Guides / September 28, 2026
A Simple DFARS Readiness Checklist for Small Contractors
DFARS stands for Defense Federal Acquisition Regulation Supplement, the Defense Department's contract rulebook. Small contractors face the same DFARS rules as big ones. The difference is staff and budget. CUI stands for Controlled Unclassified Information, the sensitive data the rules protect. This checklist keeps the work in order. Work it top to bottom.
1. Find where your CUI lives
You cannot protect what you cannot find. Most small contractors discover CUI in places they forgot.
List every system that touches CUI: email, file shares, laptops, phones. Note who can access each system and why. Remove access nobody can explain.
Draw the boundary on paper. The systems inside that line are your covered systems. Everything outside the line should not hold CUI at all.
2. Put NIST 800-171 in place
The clause requires adequate security on systems that hold covered defense information. (DFARS 252.204-7012) For most companies that means the NIST 800-171 requirements. (DFARS 252.204-7012)
Start with the basics that stop most attacks:
- Turn on multi-factor authentication for remote access.
- Encrypt CUI on laptops, phones, and portable drives.
- Keep an inventory of every device that touches CUI.
- Patch systems on a schedule and record each round.
Then work through the rest of the requirements one family at a time. Do not cherry-pick. The clause expects all of them.
3. Write your System Security Plan
Assessors read your documents before they touch your systems. A System Security Plan describes your systems and the controls on them.
Write the plan in plain language. Name each system, who uses it, and which controls protect it. Note any extra measures your risk called for. (DFARS 252.204-7012)
Also write an incident response plan with names and phone numbers. Review both documents once a year and note the date.
4. Set up incident reporting before you need it
Cyber incidents must be reported within 72 hours of discovery. (DFARS 252.204-7012) To file, you need a DoD-approved medium assurance certificate. (DFARS 252.204-7012)
Get the certificate now. Bookmark the Defense Department's reporting portal. Name one person who owns the response, and keep the contracting officer's contact info handy.
After an incident, preserve system images and packet capture data for at least 90 days. (DFARS 252.204-7012) Do not wipe a machine before that clock runs out.
5. Flow the rules down to subcontractors
Put the DFARS clause in every subcontract that will involve covered defense information. (DFARS 252.204-7012)
For CMMC, flow down the correct CMMC level to each sub. (DFARS 252.204-7021) Before awarding the work, confirm the sub holds a current CMMC status. (DFARS 252.204-7021)
Keep a list of every sub that touches your CUI. Ask each one for their own readiness proof before you sign.
6. Track your CMMC status in SPRS
SPRS stands for the Supplier Performance Risk System. It is where your CMMC status lives.
Your contract will name a CMMC level. You must have and maintain a current CMMC status at that level for the whole contract. (DFARS 252.204-7021)
Each year, your affirming official must affirm continuous compliance in SPRS. (DFARS 252.204-7021) Self-assessment results go into SPRS for each CMMC UID. (DFARS 252.204-7021) CMMC UID stands for the unique identifier tied to each assessment.
Check your SPRS entries before every bid. An expired status can kill a proposal.
7. Watch, log, and prove it
Turn on logging for logins, file access, and admin actions. Review logs on a schedule, not just after incidents.
Save system reports that show controls are working. Organize proof by control so an assessor can follow it. Refresh proof monthly instead of scrambling before audits.
8. Assign owners and dates
Checklists only work if someone owns them. Give each section to one person with a due date. Review the whole list quarterly.
PolicyCortex reads live Azure configuration and maps it to NIST 800-171 controls, clearing the hardest evidence items first.
Sources
- DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting (May 2024)
- DFARS 252.204-7021, Contractor Compliance With the Cybersecurity Maturity Model Certification Level Requirements (Nov 2025)
Next step
Working through this list on Azure? Start with finding your CUI, then let automated evidence collection handle the proof.
See how PolicyCortex maps your Azure configuration to NIST 800-171