What is CMMC and which federal contracts require it under DFARS 252.204-7012 and 252.204-7021?
Details / How it works
What CMMC is
The Cybersecurity Maturity Model Certification (CMMC) is a DoD program, established under 32 CFR Part 170, that verifies contractors protect Federal Contract Information (FCI) and Controlled Unclassified Information (CUI) on their information systems. The CMMC Assessment and Certification Ecosystem comprises private-sector businesses and other entities that perform assessments and certifications under the program.
When CMMC is required (DFARS 252.204-7021 and 32 CFR 170)
- Until November 9, 2028: DFARS clause 252.204-7021 is included when the program office or requiring activity determines a specific CMMC level is required for the contract.
- On or after November 10, 2028: the clause applies whenever the contractor will use information systems to process, store, or transmit FCI or CUI (full implementation).
- Exemption: acquisitions solely for COTS items. CMMC also does not apply below the micro-purchase threshold.
What contracting officers must do
Solicitations state the required CMMC level. Contracting officers shall NOT award a contract, task order, or delivery order to an offeror without a current CMMC status at the required level — and contractors must achieve the required CMMC status at time of award and maintain it, at that level or higher, throughout performance.
Phased implementation
- Phase 1: Begins on the effective date of the 48 CFR part 204 rule. Requires Level 1 (Self) or Level 2 (Self) for applicable contracts.
- Phase 2: Begins one calendar year after Phase 1. Adds Level 2 (C3PAO) for applicable contracts.
- Phase 3: Begins one calendar year after Phase 2. Requires Level 2 (C3PAO) for all applicable contracts.
DFARS 252.204-7012 and NIST SP 800-171
DFARS clause 252.204-7012 is used in all DoD solicitations and contracts — including FAR Part 12 commercial acquisitions — EXCEPT those solely for COTS items. It requires contractors to provide "adequate security" on covered contractor information systems — at minimum implementing NIST SP 800-171. Contractors must also have at least a Basic NIST SP 800-171 DoD Assessment that is current (not more than three years old), with the score posted in the Supplier Performance Risk System (SPRS), before contract award or option exercise (DFARS 252.204-7019/7020 companion provisions).
Cyber incident reporting
DFARS 252.204-7012 requires contractors to rapidly report cyber incidents — within 72 hours of discovery — directly to DoD at dibnet.dod.mil. Subcontractors report to DoD and provide the incident report number up the chain to the prime contractor.
Flowdown
The clause flows down to subcontractors at all tiers when performance involves covered defense information or operationally critical support.
Numbers & thresholds
| Requirement | Threshold / Date |
|---|---|
| CMMC applicability (FCI/CUI) | Contracts where contractor processes, stores, or transmits FCI or CUI |
| COTS exemption | Acquisitions solely for COTS items are exempt |
| Micro-purchase threshold exemption | CMMC does not apply below the micro-purchase threshold |
| Phase 1 start | Effective date of 48 CFR part 204 rule |
| Phase 2 start | One calendar year after Phase 1 |
| Phase 3 start | One calendar year after Phase 2 |
| Full implementation | On or after November 10, 2028 |
| Conditional inclusion period | Until November 9, 2028 (program office determines level) |
| Cyber incident reporting deadline | Within 72 hours of discovery |
| NIST SP 800-171 Assessment currency | Not more than 3 years old (unless lesser time specified) |
Exceptions & edge cases
- COTS items: CMMC and DFARS 252.204-7012 do not apply to contracts solely for the acquisition of commercially available off-the-shelf (COTS) items.
- Micro-purchase threshold: CMMC requirements do not apply below the micro-purchase threshold.
- Federal information systems: CMMC program requirements do not apply to Federal information systems operated by contractors or subcontractors on behalf of the Government (32 CFR 170.3(b)).
- Waivers: Application of CMMC Program requirements to a procurement or class of procurements may be waived in advance of the solicitation at the discretion of DoD in accordance with all applicable policies, procedures, and approval requirements (32 CFR 170.3(c)(2)).
- Phase 1 and 2 discretion: During Phase 1, DoD may at its discretion require Level 2 (C3PAO) instead of Level 2 (Self). During Phase 2, DoD may delay the Level 2 (C3PAO) requirement to an option period, and may include Level 3 (DIBCAC).
- Subcontractors: DFARS 252.204-7012 flows down to subcontractors at all tiers when performance involves covered defense information or operationally critical support. Subcontractors must report cyber incidents to DoD and provide the incident report number up the chain to the prime contractor.
Sources
- [1]Acquisition.gov (Defense Acquisition Regulations System) — DFARS Subpart 204.75 — Cybersecurity Maturity Model Certification · as of 2026-08-22
- [2]eCFR — Code of Federal Regulations — 32 CFR 170.3 — Applicability (CMMC Program) · as of 2026-08-22
- [3]Acquisition.gov (Defense Acquisition Regulations System) — DFARS Subpart 204.73 — Safeguarding Covered Defense Information and Cyber Incident Reporting · as of 2026-08-22
Ask this MIND
This answer is static and source-locked. Ask Government Contracting your version of this question.
Related questions
This page is one mind’s knowledge, published.
MIND turns your documents into a queryable, citable knowledge graph.
Make your own MIND →