4.2 FAR, DFARS & 32 CFR Part 170
Key Takeaways
- FAR 52.204-21 supplies the 15 basic safeguarding requirements used at CMMC Level 1.
- DFARS 252.204-7012 addresses adequate security, 72-hour cyber-incident reporting, 90-day media preservation, cloud safeguards, and flowdown for covered defense information.
- DFARS 252.204-7019 and -7020 govern NIST SP 800-171 assessment records in SPRS and government assessment access.
- 32 CFR part 170 establishes the CMMC program; contractual CMMC obligations apply through the acquisition rule and the clauses actually included in a solicitation or contract.
- Current rollout is paused in Phase I after the July 13, 2026 suspension of Phase II requirements; existing NIST and DFARS duties continue.
4.2 FAR, DFARS & 32 CFR Part 170
CMMC operates through both a program rule and contract clauses. A regulation can define the CMMC architecture without automatically inserting the same requirement into every contract. For a scenario, read the data, solicitation or contract, applicable clause, required CMMC status, and implementation date.
FAR 52.204-21 and Level 1
FAR 52.204-21, Basic Safeguarding of Covered Contractor Information Systems, applies when a covered contractor system processes, stores, or transmits Federal Contract Information, subject to the clause's terms and exceptions. Its 15 basic safeguarding requirements form CMMC Level 1 across six families:
| Family | Requirement themes |
|---|---|
| Access Control | Authorized users and functions; external connections; public-system posting |
| Identification and Authentication | Identify and authenticate users, processes, and devices |
| Media Protection | Sanitize or destroy media before disposal or reuse |
| Physical Protection | Limit physical access; escort and monitor visitors; maintain logs; manage access devices |
| System and Communications Protection | Protect boundaries; separate public-facing components |
| System and Information Integrity | Correct flaws; protect against malicious code; update protection; perform periodic and real-time scans as specified |
Level 1 requires all 15 requirements to be MET. It is assessed annually by the organization, does not permit POA&Ms, and requires an affirmation by the Affirming Official. Do not use the superseded 17-practice count from earlier CMMC material.
DFARS 252.204-7012
DFARS 252.204-7012 applies to covered defense information and operationally critical support as specified by the clause. It requires adequate security on covered contractor information systems, including NIST SP 800-171 requirements for nonfederal systems unless an authorized variance applies.
A contractor must rapidly report a covered cyber incident to DoD within 72 hours of discovery. It must preserve and protect images of known affected systems identified in the required review, plus relevant monitoring or packet-capture data, for at least 90 days from report submission so DoD can request them. The exact clause controls what must be reviewed, reported, preserved, submitted, and flowed down.
When an external cloud service provider will store, process, or transmit covered defense information, the provider must meet the security requirements in the clause, including FedRAMP Moderate authorization or the applicable DoD definition of Moderate equivalency, and comply with incident-support obligations. “CMMC ready” marketing is not a substitute for the required authorization or body of evidence.
The 7012 flowdown is tied to subcontract performance involving covered defense information or operationally critical support, not merely to the prime's overall status. Information flow and subcontract language must align.
DFARS 252.204-7019 and -7020
DFARS 252.204-7019 gives notice of NIST SP 800-171 DoD assessment requirements and requires a current assessment in SPRS when the clause applies. DFARS 252.204-7020 provides for DoD assessment and access and requires applicable subcontract verification and flowdown.
The DoD Assessment Methodology begins at 110 and deducts one, three, or five points for unmet requirements, with a possible low score of -203. Basic, Medium, and High assessments indicate different confidence levels. That score is related to CMMC Level 2 but is not interchangeable with a CMMC certificate or the conditional-status ratio in §170.21.
32 CFR part 170 and acquisition implementation
32 CFR part 170 establishes the CMMC program: levels, assessment types, scoping, roles, status periods, scoring, POA&M limits, affirmations, C3PAO and assessor requirements, and standards acceptance. The acquisition rule and contract clause implement CMMC as a condition in covered procurements. A C3PAO does not decide whether a procurement requires Level 1, Level 2 Self, Level 2 C3PAO, or Level 3; the solicitation or contract does.
CMMC status and affirmation are different records. An assessment establishes a status for a defined scope and period. The organization's Affirming Official then submits the required affirmation in SPRS after the assessment and annually thereafter. A C3PAO uploads certification-assessment results through CMMC eMASS under CAP.
POA&M and status essentials
Level 1 permits no POA&M. Level 2 conditional status is possible only when the score divided by 110 applicable Level 2 requirements is at least 0.8 and every remaining item satisfies §170.21. Requirements worth more than one point are generally excluded, subject to the narrow nonvalidated-encryption exception for SC.L2-3.13.11, and six named requirements are categorically excluded. Closeout is due within 180 days or conditional status expires.
Current implementation status
DoD began CMMC Phase I on November 10, 2025. On July 13, 2026, it suspended Phase II requirements, so rollout is currently paused in Phase I. Phase I self-assessment requirements remain in effect where applied. The suspension does not cancel existing DFARS 252.204-7012, -7019, or -7020 obligations, NIST SP 800-171 duties, professional credentialing, or voluntary preparation. Because rollout is time-sensitive, verify the current DoD implementation notice before an exam or contract decision.
Clause-analysis sequence
For an exam scenario: classify the information; identify the system and provider; read the incorporated clause; identify the assessment or status required at award and during performance; determine the correct record system; and apply flowdown only to the subcontract work and data that trigger it. This sequence avoids turning general program rules into unsupported universal contract claims.
How many requirements are in current CMMC Level 1?
Which clause contains the 72-hour cyber-incident reporting and 90-day preservation duties?
What did the July 13, 2026 DoD action do?