Skip to content
Secure Open Solutions

Home / DFARS readiness

DEFENSE CONTRACTORS / A PLAIN-LANGUAGE GUIDE

DFARS 252.240-7997: Be ready to demonstrate your safeguards.

Protecting sensitive defense information means being able to show how you protect it. This contract clause gives the government a way to review the safeguards in your covered systems. Here is what it means, how it differs from CMMC, and how to prepare.

01 / WHAT IT IS

A contract requirement to show the government your security is working.

DFARS is the set of additional purchasing rules used by the Department of Defense. Clause 252.240-7997, NIST SP 800-171 DoD Assessment Requirements, addresses government reviews of contractor systems that must protect covered defense information under DFARS 252.204-7012. NIST SP 800-171 is the security requirement set; the clause supplies a way for the government to verify implementation.

In everyday terms: your security plan says what your organization does. A government review checks whether that description matches the people, processes and technology actually in use.

New numbering, a familiar assessment responsibility

The clause was introduced through Class Deviation 2026-O0025 for use beginning February 1, 2026 in acquisitions using the deviation. It carries the government assessment role previously associated with DFARS 252.204-7020. Check the latest deviation and the clauses incorporated into your own solicitation or contract; a website explanation does not determine which version governs your work.

02 / HOW IT DIFFERS FROM CMMC

Related safeguards. Different assessment routes.

CMMC means Cybersecurity Maturity Model Certification. It establishes the assessment level and compliance status required for systems handling federal contract information or controlled unclassified information. DFARS 252.240-7997 addresses a government review of covered systems. The evidence can overlap, but the requirements must be checked separately.

DFARS 252.240-7997 compared with CMMC
QuestionDFARS 252.240-7997CMMC
What is the purpose?Allow government verification of NIST SP 800-171 implementation in covered contractor systems.Establish and maintain the CMMC level and assessment status required by the contract.
Who conducts the assessment?Government personnel conduct Medium or High assessments.The required route may involve a contractor self-assessment, an authorized C3PAO at Level 2, or a government assessment at Level 3.
What is reviewed?The security plan, supporting records, personnel explanations and, for a High assessment, verification and demonstrations of implementation.The requirements for the specified CMMC level and assessment scope. Level 2 uses the 110 NIST SP 800-171 Revision 2 requirements under the current CMMC framework.
What is recorded?Government assessment summary scores and related information are posted to SPRS, the government’s supplier risk system.CMMC assessment status, scope and required affirmations are recorded through the applicable CMMC/SPRS process.
Does one automatically satisfy the other?Do not assume a government review grants CMMC certification. Applicable DCMA results have precedence under the referenced CMMC rules.Do not assume CMMC status removes the government’s right to review implementation. Follow the applicable contract and assessment rules.

A self-assessment score, a CMMC status and a government verification result answer different questions. Keep each required record accurate and consistent with the same real operating environment.

03 / HOW IT MATERIALIZES

It reaches your business through the contract.

  1. A solicitation, award or applicable modification contains the requirement.

    Your contracts team identifies the incorporated clauses, required security baseline, covered systems and any assessment conditions. Clause inclusion alone does not mean every contractor must obtain a government assessment before award.

  2. A prime passes obligations to a subcontractor.

    The clause requires its substance to flow into subcontracts and other contractual instruments, including commercial products and services, excluding commercially available off-the-shelf items. Its assessment applicability remains tied to covered systems subject to DFARS 252.204-7012. Ask what information your work will handle and which systems are in scope.

  3. The government requests a Medium or High assessment when necessary.

    You provide necessary access to facilities, systems and personnel. A Medium review examines documentation and discusses implementation. A High review also verifies and demonstrates the safeguards described in the security plan.

  4. Results become visible in the government’s supplier records.

    The government provides assessment summary scores and an opportunity to respond before posting them to SPRS. The clause provides 14 business days after assessment to supply additional information or rebut findings.

A practical example

A manufacturer receives defense drawings through a prime. Its covered environment includes the approved file workspace, authorized users and the transfer path to production. Reviewers may ask for the security plan, examples of access approvals, records of updates and demonstrations of how files are protected. A written policy alone does not show that the process is operating.

04 / THE BUSINESS IMPACT

Your prime may require demonstrable compliance before DoW does.

A prime may request evidence during supplier selection or onboarding even before a government review is scheduled. Separate a prime’s commercial qualification request from a government assessment requirement, and confirm both in writing.

Bid and supplier readiness

Understand required clauses, assessment records and customer conditions early. Missing or inconsistent evidence can create qualification questions and delay decisions.

People and operating time

Assign control owners and prepare the people who approve access, manage systems, handle information and resolve findings. Reviews require their time as well as documentation.

Honest scope and accurate records

Make the security plan, system boundary, assessment score and remediation plan agree. An enclave can focus protection on a defined workflow, but its scope must include the actual information paths and responsibilities.

Budget for implementation and sustainment

Plan for safeguards, provider responsibilities, remediation, evidence collection and ongoing operation. Purchasing a cloud platform or completing a questionnaire alone does not establish compliance.

05 / WHAT TO DO NOW

Scope it. Implement it. Prove it. Keep it current.

01 / Confirm the obligation

Review clauses and flow-downs with your contracts lead. Confirm the applicable NIST revision, assessment route, deadlines and systems. CMMC Level 2 and a separate Revision 3 requirement should not be treated as interchangeable.

02 / Define the boundary

Identify sensitive information, users, devices, cloud services, specialized assets and transfer paths. Document what your team does and what providers supply.

03 / Close gaps and organize proof

Maintain an accurate system security plan (SSP), track open actions in a plan of action and milestones (POA&M), and connect each requirement to usable records. A remediation plan does not by itself satisfy a missing safeguard.

04 / Rehearse and sustain

Practice retrieving evidence and explaining the workflow. Keep required SPRS records and CMMC affirmations current, review changes and retain evidence of ongoing operation.

06 / WHAT IT MEANS GOING FORWARD

Treat evidence as an operating capability.

Contract language and implementation schedules can change. Monitor official updates and contract modifications, and ask your contracting officer or prime to resolve unclear requirements. Changes in numbering or timing should not be treated as permission to stop protecting covered information.

Build one consistent body of evidence around the environment you actually operate. GCC High and Azure Government virtualization, AVD isolation, repeatable infrastructure as code, controlled OT transfer paths and continuous monitoring can support that approach when appropriately scoped and configured. They are implementation mechanisms; they do not automatically confer a passing assessment or government approval.

SOS can connect Level 2 self-assessment and SPRS readiness, enclave implementation and continuous compliance, with C3PAO assessment capability as a separate assurance layer. For OT and authorization work, the same discipline connects live telemetry to NIST SP 800-53 controls, POA&M status and current authorization evidence. RMF/ATO and DFARS assessment obligations remain distinct.

Start with your contract. Build a reviewable plan.

Share the requirements identified by your prime or agency, the information you handle and your target timeframe. SOS can help define the boundary, review implementation gaps, prepare evidence and sustain the program.

Government assessment decisions remain with the government. Independent CMMC assessment engagements are subject to conflict-of-interest and impartiality review.

Official sources and contract checks

Reviewed October 6, 2026. This is general readiness guidance. Your solicitation, contract, applicable deviation and modifications determine your obligations.