
| Ask your prime | As a subcontractor, your obligation can flow from the prime's contract even when your own paperwork is thin. If you receive CUI from a prime, assume the family applies and confirm in writing. |