Skip to main content

Elevate

DFARS Compliance Checklist: Clauses, Evidence, and Deadlines

DFARS compliance is not a single requirement but a set of specific contract clauses, and for a defense supplier the difference between meeting them and missing one can be the difference between winning an award and being ruled ineligible for it. The clauses that matter most for cybersecurity are a small, related group, each with its own obligations, evidence, and deadlines, and some of them gate your eligibility to compete at all. This checklist walks the clauses that matter, the evidence each requires, and the traps that quietly stall contract awards.

The value of a DFARS compliance checklist is that it turns a vague sense of obligation into a concrete list you can verify against your contracts and your records. Each clause either applies to a given contract or it does not, and where it applies, it demands specific, evidenceable things. Working through them one by one is how a supplier moves from hoping it is compliant to knowing it is.

The DFARS Clauses That Matter

Four DFARS clauses carry the cybersecurity obligations that most affect defense suppliers, and they work together: one sets the security standard and reporting duty, two govern the assessment and its posting to a government system, and one adds the certification requirement. The table below is the fastest way to see the whole cluster at once.

DFARS clauseWhat it requiresWhat you must have
252.204-7012Safeguard covered defense information and report cyber incidentsNIST 800-171 implemented, a working incident reporting process
252.204-7019A current NIST 800-171 assessment score in SPRS to be eligible for awardA posted Basic assessment score, kept current
252.204-7020Maintain the assessment, allow government assessment, and flow the requirement downA current SPRS score and the clause in relevant subcontracts
252.204-7021Meet the CMMC level specified in the contractThe required CMMC status, with third-party verification currently paused

The table shows why these clauses cannot be treated in isolation: the security work under 252.204-7012 produces the score that 252.204-7019 requires you to post before award, which 252.204-7020 requires you to keep current, and which 252.204-7021 will eventually require to be independently verified. They are four views of one obligation, and a gap in any of them is a gap in your DFARS compliance.

What Each Clause Requires

Understanding the evidence behind each clause is what turns the table into an actionable checklist, because each clause asks for something specific and provable.

DFARS 252.204-7012

This is the foundational clause, requiring adequate security for covered defense information by implementing NIST SP 800-171, and rapid reporting of cyber incidents to the Department of War within 72 hours of discovery. Its evidence is your implemented controls, your documentation, and a reporting process you can execute on short notice. Because it is the most substantial of the four, it is covered in depth in the guide to DFARS 7012 compliance.

DFARS 252.204-7019

This clause is the one that most directly affects your ability to win work, because it requires that an offeror have a current NIST 800-171 assessment score posted in the Supplier Performance Risk System before a contract can be awarded. A score that is missing or out of date can make you ineligible, regardless of how good your actual security is, so the evidence here is simply a current, posted assessment score. The score itself comes from the assessment covered in the guide to the NIST 800-171 assessment.

DFARS 252.204-7020

Where 7019 requires a score to exist, 7020 governs keeping it valid and honest over time. It requires a contractor to maintain a current assessment in SPRS, to provide the government access needed to conduct higher-level assessments if it chooses, and to flow the requirement down to subcontractors who will handle covered defense information. The evidence is a maintained SPRS entry and the presence of the requirement in your relevant subcontracts, which is an easy obligation to overlook and a consequential one to miss.

DFARS 252.204-7021

This is the CMMC clause, requiring a contractor to hold the CMMC level specified in a given contract. Under the current suspension, the third-party verification that this clause ultimately depends on is paused, so in practice the live obligation is the self-assessment posture rather than a third-party certification. The clause still matters for planning, because CMMC verification will resume, and contracts increasingly reference it. Understanding how it relates to the underlying standard is covered in the comparison of NIST 800-171 versus CMMC.

Traps That Stall Contract Awards

The clauses above create several specific traps that can delay or block an award, and they catch suppliers who assumed their security was the only thing being judged. The most common is the absence of a current SPRS score: because 252.204-7019 makes that score a precondition of award, a missing or expired assessment can rule you out before your proposal is even evaluated. An assessment older than the permitted window has the same effect as no assessment at all, so a lapsed score is its own trap.

A second trap is a posted score that reflects unaddressed gaps with no plan attached, which can raise questions about your readiness even when a score exists. A third is a broken flowdown: if the required clauses are not in your subcontracts, your compliance is incomplete in a way that surfaces at exactly the wrong moment. A fourth is a cloud environment that handles covered defense information without meeting the required equivalency, which is a 252.204-7012 gap that can undermine the whole package. None of these is about the quality of your security directly; each is about the administrative and contractual completeness that DFARS compliance demands alongside it.

DFARS Compliance Under the Current Suspension

The 2026 suspension of third-party CMMC assessment has changed one of these clauses and left the others untouched, and knowing which is which prevents a costly misread. The suspension paused the third-party verification tied to 252.204-7021, so CMMC certification assessment is not currently a gating step. It did nothing to 252.204-7012, 252.204-7019, or 252.204-7020, which remain fully in force.

This matters because the award gate that most affects suppliers, the current SPRS score required by 252.204-7019, is entirely unaffected by the suspension. A supplier that relaxes its DFARS attention because CMMC assessment is paused can still find itself ineligible for award over a missing or expired SPRS score. The self-assessment obligations under these clauses are the live requirement, and the checklist above applies today regardless of the CMMC pause.

How to Use This DFARS Compliance Checklist

Working this DFARS compliance checklist starts with reading your contracts to see which of these clauses they contain, because the clauses apply when they are included, and knowing which ones you are bound by focuses the effort. With that established, confirm that you have a current NIST 800-171 assessment score posted in SPRS, that your 800-171 implementation genuinely supports it, that your incident reporting process can meet the 72-hour deadline, and that the required clauses have flowed down to the subcontractors who need them.

Much of the evidence the clauses require rests on written policy, which is the slowest part to build from scratch, so starting from a proven, tailored policy set accelerates it considerably. Elevate’s CMMC Level 2 Master Policy Compendium provides policy sets that support the 800-171 implementation these clauses depend on, turning documentation into a tailoring exercise. Elevate helps defense suppliers work through their full DFARS obligations and keep their award eligibility intact as part of its CMMC advisory services.

Conclusion

A DFARS compliance checklist for a defense supplier comes down to four clauses working together: 252.204-7012 sets the security and reporting duty, 252.204-7019 makes a current SPRS score a precondition of award, 252.204-7020 keeps that score valid and flows the requirement down, and 252.204-7021 adds the CMMC certification requirement. The evidence each demands is specific and provable, and the traps that stall awards are almost always administrative completeness rather than security quality, with a missing or expired SPRS score the most common of all.

The suspension paused only the CMMC verification clause and left the award-gating obligations fully in force, so this checklist is as relevant today as ever. To confirm your DFARS compliance across all four clauses and protect your eligibility for award, book a call with an Elevate advisor.

Key Takeaways

DFARS compliance for a defense supplier means satisfying four related clauses, some of which gate your eligibility for award.

  • Four clauses carry the obligations: 252.204-7012 for safeguarding and reporting, 252.204-7019 for a current SPRS score before award, 252.204-7020 for maintaining it and flowing it down, and 252.204-7021 for CMMC.
  • A current SPRS score gates award: 252.204-7019 makes a posted, current NIST 800-171 assessment score a precondition of award, so a missing or expired score can rule you out before evaluation.
  • The traps are administrative: most award-stalling problems are completeness issues, a lapsed score, a broken flowdown, an unaddressed gap with no plan, or a non-compliant cloud, rather than the quality of your security.
  • The suspension touched only one clause: third-party CMMC verification under 252.204-7021 is paused, but 252.204-7012, 7019, and 7020 remain fully in force, including the award-gating SPRS requirement.
  • Start by reading your contracts: the clauses apply when included, so confirm which bind you, then verify your SPRS score, your implementation, your reporting process, and your flowdown.

FAQs

Q1. What are the main DFARS cybersecurity clauses? The four DFARS clauses that carry the cybersecurity obligations for defense suppliers are 252.204-7012, which requires safeguarding covered defense information and reporting cyber incidents; 252.204-7019, which requires a current NIST 800-171 assessment score in SPRS to be eligible for award; 252.204-7020, which requires maintaining that assessment, allowing government assessment, and flowing the requirement down; and 252.204-7021, which requires meeting the CMMC level specified in the contract. They work together, since the security work under 7012 produces the score the others govern.

Q2. What does DFARS 252.204-7019 require before a contract award? DFARS 252.204-7019 requires an offeror to have a current NIST 800-171 assessment score posted in the Supplier Performance Risk System before a contract can be awarded. A score that is missing or older than the permitted window can make a supplier ineligible, regardless of the actual quality of its security. In practice this makes maintaining a current, posted assessment score one of the most award-critical parts of DFARS compliance, because it is checked as a precondition rather than evaluated as a strength.

Q3. What are the common DFARS compliance traps that stall awards? The most common trap is the absence of a current SPRS score, which 252.204-7019 makes a precondition of award, so a missing or expired assessment can rule a supplier out before evaluation. Other traps include a posted score with unaddressed gaps and no plan attached, a broken flowdown where required clauses are missing from subcontracts, and a cloud environment handling covered defense information without meeting the required equivalency. These are matters of administrative and contractual completeness rather than the quality of the security itself.

Q4. Does the 2026 CMMC suspension change DFARS compliance? Only partially. The suspension paused the third-party verification tied to DFARS 252.204-7021, the CMMC clause, so CMMC certification assessment is not currently a gating step. It did not affect 252.204-7012, 252.204-7019, or 252.204-7020, which remain fully in force. The award gate that most affects suppliers, the current SPRS score required by 252.204-7019, is entirely unaffected, so a supplier cannot safely relax its DFARS attention because CMMC assessment is paused.

Q5. How do I know which DFARS clauses apply to my contracts? The clauses apply when they are included in a given contract, so reading your contracts for the specific clause numbers is the reliable way to know what binds you. Once you have identified the applicable clauses, the checklist is concrete: confirm a current SPRS score, ensure your NIST 800-171 implementation genuinely supports it, verify that your incident reporting process can meet the 72-hour deadline, and check that the required clauses have flowed down to relevant subcontractors. This turns an abstract obligation into a specific list you can verify.