Skip to main content

🔔 Notifications Hub: See compliance updates in one place

DFARS (Defense Federal Acquisition Regulation Supplement)

DFARS supplements the Federal Acquisition Regulation (FAR) with rules specific to Department of Defense contracts. For contractors, the cybersecurity clauses matter most: 252.204-7012 (protect CUI using NIST SP 800-171), 252.204-7019 and 7020 (report and score NIST 800-171 implementation to SPRS), and 252.204-7021 (achieve CMMC certification before award).

How DFARS Works

The FAR applies to every federal agency. DFARS adds DoD-specific rules on top of the FAR for anything the Department of Defense buys. When you read a DoD contract, you are reading FAR clauses plus DFARS clauses.

The Four Cybersecurity Clauses

  • 252.204-7012 (Safeguarding Covered Defense Information and Cyber Incident Reporting): Requires NIST SP 800-171 implementation, cyber incident reporting within 72 hours to DIBNet, and flow-down to subcontractors who handle CUI.
  • 252.204-7019 (Notice of NIST SP 800-171 DoD Assessment Requirements): You must have a current Basic Assessment score in SPRS before the contract is awarded.
  • 252.204-7020 (NIST SP 800-171 DoD Assessment Requirements): Lets DIBCAC perform Medium or High Assessments on the contractor.
  • 252.204-7021 (CMMC Requirements): Requires the specified CMMC level at the time of award, maintained through the life of the contract.

Incident Reporting: The 72-Hour Clock

If you discover a cyber incident that affects CDI, you have 72 hours to report it at dibnet.dod.mil. The report includes what happened, what data was affected, and what systems were involved. You also preserve media images for 90 days in case DC3 requests them.

Flow-Down to Subcontractors

If CUI enters the subcontract, the prime must include 252.204-7012 in that subcontract. This is how a small machine shop three tiers down ends up with the same cybersecurity obligations as the prime.

What Happens If You Misrepresent Compliance

The DOJ's Civil Cyber-Fraud Initiative has used the False Claims Act to pursue contractors who submitted inflated SPRS scores or falsely certified NIST 800-171 compliance. Settlements have ranged from $300,000 (Jelly Bean Communications Design, 2022) to $11.3M (Verizon Business Network Services, 2023). Both cases turned on false statements, not breach events.