DFARS 252.204-7012 vs CMMC: What Contractors Must Know
DFARS 252.204-7012 is the contract clause that tells you to protect defense information. CMMC is the program that makes you prove you did. They are not two competing rules you get to choose between. They are two ends of the same obligation, and the number that connects them is your SPRS score.
Most contractors treat these as separate projects, or assume one replaced the other. Neither is true. The clause has been in your contracts for years and still governs your day-to-day duty to safeguard data. CMMC is the new verification layer the Department of Defense built on top of it because self-attestation alone stopped being good enough. If you handle defense data, you live under both at once. This guide draws the line between them so you know exactly what each one asks of you.
If you want the broader background on the certification program first, start with our complete guide to CMMC 2.0 and come back here for the comparison.
The short answer: one says what to protect, the other makes you prove it
Here is the distinction in one breath. DFARS 252.204-7012 is an ongoing operational obligation. CMMC is a certification milestone. The clause requires you to implement a security standard and report incidents, and it lets you self-attest that you have done so. CMMC takes that same security standard and adds independent verification, so a contracting officer is no longer taking your word for it.
The part that trips people up is that both point at the exact same controls. DFARS 7012 requires you to implement NIST SP 800-171, all 110 controls. CMMC Level 2, the level that applies to most contractors handling sensitive data, requires those same 110 controls. There is no separate CMMC control set to learn. The security work is identical. What changes is how you prove it: under the clause you score yourself, under CMMC a third party may score you instead.
What DFARS 252.204-7012 actually requires
The clause has been mandatory in DoD contracts involving covered defense information since 2017. Strip away the legalese and it asks four things of you.
- Implement NIST SP 800-171. All 110 security controls, across the 14 control families, protecting controlled unclassified information on your systems.
- Report cyber incidents within 72 hours. The clock starts when you discover the incident, not when it happened. A breach you uncover today that began weeks ago gives you 72 hours from today.
- Use cloud that meets FedRAMP Moderate. If a cloud provider stores, processes, or transmits your covered defense information, it has to meet security requirements equivalent to the FedRAMP Moderate baseline.
- Flow the clause down to subcontractors. Every subcontractor that touches covered defense information inherits the same 110 controls and the same 72-hour reporting duty. You cannot offload the obligation by handing the data to a supplier.
Here is the operative word in all of it: self-attest. Until recently, you proved compliance with DFARS 7012 by entering a score into a government database and signing your name. No assessor walked your floor. No certificate changed hands. You said you were compliant, and the contract proceeded on that representation. That single fact is what created the problem CMMC exists to fix.
What CMMC adds on top
The Cybersecurity Maturity Model Certification program does not change the controls. It changes the proof. The Department of Defense found, through its own assessments, that a large share of contractors who had attested to compliance had not actually implemented the controls they claimed. CMMC is the response: a graded, verified status you carry into a contract.
It comes in three levels, and the level is set by the kind of data your contract involves:
- Level 1, Foundational. Covers contractors that only handle federal contract information, the basic non-public data of a contract. It maps to 15 controls and stays a self-assessment.
- Level 2, Advanced. The level for controlled unclassified information. It is the full 110 NIST SP 800-171 controls, and for most prioritized CUI it requires a certified assessment by an accredited third party, a C3PAO, every three years.
- Level 3, Expert. Reserved for the most sensitive programs. It adds a subset of NIST SP 800-172 controls on top of Level 2 and is assessed by the government itself, not a C3PAO.

There is one more piece CMMC adds that the clause never required: an annual affirmation. Each year a senior official has to log into the government system and personally attest that your company still meets the controls. That signature is not a formality. It is a named individual putting their name on the line, which matters a great deal when we get to the legal risk below.
FCI or CUI? The question that sets your obligation
Before any of this applies cleanly, you have to know which kind of data you handle, because it decides everything downstream. Two terms matter.
Federal contract information, or FCI, is information provided by or generated for the government under a contract that is not meant for public release. Controlled unclassified information, or CUI, is more sensitive data that law or policy requires you to safeguard. The rule of thumb: all CUI in a contractor's hands is also FCI, but not all FCI rises to CUI.
The line has real consequences. If you only ever handle FCI, you fall under basic safeguarding and CMMC Level 1, roughly 15 to 17 controls. The moment CUI enters your environment, DFARS 252.204-7012 attaches, all 110 controls apply, and you are looking at CMMC Level 2. Many contractors get their scope wrong here, assuming they only touch FCI when a single email or drawing pulls CUI into their systems. Getting this classification right is the first step of any honest compliance program.
Your SPRS score is the link between the two
If DFARS 7012 and CMMC feel like two systems, the Supplier Performance Risk System, or SPRS, is the wire running between them. SPRS is the government database where your NIST 800-171 assessment score lives. Under the clause, you self-report your score there. Under CMMC, your assessment result is posted there too. It is the one number a contracting officer can pull up to decide whether you are eligible to compete.

The math behind the score surprises people, so it is worth understanding before you report one.
- It is subtractive. You start at a perfect 110 and subtract points for every control you have not fully implemented. You do not earn your way up; you lose your way down.
- Controls are weighted 1, 3, or 5 points. A missing 5-point control, like multi-factor authentication, costs far more than a missing 1-point control. The weighting reflects how much each gap actually exposes you.
- There is no partial credit, and the score can go negative. A control is fully met or it is not met. The range runs from positive 110 at the top all the way down to negative 203.
To produce a valid score you need two documents behind it: a current System Security Plan that describes how you meet each control, and a Plan of Action and Milestones, a POA&M, that lists every gap and the date you will close it. A score with no SSP and POA&M underneath it is a guess, and an assessor will treat it as one. This is exactly where a clean SSP and POA&M earns its keep.
CMMC does add one rule the clause never had: a floor for deferring work. To earn a conditional Level 2 status with open items, you have to score at least 80 percent, which is 88 of the 110 points, and the gaps you defer must be low-weighted 1-point controls. You then have 180 days to close them out. Below 88, a POA&M will not carry you. The high-value 3-point and 5-point controls cannot be deferred at all.
Why a wrong SPRS score is now a legal problem
Here is the uncomfortable part. Because your SPRS score is a representation you make to the government to win a contract, an inflated score is not just a compliance miss. It is a potential violation of the False Claims Act, which carries treble damages, three times the government's loss, plus penalties.
This is not theoretical. The Department of Justice has settled more than a dozen civil cyber-fraud cases, and the pace is accelerating. In one settlement, defense contractor MORSECORP agreed to pay 4.6 million dollars after submitting SPRS scores it knew were incorrect and failing to update a positive score after a third-party assessment came back failing. The case turned on a misrepresentation, not a breach. No data had to be stolen for the liability to attach.
Remember that annual affirmation CMMC introduced? This is why it matters. A named senior official is now personally attesting to the score. That makes a knowingly inflated number harder to wave off as an honest mistake, and it gives a whistleblower, often a former employee, a signed document to point at. The lesson operators should take from this is blunt: a low SPRS score reported honestly is a manageable problem. A high score you cannot defend is a lawsuit waiting for a trigger.
What changed in 2025 and 2026
The program stopped being a proposal and became a contract reality. Two rules drove the shift.
The CMMC Program rule, 32 CFR, took effect on December 16, 2024, standing up the framework, the levels, and the assessment ecosystem. Then the acquisition rule, 48 CFR, took effect on November 10, 2025, authorizing contracting officers to put CMMC requirements directly into solicitations. That second date is the one that put teeth into the program, and it kicked off a four-phase rollout.
- Phase 1, beginning November 10, 2025. New solicitations start requiring self-assessed Level 1 or Level 2 scores in SPRS as a condition of award.
- Phase 2, beginning November 10, 2026. Third-party C3PAO certification at Level 2 starts appearing as a requirement in new contracts.
- Phases 3 and 4, 2027 and 2028. Level 3 assessments arrive, and certification requirements extend until they reach effectively all applicable DoD contracts.

There was also some housekeeping in the clause family. As the CMMC mechanism came online, the older standalone self-assessment clause, DFARS 252.204-7019, was removed, and the assessment obligation now runs through the CMMC clause, 252.204-7021. The takeaway is not the renumbering. It is that the self-attestation era is closing and the verification era has started. The phase-in is a runway, not a reprieve. Contracting officers can require CMMC early, and the higher-risk programs are first in line.
What contractors should do now
You do not start with 110 controls. You start with two questions, and the rest of the work organizes itself behind them: what data do you actually handle, and what does your contract require you to prove. From there the sequence is steady.
- Classify your data. Confirm whether you touch CUI or only FCI. This sets your level and your control count before you spend a dollar.
- Run a gap assessment for a real SPRS baseline. Score yourself honestly against all 110 controls so you know where you actually stand, not where you hope you stand.
- Fix the 5-point controls first. They move your score the most and cannot be deferred onto a POA&M. This is where preparation pays the highest return.
- Write the SSP and POA&M as you go. Document each control as you implement it, not in a panic the week before an assessment. The documentation is half of what an assessor grades.
- Confirm your assessment path early. Know whether your contracts trigger a self-assessment or a C3PAO certification, because the cost and timeline differ sharply, and discovering the requirement during a bid is the expensive way to learn it.
Consilien runs this process end to end for defense contractors and manufacturers across California, from the first data-classification review through CMMC compliance services and the broader managed cybersecurity that keeps those 110 controls in place after the certificate is issued. If you are staring at a negative SPRS score and a contract deadline, that is the moment to get help, not after the affirmation is signed.