AuditXYZ

Compliance Framework

Defense Federal Acquisition Regulation Supplement (DFARS 252.204-7012) (DFARS)

DFARS cybersecurity requirements mandate protection of Controlled Unclassified Information in the defense supply chain. This guide covers NIST 800-171, CMMC 2.0, and compliance for defense contractors.

$50,000–$500,0006–18 monthsAudit Required2024 (with CMMC 2.0 transition)
Issuing BodyUnited States Department of Defense (DoD)
First Published2013-11-18
Latest Version2024 (with CMMC 2.0 transition)
Typical Cost$50,000–$500,000
Typical Timeline6–18 months
Audit RequiredYes
Audit FrequencyCMMC 2.0 requires Level 2 triennial assessment by C3PAO for CUI. Level 1 requires annual self-assessment. Level 3 requires government-led assessment.
Geographyunited-states

DFARS: Defense Federal Acquisition Regulation Supplement Guide

The DFARS cybersecurity clause (252.204-7012) requires all defense contractors and subcontractors handling Controlled Unclassified Information (CUI) to implement the 110 security controls specified in NIST SP 800-171. The Cybersecurity Maturity Model Certification (CMMC 2.0) program builds on DFARS by adding third-party assessment requirements, making cybersecurity compliance a verified prerequisite for defense contract awards. For any company in or entering the defense industrial base, DFARS/CMMC compliance is not optional — it is the price of participation in a market that awards over $400 billion in contracts annually.

What DFARS Is and Who Issues It

DFARS (Defense Federal Acquisition Regulation Supplement) is the DoD's supplement to the Federal Acquisition Regulation (FAR), adding defense-specific requirements to federal procurement rules. DFARS clause 252.204-7012, first enacted in 2013 and substantially strengthened in subsequent years, mandates specific cybersecurity requirements for contractors handling CUI.

The Defense Pricing and Contracting (DPC) and the DoD CIO jointly administer DFARS cybersecurity requirements. The Office of the Under Secretary of Defense for Acquisition and Sustainment (USD(A&S)) oversees CMMC implementation.

CMMC (Cybersecurity Maturity Model Certification) was introduced in 2020 and substantially revised as CMMC 2.0 in 2021. CMMC 2.0 reduced the original five maturity levels to three, eliminated unique CMMC-specific practices, and aligned the requirements directly with NIST SP 800-171 (Level 2) and NIST SP 800-172 (Level 3). CMMC 2.0 has been phasing into DoD contracts through 2025–2026, with full implementation expected across all applicable contracts.

Who Needs DFARS/CMMC Compliance

All DoD contractors and subcontractors handling Federal Contract Information (FCI) or Controlled Unclassified Information (CUI) must comply. This includes:

  • Prime contractors on DoD contracts
  • Subcontractors at all tiers that receive FCI or CUI from primes
  • Cloud service providers hosting defense contractor data
  • Managed service providers (MSPs) supporting defense contractors with access to covered systems

The defense industrial base (DIB) includes over 300,000 companies — many of them small and medium-sized businesses in manufacturing, engineering, IT services, and professional services. CMMC 2.0 is being phased into DoD solicitations and contracts through a defined rollout, with compliance becoming a contract award requirement (rather than just a self-attestation requirement) for an expanding share of the defense market.

The specific CMMC level required depends on the type of information handled. Contractors handling only FCI need Level 1. Contractors handling CUI — the vast majority of defense supply chain participants — need Level 2. A small subset of contractors on the most sensitive programs may need Level 3.

Key Requirements: NIST SP 800-171 and CMMC Levels

CMMC 2.0 defines three levels with requirements directly aligned to NIST publications.

Level 1 (Foundational) requires 17 basic safeguarding practices derived from FAR 52.204-21 for Federal Contract Information. These cover fundamental cybersecurity hygiene: limit access to authorized users, identify CUI, sanitize or destroy media before disposal, limit physical access, screen individuals before authorizing access, escort visitors and monitor visitor activity, maintain configuration settings for IT products, perform maintenance on systems, provide awareness training, authenticate users before allowing access, and limit communications to effective security measures. Level 1 requires annual self-assessment with results submitted to the Supplier Performance Risk System (SPRS).

Level 2 (Advanced) requires all 110 security requirements from NIST SP 800-171 across 14 control families. This is the level required for any contractor handling CUI. Level 2 requires a triennial assessment by a CMMC Third Party Assessment Organization (C3PAO) for most contractors, though some lower-risk Level 2 programs may permit annual self-assessment. Assessment results must be submitted to SPRS.

Level 3 (Expert) applies to contractors on the most sensitive DoD programs — those deemed critical to national security. Level 3 requirements build on Level 2 by adding a subset of enhanced requirements from NIST SP 800-172 addressing advanced persistent threats. Level 3 assessments are government-led, conducted by the Defense Contract Management Agency (DCMA) DIBCAC (Defense Industrial Base Cybersecurity Assessment Center).

The 14 NIST SP 800-171 Control Families

Access Control (AC) — limit system access to authorized users and processes. Awareness and Training (AT) — ensure personnel are aware of security risks. Audit and Accountability (AU) — create and retain audit records. Configuration Management (CM) — establish baseline configurations and maintain control inventories. Identification and Authentication (IA) — verify identities before system access. Incident Response (IR) — establish incident handling capabilities and report to DoD within 72 hours. Maintenance (MA) — perform controlled maintenance of systems. Media Protection (MP) — protect and sanitize CUI on system media. Personnel Security (PS) — screen individuals and establish termination procedures. Physical Protection (PE) — limit physical access to systems. Risk Assessment (RA) — periodically assess risk to operations. Security Assessment (CA) — assess controls and create system security plans. System and Communications Protection (SC) — monitor communications and implement boundary protections. System and Information Integrity (SI) — identify, report, and correct information and information system flaws.

The System Security Plan (SSP) and SPRS Score

Every contractor in scope must maintain a System Security Plan (SSP) documenting how each of the 110 NIST SP 800-171 controls is implemented. Where controls are not yet implemented, a Plan of Action and Milestones (POA&M) must document remediation plans with target completion dates.

The SPRS (Supplier Performance Risk System) score is a self-assessed score from -203 to 110 representing the contractor's implementation status against the 110 Level 2 controls. Contractors must submit their SPRS score to DoD before contract award. A higher score indicates stronger compliance. DoD uses SPRS scores as an input to contract award decisions.

The CMMC Assessment Process

For Level 2, the C3PAO assessment involves document review, interviews, and technical testing of controls across all 110 NIST SP 800-171 requirements. The C3PAO submits findings to the Cyber Accreditation Body (Cyber AB), which issues CMMC certification. The certification is valid for three years, with annual affirmations of continued compliance required.

C3PAOs are accredited by the Cyber AB. Organizations must engage a Cyber AB-accredited C3PAO — using an unaccredited assessor does not produce CMMC certification. The marketplace of C3PAOs is still maturing, and scheduling windows can be months in advance.

Preparing for a C3PAO assessment typically involves:

  1. Completing and documenting the SSP
  2. Addressing all POA&M items (C3PAOs generally cannot certify organizations with open POA&Ms for most practice areas)
  3. Conducting an internal readiness assessment or mock audit
  4. Implementing any remaining technical controls
  5. Scheduling and executing the formal assessment

Costs and Timeline

CMMC LevelEstimated Compliance CostTimeline
Level 1 (self-assessment)$25K–$75K2–4 months
Level 2 (small contractor)$75K–$200K6–12 months
Level 2 (mid-size contractor)$150K–$400K9–15 months
Level 2 (large contractor, complex environment)$300K–$500K+12–18 months
C3PAO assessment fees (Level 2)$50K–$150K3–6 months assessment period
Level 3$500K+18+ months

Small business compliance costs are a recognized policy concern. DoD has explored mechanisms to support small DIB companies, including shared assessment costs and assistance through the DoD DIB Cybersecurity Service. Organizations should monitor DoD's small business cybersecurity support programs as these continue to evolve.

DFARS/CMMC maps at 95% to NIST SP 800-171 — they are essentially the same requirement with CMMC adding the third-party assessment layer. FedRAMP Moderate overlaps at approximately 60% — FedRAMP authorization is not equivalent to CMMC but shares many control requirements. ISO 27001 overlaps at approximately 55% — ISO 27001 demonstrates information security management system maturity but does not satisfy CMMC requirements.

ITAR (approximately 40% overlap) addresses export control obligations for defense articles and technical data. Many defense contractors face both DFARS/CMMC and ITAR requirements. The two frameworks are complementary — DFARS/CMMC addresses cybersecurity controls for information systems; ITAR controls the export of controlled information and physical items. Contractors handling ITAR-controlled technical data in digital systems need both programs.

For companies navigating the full defense compliance landscape, see our government compliance guide.

How Automation Helps

NIST SP 800-171's 110 controls generate extensive documentation requirements — SSPs, POA&Ms, SPRS scores, evidence of control implementation, and audit records must be maintained continuously and made available to C3PAOs on short notice.

LowerPlane supports DFARS/CMMC as part of its 50+ framework library. Its SSP generation assistance, control evidence collection, and SPRS score tracking capabilities reduce the manual documentation burden substantially. For defense contractors managing CMMC alongside other frameworks (ISO 27001, FedRAMP), LowerPlane's multi-framework evidence sharing reduces duplicate work. Starting at $4,000 per year with a free tier. AuditXYZ rated LowerPlane 9.4/10.

Frequently Asked Questions

When is CMMC 2.0 fully in effect? CMMC 2.0 has been phasing into DoD contracts since 2024, with the rulemaking completed and CMMC requirements appearing in a growing share of DoD solicitations and contracts. By 2026, CMMC requirements are expected to be present in all applicable DoD contracts. Organizations should not wait — the assessment scheduling backlog and implementation timeline mean starting now is essential for organizations seeking to remain DoD-eligible.

What is the difference between CMMC Level 2 self-assessment and C3PAO assessment? CMMC 2.0 allows some Level 2 contracts to permit self-assessment (annual affirmation to DoD) rather than requiring a C3PAO third-party assessment. However, contracts deemed to involve "critical programs or technologies" require C3PAO assessment. DoD is still defining which contracts fall into which category. In practice, contractors should plan for C3PAO assessment to ensure they can bid on the broadest range of Level 2 contracts.

What counts as CUI (Controlled Unclassified Information)? CUI is unclassified information that requires safeguarding under law, regulation, or government-wide policy. The National Archives maintains the CUI Registry, which lists dozens of CUI categories including technical data about weapons systems, export-controlled information, financial information, and privacy-protected data. If a contract includes a DFARS 252.204-7012 clause, the contractor handles CUI and must implement NIST SP 800-171.

Can a managed security service provider (MSSP) help achieve CMMC compliance? Yes, but carefully. MSSPs providing IT services to defense contractors may themselves need to be CMMC-compliant if they have access to CUI systems. Using an MSSP for security operations (SOC, SIEM, patching) is a valid approach to addressing specific control families, but the prime contractor retains accountability for overall CMMC compliance. The MSSP's access to CUI systems means they are in scope and must meet the same CMMC Level as the contractor.

What happens to existing contracts if a contractor is not CMMC compliant? For contracts already in place before CMMC requirements appear in that contract vehicle, existing contract terms continue to apply. However, at contract renewal or modification, CMMC requirements may be incorporated. For new solicitations requiring CMMC, non-compliant contractors cannot bid. The consequence is exclusion from the defense market — an existential risk for companies dependent on DoD revenue.

Request a DFARS consultation

Step 1 of 520%

Which framework do you need?

Framework Mappings

Overlap with other frameworks

NIST SP 800 171High95%
FedRAMPMedium60%
ISO 27001Medium55%

Get matched with a DFARS auditor in 24 hours

Free, no-obligation — just tell us your email and we'll do the rest.

By submitting, you agree to our privacy policy.