Defense contractors often hear DFARS and CMMC used almost interchangeably — but they are two different things that work as a pair. DFARS is the contract language that creates your cybersecurity obligation. CMMC is the program that verifies you have met it. Understanding how they fit together is the key to staying eligible for DoD work.
What DFARS is
The Defense Federal Acquisition Regulation Supplement (DFARS) is the set of rules and clauses that govern how the Department of Defense buys goods and services. When it comes to cybersecurity, a few clauses matter most:
- DFARS 252.204-7012 (in effect since 2016) requires contractors to safeguard Covered Defense Information, implement the 110 controls of NIST SP 800-171, and report cyber incidents to DoD within 72 hours.
- DFARS 252.204-7019 / -7020 (2020 interim rule) required contractors to post a NIST 800-171 self-assessment score in the Supplier Performance Risk System (SPRS) and gave DoD the right to verify it.
- DFARS 252.204-7021 is the CMMC clause — it requires a contractor to hold the specific CMMC level named in the contract before award.
What CMMC is
The Cybersecurity Maturity Model Certification (CMMC) is the DoD program that confirms a contractor has actually implemented the required controls. It defines levels — Level 1 for Federal Contract Information, Level 2 (the 110 NIST 800-171 controls) for Controlled Unclassified Information, and Level 3 for the most sensitive programs. CMMC does not invent new controls; it verifies the ones DFARS already requires.
How they work together
Think of it as a chain: DFARS puts the requirement in your contract, NIST SP 800-171 defines the controls, and CMMC proves you meet them. DFARS 7012 says “protect this information.” DFARS 7021 says “and hold the CMMC level that proves it.” Remove any link and the others do not function — which is why they are best understood as one system, not three separate mandates.
Similarities
- Both exist to protect the same data — FCI and CUI in the defense supply chain.
- Both anchor on the same technical backbone: NIST SP 800-171.
- Both flow down to subcontractors — a prime cannot simply absorb the requirement.
- Both are contract-driven: if the clause is in your contract, compliance is a condition of award and payment.
Differences
- Nature. DFARS is regulation — binding contract clauses. CMMC is an assessment and certification program.
- Proof. DFARS 7012 historically relied on self-attestation. CMMC adds a maturity-level model and, at higher levels, independent third-party verification.
- Scope. DFARS clauses cover more than control implementation — incident reporting, cloud service requirements, and media preservation. CMMC is specifically about certifying that the controls are in place.
- Enforcement. DFARS obligations are enforced through the contract and, increasingly, the False Claims Act. CMMC is enforced through the assessment result and an annual affirmation in SPRS.
Key regulatory shifts
The framework has moved quickly. The milestones that matter:
- 2016 — DFARS 252.204-7012 establishes the NIST 800-171 + 72-hour reporting baseline.
- 2020 — the interim rule adds 7019/7020 and the SPRS self-assessment score.
- December 16, 2024 — the CMMC Program rule (32 CFR Part 170) takes effect.
- September 10, 2025 — DoD publishes the final DFARS acquisition rule (48 CFR) carrying the revised 252.204-7021 clause.
- November 10, 2025 — Phase 1 goes live; the 7021 clause begins appearing in solicitations with self-assessment requirements.
- 2026 — the older 7019/7020 requirements are streamlined as assessment obligations move under CMMC and 7021.
- July 13, 2026 — DoD suspends the start of Phase 2 (which would require third-party C3PAO certification) pending a program review, so current Level 2 obligations are generally met via self-assessment plus annual affirmation.
What to do now
- Identify where FCI and CUI live in your environment.
- Self-assess against all 110 NIST SP 800-171 controls and post your score in SPRS.
- Maintain a System Security Plan (SSP) and a Plan of Action & Milestones (POA&M).
- Watch new solicitations for the 7021 clause and the required CMMC level.
- Prepare now for Phase 2’s return — getting third-party-ready early is a competitive advantage.
Want the control-level view? See CMMC & NIST SP 800-171: what every defense contractor needs to know.