Since February 2026, 7012 still covers safeguarding and 72-hour reporting, 7019 no longer appears in new solicitations, 7020 is renumbered, and 7021 governs CMMC.
The DFARS cybersecurity clause set changed materially in February 2026, and most guides online still describe the old landscape. Here is the current state: DFARS 252.204-7012 (safeguarding CUI and 72-hour cyber-incident reporting) remains in full effect. Since February 1, 2026, DFARS 252.204-7019 no longer appears in new solicitations, DFARS 252.204-7020 has been renumbered 252.240-7997, and FAR 52.204-21 has been renumbered FAR 52.240-93. DFARS 252.204-7021, the CMMC clause, remains and is now the primary assessment mechanism, paired with the provision 252.204-7025. Older contracts may still carry the legacy clause numbers, so the old "7012 / 7019 / 7020 / 7021" shorthand now describes only those older contracts. Separately, the Department of War (DoW) has suspended CMMC Phase 2, the third-party assessment requirement that was scheduled to begin November 10, 2026, while it reviews the program. This guide maps every clause to its current status and what it actually requires of you.
Start here, because this is the table every stale consultant post gets wrong. As part of the "Revolutionary FAR Overhaul" (RFO), the Department issued Class Deviation 2026-O0025, effective February 1, 2026, which reshaped the cyber clause set and moved it into a new DFARS Part 240. DoW has revised the deviation since: Revision 3, issued September 3, 2026, wrote the CMMC Phase 2 suspension into contracting text and still permits Level 1 and Level 2 self-assessments. Here is where each clause stands now:
| Clause | Status now | What it requires of you |
|---|---|---|
| 252.204-7012 | Remains in full effect | Implement NIST SP 800-171 (Rev 2 per class deviation), maintain an SSP, report cyber incidents within 72 hours to the Department via DIBNet, preserve affected media, flow down to subcontractors |
| 252.204-7019 | Removed from new solicitations (Feb 1, 2026) | Formerly: required a current (within 3 years) NIST 800-171 self-assessment posted in SPRS as a condition of award. Older contracts may still carry it, and SPRS score currency and affirmations are still required for awards and option exercises |
| 252.204-7020 | Renumbered to 252.240-7997 (Feb 1, 2026) | Provide DoW access to facilities, systems, and personnel for government-performed Medium and High assessments (conducted by DIBCAC); flow the requirement down. The new clause drops the Basic self-assessment and defines only the Medium and High assessments |
| 252.204-7021 | Remains; now the primary assessment clause | Achieve and maintain the CMMC level and assessment type stated in the contract, affirm annually, flow CMMC down to subcontractors (except COTS-only). Phase 2 third-party assessments are suspended |
| 252.204-7025 | Current provision | Solicitation notice stating the required CMMC level, titled "Notice of CMMC Level Requirements" |
| FAR 52.204-21 | Renumbered to FAR 52.240-93 (Feb 1, 2026) | Basic safeguarding of Federal Contract Information: the 15 requirements behind CMMC Level 1 |
Sources: DFARS Class Deviation 2026-O0025, including Revision 3 of September 3, 2026; Summit 7, Secureframe, and Cuick Trac for the RFO analysis; acquisition.gov and the Federal Register for 7021 and 7025.
The live set, in plain terms, is now effectively four things: 7012 (safeguarding + reporting), 7021 (the CMMC requirement), 7025 (the CMMC notice provision), and 252.240-7997 (assessment access, formerly 7020). If a page published after February 2026 still lists "7019 and 7020" as current requirements for new contracts, it is out of date, although an older contract you already hold may still cite them.
Everything else in the DFARS cyber world orbits 7012, so understand it first. It has been in defense contracts since 2016, it remains in effect after the 2026 overhaul, and it is the clause that obligates you to protect CUI in the first place.
252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting, imposes four core obligations on any contractor that processes, stores, or transmits Covered Defense Information (a category that includes CUI) on its systems:
You must implement the security requirements in NIST SP 800-171 to protect covered defense information. Under Class Deviation 2024-O0013, the operative baseline is Revision 2 (110 requirements), even though NIST finalized Revision 3 in May 2024. The Department assesses against Rev 2: the 2024 deviation ties 7012 to Rev 2 until it is rescinded, and the September 3, 2026 deviation keeps Rev 2. An interim final rule to move to Rev 3 (RIN 0790-AM01) was targeted for July 2026 but had not been published as of late September 2026. For how those 110 requirements map into CMMC Level 2, see our CMMC levels guide.
7012 requires you to have an SSP (and associated plans) describing how you meet each requirement. This is not a formality - it is the document assessors and contracting officers rely on, and a thin SSP undermines everything downstream. See how to write an SSP.
This is the obligation that catches contractors off guard. If you discover a cyber incident affecting covered defense information or your ability to perform, you must report it to the Department within 72 hours via DIBNet (dibnet.dod.mil). Reporting requires a DoD-approved medium assurance certificate, which you should obtain before an incident - scrambling for credentials mid-breach is exactly the wrong time. You must also preserve and protect affected media for at least 90 days so the Department can request it.
You must include 7012 in subcontracts where subcontractors will handle covered defense information. Prime responsibility does not end at your own boundary - your supply chain inherits the obligation.
Bottom line on 7012: it is the safeguarding-and-reporting backbone, still in effect after the 2026 overhaul, and it applies today regardless of where you sit in the CMMC phase-in or of the Phase 2 suspension.
For years, 7019 and 7020 rode alongside 7012 as the "assessment" clauses. The 2026 RFO changed that, and understanding why prevents you from following outdated guidance.
252.204-7019 no longer appears in new solicitations. It formerly required contractors to have a current NIST 800-171 self-assessment (within the last three years) posted in SPRS as a condition of award eligibility. With CMMC's own affirmation and status process running through 7021, DoW dropped the standalone 7019 provision from new solicitations on February 1, 2026. Older contracts may still include it.
The removal of 7019 does not end SPRS submissions, and a lot of hot-take posts get this wrong. SPRS remains the system of record, and a current SPRS score and affirmation are still required for awards and option exercises. What changed is the clause text: the new clause no longer defines the Basic self-assessment the old clauses described, and CMMC self-assessment results and affirmations are recorded in SPRS under 7021. Medium and High assessments conducted by DIBCAC still result in scores uploaded to SPRS by DIBCAC. For the mechanics of scoring and submission, see our SPRS score guide.
252.204-7020 was renumbered to 252.240-7997. Its access requirement carried forward: it requires you to provide DoW access to your facilities, systems, and personnel so DIBCAC can conduct Medium and High assessments, and to flow that requirement down. The clause moved into the new DFARS Part 240 as part of the broader FAR restructuring. The new clause also drops the Basic self-assessment and defines only the government-performed Medium and High assessments, so expect 252.240-7997 in new contracts and the old 7020 number only in older ones.
If 7012 is the safeguarding backbone, 7021 is the CMMC verification clause, and after February 2026 it is the primary assessment clause. It is also the clause tied directly to the CMMC phase-in, so its effect on your contracts depends on which phase is in force.
252.204-7021, Cybersecurity Maturity Model Certification Requirements, requires you to:
7021 is prescribed for use alongside the provision 252.204-7025, the Notice of CMMC Level Requirements, which is what tells you, in the solicitation, which level and assessment type apply. You do not choose your level; 7025 states it, and 7021 obligates you to meet it.
Here is the phase-in nuance that matters for reading your contracts today. CMMC was set to roll out over a three-year phase-in keyed to the November 10, 2025 acquisition-rule effective date, and 7021 currently appears only in contracts where DoW has determined to apply CMMC. The Department has suspended CMMC Phase 2, the third-party assessment requirement that was scheduled to begin November 10, 2026, while it reviews the program, and Phases 3 and 4 are on hold as well. Phase 1 remains in effect: contracts can still require CMMC Level 1 and Level 2 self-assessments with affirmations in SPRS, and DFARS 252.204-7012 still requires all 110 NIST SP 800-171 Rev 2 security requirements. During the pause, the Department has said it is enforcing through self-assessments and select government-led assessments against NIST SP 800-171 Rev 2. As of late September 2026, the review's recommendations have not been made public and no new Phase 2 date has been announced. So if you see 7021 in a solicitation, read the 7025 notice carefully, because it tells you exactly what you must achieve.
| Phase | Original start | 7021's effect on applicable contracts |
|---|---|---|
| Phase 1 (in effect) | Nov 10, 2025 | Level 1 and Level 2 self-assessments with affirmations in SPRS |
| Phase 2 (suspended) | Was scheduled for Nov 10, 2026 | Would have made Level 2 (C3PAO) a standard award condition; suspended July 13, 2026 while DoW reviews the program, with no new date announced |
| Phase 3 (on hold) | Was scheduled for Nov 10, 2027 | Would add Level 3 (DIBCAC) to applicable contracts |
| Phase 4 (on hold) | Was scheduled for Nov 10, 2028 | Full implementation across applicable contracts (except COTS-only) |
Source: 32 CFR 170.3(e) for the original schedule; DoW's July 13, 2026 suspension of Phase 2.
For a contractor handling CUI in 2026, the clause obligations stack like this:
Get those straight and you are reading your contracts correctly, which is more than can be said for guidance that still treats 7019 and 7020 as current requirements for new contracts.
It requires contractors handling covered defense information (including CUI) to implement NIST SP 800-171 (Rev 2 per the current class deviation), maintain a System Security Plan, report cyber incidents to DoW within 72 hours via DIBNet, preserve affected media, and flow the clause down to subcontractors. It remains in full effect after the February 2026 DFARS overhaul.
Not for new contracts. Since February 1, 2026, DFARS 252.204-7019 no longer appears in new solicitations under the Revolutionary FAR Overhaul (Class Deviation 2026-O0025), although older contracts may still carry it. It formerly required a current NIST 800-171 self-assessment posted in SPRS as a condition of award. A current SPRS score and affirmation are still required for awards and option exercises, and CMMC assessment obligations run through the CMMC clause, 252.204-7021.
It was renumbered to DFARS 252.240-7997 effective February 1, 2026, with its content moved to the new DFARS Part 240. The access requirement carried forward: it requires contractors to give DoW access to facilities, systems, and personnel for Medium and High assessments conducted by DIBCAC, and to flow that requirement down. The new clause drops the Basic self-assessment and defines only the government-performed Medium and High assessments.
It is the CMMC clause and now the primary assessment clause. It requires a contractor to achieve and maintain the CMMC level and assessment type specified in the contract, affirm that status annually, and flow CMMC requirements down to subcontractors. It is paired with the solicitation provision 252.204-7025, which states the required level. The Department has suspended CMMC Phase 2 while it reviews the program, and contracts can still require Level 1 and Level 2 self-assessments with affirmations in SPRS.
Yes. SPRS remains the system of record, and a current score and affirmation are still required for awards and option exercises. Removing 7019 from new solicitations took away a standalone posting clause, but your NIST 800-171 score and CMMC status still flow into SPRS through the CMMC affirmation process, and DIBCAC uploads Medium and High assessment scores directly.
Revision 2 (110 requirements). Class Deviation 2024-O0013 ties the 7012 baseline to Rev 2 until it is rescinded, even though Rev 3 was finalized in May 2024, and the Department's September 3, 2026 class deviation keeps Rev 2. DoW assesses against Rev 2, and the interim final rule that would move it to Rev 3 had not been published as of late September 2026.
Compli.ai keeps the program behind these clauses in one place inside your own Microsoft 365 tenant. It carries all 110 NIST SP 800-171 Rev 2 requirements and 320 assessment objectives, holds the SSP implementation statement for each requirement, tracks the SPRS score your affirmation depends on, and manages the POA&M under the 32 CFR 170.21 eligibility rules so an assessor can see your remediation plan.
See our CMMC compliance platform and CMMC compliance software, review what counts as CUI to scope your obligations, and book a demo to map the clause set to your contracts.