Guides / September 30, 2026
What Are DFARS 252.204-7019 and 7020?
Two clause numbers keep appearing in your solicitations, and nobody can explain what each one requires.
The short version
DFARS is the Defense Federal Acquisition Regulation Supplement. It is the Pentagon's add-on to federal buying rules. Clauses 252.204-7019 and 252.204-7020 both deal with one thing: proving you protect CUI. CUI is Controlled Unclassified Information.
7019 is the gate before award. 7020 is the rulebook during the contract. Here is what each one asks of you.
7019: the gate before award
7019 is a solicitation provision. It shows up in bids, not in signed contracts. Its job is simple. It tells you what you need before DoD will consider your offer. DoD is the Department of Defense.
If you must implement NIST SP 800-171, you need a current assessment. It must cover each covered contractor system tied to the offer. A covered contractor system is a system that handles covered defense information under DFARS 252.204-7012. (DFARS 252.204-7019)
You must also verify that summary scores are posted in SPRS. SPRS is the Supplier Performance Risk System. If you have no current score posted, you may conduct a Basic Assessment and submit it for posting. No current score means no award. (DFARS 252.204-7019)
7020: the clause inside the contract
7020 is a contract clause. It applies once you hold the work. It defines three assessment levels and sets your duties during performance.
Basic Assessment is your own self-assessment. It is based on your system security plan and follows the DoD Assessment Methodology. DoD treats its confidence level as low, because the score is self-generated.
Medium Assessment is done by the Government. It reviews your Basic Assessment, reviews your documents, and includes discussions with your team. Its confidence level is medium.
High Assessment is done by Government personnel using NIST SP 800-171A. It adds verification, examination, and demonstration of your system security plan. Its confidence level is high. (DFARS 252.204-7020)
If DoD needs to run a Medium or High assessment, you must grant access. That means your facilities, systems, and people.
Scores are posted to SPRS. For Medium and High assessments, DoD posts the score and gives you 14 business days to rebut findings first.
You must flow the clause down to subcontractors. Do not award subcontracts subject to 800-171 without checking one thing. The subcontractor must hold a Basic Assessment from within the last 3 years. (DFARS 252.204-7020)
The scoring method both clauses use
Both clauses point to one document: the NIST SP 800-171 DoD Assessment Methodology. The method starts you at 110 points. Each unmet requirement subtracts points. Your SPRS score is the total, not the per-requirement detail. (NIST SP 800-171 DoD Assessment Methodology)
What to do this week
For 7019: score yourself honestly against all 110 requirements using the DoD methodology. Confirm the resulting summary score is posted in SPRS. If it is older than 3 years, redo it before your next bid.
For 7020: list every subcontractor that handles covered defense information. Confirm each one holds a current Basic Assessment. Add the flow-down clause to any subcontract missing it.
Then set a yearly reminder. The CMMC program rules require a senior official to affirm your status in SPRS each year. (32 CFR Part 170)
Sources
- DFARS 252.204-7019, Notice of NIST SP 800-171 DoD Assessment Requirements: https://www.acquisition.gov/dfars/252.204-7019-notice-nist-sp-800-171-dod-assessment-requirements.?searchTerms=DFARS+Provision+252.204-7019%3A+Notice+of+NIST+SP+800-171+DoD+Assessment+Requirements
- DFARS 252.204-7020, NIST SP 800-171 DoD Assessment Requirements: https://www.acquisition.gov/dfars/252.204-7020-nist-sp-800-171dod-assessment-requirements.
- NIST SP 800-171 DoD Assessment Methodology, version 1.2.1: https://www.acq.osd.mil/asda/dpc/cp/cyber/docs/safeguarding/NIST-SP-800-171-Assessment-Methodology-Version-1.2.1-6.24.2020.pdf
- 32 CFR Part 170, Cybersecurity Maturity Model Certification (CMMC) Program: https://www.ecfr.gov/current/title-32/subtitle-A/chapter-I/subchapter-G/part-170
Next step
Score yourself against live data instead of memory. PolicyCortex reads live Azure configuration, evaluates it against NIST 800-171, and re-verifies after you remediate. See how it works.