Much of the defense industrial base is now working through CMMC, with self-assessment requirements appearing in new contracts since Phase 1 began in November 2025. But many contractors overlook a critical fact: the core security requirements behind CMMC Level 2 are not new. They already exist under DFARS 252.204-7012 and its required implementation of NIST SP 800-171. These two pillars have governed defense cybersecurity for nearly a decade, yet organizations often remain unaware of their depth and enforcement expectations.
For executives, program leaders, and CISOs, understanding these rules is essential. DFARS 7012 is not optional. It is a contract clause, and noncompliance can result in legal, financial, and reputational consequences. NIST SP 800-171, the technical standard behind the clause, defines exactly how CUI must be protected. CMMC simply verifies and certifies that a contractor is meeting these same requirements.
This article is an executive-level guide to DFARS 7012, NIST SP 800-171, and their direct relationship with CMMC.
What Is DFARS 252.204-7012?
DFARS 252.204-7012, titled Safeguarding Covered Defense Information and Cyber Incident Reporting, is a mandatory clause included in most DoD contracts. You can read the full rule here: Official DFARS 7012.
The clause requires contractors to:
- Implement the full NIST SP 800-171 security control set.
- Report cyber incidents affecting CUI within 72 hours to the DoD.
- Flow these requirements down to all subcontractors handling CUI.
The clause has been in place since 2016, with full NIST SP 800-171 implementation required by December 31, 2017, and it remains fully enforceable today.
Many organizations mistakenly assume DFARS 7012 is optional until CMMC appears in a contract. That is incorrect. If you handle CUI today, you must be compliant today.
What Counts as Covered Defense Information
The DFARS clause uses the term Covered Defense Information (CDI), which mostly overlaps with CUI. CDI includes information provided by or generated for the DoD under a contract that requires safeguarding.
Examples include:
- Technical data and engineering drawings
- System specifications
- Software source code
- Contract performance data
- Export controlled information
- Research files and prototypes
For deeper reference, you can review the DoD CUI Registry documentation. If your organization touches any of the above, DFARS 7012 applies.
Incident Reporting Requirements Under DFARS 7012
One of the most heavily enforced parts of DFARS 7012 is the cyber incident reporting requirement. If an incident affects the confidentiality, integrity, or availability of systems containing CUI, you must report it within 72 hours.
Reports go to the DoD Cyber Crime Center (DC3) through its DCISE program. The longstanding DIBNet portal was retired in 2025, and the former dibnet.dod.mil address now redirects there. Confirm the current submission process before you need it, and set up access in advance, because the credentials required to report take time to obtain.
Reports must include:
- A narrative description of what occurred
- Indicators of compromise
- Systems impacted
- Actions taken
- Mitigation plans
Contractors must also preserve logs, evidence, and forensic images for at least 90 days to support potential DoD follow up. Failure to report can result in contractual penalties, investigations, and False Claims Act exposure.
How NIST SP 800-171 Fits In
DFARS 7012 requires contractors to fully implement NIST SP 800-171, the technical standard for protecting CUI. It defines 110 security requirements across 14 control families:
- Access Control
- Awareness and Training
- Audit and Accountability
- Configuration Management
- Identification and Authentication
- Incident Response
- Maintenance
- Media Protection
- Personnel Security
- Physical Protection
- Risk Assessment
- Security Assessment
- System and Communications Protection
- System and Information Integrity
These are the same controls required for CMMC Level 2.
A Note on NIST SP 800-171 Revision 3
NIST published Revision 3 in May 2024, which reorganizes the controls into a different structure. DFARS 7012 and CMMC Level 2 still reference Revision 2, so Revision 2 and its 110 requirements across 14 families remain what governs your compliance today. Do not implement Revision 3 for CMMC or DFARS purposes until DoD formally adopts it.
How DFARS 7012 and NIST SP 800-171 Connect to CMMC
CMMC does not replace DFARS. It verifies it. The relationship works in three layers:
- DFARS 7012: The legal requirement in your contract.
- NIST SP 800-171: The technical controls you must implement.
- CMMC Level 2: The assessment process that proves implementation.
By the time CMMC appears in your contract, full NIST SP 800-171 implementation should already be complete. CMMC simply adds third-party assessment, evidence review, recertification cycles, and continuous compliance expectations. If your organization is not fully aligned with DFARS and NIST today, the gap to CMMC will be significant.
Why Organizations Fall Out of Compliance
Even mature contractors frequently slip out of compliance with DFARS and NIST requirements. Common pitfalls include:
- Controls implemented without evidence
- Outdated system security plans
- Plans of action that never progress
- Missing audit trails and logs
- Inconsistent training
- Poor subcontractor oversight
- No monitoring of changes in NIST or DoD guidance
These gaps become immediate failures during CMMC assessments.
Practical Steps to Strengthen DFARS and NIST Compliance
1. Conduct a full gap assessment
Compare your current controls and documentation against all 110 NIST SP 800-171 requirements. Structured tools speed this up. We have created a free, easy to use CMMC policy template to get you started.
2. Update the System Security Plan (SSP)
The SSP should document system boundaries, in-scope assets, implemented controls, roles and responsibilities, and evidence references. It must be updated whenever systems or processes change. Our free System Security Plan template provides a structured starting point.
3. Build and execute a remediation plan
A Plan of Action and Milestones (POA&M) should have clear timelines, assigned owners, realistic budgets, and regular progress tracking.
4. Establish continuous monitoring
Compliance is ongoing. You need recurring cycles for vulnerability scanning, log review, internal audits, incident response testing, policy reviews, and subcontractor compliance verification.
5. Validate evidence for CMMC readiness
Everything in NIST SP 800-171 must be backed by documentation, technical evidence, records of user activity, and testing and monitoring outputs. This evidence is what assessors review during a CMMC Level 2 assessment to verify that each requirement is fully implemented and consistently maintained.
6. Prepare for formal assessments
Before any CMMC Level 2 assessment, conduct a thorough internal validation. This confirms that all 110 controls are implemented, evidence is mapped cleanly to each requirement, documentation is current and consistent, and policies match actual technical behavior. This step prevents the last-minute surprises that often derail assessments.
DFARS, NIST, and CMMC: A Unified View
A helpful way to understand these frameworks is to view them as layers of the same requirement set:
- DFARS 252.204-7012: The legal and contractual requirement to secure CUI and report incidents.
- NIST SP 800-171: The technical security blueprint that defines exactly how CUI must be protected.
- CMMC Level 2: The formal assessment model that verifies and certifies compliance with NIST SP 800-171.
If your organization is compliant with DFARS and fully aligned with NIST SP 800-171, the transition to CMMC is straightforward.
Strengthening Compliance Across the Supply Chain
DFARS 7012 requires organizations not only to secure their own systems, but also to ensure that subcontractors handling CUI meet the same obligations. That means you must:
- Identify all vendors and subs touching CUI
- Use contractual flow-down clauses
- Conduct periodic verification of compliance
- Require incident reporting from subs
Supply chain risk is one of the highest priority areas for the DoD. Maintaining strong oversight protects both compliance standing and operational continuity.
Why Compliance Must Be Continuous
Organizations often treat DFARS and NIST compliance as annual tasks. In reality, compliance is continuous. Threats change, systems evolve, and documentation must be updated regularly. Continuous compliance involves quarterly internal audits, annual policy updates, routine evidence collection, ongoing awareness training, and regular POA&M progress updates. Structured frameworks and recurring checklists help maintain alignment throughout the year.
Conclusion
DFARS 252.204-7012 and NIST SP 800-171 are the foundation of defense cybersecurity. These requirements apply today, regardless of whether CMMC has appeared in a given contract yet. By understanding the rules and implementing the controls correctly, organizations strengthen their security posture, protect sensitive data, and maintain eligibility for current and future DoD opportunities.
Contractors that establish mature processes now will face fewer challenges during CMMC Level 2 assessments. The best path forward is to treat DFARS and NIST compliance as ongoing business functions supported by clear policies, continuous monitoring, and proactive remediation.
