---
name: dfars-cyber-check
description: >-
  Checks a Department of War solicitation or contract for the DFARS cybersecurity clauses 252.204-7012,
  252.204-7019, 252.204-7020, 252.204-7021 and 252.204-7025. Looks for covered defense information and
  controlled unclassified information, the cyber incident report to DIBNet within 72 hours, the SPRS basic
  assessment required before award, and the CMMC level.
---

# DFARS cybersecurity check

## Who this applies to

These clauses reach every Department of War (formerly Department of Defense) solicitation and
contract that is not solely for commercially available off-the-shelf items, including commercial
buys, and the trigger is the data rather than the money: there is no dollar threshold for
252.204-7012. The CMMC clauses 252.204-7021 and 252.204-7025 add a money element, reaching
solicitations above the micro-purchase threshold, again except COTS-only. If this is not a
Department of War acquisition, say so in one sentence and stop; a civilian agency's own supplement
governs instead. Do not apply this check to a grant.

## The clause and requirement text is in this Skill's own folder

The rules this check cites are bundled under `reference/`, so quote the rule itself
rather than only naming it. The NIST files and 32 CFR 170 are long, which is why you should `grep`
for the requirement number or the defined term you want and read the region around the hit. Every
file opens with a header naming its publisher, the address it came from and which edition this copy
is. Where the bundled copy and the publisher's current version differ, the publisher's version
governs and this copy is stale.

| File under `reference/`                                     | What it settles                                                            |
| ----------------------------------------------------------- | -------------------------------------------------------------------------- |
| `dfars-252-204-7012-safeguarding-and-incident-reporting.md` | the clause itself, including what "rapidly report" means                   |
| `dfars-252-204-assessment-and-cmmc-clauses.md`              | the text of 252.204-7019, -7020, -7021 and -7025                           |
| `dfars-subpart-204-73-safeguarding.md`                      | when the contracting officer must insert 252.204-7012, at 204.7304         |
| `dfars-subpart-204-75-cmmc.md`                              | when the CMMC clauses must be inserted                                     |
| `far-52-204-21-basic-safeguarding.md`                       | the fifteen-requirement floor below the covered-defense-information line   |
| `32-cfr-170-cmmc-program.md`                                | the CMMC levels, the phase-in, and the incorporation by reference at 170.2 |
| `nist-sp-800-171r2-security-requirements.md`                | the 110 requirements an assessor will actually check                       |
| `nist-sp-800-171r3-current-requirements.md`                 | what NIST says today, which is not what CMMC assesses                      |

**Two revisions of SP 800-171 are bundled, and confusing them is the commonest error here.** NIST
has formally withdrawn Revision 2, and serves the PDF behind its own notice saying the publication
is archived and provided solely for historical purposes. Revision 2 is nevertheless the operative
version for CMMC, because 32 CFR 170.2 incorporates it by reference and assessment runs against SP
800-171A of June 2018. So Revision 2 answers "what will an assessor check", Revision 3 answers
"what does NIST currently say", and a document citing Revision 3 for a CMMC obligation is wrong
until the rule is amended. Say which revision you are quoting every time you quote one.

SP 800-171A, the assessment procedures themselves, is not bundled, so a question about how an
assessor scores a requirement is one to name as unchecked.

## Do this

1. Read the whole document. Identify the issuing DoW component, the
   solicitation or contract number, whether it is COTS-only, and whether the contractor will
   handle covered defense information or CUI.
2. Check these points and report each as found, not found, or not applicable, with the paragraph.
   Before you report a point, grep the bundled file named beside it:
   - 252.204-7012 appears at all, unless the buy is solely COTS. The prescription is at 204.7304.
   - The 72-hour reporting obligation is stated, with the definition of "rapidly report" and the
     DIBNet address, both of which are in paragraph (a) and paragraph (c) of the clause.
   - A Basic Assessment not more than three years old, posted in SPRS, is required before award and
     before exercising an option (252.204-7019 and 252.204-7020).
   - The CMMC level and the applicable phase are named (252.204-7021 and 252.204-7025). Take the
     phase dates from `32-cfr-170-cmmc-program.md` rather than from memory.
   - Flow-down to subcontractors is addressed, which is paragraph (m) of 252.204-7012.
   - Where a NIST revision is cited, it is Revision 2 with SP 800-171A, and not Revision 3.
   - Where the document names individual security requirements, they match the Revision 2
     numbering in `nist-sp-800-171r2-security-requirements.md`.
3. Suggest an edit only where the fix is wording inside this document for one of the points above,
   such as a wrong NIST revision or a missing reporting window; otherwise describe the gap in one line.
4. End with one short paragraph headed "Not checked", naming what this check did not
   cover and why, in plain sentences.

## Sources

Every rule quoted above is carried in the bundled `reference/` folder, so this check does not
need to fetch anything. These are the editions it was built from, and the place to confirm a
point that matters:

- **DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting**  
  https://www.ecfr.gov/current/title-48/chapter-2/subchapter-H/part-252/subpart-252.2/section-252.204-7012  
  eCFR as amended through 2026-09-01
- **DFARS 252.204-7019, 252.204-7020, 252.204-7021 and 252.204-7025**  
  https://www.ecfr.gov/current/title-48/chapter-2/subchapter-H/part-252/subpart-252.2  
  eCFR as amended through 2026-09-01
- **DFARS Subparts 204.73 and 204.75, which prescribe those clauses**  
  https://www.ecfr.gov/current/title-48/chapter-2/subchapter-A/part-204  
  eCFR as amended through 2026-09-01
- **FAR 52.204-21, Basic Safeguarding of Covered Contractor Information Systems**  
  https://www.ecfr.gov/current/title-48/chapter-1/subchapter-H/part-52/section-52.204-21  
  eCFR as amended through 2026-09-01
- **32 CFR Part 170, Cybersecurity Maturity Model Certification (CMMC) Program**  
  https://www.ecfr.gov/current/title-32/subtitle-A/chapter-I/subchapter-D/part-170  
  eCFR as amended through 2026-09-01
- **NIST SP 800-171 Revision 2, the requirements CMMC assesses against, WITHDRAWN by NIST and still incorporated by reference at 32 CFR 170.2**  
  https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171r2.pdf  
  Revision 2, February 2020, updated 2021-01-28
- **NIST SP 800-171 Revision 3, the current NIST publication, which CMMC does NOT assess against**  
  https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171r3.pdf  
  Revision 3, May 2024
- **NIST SP 800-171A, the assessment procedures, which are named rather than carried here**  
  https://csrc.nist.gov/pubs/sp/800/171/a/final  
  June 2018
