FAR 52.204-21 protects FCI with 15 basic safeguards. DFARS 252.204-7012 is the workhorse: it triggers on CDI and requires adequate security, NIST SP 800-171 Rev 2, a 72-hour incident report, 90-day media preservation, FedRAMP-Moderate-equivalent cloud protection, and flowdown. -7019 requires a current SPRS score before award (generally not more than three years old). -7020 gives the government assessment access, defines the Basic/Medium/High confidence levels, and restricts subcontract award without a current Basic Assessment. -7021 makes a specified CMMC status a condition of award, with annual affirmations and up to 180 days of conditional status. Underneath all of it runs a separate gate — source allowability — where a technology that satisfies every one of these can still be excluded from a covered contract.
The summaries below describe the operative function of each clause. Applicability must always be verified against your actual solicitation, contract, order, and flowdowns — this is educational analysis, not legal advice or contract review.
The five-clause map
Almost all defense cybersecurity obligation flows from five clauses. Teams that can state each clause's trigger, obligation, and flowdown from memory make dramatically better scoping decisions than teams that treat “compliance” as one undifferentiated blob.
FAR 52.204-21 — Basic Safeguarding
Trigger. A contractor or subcontractor information system may have FCI residing in or transiting through it. The substance flows down when a subcontractor may handle FCI, including commercial-product and commercial-service subcontracts other than COTS items.
Obligation. Apply 15 basic safeguarding requirements, covering access limitation, authentication, external-system controls, media sanitization, physical protection, boundary protection, flaw remediation, malicious-code protection, and system scanning.
This is the government-wide floor for contractor systems handling FCI. CMMC Level 1 uses the same 15 requirements and adds an annual self-assessment and affirmation when the acquisition requires that CMMC status. If you do federal work of any kind, this is your baseline — not an advanced goal.
DFARS 252.204-7012 — Safeguarding CDI and Cyber Incident Reporting
Trigger. A covered contractor information system processes, stores, or transmits CDI, or the contractor provides operationally critical support identified in the contract.
Obligations. This is the densest clause in the stack:
- Provide adequate security, implementing the 110 requirements of NIST SP 800-171 Rev 2 for applicable covered systems.
- Document the implementation in a System Security Plan (SSP).
- Rapidly report qualifying cyber incidents within 72 hours.
- Preserve and protect system images and relevant monitoring data for at least 90 days.
- Submit malicious software when requested, and support Department forensic and damage-assessment activities.
- Flow the clause down to qualifying subcontractors.
Cloud. If an external cloud service provider stores, processes, or transmits CDI in contract performance, the contractor must require and ensure that the CSP meets security requirements equivalent to the FedRAMP Moderate baseline, and complies with the clause's incident, malicious-software, preservation, forensic-access, and damage-assessment provisions.
DFARS 7012 does not name GCC High and does not prohibit every commercial offering. The determination is offering-specific: validate FedRAMP authorization or documented equivalency, the additional paragraphs, contract terms, CMMC scope, export controls, and support-personnel access before selecting the service. See GCC High vs. Commercial Microsoft 365.
DFARS 252.204-7019 — Pre-Award Assessment Notice
An offeror required to implement NIST SP 800-171 must verify that current summary-level scores are posted in SPRS for every covered contractor information system relevant to the offer.
“Current” generally means not more than three years old, unless the solicitation specifies a shorter period. If no current score exists, the offeror may conduct and submit a Basic Assessment for posting.
In practice this clause is a quiet eligibility gate: a missing or stale score can remove you from consideration before anyone evaluates your technical proposal. If you are unsure how the number is produced, start with Your SPRS Score, Explained.
DFARS 252.204-7020 — Government Assessment and Supply-Chain Verification
The contractor must provide access to facilities, systems, and personnel needed for a government Medium or High NIST SP 800-171 DoD Assessment. The clause establishes the Basic, Medium and High assessment confidence levels, provides a rebuttal process for government assessments, and restricts subcontract award when an applicable subcontractor lacks a current Basic Assessment.
A self-generated SPRS score is a low-confidence score — it is not a certification. Maintain the SSP, the score worksheet, objective-level evidence, and POA&M history so the posted result can survive government review. A Medium or High assessment can overwrite your number.
DFARS 252.204-7021 — CMMC Contract Requirement
When the clause and a specified CMMC status are included, the contractor must hold the required status — or a higher eligible status — for each contractor information system that will process, store, or transmit FCI or CUI in performance; maintain that status; complete annual affirmations; identify applicable CMMC UIDs; and flow the appropriate status to subcontractors and suppliers.
The clause permits Level 2 and Level 3 conditional status for no more than 180 days when the applicable POA&M criteria are satisfied. Award may occur with an eligible conditional status; Level 1 requires a final status.
During the CMMC Phase II suspension, requiring activities may use only Level 1 (Self) or Level 2 (Self). They may not designate Level 2 (C3PAO) or Level 3 (DIBCAC) requirements; active solicitations containing those designations are to be amended, and existing contracts modified as directed. The clause itself is unchanged — what is paused is which assessment types may be designated.
Clause relationships at a glance
| Authority | Primary job | Assessment / record | Flowdown |
|---|---|---|---|
| FAR 52.204-21 | Protect FCI systems | 15 safeguards; no FAR score | Qualifying FCI subcontracts |
| DFARS 7012 | Protect CDI and report incidents | SSP, NIST 800-171 implementation, incident evidence | Qualifying CDI subcontracts |
| DFARS 7019 | Pre-award SPRS notice | Current summary-level score | Operates with the 7012 / 7020 structure |
| DFARS 7020 | Government assessment authority | Basic, Medium or High assessment | Subcontract assessment eligibility |
| DFARS 7021 | CMMC award and performance condition | CMMC status, UID and annual affirmation | Appropriate level by information flowed down |
The four gates — and the one most programs skip
Alongside the cybersecurity clauses runs an independent acquisition gate. Under 10 U.S.C. §3252 and DFARS Subpart 239.73, authorized officials may exclude a source, withhold consent to subcontract with a source, or direct source exclusion in a covered procurement after a required determination and notification process. DFARS 252.239-7018 separately requires the contractor to mitigate supply-chain risk in supplies and services furnished to the government.
A technology can satisfy CMMC, NIST SP 800-171, FedRAMP authorization or equivalency, export-control and data-security requirements — and still be prohibited on a particular defense contract because the source has been excluded or ordered removed.
Reading every technology decision through four gates makes that risk visible before it becomes an emergency migration:
| Gate | The question | Typical evidence | Failure consequence |
|---|---|---|---|
| 1 · Data authority | What information is involved — FCI, CUI, CDI, export-controlled, classified? | Contract, CUI markings, data inventory, export classification | Wrong protection, release or authorization model |
| 2 · Cybersecurity baseline | Which FAR, DFARS, NIST and CMMC duties apply? | SSP, assessment results, SPRS score, control evidence | Control or contract noncompliance |
| 3 · Offering qualification | Does the exact service meet cloud, incident, forensic, location and scope requirements? | Authorization package, equivalency evidence, shared-responsibility matrix | Offering is unsuitable even if the vendor is generally approved |
| 4 · Source allowability | Is the vendor, model, API and material subprocessor permitted for this contract and mission? | Contract clauses, modifications, contracting-officer direction, source-risk decision | Exclude, replace or remove the source |
Every gate must pass independently. Passing three of four is a failure. Most programs are well built for gates 2 and 3, assume gate 1, and have no process at all for gate 4 — which is precisely the gate that produces short-notice removal work.
Practical mitigations: keep an AI/ICT dependency register (an AIBOM/SBOM covering models, APIs, hosting platforms, agents, libraries, data sources, integrations, subprocessors and downstream consumers); require contract, program, supply-chain and legal review before a new source enters a defense workflow; and design for portability so a source restriction becomes a migration rather than an outage.
Confirm scope with the contracting officer; preserve incident and audit evidence before decommissioning; export only authorized records; revoke keys and service accounts; address vendor retention and backups; validate deletion; and reassess the replacement as a new external service. A rushed migration can create a fresh CUI exposure while closing an old one.
Key takeaways
- FAR 52.204-21 is the floor — 15 safeguards wherever FCI lives, plus flowdown.
- DFARS 7012 is the workhorse — CDI trigger, 110 Rev 2 requirements, SSP, 72-hour report, 90-day preservation, FedRAMP-Moderate-equivalent cloud, flowdown.
- 7019 and 7020 are about the record — a current SPRS score (generally ≤3 years) and the government's authority to assess and overwrite it.
- 7021 is the award condition — required CMMC status, UIDs, annual affirmation, flowdown, and up to 180 days of conditional status.
- Source allowability is a fourth, independent gate. Compliance is not approval — inventory dependencies and design for portability.
Sources
- Acquisition.gov — FAR 52.204-21 (basic safeguarding) ↗
- Acquisition.gov — DFARS 252.204-7012 (safeguarding CDI and cyber incident reporting) ↗
- Acquisition.gov — DFARS 252.204-7019 (notice of NIST SP 800-171 DoD assessment requirements) ↗
- Acquisition.gov — DFARS 252.204-7020 (NIST SP 800-171 DoD assessment requirements) ↗
- Acquisition.gov — DFARS 252.204-7021 (CMMC status requirement) ↗
- Acquisition.gov — DFARS Subpart 239.73 (supply chain risk) ↗
- Acquisition.gov — DFARS 252.239-7018 (supply chain risk) ↗
- NIST SP 800-171 Rev 2 (Protecting CUI in nonfederal systems) ↗
Cloud consoles and federal guidance change; confirm control text and clause language against the official publication that applies to your contract. This article is independent education and does not by itself establish compliance or confer CMMC certification.