Mandatory cybersecurity compliance for Department of Defense (DoD) contracts is governed by a combination of federal regulations and security standards designed to protect sensitive government information.
NIST SP 800-171 – Protection of Controlled Unclassified Information (CUI)
NIST SP 800-171 is the set of cybersecurity requirements that all DoD contractors must follow to protect Federal Contract Information (FCI) and Controlled Unclassified Information (CUI).
These requirements are incorporated into DoD contracts through DFARS 252.204-7012 and related clauses and apply to both prime contractors and subcontractors.
FAR 52.204-21 – Basic Safeguarding of Covered Contractor Information Systems
FAR 52.204-21 establishes the minimum cybersecurity requirements for any contractor or subcontractor that handles or may have access to Federal Contract Information (FCI). These safeguards apply broadly across DoD contracts and require basic protections such as access control, data handling procedures, and system security measures.
DFARS 252.204-7012 – Safeguarding Covered Defense Information and Cyber Incident Reporting
DFARS 252.204-7012 is the DoD clause that requires contractors and subcontractors to safeguard Covered Defense Information (CDI) and to report certain cybersecurity incidents that affect DoD information systems.
This clause applies to any contractor or subcontractor that processes, stores, or transmits CDI, which includes Controlled Unclassified Information (CUI) and other sensitive defense-related information. When DFARS 252.204-7012 is included in a contract, it imposes specific cybersecurity and reporting obligations.
Key Requirements Under DFARS 252.204-7012:
Contractors and subcontractors must:
- Implement and maintain cybersecurity controls in accordance with NIST SP 800-171
- Provide adequate security to protect Covered Defense Information
- Rapidly report cyber incidents that affect CDI (generally within 72 hours)
- Preserve and protect affected systems and data for forensic analysis
- Flow down applicable requirements to subcontractors at all tiers
Relationship to CMMC
DFARS 252.204-7012 establishes the underlying safeguarding and reporting requirements, while CMMC 2.0 provides the DoD’s framework for verifying compliance with those requirements. If your organization is required to comply with CMMC, it is because DFARS 252.204-7012 (and related clauses) apply to the work being performed.
DFARS 252.204-7021 – Contractor Compliance With the Cybersecurity Maturity Model Certification (CMMC) Level Requirements
DFARS 252.204-7021 implements the Cybersecurity Maturity Model Certification (CMMC) 2.0 framework, which is the DoD’s mechanism for verifying compliance with applicable cybersecurity requirements.
Under CMMC 2.0, contractors and subcontractors must:
- Maintain a current certification level (1, 2, or 3 depending on the specific contract requirements)
- Meet the appropriate CMMC level based on the type of information accessed (FCI or CUI)
- Complete annual affirmations of compliance
- Maintain required documentation and security practices
- Obtain third-party certification where applicable
CMMC Level 1 applies to contractors, subcontractors, vendors, and suppliers that store, process, or transmit FCI only (not CUI). Compliance requires implementation of seventeen (17) basic safeguarding requirements derived from FAR 52.204-21.
In Simple Terms
- NIST SP 800-171 = Detailed cybersecurity controls for protecting Controlled Unclassified Information (CUI)
- CMMC = The Department of Defense’s framework for verifying and enforcing compliance with these cybersecurity requirements
- FAR 52.204-21 = Basic cybersecurity requirements for protecting Federal Contract Information (FCI)
- DFARS 252.204-7012 = Requires safeguarding Covered Defense Information (CDI) and reporting qualifying cybersecurity incidents
- DFARS 252.204-7021 = Implements CMMC 2.0 requirements and defines when certification and compliance validation are required
Compliance with these standards is no longer optional and will be required for applicable Department of Defense task orders and solicitations beginning in 2026.