DFARS 252.204-7019Notice of NIST SP 800-171 DoD Assessment Requirements
Looking for the official text? Read DFARS 252.204-7019 (NOV 2023) at acquisition.gov. It is a solicitation provision, so it binds the Offeror before award. Everything below is checked against that text.
Overview
DFARS 252.204-7019 is a solicitation provision — not a contract clause — in its NOV 2023 version, prescribed at DFARS 204.7304(d). It binds the Offeror rather than the Contractor: paragraph (b) says that “in order to be considered for award, if the Offeror is required to implement NIST SP 800-171, the Offeror shall have a current assessment (i.e., not more than 3 years old unless a lesser time is specified in the solicitation)” for each covered contractor information system relevant to the offer. Paragraph (c)(1) requires the Offeror to verify that its summary level scores are posted in the Supplier Performance Risk System (SPRS); paragraph (c)(2) says that if they are not, the Offeror may conduct and submit a Basic Assessment. Paragraph (d) sets the posting timeline: summary level scores are posted 30 days post-assessment in SPRS. Everything about subcontractors — the flowdown, and the bar on awarding a subcontract to a firm without a current Basic Assessment — is in the companion clause 252.204-7020(g), not here.
This is a provision, not a clause
Provisions go into solicitations and impose obligations on the Offeror; clauses go into contracts and impose obligations on the Contractor. DFARS 252.204-7019 is prescribed with the words “use the following provision”, so it does its work before award and is not carried into the awarded contract. That is also why it has no subcontract paragraph.
Do not confuse it with DFARS 252.204-7020
DFARS 252.204-7020 is the post-award clause that carries the same assessment requirement into contract performance — and, at paragraph (g), the subcontract flowdown and the bar on awarding a NIST SP 800-171-relevant subcontract to a firm without a current Basic Assessment. Read DFARS 252.204-7020.
Still in force after the CMMC Phase 2 suspension — July 13, 2026
The Department of War suspended CMMC Phase 2 on July 13, 2026 pending an acquisition-reform review, which paused third-party (C3PAO) certification as a condition of award. It did not amend DFARS 252.204-7012, 252.204-7019 or 252.204-7020 — those were never part of the CMMC rule and bind you today exactly as they did before. What changed, and what still binds.
When Does This Apply?
DoD solicitations, including solicitations for commercial products and commercial services, where the resulting contract will contain DFARS 252.204-7012 and the offeror is therefore required to implement NIST SP 800-171. Because it is a provision, it does its work before award and is not physically carried into the awarded contract; the ongoing assessment obligations you perform under the contract come from clause 252.204-7020.
Key Requirements
- 1Hold a current assessment before award — “not more than 3 years old unless a lesser time is specified in the solicitation” (paragraph (b))
- 2Verify the summary level scores are actually posted in SPRS for every covered contractor information system relevant to the offer (paragraph (c)(1))
- 3If no current score is posted, the Offeror may conduct and submit a Basic Assessment — a self-assessment, conducted under the NIST SP 800-171 DoD Assessment Methodology (paragraph (c)(2))
- 4Expect a 30-day lag: summary level scores are posted 30 days post-assessment in SPRS (paragraph (d))
- 5Score on the DoD Assessment Methodology scale, which runs from +110 down to −203 — not one point per requirement
Work out the score this provision asks for
The number in SPRS is not “how many of the 110 requirements did you do”. Under the NIST SP 800-171 DoD Assessment Methodology — the methodology both 252.204-7019 and 252.204-7020 cite by name — 44 requirements are worth 5 points, 14 are worth 3 and 51 are worth 1, with partial credit on 3.5.3 (MFA) and 3.13.11 (FIPS-validated cryptography) and no points at all on 3.12.4, the System Security Plan, which gates whether the assessment can be conducted. The scale runs from +110 to -203.
Free, no signup, and nothing you enter leaves your browser. Built from NIST SP 800-171 DoD Assessment Methodology, Version 1.2.1 (June 24, 2020), Annex A / §5.
Flowdown to Subcontractors
No — DFARS 252.204-7019 does not flow down to subcontractors of its own force.
A solicitation provision prescribed at DFARS 204.7304(d). Its paragraphs run (a) through (d) and every obligation in them is the Offeror’s; there is no subcontract paragraph. Subcontractor flowdown for the same assessment requirement lives in the contract clause 252.204-7020, at its paragraph (g).
Checked against the provision text at acquisition.gov, read 27 July 2026.
Real-World Example
A mid-size IT services contractor bids a DoD cybersecurity modernization contract whose solicitation contains 252.204-7019. Its ISSO ran an assessment three and a half years earlier and never refreshed it, so the summary level score in SPRS is stale under paragraph (b) — “not more than 3 years old” — and the offer cannot be considered for award on that basis alone, whatever its technical merit. The fix is not an assessor engagement, because a Basic Assessment is a self-assessment: paragraph (c)(2) lets the Offeror conduct one and submit it for posting. What actually costs the bid is paragraph (d), the 30-day posting lag, which the team discovers eight days before the proposal is due. The second lesson lands after award, and it is a different instrument: under 252.204-7020(g)(2) the prime may not award a NIST SP 800-171-relevant subcontract unless the subcontractor “has completed, within the last 3 years, at least a Basic NIST SP 800-171 DoD Assessment” — so the teaming questions the prime should have asked during capture were owed under 7020, not 7019.
Why This Matters for Your Business
252.204-7019 is a gate on eligibility, not a scoring factor: paragraph (b) conditions being “considered for award” on holding a current assessment, so a missing or stale SPRS score can end an otherwise winning proposal without any evaluation of its merits. Two things are widely got wrong about it, and both cost money. First, it is a provision that binds the Offeror and has no flowdown paragraph — a prime that believes it is flowing 7019 down is not doing the thing the regulation actually requires, which is the pre-award check in 252.204-7020(g)(2) that the subcontractor holds a Basic Assessment less than three years old. Second, the Basic Assessment behind the score is a self-assessment carrying a “Low” confidence level precisely because it is self-generated, which makes the number a representation to the Government rather than an assessor’s finding. The Department of War’s July 13, 2026 suspension of CMMC Phase 2 paused third-party certification and left 7012, 7019 and 7020 exactly where they were — so for the moment the self-generated score is the only number the Government has, and the Department of Justice Civil Cyber-Fraud Initiative has made clear that an inaccurate one is False Claims Act exposure rather than an evaluation deduction.
Compliance Checklist for DFARS 252.204-7019
- 1ISSO confirms a current system security plan exists for every covered contractor information system relevant to the offer — requirement 3.12.4 scores nothing but the assessment cannot be conducted without it.
- 2ISSO scores all 110 requirements under the NIST SP 800-171 DoD Assessment Methodology weights (44 at five points, 14 at three, 51 at one) rather than counting requirements met.
- 3Contracts verifies in SPRS that the summary level score is posted — not merely submitted — for each relevant system, as paragraph (c)(1) requires.
- 4Contracts checks the assessment date against the solicitation, which may specify less than the default three years under paragraph (b).
- 5If no current score is posted, ISSO conducts a Basic Assessment under paragraph (c)(2) and submits it at least 30 days before the proposal is due, allowing for the paragraph (d) posting lag.
- 6Capture lead collects subcontractor SPRS status under DFARS 252.204-7020(g)(2) — the prime may not award a NIST SP 800-171-relevant subcontract unless the subcontractor completed at least a Basic Assessment within the last three years.
- 7Program manager diarises the next assessment before the three-year window closes, so no proposal is ever blocked by an expired score.
- 8Compliance officer records the evidence behind each requirement’s score, since a self-generated score is a representation to the Government and must be defensible line by line.
Estimated Compliance Cost
The assessment itself has no invoice. A Basic Assessment is a self-assessment conducted under the DoD Assessment Methodology, so its direct cost is internal time — typically an ISSO or security lead working through 110 requirements against the system security plan, plus the contracts time to verify the posting in SPRS. Budgeting a C3PAO fee against 252.204-7019 is a category error; C3PAO assessments belong to CMMC, whose third-party leg was suspended on July 13, 2026. What does cost money is whatever the score reveals: closing unmet requirements before the next assessment, and the two prerequisites the methodology assumes — a system security plan (requirement 3.12.4, which scores nothing but gates the assessment) and a defensible scope boundary. Prioritise by weight rather than by count: 44 five-point requirements hold 220 of the 313 deductible points, so a handful of them moves the score further than sweeping every one-point item.
Cross-References & Related Requirements
252.204-7019 sits between two clauses and is often confused with both. DFARS 252.204-7012 is the substantive obligation — implement NIST SP 800-171 and report cyber incidents — and 7019 exists to make the resulting score visible before award. DFARS 252.204-7020 is 7019’s post-award counterpart: same NIST SP 800-171 DoD Assessment Methodology, same three-year currency window, but it adds the Government’s access rights for Medium and High Assessments and, at paragraph (g), the subcontract flowdown and the bar on awarding a subcontract to a firm without a current Basic Assessment. DFARS 252.204-7021 layers CMMC on top and reads the same SPRS score; its third-party assessment leg was suspended on July 13, 2026, which changed nothing in 7012, 7019 or 7020. On the control side, the scored requirements are the whole of NIST SP 800-171 rather than a subset, with the CA family (3.12.1 through 3.12.4) governing the assessment activity itself.
How This Clause Affects Your Proposal
Treat it as a responsibility gate you clear before the proposal, not a section you write. Do three things in order. First, log into SPRS and confirm what is actually posted for each covered contractor information system relevant to the offer — paragraph (c)(1) asks you to verify, and “we submitted it” is not the same as “it is posted”. Second, check the date against the solicitation, not against a three-year rule of thumb: the parenthetical is “not more than 3 years old unless a lesser time is specified in the solicitation”. Third, if nothing is posted, use paragraph (c)(2) — conduct a Basic Assessment and submit it — and start at least 30 days out, because paragraph (d) posts summary level scores 30 days post-assessment. For teaming, ask your subcontractors for their SPRS status during capture, but ask for the right reason: the obligation is 252.204-7020(g)(2), which bars you from awarding a NIST SP 800-171-relevant subcontract to a firm without a Basic Assessment completed in the last three years. Do not represent a score you have not computed line by line.
Frequently Asked Questions
What is DFARS 252.204-7019?
DFARS 252.204-7019, Notice of NIST SP 800-171 DoD Assessment Requirements (NOV 2023), is the solicitation provision that makes a current NIST SP 800-171 assessment score a condition of being considered for award. Paragraph (b): “In order to be considered for award, if the Offeror is required to implement NIST SP 800-171, the Offeror shall have a current assessment (i.e., not more than 3 years old unless a lesser time is specified in the solicitation)” for each covered contractor information system relevant to the offer. Paragraph (c)(1) makes the Offeror verify that its summary level scores are posted in the Supplier Performance Risk System (SPRS); (c)(2) lets an Offeror without a posted score conduct and submit a Basic Assessment; (d) states that summary level scores are posted 30 days post-assessment. It is a provision, so it binds the Offeror at proposal time and contains no subcontractor flowdown.
Does DFARS 252.204-7019 flow down to subcontractors?
No. DFARS 252.204-7019 does not flow down to subcontractors of its own force, and this page said the opposite until 27 July 2026. It is a solicitation provision prescribed at DFARS 204.7304(d); its paragraphs run (a) through (d) and every obligation in them is the Offeror’s, with no subcontract paragraph anywhere in it. The obligation people attribute to 7019 belongs to the clause 252.204-7020, at paragraph (g): “The Contractor shall insert the substance of this clause, including this paragraph (g), in all subcontracts and other contractual instruments, including subcontracts for the acquisition of commercial products or commercial services (excluding commercially available off-the-shelf),” and the Contractor “shall not award a subcontract … unless the subcontractor has completed, within the last 3 years, at least a Basic NIST SP 800-171 DoD Assessment.” If you are writing subcontract terms, cite 7020(g), not 7019.
Is DFARS 252.204-7019 a clause or a provision?
A provision. acquisition.gov prescribes it at DFARS 204.7304(d) with the words “use the following provision”, and the distinction is not pedantry. Provisions go into solicitations and impose obligations on the Offeror; clauses go into contracts and impose obligations on the Contractor. That is why 252.204-7019 has no flowdown paragraph and why the obligations you perform after award — including the subcontract rules — come from the clause 252.204-7020 instead. Most secondary sources, ours included until this correction, call 7019 a clause.
What is the difference between DFARS 252.204-7019 and 252.204-7020?
They are two halves of one requirement. 252.204-7019 is the solicitation provision: before award, the Offeror must have a current assessment and must verify the score is posted in SPRS. 252.204-7020 is the contract clause: after award, the Contractor keeps a current score, gives DoD access if a Medium or High Assessment is ordered, and — at paragraph (g) — flows the clause down and may not award a subcontract subject to NIST SP 800-171 “unless the subcontractor has completed, within the last 3 years, at least a Basic NIST SP 800-171 DoD Assessment”. So if your question is “what do I have to do to bid?” the answer is in 7019; if it is “what do I have to make my subcontractors do?” the answer is in 7020(g).
What is a Basic Assessment, and who performs it?
You do. 252.204-7020(a) defines a Basic Assessment as “a contractor’s self-assessment of the contractor’s implementation of NIST SP 800-171 that is based on the Contractor’s review of their system security plan(s) associated with covered contractor information system(s); is conducted in accordance with the NIST SP 800-171 DoD Assessment Methodology; and results in a confidence level of ‘Low’ in the resulting score, because it is a self-generated score.” There is no assessor fee, because there is no assessor: the Basic Assessment is not a C3PAO engagement and never was. The Medium and High Assessments in the same definition paragraph are conducted by the Government, not purchased by you.
How current does my SPRS score have to be?
Not more than three years old, unless the solicitation specifies less — the parenthetical appears in 7019(b), in 7019(c)(1) and (c)(2), and again in 7020(g)(3) for subcontractors. Read the solicitation before assuming three years: the provision explicitly contemplates a shorter window being imposed. Note also the 30-day lag in 7019(d) — a score submitted the week a proposal is due may not be posted in time to be verified.
Does DFARS 252.204-7019 still apply after the CMMC Phase 2 suspension?
Yes. The Department of War suspended CMMC Phase 2 on July 13, 2026 pending an acquisition-reform review, which paused third-party (C3PAO) certification as a condition of award. It did not touch DFARS 252.204-7012, 252.204-7019 or 252.204-7020: those were never part of the CMMC rule and remain in force unchanged. If anything the suspension sharpens 7019, because with no assessor standing behind the number, the score you verify in SPRS is a self-generated representation to the Government — and the Department of Justice Civil Cyber-Fraud Initiative treats false cybersecurity attestations as False Claims Act material.
How is the SPRS score in DFARS 252.204-7019 calculated?
Under the NIST SP 800-171 DoD Assessment Methodology, which both 7019 and 7020 cite by name. You start at 110 and subtract the weight of every unmet requirement, and the weights are not equal: 44 requirements are worth 5 points, 14 are worth 3, and 51 are worth 1. Multi-factor authentication (3.5.3) and FIPS-validated cryptography (3.13.11) carry partial credit, and the System Security Plan (3.12.4) carries no points at all because it gates whether the assessment can be conducted. The scale therefore runs from +110 to −203, and a negative score is ordinary rather than an error.
When does DFARS 252.204-7019 apply?
It appears in DoD solicitations whose resulting contract will contain DFARS 252.204-7012 — that is, whenever the offeror is required to implement NIST SP 800-171 — and it operates before award. Because it is a provision, it is not carried into the awarded contract: once you are on contract, the live instrument is 252.204-7020.
Related Guides
Free Compliance Tools
SPRS Score Calculator
Your Basic Assessment score on the real DoD weights — 44 requirements at five points, 14 at three, 51 at one, +110 to −203.
🛡CUI Auditor
Audit your tech stack for CUI handling gaps across 80+ enterprise tools.
🗺CUI Flow Mapper
Map how CUI flows through your organization and identify spillage risks.
Is your tech stack DFARS 252.204-7019 compliant?
Run our free CUI Auditor to check if your tools meet this clause's requirements.
Audit Your Tech Stack FreeTurn this gap analysis into a remediation plan
This DFARS 252.204-7019 breakdown is the start, not the answer. Book a 25-minute compliance assessment — you leave with a prioritized roadmap and a fixed-fee implementation quote.
Book a 25-min assessmentRelated: how much CMMC certification costs — DoD’s own priced figures
Discussion
Share your experience implementing this in your organization.
Join the Club to unlock joining discussions
Free membership — access intelligence, save your work, and more.
Create free account