If you have read a defense contract lately, you have seen a wall of DFARS clause numbers. Four of them do most of the work when it comes to protecting CUI and CMMC, and they flow down to subcontractors. Knowing what each requires keeps you from either over- or under-scoping your obligations.
252.204-7012 — Safeguarding CDI and incident reporting
The foundational clause. It requires you to protect Covered Defense Information by implementing NIST SP 800-171, to report cyber incidents to DoD within 72 hours, and to flow the requirement down to subcontractors whose work involves covered information. It has been in contracts for years and predates CMMC.
252.204-7019 — Assessment scoring in SPRS
Requires you to have a current NIST SP 800-171 assessment (not older than three years) and to post the score in the Supplier Performance Risk System (SPRS) before award. It is how the government sees your self-assessed posture.
252.204-7020 — NIST SP 800-171 DoD Assessment Requirements
Obligates you to provide the government access to conduct higher-level assessments and to ensure your subcontractors have posted their scores too. It formalizes the assessment methodology behind the score.
252.204-7021 — CMMC requirement
The clause that ties it together: it requires you to hold the CMMC level the contract specifies, for the life of the contract, and to flow the requirement down to subcontractors at the level appropriate to the information they handle.
The flow-down trap
Flow-down is where primes get surprised. You cannot hand a subcontractor CUI and assume they are covered — the obligation follows the information. A prime is responsible for ensuring its subs carry the right clauses and meet the right level. If your supply chain touches CUI, map it early: who gets what information, and what does each of them owe as a result?
We help primes and subs sort out flow-down and get ready for the level their contracts require. See how we support DIB contractors across the supply chain.