DFARS 252.204-7021Cybersecurity Maturity Model Certification Requirements
Looking for the official text? Read DFARS 252.204-7021 (NOV 2025) at acquisition.gov. It is a contract clause, so it binds the Contractor during performance. Everything below is checked against that text.
Overview
This clause implements the CMMC program and ties a specified CMMC level to DoD contracts. Level 1 covers basic safeguarding, Level 2 covers all 110 NIST 800-171 controls, and Level 3 adds enhanced controls. On July 13, 2026 the Department of War suspended Phase 2 of the rollout — third-party C3PAO assessment at Level 2 and Level 3 designation — as a condition of award, pending an acquisition-reform review. Phase 1 Level 1 and Level 2 self-assessments, in force since November 2025, are unaffected, and neither the clause nor the underlying rules have been rescinded.
This is a clause, not a provision
Clauses go into contracts and bind the Contractor during performance; provisions go into solicitations and bind the Offeror before award. DFARS 252.204-7021 is prescribed with the words “use the following clause”, so it governs how you perform, not how you bid.
When Does This Apply?
DoD contracts that specify a required CMMC level. Phase 1 self-assessment requirements are live; the Phase 2 transition to third-party assessment was suspended on July 13, 2026 pending review, and program managers may not designate C3PAO (Level 2) or DIBCAC (Level 3) assessments during that period.
Key Requirements
- 1Meet the specified CMMC level — Level 1 or Level 2 self-assessment while Phase 2 is suspended
- 2Maintain that security posture throughout contract performance
- 3Undergo C3PAO assessment for Level 2 and above if and when third-party certification resumes
- 4Self-assessment is the operative gate at Level 1 and, during the suspension, at Level 2
- 5Flowdown CMMC requirements to subcontractors handling CUI
Work out the score this clause asks for
The number in SPRS is not “how many of the 110 requirements did you do”. Under the NIST SP 800-171 DoD Assessment Methodology — the methodology both 252.204-7019 and 252.204-7020 cite by name — 44 requirements are worth 5 points, 14 are worth 3 and 51 are worth 1, with partial credit on 3.5.3 (MFA) and 3.13.11 (FIPS-validated cryptography) and no points at all on 3.12.4, the System Security Plan, which gates whether the assessment can be conducted. The scale runs from +110 to -203.
Free, no signup, and nothing you enter leaves your browser. Built from NIST SP 800-171 DoD Assessment Methodology, Version 1.2.1 (June 24, 2020), Annex A / §5.
Flowdown to Subcontractors
Yes — DFARS 252.204-7021 carries its own subcontract flowdown.
Paragraph (f), Subcontracts: the Contractor shall “Insert the substance of this clause, including this paragraph (f) and excluding paragraph (e)(1), in subcontracts and other contractual instruments … excluding commercially available off-the-shelf items,” and, before award, ensure the subcontractor holds the CMMC status appropriate to that subcontract.
Checked against the clause text at acquisition.gov, read 27 July 2026.
Real-World Example
MidTech Solutions, a 150-employee software development firm, bid on a $12M DoD IT modernization contract requiring CMMC Level 2 certification. Despite having ISO 27001 certification, they discovered their existing controls didn't meet 23 specific NIST 800-171 requirements, including multi-factor authentication for all CUI access and encrypted storage protocols. The C3PAO assessment revealed gaps that required $280,000 in security infrastructure upgrades and 8 months to remediate. MidTech lost the initial contract opportunity, costing them $1.8M in projected first-year revenue. They invested in a compliance consultant ($45,000), upgraded their security architecture, and achieved CMMC Level 2 certification 14 months later. The lesson: CMMC gaps can't be bridged with existing commercial certifications—DoD requires specific NIST 800-171 implementation, and that remediation work is the same whether the resulting score is self-attested or validated by an authorized assessor.
Why This Matters for Your Business
DFARS 252.204-7021 is how the CMMC program reaches a contract, and it affects every contractor handling Controlled Unclassified Information (CUI), from primes through the supply chain. As designed it escalates the older self-attestation model to third-party validation at Level 2 and above — but that leg was suspended on July 13, 2026 pending an acquisition-reform review, so self-assessment is the live gate today. That makes the underlying obligations sharper, not softer: DFARS 252.204-7012, NIST 800-171 implementation, SPRS score submission, and annual affirmations all still bind, and with no assessor standing behind the number, a score you submit is a representation to the government. Worst-case consequences are unchanged — False Claims Act liability for a false attestation under the DOJ Civil Cyber-Fraud Initiative, and potential suspension or debarment. Neither the 32 CFR CMMC Program rule nor the DFARS acquisition rule was amended, so the third-party requirement can return without new rulemaking.
Compliance Checklist for DFARS 252.204-7021
- 1ISSO conducts comprehensive gap analysis against NIST 800-171 requirements using official CMMC Assessment Guides to identify specific control deficiencies.
- 2Contracts team reviews all active DoD contracts and pending solicitations to identify CMMC level requirements and implementation timelines.
- 3Legal counsel evaluates CMMC certification requirements in proposal language and ensures accurate capability representations in SAM.gov registrations.
- 4ISSO develops System Security Plan (SSP) documenting all 110 NIST 800-171 security requirements and their implementation status.
- 5IT department implements required security controls and documents evidence in Plan of Action & Milestones (POA&M) for any gaps.
- 6ISSO coordinates C3PAO selection and scheduling for formal assessment, ensuring all documentation meets CMMC program requirements.
- 7Contracts team develops flowdown language for subcontractors and verifies their CMMC compliance through SPRS score validation.
- 8ISSO maintains continuous monitoring program and prepares for triennial recertification assessments as required by CMMC program rules.
Estimated Compliance Cost
Initial CMMC Level 2 compliance typically costs $150,000-$500,000 for mid-size contractors, driven by security infrastructure gaps, process documentation, and C3PAO assessment fees ($25,000-$75,000). Annual maintenance costs range $50,000-$150,000 for ongoing monitoring, annual assessments, and security tool licensing. Non-compliance remediation can exceed $300,000 when addressing findings under contract performance pressure. Timeline to achieve Level 2 certification averages 12-18 months from gap analysis to C3PAO validation. Cost variation depends on existing security maturity, company size, CUI scope, and chosen technology solutions—companies with mature security programs may achieve compliance for under $100,000, while those requiring comprehensive security transformation can exceed $750,000.
Cross-References & Related Requirements
DFARS 252.204-7021 builds upon the foundation established by 252.204-7012 (Safeguarding Covered Defense Information), which requires basic NIST 800-171 compliance but relies on contractor self-assessment. The CMMC clause elevates this to third-party validation for Level 2 requirements, directly correlating to the same 110 security controls. It integrates with 252.204-7019 (Notice of NIST 800-171 DOD Assessment Methodology), which requires SPRS score reporting that becomes the baseline for CMMC assessment. The clause also connects to 252.204-7020 (NIST 800-171 DoD Assessment Requirements) for contractors undergoing DoD assessments. CMMC Level 1 addresses basic safeguarding (14 practices), Level 2 encompasses all NIST 800-171 requirements (110 practices), and Level 3 adds enhanced controls for advanced persistent threats, creating a progressive security framework that supersedes standalone NIST 800-171 compliance requirements.
How This Clause Affects Your Proposal
DFARS 252.204-7021 appears in solicitations containing CUI requirements, with the specific CMMC level clearly identified in Section L instructions and evaluated under Section M criteria. Since the July 13, 2026 suspension of Phase 2, contracting officers may not designate C3PAO or DIBCAC assessments and are directed to amend solicitations and modify awarded contracts to remove those requirements — but that removal is not self-executing, so check whether it has actually issued before you change how you perform. Prepare your proposal by including your current CMMC status and self-assessment score, planned certification timeline if pursuing, and evidence of existing security controls alignment. Address CMMC requirements in your management approach, demonstrating understanding of continuous monitoring obligations. For subcontractor management plans, document how you'll verify and maintain subcontractor CMMC compliance throughout contract performance. Keep your SPRS score current and accurate and your SAM.gov registration consistent with it—while third-party certification is paused that self-attestation is the representation the government evaluates, and an inaccurate one carries False Claims Act exposure rather than a mere evaluation deduction.
Frequently Asked Questions
What is DFARS 252.204-7021?
DFARS 252.204-7021 (Cybersecurity Maturity Model Certification Requirements) is the clause that implements the CMMC program in DoD contracts. Level 1 covers basic safeguarding, Level 2 covers all 110 NIST 800-171 controls, and Level 3 adds enhanced controls. Since July 13, 2026 the third-party (C3PAO) assessment leg of the clause has been suspended pending an acquisition-reform review; Level 1 and Level 2 self-assessment, SPRS score submission, and annual affirmations continue to apply.
Does DFARS 252.204-7021 flow down to subcontractors?
Yes. DFARS 252.204-7021 carries its own subcontract flowdown. Paragraph (f), Subcontracts: the Contractor shall “Insert the substance of this clause, including this paragraph (f) and excluding paragraph (e)(1), in subcontracts and other contractual instruments … excluding commercially available off-the-shelf items,” and, before award, ensure the subcontractor holds the CMMC status appropriate to that subcontract.
When does DFARS 252.204-7021 apply?
DoD contracts that specify a required CMMC level. Phase 1 self-assessment requirements are live; the Phase 2 transition to third-party assessment was suspended on July 13, 2026 pending review. Removal is not self-executing — until a contracting officer amends the solicitation or modifies the contract, the clause text stays in your instrument.
Related Guides
Free Compliance Tools
SPRS Score Calculator
Your Basic Assessment score on the real DoD weights — 44 requirements at five points, 14 at three, 51 at one, +110 to −203.
🛡CUI Auditor
Audit your tech stack for CUI handling gaps across 80+ enterprise tools.
🗺CUI Flow Mapper
Map how CUI flows through your organization and identify spillage risks.
Is your tech stack DFARS 252.204-7021 compliant?
Run our free CUI Auditor to check if your tools meet this clause's requirements.
Audit Your Tech Stack FreeTurn this gap analysis into a remediation plan
This DFARS 252.204-7021 breakdown is the start, not the answer. Book a 25-minute compliance assessment — you leave with a prioritized roadmap and a fixed-fee implementation quote.
Book a 25-min assessmentRelated: how much CMMC certification costs — DoD’s own priced figures
Discussion
Share your experience implementing this in your organization.
Join the Club to unlock joining discussions
Free membership — access intelligence, save your work, and more.
Create free account