DFARS 252.204-7012 vs CMMC: What Contractors Must Know

06/22/2026
Compliance
DFARS 252.204-7012 vs CMMC: What Contractors Must Know

DFARS 252.204-7012 is the contract clause that tells you to protect defense information. CMMC is the program that makes you prove you did. They are not two competing rules you get to choose between. They are two ends of the same obligation, and the number that connects them is your SPRS score.

Most contractors treat these as separate projects, or assume one replaced the other. Neither is true. The clause has been in your contracts for years and still governs your day-to-day duty to safeguard data. CMMC is the new verification layer the Department of Defense built on top of it because self-attestation alone stopped being good enough. If you handle defense data, you live under both at once. This guide draws the line between them so you know exactly what each one asks of you.

If you want the broader background on the certification program first, start with our complete guide to CMMC 2.0 and come back here for the comparison.

The short answer: one says what to protect, the other makes you prove it

Here is the distinction in one breath. DFARS 252.204-7012 is an ongoing operational obligation. CMMC is a certification milestone. The clause requires you to implement a security standard and report incidents, and it lets you self-attest that you have done so. CMMC takes that same security standard and adds independent verification, so a contracting officer is no longer taking your word for it.

The part that trips people up is that both point at the exact same controls. DFARS 7012 requires you to implement NIST SP 800-171, all 110 controls. CMMC Level 2, the level that applies to most contractors handling sensitive data, requires those same 110 controls. There is no separate CMMC control set to learn. The security work is identical. What changes is how you prove it: under the clause you score yourself, under CMMC a third party may score you instead.

What DFARS 252.204-7012 actually requires

The clause has been mandatory in DoD contracts involving covered defense information since 2017. Strip away the legalese and it asks four things of you.

  • Implement NIST SP 800-171. All 110 security controls, across the 14 control families, protecting controlled unclassified information on your systems.
  • Report cyber incidents within 72 hours. The clock starts when you discover the incident, not when it happened. A breach you uncover today that began weeks ago gives you 72 hours from today.
  • Use cloud that meets FedRAMP Moderate. If a cloud provider stores, processes, or transmits your covered defense information, it has to meet security requirements equivalent to the FedRAMP Moderate baseline.
  • Flow the clause down to subcontractors. Every subcontractor that touches covered defense information inherits the same 110 controls and the same 72-hour reporting duty. You cannot offload the obligation by handing the data to a supplier.

Here is the operative word in all of it: self-attest. Until recently, you proved compliance with DFARS 7012 by entering a score into a government database and signing your name. No assessor walked your floor. No certificate changed hands. You said you were compliant, and the contract proceeded on that representation. That single fact is what created the problem CMMC exists to fix.

What CMMC adds on top

The Cybersecurity Maturity Model Certification program does not change the controls. It changes the proof. The Department of Defense found, through its own assessments, that a large share of contractors who had attested to compliance had not actually implemented the controls they claimed. CMMC is the response: a graded, verified status you carry into a contract.

It comes in three levels, and the level is set by the kind of data your contract involves:

  • Level 1, Foundational. Covers contractors that only handle federal contract information, the basic non-public data of a contract. It maps to 15 controls and stays a self-assessment.
  • Level 2, Advanced. The level for controlled unclassified information. It is the full 110 NIST SP 800-171 controls, and for most prioritized CUI it requires a certified assessment by an accredited third party, a C3PAO, every three years.
  • Level 3, Expert. Reserved for the most sensitive programs. It adds a subset of NIST SP 800-172 controls on top of Level 2 and is assessed by the government itself, not a C3PAO.

The three CMMC levels rising from Level 1 Foundational to Level 2 Advanced to Level 3 Expert

There is one more piece CMMC adds that the clause never required: an annual affirmation. Each year a senior official has to log into the government system and personally attest that your company still meets the controls. That signature is not a formality. It is a named individual putting their name on the line, which matters a great deal when we get to the legal risk below.

FCI or CUI? The question that sets your obligation

Before any of this applies cleanly, you have to know which kind of data you handle, because it decides everything downstream. Two terms matter.

Federal contract information, or FCI, is information provided by or generated for the government under a contract that is not meant for public release. Controlled unclassified information, or CUI, is more sensitive data that law or policy requires you to safeguard. The rule of thumb: all CUI in a contractor's hands is also FCI, but not all FCI rises to CUI.

The line has real consequences. If you only ever handle FCI, you fall under basic safeguarding and CMMC Level 1, roughly 15 to 17 controls. The moment CUI enters your environment, DFARS 252.204-7012 attaches, all 110 controls apply, and you are looking at CMMC Level 2. Many contractors get their scope wrong here, assuming they only touch FCI when a single email or drawing pulls CUI into their systems. Getting this classification right is the first step of any honest compliance program.

Your SPRS score is the link between the two

If DFARS 7012 and CMMC feel like two systems, the Supplier Performance Risk System, or SPRS, is the wire running between them. SPRS is the government database where your NIST 800-171 assessment score lives. Under the clause, you self-report your score there. Under CMMC, your assessment result is posted there too. It is the one number a contracting officer can pull up to decide whether you are eligible to compete.

An SPRS score gauge climbing toward 110, the perfect NIST 800-171 score

The math behind the score surprises people, so it is worth understanding before you report one.

  • It is subtractive. You start at a perfect 110 and subtract points for every control you have not fully implemented. You do not earn your way up; you lose your way down.
  • Controls are weighted 1, 3, or 5 points. A missing 5-point control, like multi-factor authentication, costs far more than a missing 1-point control. The weighting reflects how much each gap actually exposes you.
  • There is no partial credit, and the score can go negative. A control is fully met or it is not met. The range runs from positive 110 at the top all the way down to negative 203.

To produce a valid score you need two documents behind it: a current System Security Plan that describes how you meet each control, and a Plan of Action and Milestones, a POA&M, that lists every gap and the date you will close it. A score with no SSP and POA&M underneath it is a guess, and an assessor will treat it as one. This is exactly where a clean SSP and POA&M earns its keep.

CMMC does add one rule the clause never had: a floor for deferring work. To earn a conditional Level 2 status with open items, you have to score at least 80 percent, which is 88 of the 110 points, and the gaps you defer must be low-weighted 1-point controls. You then have 180 days to close them out. Below 88, a POA&M will not carry you. The high-value 3-point and 5-point controls cannot be deferred at all.

Why a wrong SPRS score is now a legal problem

Here is the uncomfortable part. Because your SPRS score is a representation you make to the government to win a contract, an inflated score is not just a compliance miss. It is a potential violation of the False Claims Act, which carries treble damages, three times the government's loss, plus penalties.

This is not theoretical. The Department of Justice has settled more than a dozen civil cyber-fraud cases, and the pace is accelerating. In one settlement, defense contractor MORSECORP agreed to pay 4.6 million dollars after submitting SPRS scores it knew were incorrect and failing to update a positive score after a third-party assessment came back failing. The case turned on a misrepresentation, not a breach. No data had to be stolen for the liability to attach.

Remember that annual affirmation CMMC introduced? This is why it matters. A named senior official is now personally attesting to the score. That makes a knowingly inflated number harder to wave off as an honest mistake, and it gives a whistleblower, often a former employee, a signed document to point at. The lesson operators should take from this is blunt: a low SPRS score reported honestly is a manageable problem. A high score you cannot defend is a lawsuit waiting for a trigger.

What changed in 2025 and 2026

The program stopped being a proposal and became a contract reality. Two rules drove the shift.

The CMMC Program rule, 32 CFR, took effect on December 16, 2024, standing up the framework, the levels, and the assessment ecosystem. Then the acquisition rule, 48 CFR, took effect on November 10, 2025, authorizing contracting officers to put CMMC requirements directly into solicitations. That second date is the one that put teeth into the program, and it kicked off a four-phase rollout.

  • Phase 1, beginning November 10, 2025. New solicitations start requiring self-assessed Level 1 or Level 2 scores in SPRS as a condition of award.
  • Phase 2, beginning November 10, 2026. Third-party C3PAO certification at Level 2 starts appearing as a requirement in new contracts.
  • Phases 3 and 4, 2027 and 2028. Level 3 assessments arrive, and certification requirements extend until they reach effectively all applicable DoD contracts.

The phased CMMC rollout from 2024 through 2028 leading to full certification requirements

There was also some housekeeping in the clause family. As the CMMC mechanism came online, the older standalone self-assessment clause, DFARS 252.204-7019, was removed, and the assessment obligation now runs through the CMMC clause, 252.204-7021. The takeaway is not the renumbering. It is that the self-attestation era is closing and the verification era has started. The phase-in is a runway, not a reprieve. Contracting officers can require CMMC early, and the higher-risk programs are first in line.

What contractors should do now

You do not start with 110 controls. You start with two questions, and the rest of the work organizes itself behind them: what data do you actually handle, and what does your contract require you to prove. From there the sequence is steady.

  • Classify your data. Confirm whether you touch CUI or only FCI. This sets your level and your control count before you spend a dollar.
  • Run a gap assessment for a real SPRS baseline. Score yourself honestly against all 110 controls so you know where you actually stand, not where you hope you stand.
  • Fix the 5-point controls first. They move your score the most and cannot be deferred onto a POA&M. This is where preparation pays the highest return.
  • Write the SSP and POA&M as you go. Document each control as you implement it, not in a panic the week before an assessment. The documentation is half of what an assessor grades.
  • Confirm your assessment path early. Know whether your contracts trigger a self-assessment or a C3PAO certification, because the cost and timeline differ sharply, and discovering the requirement during a bid is the expensive way to learn it.

Consilien runs this process end to end for defense contractors and manufacturers across California, from the first data-classification review through CMMC compliance services and the broader managed cybersecurity that keeps those 110 controls in place after the certificate is issued. If you are staring at a negative SPRS score and a contract deadline, that is the moment to get help, not after the affirmation is signed.

Know Your Real SPRS Score Before the DoD Does

Consilien scores your environment against all 110 NIST 800-171 controls, builds the SSP and POA&M your assessor will accept, and takes you from a DFARS 7012 self-attestation to CMMC Level 2 certification readiness. Defend the number you report.

Frequently Asked Questions About DFARS 252.204-7012 and CMMC

Does CMMC replace DFARS 252.204-7012?
No. DFARS 252.204-7012 remains your ongoing duty to safeguard covered defense information, report incidents within 72 hours, and flow the clause down to subcontractors. CMMC is the verification layer that proves you have implemented the NIST 800-171 controls the clause requires. You comply with both at the same time.
What is the difference between a DFARS self-assessment and a CMMC assessment?
Both score you against the same 110 NIST 800-171 controls. A DFARS self-assessment is internal: you score yourself and submit the result to SPRS. A CMMC Level 2 assessment, for most prioritized CUI, is conducted by an accredited third party, a C3PAO, which issues a formal certification. The controls are identical; the independence of the verification is what changes.
How does my SPRS score connect DFARS and CMMC?
SPRS is the government database that holds your NIST 800-171 score. Under DFARS 7012 you self-report it there; under CMMC your assessment result is posted there. It is the single number a contracting officer checks to confirm you are eligible to bid. The score starts at 110 and subtracts weighted points for every control you have not fully implemented, down to a floor of negative 203.
Can I be sued for reporting a wrong SPRS score?
Yes. A knowingly inflated SPRS score can trigger False Claims Act liability, which carries treble damages and penalties, even with no data breach involved. The Department of Justice has settled multiple cyber-fraud cases on exactly this basis, including a defense contractor that paid 4.6 million dollars for submitting scores it knew were incorrect. A low score reported honestly is far safer than a high score you cannot defend.
Do I need CMMC Level 1 or Level 2?
It depends on the data your contract involves. If you only handle federal contract information (FCI), Level 1 and its roughly 15 controls apply, by self-assessment. If you store, process, or transmit controlled unclassified information (CUI), DFARS 7012 attaches, all 110 controls apply, and you fall under Level 2, which often requires a C3PAO certification. Classifying your data correctly is the first step.
When do CMMC requirements actually hit my contracts?
They already have. The CMMC Program rule took effect December 16, 2024, and the acquisition rule took effect November 10, 2025, starting a phased rollout. Phase 1 requires self-assessed scores in SPRS, Phase 2 (November 2026) adds third-party certification at Level 2, and Phases 3 and 4 extend requirements through 2028. Contracting officers can include CMMC early, so waiting until a clause appears in a bid you want means you are already behind.

Related Articles

Stay ahead with expert tips, industry trends, and actionable strategies.