DFARS 252.204-7021: CMMC Levels, SPRS Posting, and Flowdown

DFARS 252.204-7021 requires defense contractors to hold, and continuously maintain, a current Cybersecurity Maturity Model Certification (CMMC) at the level the contracting officer specifies in the solicitation before they can be awarded a DoD contract or have an option exercised. The DFARS 252.204-7021 CMMC requirements apply whenever a contractor or subcontractor will process, store, or transmit Federal Contract Information (FCI) or Controlled Unclassified Information (CUI) on unclassified systems, and they reach every tier of the supply chain that touches that data. Phase 1 of the rollout began November 10, 2025, and full implementation follows by November 10, 2028.

When the Clause Applies to You

The clause is inserted in DoD solicitations and contracts where the work involves FCI or CUI on unclassified systems and the contract value is above the micro-purchase threshold.1eCFR. 32 CFR Part 170 – Cybersecurity Maturity Model Certification FCI is any information generated or provided under a government contract that isn’t meant for public release. CUI is information the government creates or possesses that a law, regulation, or government-wide policy requires agencies to protect through safeguarding or dissemination controls, and it covers things like technical drawings for defense systems, vulnerability assessments, and export-controlled engineering data.2eCFR. 48 CFR 252.204-7021 – Contractor Compliance With the Cybersecurity Maturity Model Certification Level Requirements Which category your data falls into drives which certification level the contract will require.

One boundary worth flagging up front: contracts exclusively for commercial off-the-shelf products are exempt.1eCFR. 32 CFR Part 170 – Cybersecurity Maturity Model Certification The moment a contract involves customization, integration work, or access to protected data, that exemption is gone. Reading the contract terms carefully matters here; assuming COTS treatment when the work has any tailoring in it is a fast way to end up out of compliance.

The Three CMMC Levels and Who Assesses You

The contracting officer assigns a level during acquisition planning based on the sensitivity of the data. That level appears in the solicitation and is a binding eligibility requirement. Bidders without the specified certification cannot receive the award.

Level 1 — Basic Safeguarding of FCI

Level 1 applies to contractors that handle only FCI. It requires the 15 basic safeguards from FAR 52.204-21, covering fundamentals such as limiting system access to authorized users, protecting external communications boundaries, scanning for malicious code, and sanitizing media before disposal.3Acquisition.GOV. 52.204-21 Basic Safeguarding of Covered Contractor Information Systems The evaluation is an annual self-assessment. No third party is involved, no Plan of Action and Milestones is permitted, and every requirement must be fully met.4Department of Defense Chief Information Officer. About CMMC

Level 2 — Protection of CUI

Level 2 applies to contractors handling CUI and requires compliance with all 110 security requirements in NIST SP 800-171 Revision 2. Not every Level 2 contract triggers a third-party assessment. The solicitation specifies whether a self-assessment is sufficient or whether an authorized CMMC Third-Party Assessment Organization (C3PAO) must perform the evaluation. Either way, the assessment is on a three-year cycle with annual affirmations in between.4Department of Defense Chief Information Officer. About CMMC

Level 3 — Advanced Protection

Level 3 is reserved for the most sensitive CUI, and it layers 24 additional requirements from NIST SP 800-172 on top of the 110 required at Level 2.4Department of Defense Chief Information Officer. About CMMC Level 3 assessments are performed directly by the Defense Contract Management Agency’s Defense Industrial Base Cybersecurity Assessment Center (DIBCAC), not by C3PAOs. A contractor must already hold Final Level 2 (C3PAO) status before it can even undergo a Level 3 assessment.

Implementation Timeline

The DoD is phasing the requirement in over three years:

  • Phase 1, November 10, 2025: solicitations begin requiring Level 1 and Level 2 self-assessments where applicable.
  • Phase 2, November 10, 2026: solicitations begin requiring Level 2 C3PAO certification assessments; the DoD may defer the certification requirement to an option period.
  • Phase 3, November 10, 2027: solicitations begin requiring Level 3 DIBCAC assessments, with the same option-period flexibility.
  • Phase 4, November 10, 2028: full implementation across all applicable contracts.4Department of Defense Chief Information Officer. About CMMC

If your work involves CUI and your next competitive opportunity falls in Phase 2, engagement with a C3PAO needs to be happening now. Assessor capacity is finite.

What You Have to Produce and Maintain

System Security Plan

The System Security Plan (SSP) is the primary record of how you protect your systems. It describes the boundary of the systems handling FCI or CUI, identifies each applicable control, and explains how each is implemented. NIST SP 800-171 Revision 2 requires it under requirement 3.12.4 without prescribing a format.5National Institute of Standards and Technology. NIST Special Publication 800-171 Revision 2 Assessors compare the SSP against what they actually observe. Gaps between the two are where most failures originate.

Plan of Action and Milestones — With Real Limits

Where controls are not yet fully implemented, a Plan of Action and Milestones (POA&M) records the open items, the resources needed, and target completion dates.1eCFR. 32 CFR Part 170 – Cybersecurity Maturity Model Certification The POA&M is not a general-purpose safety net. At Level 1, no POA&M is allowed. At Level 2 and Level 3, a POA&M is permitted only if your score is at least 80% of the total requirements, no single open item carries a point value above one (with one narrow encryption exception), and certain high-priority controls are not eligible to be listed on a POA&M at all.6eCFR. 32 CFR 170.21 – Plan of Action and Milestones Requirements

Posting to SPRS (and eMASS)

Assessment results and affirmations are posted in the Supplier Performance Risk System (SPRS), the DoD’s authoritative record of contractor cybersecurity posture.7Supplier Performance Risk System. Supplier Performance Risk System For third-party and DIBCAC assessments, results also pass through CMMC eMASS, which calculates the score, sets Final or Conditional status, and generates the CMMC unique identifier and expiration date.8Department of Defense Chief Information Officer. CMMC-eMASS Contracting officers check SPRS before award. A missing or expired entry means you are ineligible regardless of how secure your systems actually are.

Conditional Status and the 180-Day Clock

Assessments produce one of three outcomes: Final status, Conditional status, or no status. Final means every applicable requirement was met. Conditional means you scored at or above 80% and your open POA&M items fit the rules described above. Conditional status runs for exactly 180 days from the Conditional CMMC Status Date. You must close every POA&M item and pass a closeout assessment within that window. Miss it, and the status reverts to no status.6eCFR. 32 CFR 170.21 – Plan of Action and Milestones Requirements There is no extension, and the closeout assessment cannot produce a fresh Conditional status. It either reaches Final or it fails.8Department of Defense Chief Information Officer. CMMC-eMASS

Final Level 2 and Level 3 status are valid for three years. Final Level 1 requires annual reassessment. All levels require an annual affirmation to remain current.9eCFR. 48 CFR 252.204-7021

Annual Affirmation

After each assessment and every year thereafter, a senior official designated as the Affirming Official must submit an affirmation in SPRS attesting that the organization has implemented and continues to maintain all applicable CMMC security requirements.10eCFR. 32 CFR 170.22 – Affirmation The DFARS clause defines a “current” affirmation as one no more than a year old.9eCFR. 48 CFR 252.204-7021 A lapsed affirmation makes your status non-current, which makes you ineligible for award or for the exercise of options. Level 3 contractors have to keep submitting the Level 2 (C3PAO) affirmation annually alongside the Level 3 affirmation.4Department of Defense Chief Information Officer. About CMMC

Flowing the Clause to Subcontractors

DFARS 252.204-7021 must be flowed down to every subcontractor that will process, store, or transmit FCI or CUI under the contract.9eCFR. 48 CFR 252.204-7021 The contracting officer sets the required level for the prime; the prime determines the appropriate level for each subcontractor based on the data that subcontractor will handle. That means verifying each supplier’s CMMC status in SPRS before awarding a subcontract, and confirming that assessments are current and backed by a valid annual affirmation.7Supplier Performance Risk System. Supplier Performance Risk System A prime that subcontracts to an uncertified supplier has put its own contract at risk.

What a Lapse Costs

The clause obligates contractors to “have and maintain for the duration of the contract a current CMMC status” at the specified level.11Acquisition.GOV. Contractor Compliance With the Cybersecurity Maturity Model Certification Level Requirements Letting the certification expire, missing an affirmation, or failing to close a Conditional POA&M within 180 days puts you in breach of a material contract term. That can lead to termination for default, negative performance evaluations, suspension or debarment, and False Claims Act liability if you kept accepting payment while knowing you were out of compliance.

The False Claims Act exposure is the sharpest edge. Every SPRS score and every annual affirmation is a statement to the government. If that statement is false when made, or made with reckless disregard for its truth, the contractor is liable under 31 U.S.C. § 3729.12Office of the Law Revision Counsel. 31 USC 3729 – False Claims Civil penalties run between $14,308 and $28,618 per false claim (as adjusted for inflation through 2025), plus treble damages.13Federal Register. Civil Monetary Penalty Inflation Adjustment Treble damages can be reduced to double damages only if the contractor self-discloses within 30 days, fully cooperates, and reports before learning of any investigation. The False Claims Act also lets private whistleblowers bring qui tam actions and share in the recovery, so enforcement does not depend on a government auditor spotting the problem.

Signing an affirmation that says you are fully compliant when you know you are not is not a paperwork shortcut. Contractors approaching a status expiration should start reassessment work well before the date, because the certification either exists on award day or the contract goes to someone else.