Minds → Government Contracting → What is CMMC and which federal contracts require it under DFARS 252.204-7012 and 252.204-7021?
US Federal

What is CMMC and which federal contracts require it under DFARS 252.204-7012 and 252.204-7021?

As of the phased implementation through November 10, 2028, the Cybersecurity Maturity Model Certification (CMMC) is a DoD program requiring contractors to protect Federal Contract Information (FCI) and Controlled Unclassified Information (CUI) on their information systems. DFARS clause 252.204-7021 requires CMMC in all DoD solicitations and contracts where a contractor will process, store, or transmit FCI or CUI, including most commercial-item acquisitions, with exemptions for acquisitions solely for COTS items and those below the micro-purchase threshold. DFARS 252.204-7012 separately mandates NIST SP 800-171 for safeguarding covered defense information and applies to all DoD contracts except those solely for COTS items.
Last verified: 2026-08-22 · Sources checked: 3/3 resolving · Next scheduled review: 2026-11-20

Details / How it works

What CMMC is

The Cybersecurity Maturity Model Certification (CMMC) is a DoD program, established under 32 CFR Part 170, that verifies contractors protect Federal Contract Information (FCI) and Controlled Unclassified Information (CUI) on their information systems. The CMMC Assessment and Certification Ecosystem comprises private-sector businesses and other entities that perform assessments and certifications under the program.

When CMMC is required (DFARS 252.204-7021 and 32 CFR 170)

  • Until November 9, 2028: DFARS clause 252.204-7021 is included when the program office or requiring activity determines a specific CMMC level is required for the contract.
  • On or after November 10, 2028: the clause applies whenever the contractor will use information systems to process, store, or transmit FCI or CUI (full implementation).
  • Exemption: acquisitions solely for COTS items. CMMC also does not apply below the micro-purchase threshold.

What contracting officers must do

Solicitations state the required CMMC level. Contracting officers shall NOT award a contract, task order, or delivery order to an offeror without a current CMMC status at the required level — and contractors must achieve the required CMMC status at time of award and maintain it, at that level or higher, throughout performance.

Phased implementation

  • Phase 1: Begins on the effective date of the 48 CFR part 204 rule. Requires Level 1 (Self) or Level 2 (Self) for applicable contracts.
  • Phase 2: Begins one calendar year after Phase 1. Adds Level 2 (C3PAO) for applicable contracts.
  • Phase 3: Begins one calendar year after Phase 2. Requires Level 2 (C3PAO) for all applicable contracts.

DFARS 252.204-7012 and NIST SP 800-171

DFARS clause 252.204-7012 is used in all DoD solicitations and contracts — including FAR Part 12 commercial acquisitions — EXCEPT those solely for COTS items. It requires contractors to provide "adequate security" on covered contractor information systems — at minimum implementing NIST SP 800-171. Contractors must also have at least a Basic NIST SP 800-171 DoD Assessment that is current (not more than three years old), with the score posted in the Supplier Performance Risk System (SPRS), before contract award or option exercise (DFARS 252.204-7019/7020 companion provisions).

Cyber incident reporting

DFARS 252.204-7012 requires contractors to rapidly report cyber incidents — within 72 hours of discovery — directly to DoD at dibnet.dod.mil. Subcontractors report to DoD and provide the incident report number up the chain to the prime contractor.

Flowdown

The clause flows down to subcontractors at all tiers when performance involves covered defense information or operationally critical support.

Numbers & thresholds

Requirement Threshold / Date
CMMC applicability (FCI/CUI) Contracts where contractor processes, stores, or transmits FCI or CUI
COTS exemption Acquisitions solely for COTS items are exempt
Micro-purchase threshold exemption CMMC does not apply below the micro-purchase threshold
Phase 1 start Effective date of 48 CFR part 204 rule
Phase 2 start One calendar year after Phase 1
Phase 3 start One calendar year after Phase 2
Full implementation On or after November 10, 2028
Conditional inclusion period Until November 9, 2028 (program office determines level)
Cyber incident reporting deadline Within 72 hours of discovery
NIST SP 800-171 Assessment currency Not more than 3 years old (unless lesser time specified)

Exceptions & edge cases

  • COTS items: CMMC and DFARS 252.204-7012 do not apply to contracts solely for the acquisition of commercially available off-the-shelf (COTS) items.
  • Micro-purchase threshold: CMMC requirements do not apply below the micro-purchase threshold.
  • Federal information systems: CMMC program requirements do not apply to Federal information systems operated by contractors or subcontractors on behalf of the Government (32 CFR 170.3(b)).
  • Waivers: Application of CMMC Program requirements to a procurement or class of procurements may be waived in advance of the solicitation at the discretion of DoD in accordance with all applicable policies, procedures, and approval requirements (32 CFR 170.3(c)(2)).
  • Phase 1 and 2 discretion: During Phase 1, DoD may at its discretion require Level 2 (C3PAO) instead of Level 2 (Self). During Phase 2, DoD may delay the Level 2 (C3PAO) requirement to an option period, and may include Level 3 (DIBCAC).
  • Subcontractors: DFARS 252.204-7012 flows down to subcontractors at all tiers when performance involves covered defense information or operationally critical support. Subcontractors must report cyber incidents to DoD and provide the incident report number up the chain to the prime contractor.

Sources

  1. [1]Acquisition.gov (Defense Acquisition Regulations System) — DFARS Subpart 204.75 — Cybersecurity Maturity Model Certification · as of 2026-08-22
  2. [2]eCFR — Code of Federal Regulations — 32 CFR 170.3 — Applicability (CMMC Program) · as of 2026-08-22
  3. [3]Acquisition.gov (Defense Acquisition Regulations System) — DFARS Subpart 204.73 — Safeguarding Covered Defense Information and Cyber Incident Reporting · as of 2026-08-22

Ask this MIND

This answer is static and source-locked. Ask Government Contracting your version of this question.

Related questions

This is general information, not advice. Government Contracting summarizes primary sources (GSA/Acquisition.gov, SBA, GAO, DoD) as of the dates shown. It is not tax/legal/immigration advice and doesn’t account for your situation. Consult a qualified professional before acting. About this MIND

This page is one mind’s knowledge, published.

MIND turns your documents into a queryable, citable knowledge graph.

Make your own MIND →
Content licensed CC BY 4.0 · Attribution: "Source: MIND (m-i-n-d.ai)" · License terms