DFARS 7012 vs 7021

    DFARS 252.204-7012 vs 7021: Which Clause Triggers What

    Two DFARS clauses dominate every CMMC conversation, and they're constantly confused. 252.204-7012 has required NIST SP 800-171 compliance and 72-hour incident reporting since 2017. 252.204-7021 layers CMMC certification on top of that — turning self-attestation into third-party-assessed certification. Both are active; both flow down to subcontractors. This page clarifies which clause triggers which obligations, when each appears in solicitations, and what your compliance program owes each.

    DFARS 252.204-7012 in one paragraph

    In effect since December 2017. Requires defense contractors that process, store, or transmit Covered Defense Information (CDI — DoD's term for CUI) to: (1) implement the 110 security requirements of NIST SP 800-171, (2) report cyber incidents to DoD within 72 hours, (3) preserve and protect affected systems for at least 90 days, and (4) flow the clause down to subcontractors handling the same data. Until CMMC, compliance was self-attested via a SPRS score.

    DFARS 252.204-7021 in one paragraph

    Activated through 32 CFR Part 170 (the CMMC Program rule, effective December 2024) and the DFARS Case 2019-D041 final rule. Requires contractors to maintain a current CMMC certification at the level specified in the solicitation (Level 1, 2, or 3) for the duration of contract performance, and to flow the requirement to subcontractors. CMMC certification replaces the self-attestation half of 7012; the technical NIST 800-171 requirements remain.

    How the two clauses interact

    • 7012 is the technical baseline. NIST 800-171 implementation, incident reporting, media preservation.
    • 7021 is the proof mechanism. Third-party certification (C3PAO) replaces self-attestation for Level 2 and above.
    • Both clauses flow down. Subcontractors handling CUI inherit both.
    • 7012 has been mandatory since 2017; non-compliance is a False Claims Act exposure today, with or without CMMC.
    • 7021 phases in. DoD is staging CMMC into solicitations over three years (2025–2028). Watch for it in the Section H clauses and the SPRS posting requirement.

    Which solicitations trigger which

    Any DoD prime contract that involves CDI/CUI already triggers 7012. That's been true since 2017 and hasn't changed.

    7021 is triggered by the Section H clause in the solicitation declaring the required CMMC level. As of 2025 you'll see it in DoD acquisitions with CUI, beginning with Tier 1/2 phases per the 32 CFR 170 rollout schedule. By Phase 4 (FY 2028) it's expected to appear in every contract that already carries 7012.

    Subcontractor flowdown follows the data — if you receive CUI from a prime, you carry the same clause obligations to anyone you share it with. Athena's flowdown auditor traces the chain.

    What this means for your program

    • If you have any active DoD contract with CUI, you owe 7012 today. SPRS score posted, NIST 800-171 implemented, 72-hour incident reporting capability ready.
    • If your next renewal or recompete is FY 2026+, plan a CMMC Level 2 assessment. Solicitations will increasingly require an active C3PAO certification at award.
    • Don't conflate the two. Passing CMMC doesn't relieve you of 7012's incident reporting or media preservation obligations. They're independent.
    • Document flowdown. An assessor (or a False Claims Act plaintiff) will ask for the subcontractor list with clause flowdown evidence.

    Frequently asked questions

    Is DFARS 7012 still in effect now that CMMC is here?

    Yes — 7012 has been in effect continuously since December 2017 and remains in effect. CMMC (via 7021) layers on certification as the proof mechanism, but 7012's underlying NIST 800-171 requirements and the 72-hour incident reporting obligation remain.

    Do I have to comply with both clauses?

    If both appear in your contract, yes. In practice 7012 has been mandatory for any CUI-handling DoD contract since 2017, and 7021 is being phased in starting 2025. Most CUI-handling contractors will see both within the next two years.

    What's the penalty for failing DFARS 7012 today?

    False Claims Act exposure is the largest. Aerojet Rocketdyne settled for $9M in 2022 for misrepresenting NIST 800-171 compliance. Contract termination and SPRS score downgrades are administrative outcomes. DoD also reserves the right to deny award based on a low SPRS score.

    Does DFARS 7019 / 7020 fit into this?

    Yes. 7019 requires contractors to post a current SPRS score before award. 7020 requires that DoD have access to verify the score and the underlying SSP/POA&M. Both are companion clauses to 7012 and remain active alongside the new 7021/CMMC framework.

    Further reading

    Related Athena pages and authoritative external references.

    Ready to act on this?

    Run the free Quick Score, then walk through the Assessment Pack.