DFARS vs CMMC: How the Clauses and the Program Fit
Table of Contents
- TL;DR
- DFARS vs CMMC: Why It Isn't Really a Comparison
- What the Defense Federal Acquisition Regulation Supplement Does
- What the CMMC Program Does
- The DFARS Clauses Behind Cybersecurity Compliance
- DFARS vs CMMC at a Glance
- CMMC Program Levels: Which CMMC Level Your Contract Requires
- What the Department of Defense Changed in July 2026
- What DFARS and CMMC Compliance Means for Defense Contractors
- How MotherBear Connects Clause Requirements to Evidence
- FAQs About DFARS vs CMMC
Search "DFARS vs CMMC," and you'll find plenty of comparisons. Most of them are answering the wrong question.
The two aren't competing frameworks you choose between. The Defense Federal Acquisition Regulation Supplement (DFARS) is the rulebook that puts requirements into your contract. The Cybersecurity Maturity Model Certification (CMMC) program is one of the things it puts there.
Understanding that relationship matters more than memorizing definitions, because it tells you where to look when you need to know what you actually owe. The answer is in the provisions and clauses that apply to your solicitation and contract.
The clause map shifted in 2026, and most content on this topic hasn't caught up. A class deviation created a second set of citations, so the number your contract uses may not be the number you'll find in the codified regulation.
This guide covers what each does, which ones survived the latest reorganization, how CMMC reaches your contract through them, and what the suspension did and didn't change.
TL;DR
- DFARS isn't an alternative to CMMC. It's the acquisition regulation that makes CMMC contractually binding, alongside the safeguarding requirements that came before it.
- DFARS 252.204-7012 remains the foundation. It requires safeguarding covered defense information and reporting cyber incidents within 72 hours, and it points at the National Institute of Standards and Technology (NIST) standard 800-171.
- Two citation sets now exist. Under the class deviation effective February 1, 2026, contracting officers use a new DFARS Part 240 structure that omits 252.204-7019 and redesignates the assessment clause as 252.240-7997. The codified DFARS still displays the original numbers.
- DFARS 252.204-7021 establishes the contractual requirements for CMMC, while DFARS 252.204-7025 serves as the corresponding solicitation provision. The provision identifies the required level and assessment type; the clause requires contractors to maintain the applicable status and affirm compliance.
- MotherBear keeps requirement status, evidence, and documentation in one workspace, so what your clauses demand is something you can show rather than assume.
DFARS vs CMMC: Why It Isn't Really a Comparison
Think of DFARS as the contracting rulebook and CMMC as the verification program it invokes.
DFARS is a body of acquisition regulation. It doesn't describe security controls in any detail, and it existed for decades before anyone used the word CMMC.
CMMC is a Department of Defense (DoD) regulatory program with levels, assessment procedures, and statuses. DFARS is what makes a specific CMMC requirement contractually applicable to a particular acquisition.
That's the whole relationship. CMMC exists as a regulatory program under 32 CFR Part 170, and DFARS is what makes a required CMMC level a term of a particular solicitation and contract.
What the Defense Federal Acquisition Regulation Supplement Does
The DFARS sets the rules for how the Department buys goods and services. Cybersecurity is a small corner of it, sitting alongside pricing, subcontracting, and dozens of other areas.
Its role in this conversation is mechanical. DFARS provisions and clauses are how these DoD cybersecurity requirements, including CMMC's integration into defense acquisitions, reach solicitations and contracts.
How the Acquisition Regulation Supplement (DFARS) Extends the Federal Acquisition Regulation (FAR)
The Federal Acquisition Regulation (FAR) provides the government-wide acquisition framework for executive agencies. DFARS supplements it for DoD acquisitions with additional defense-specific requirements.
That layering explains why two different clauses can both apply to you. FAR-level safeguarding establishes the baseline for Federal Contract Information (FCI), while DFARS adds DoD-specific duties for covered defense information.
What the CMMC Program Does
At Levels 1 and 2, the CMMC program verifies that organizations have implemented safeguards already tied to FAR and DFARS requirements. Level 3 adds selected requirements for designated higher-risk programs, and contractors don't develop their own alternative standard to satisfy any of it.
The program is codified at 32 CFR Part 170, and its structure is three levels tied to how sensitive the data is.
Level 1 covers FCI with 15 basic safeguarding requirements. Level 2 covers Controlled Unclassified Information (CUI) with the 110 requirements from NIST 800-171. Level 3 adds requirements for the most sensitive programs.
The program is administered through an ecosystem including the Cyber AB and its accredited assessors, with results and statuses recorded in the Supplier Performance Risk System (SPRS). Protecting sensitive data is the point of all of it.
What CMMC changed was accountability.
At Levels 1 and 2, the underlying safeguarding standards were already tied to FAR and DFARS requirements, and CMMC added a standardized mechanism for assessment, status, and affirmation. Level 3 adds selected requirements for designated higher-risk programs.
The DFARS Clauses Behind Cybersecurity Compliance
Let’s take a closer look at relevant DFARS clauses.
DFARS 252.204-7012: The Foundation
DFARS 252.204-7012 has long been the foundation of contractor cybersecurity duties for covered defense information. For covered contractor information systems that aren't operated on behalf of the Government, adequate security requires, at a minimum, implementing NIST 800-171.
It also requires 72-hour cyber incident reporting and flows down to subcontracts involving covered defense information or operationally critical support.
Two details matter for 2026. The clause is unchanged by the year's reorganization, and contractors under it work from Revision 2 of the standard, often written Rev. 2, per a class deviation that remains in effect.
What Happened to DFARS 252.204-7019 and 7020
In 2020, an interim rule added three clauses to enforce 7012. Two of them look different under the 2026 deviation, though the codified versions haven't gone anywhere.
Effective February 1, 2026, a class deviation issued by the Office of the Under Secretary of Defense for Acquisition and Sustainment directed contracting officers to a revised structure.
Under that package, 252.204-7019, the provision requiring a current NIST 800-171 DoD Assessment at least at the Basic level before award, is omitted.
The deviation also uses 252.240-7997 in place of 252.204-7020, covering only the government-performed Medium and High assessments. The codified DFARS still displays both original clauses, so which citation governs depends on the package your procurement uses.
Functionally, this removes the standalone Basic Assessment path from the deviation's assessment clause. CMMC self-assessment and status requirements remain under the CMMC provisions, while 252.240-7997 retains the Government Medium and High assessments.
One more citation to know: the deviation moves the FCI safeguarding clause from FAR 52.204-21 to 52.240-93 for acquisitions using the revised Part 40. Same title, same 15 requirements, and the codified FAR still carries 52.204-21, so both numbers stay relevant.
DFARS 252.204-7021: The CMMC Clause
This is the central CMMC contract clause, and it remains in place under its November 2025 text.
It requires a contractor to hold and maintain the CMMC status the contract specifies, for that contract's duration, complete annual affirmations, and report CMMC information to the Department.
It also flows down. Subcontractors need the status appropriate to the information they'll actually handle, which can be lower than the prime's where they only receive FCI.
DFARS 252.204-7025: The Solicitation Provision
The companion provision is where eligibility actually gets decided, and plenty of contractors miss it.
DFARS 252.204-7025 appears in solicitations and states which CMMC level and assessment type the acquisition requires, with the contracting officer inserting Level 1 (Self), Level 2 (Self), Level 2 (C3PAO), or Level 3 (DIBCAC).
It also makes current status a prerequisite rather than a deliverable. An offeror without the required status and a current affirmation in SPRS isn't eligible for award.
DFARS vs CMMC at a Glance
Here's the distinction in table form.
|
|
DFARS |
CMMC |
|
What it is |
Acquisition regulation supplementing the FAR for defense contracting |
A DoD program that verifies implementation of security requirements |
|
What it does |
Places obligations into contracts through clauses |
Defines levels, assessment methods, and statuses |
|
Scope |
All defense procurement, far beyond cybersecurity |
Protection of FCI and CUI in the defense supply chain |
|
Key cybersecurity clauses |
252.204-7012; 252.204-7021 and 7025 for CMMC; 252.240-7997 under the 2026 deviation |
Reaches contracts via DFARS 252.204-7021 and 7025 |
|
Enforcement |
Contract requirements and remedies, with False Claims Act exposure for knowingly false compliance representations |
Required status and affirmation can determine award eligibility where specified |
|
Timeline |
7012 predates CMMC; the NIST 800-171 implementation deadline was December 31, 2017 |
Contracts from November 2025 under Phase 1 |
The bottom row of that table is where the two meet. Your CMMC obligations arrive because a DFARS clause put them in your contract, not because the program exists.
CMMC Program Levels: Which CMMC Level Your Contract Requires
Levels follow the information, and the contract names the requirement.
- Level 1: Applies where you handle FCI only. Fifteen requirements, an annual self-assessment, and an annual affirmation, with no Plans of Action and Milestones (POA&Ms) permitted.
- Level 2: Applies where CUI is involved. All 110 requirements from NIST 800-171 Revision 2. Under current Phase 1, applicable Level 2 requirements use self-assessment every three years with annual affirmation, and the Phase 2 C3PAO path is suspended. Limited POA&M use is permitted here, unlike at Level 1.
- Level 3: Part of the full CMMC model, adding selected requirements aimed at advanced threats for a narrow set of programs. It sits outside the currently active Phase 1 implementation.
The solicitation is what settles it. Read the clause and the level it specifies rather than inferring from what you think you hold, and confirm with the contracting officer where it's ambiguous.
What the Department of Defense Changed in July 2026
On July 13, 2026, the Department suspended CMMC Phase 2 requirements, which had been scheduled to take effect that November, and stood up a task force to review the program.
Phase 2 would have introduced Level 2 C3PAO assessment requirements on applicable awards. Those third-party requirements are currently suspended. The security requirements underneath them are not.
Phase 1 obligations continue. Contractors still self-assess where required, record results in SPRS, and complete the annual affirmation of continuous compliance, sometimes described informally as CMMC self-attestation, which carries legal weight.
DFARS 252.204-7012 is entirely unaffected. Safeguarding covered defense information and 72-hour incident reporting continue exactly as before, which is worth stating plainly because the suspension headlines suggested otherwise.
One caution while the review runs. A memo changes policy, not the clause printed on your contract, so confirm in writing how any change applies to your specific awards.
What DFARS and CMMC Compliance Means for Defense Contractors
Strip away the numbering, and the practical obligations are stable.
- Implement the applicable safeguards: For covered defense information under DFARS 252.204-7012, that means NIST 800-171 Revision 2 under the current deviation. For FCI-only systems, the separate FAR basic safeguarding clause supplies the 15 requirements.
- Document what you did: Level 2 and CUI environments need a System Security Plan describing how the applicable requirements are implemented, and evidence matters at either self-assessment level.
- Report incidents on time: Where DFARS 252.204-7012 applies, qualifying cyber incidents go to the Department within 72 hours, a duty that exists independently of CMMC.
- Keep your status current: At self-assessment levels, contractors must enter the required results in SPRS and complete affirmations on the cadence their status requires.
- Flow requirements down: Subcontractors handling covered defense information carry their own obligations, and primes are responsible for confirming them.
Notice what isn't on that list: choosing between DFARS and CMMC. Companies don't pick one. A CMMC compliance plan can organize the work behind both the safeguarding clauses and the CMMC verification requirements, though it doesn't replace either contractual obligation.
Failure to keep a required status current is a contractual problem before it's a security one, which is why aligning your program to the clauses in hand beats tracking program news.
How MotherBear Connects Clause Requirements to Evidence
Clause numbers change. What auditors and contracting officers ask for doesn't: show me the control, show me the evidence, show me the documentation that says this is how you operate.
The 2026 renumbering shows why citations and control evidence need to stay connected without being treated as the same thing.
Citations can change while the underlying technical evidence stays reusable, so teams and their expert advisors need a way to update the regulatory mapping without rebuilding the compliance record.

MotherBear gives defense contractors and their consultants one workspace holding requirement status against NIST 800-171, an evidence repository tied to what each artifact proves, documentation, and remediation tasks with owners.
That structure is what survives regulatory reshuffling. When the citation changes, the mapping updates and the underlying proof stays where it is.
FAQs About DFARS vs CMMC
Which DFARS clause requires CMMC?
The two work together. DFARS 252.204-7021 is the contract clause requiring a contractor to hold and maintain the specified CMMC status for the contract's duration, complete affirmations, and flow the requirement down to subcontractors.
DFARS 252.204-7025 is its companion solicitation provision. It identifies the required level and assessment type and makes current status and affirmation a condition of award.
Both work alongside DFARS 252.204-7012. That clause supplies the underlying safeguarding and reporting duties, while 252.204-7021 and 252.204-7025 apply the CMMC status, affirmation, and award-eligibility requirements.
What does it mean to be DFARS-compliant?
In practice, it means satisfying the cybersecurity clauses in your specific contract, most often 252.204-7012. That involves implementing NIST 800-171 on systems handling covered defense information, reporting cyber incidents within 72 hours, and flowing the requirement down to relevant subcontractors.
The phrase is loose, though, because DFARS covers far more than cybersecurity. Ask which clauses your contract contains rather than treating DFARS compliance as a single checkbox.
Is CMMC required now?
Yes, in its first phase. CMMC requirements began entering DoD contracts in November 2025, and where provision 252.204-7025 and clause 252.204-7021 appear, holding the specified status is a condition of award.
Phase 2, which would have added third-party assessment for many contracts, was suspended on July 13, 2026, pending a program review. Phase 1 self-assessment and affirmation obligations continue throughout that review.
Who is required to be CMMC-compliant?
Any contractor whose DoD contract includes the CMMC requirement, plus subcontractors to whom that requirement is flowed down, may need the applicable status for systems handling FCI or CUI. That reaches deep into the Defense Industrial Base (DIB), including small suppliers who never deal with the Department directly.
The level depends on the information. Handling only FCI points to Level 1; CUI generally points to Level 2 or above. Commercial off-the-shelf-only suppliers are generally outside the requirement.
See a DFARS Clause in Your Contract?
Book a demo to see how MotherBear makes managing CMMC simple
