DFARS, the Defense Federal Acquisition Regulation Supplement, is the Department of Defense’s rulebook for how it buys goods and services. It sits on top of the Federal Acquisition Regulation (FAR) that governs procurement across the entire federal government, adding defense-specific requirements in areas like cybersecurity, domestic sourcing, and counterfeit parts prevention. DFARS is codified in Title 48 of the Code of Federal Regulations, Chapter 2, and it binds every company that holds a DoD contract, along with many subcontractors that never deal with the Pentagon directly.1eCFR. 48 CFR Chapter 2 – Defense Acquisition Regulations System
How DFARS Fits With the FAR
The FAR is the baseline procurement rulebook for every executive-branch agency, covering how solicitations are written, how bids are evaluated, how contracts are awarded and administered, and how disputes are resolved. It lives in Title 48, Chapter 1 of the Code of Federal Regulations.
DFARS does not replace the FAR. It supplements it. Where the FAR sets a general rule, DFARS can tighten, extend, or add to that rule for defense contracts. A company working with the DoD has to follow both the FAR and every applicable DFARS clause written into its contract. DFARS is where you find the requirements that rarely surface in civilian procurement: safeguarding sensitive defense data, sourcing certain metals domestically, keeping counterfeit parts out of weapons systems, complying with export controls.
Who DFARS Applies To
DFARS applies directly to prime contractors that sign agreements with the DoD. Its reach, though, extends much further. Many DFARS clauses include explicit flow-down language requiring the prime to insert those same clauses into subcontracts, including subcontracts for commercial products and services.2Acquisition.GOV. DFARS Part 252 – Solicitation Provisions and Contract Clauses A small machine shop three tiers deep in the supply chain can be bound by DFARS obligations even though it has never spoken with a contracting officer.
Clauses that flow down include some of the most consequential DFARS provisions: cybersecurity and incident reporting (252.204-7012), CMMC certification (252.204-7021), whistleblower protections (252.203-7002), item unique identification (252.211-7003), hexavalent chromium prohibitions (252.223-7008), and export-control restrictions (252.225-7048).2Acquisition.GOV. DFARS Part 252 – Solicitation Provisions and Contract Clauses Not every DFARS clause flows down, but enough do that any company in the defense supply chain should assume compliance obligations exist until proven otherwise.
Covered Defense Information and Controlled Unclassified Information
Two categories of sensitive data decide whether the cybersecurity-related DFARS clauses attach to your company. Controlled Unclassified Information (CUI) is the government-wide umbrella term for unclassified information that still requires safeguarding under law or regulation. Covered Defense Information (CDI) is the DoD-specific subset: controlled technical information plus any other CUI category listed in the National Archives CUI Registry, when that information is either provided to a contractor by the DoD or generated by the contractor during contract performance.3Acquisition.GOV. DFARS 252.204-7012 Safeguarding Covered Defense Information and Cyber Incident Reporting
If your systems process, store, or transmit CDI at any point, the cybersecurity obligations of DFARS 252.204-7012 apply to you regardless of whether you hold a prime contract. The clause applies to subcontracts for commercial products and commercial services without alteration.2Acquisition.GOV. DFARS Part 252 – Solicitation Provisions and Contract Clauses
Cybersecurity Requirements: DFARS 252.204-7012
The most impactful DFARS clause for most contractors is 252.204-7012, “Safeguarding Covered Defense Information and Cyber Incident Reporting.” It imposes three core duties: protect CDI, report incidents, and support damage assessment.
Protection means implementing the 110 security controls in NIST Special Publication 800-171, “Protecting Controlled Unclassified Information in Nonfederal Information Systems and Organizations.”3Acquisition.GOV. DFARS 252.204-7012 Safeguarding Covered Defense Information and Cyber Incident Reporting NIST has published Revision 3 of the standard, but a DoD class deviation issued in May 2024 keeps Revision 2 as the enforceable baseline. Contractors should not migrate to Rev 3 controls until the DoD formally updates the clause.
When a cyber incident affects CDI or the contractor’s ability to perform operationally critical support, the contractor has to report it to the DoD through the DIBNet portal within 72 hours of discovery.4eCFR. 48 CFR 252.204-7012 – Safeguarding Covered Defense Information and Cyber Incident Reporting That clock starts the moment the incident is discovered, not when the investigation wraps up. Contractors also have to preserve images of affected systems for at least 90 days and submit any malicious software they find to the DoD Cyber Crime Center.
SPRS Score Reporting
Implementing NIST 800-171 is not enough on its own. Contractors have to conduct a self-assessment against the DoD’s scoring methodology (maximum score 110, one point per control) and upload the summary score to the Supplier Performance Risk System (SPRS).5Office of the Under Secretary of Defense for Acquisition and Sustainment. NIST SP 800-171 DoD Assessment Methodology, Version 1.2.1 Each unimplemented control lowers the score by a weighted value. Along with the score, contractors enter the date of the assessment, identify each system security plan supporting contract performance, and provide the date by which they expect to hit 110. Contracting officers check SPRS scores before award, so a low or missing score can kill a deal before negotiations start.
Cybersecurity Maturity Model Certification (CMMC) 2.0
CMMC 2.0 is the DoD’s framework for verifying that contractors actually meet cybersecurity standards rather than just claiming they do. The program began phasing in on November 10, 2025, and will apply to every DoD contract involving federal contract information (FCI) or CUI by late 2028.6Department of Defense CIO. About CMMC
CMMC has three levels:
- Level 1 (Foundational) covers 17 basic security practices drawn from FAR 52.204-21. It applies to contractors that handle FCI but not CUI and requires only a self-assessment.
- Level 2 (Advanced) maps directly to the 110 controls in NIST SP 800-171 and applies to contractors handling CUI. Depending on the sensitivity of the information, the DoD may accept a self-assessment or require a certification assessment by an accredited third-party organization (a C3PAO).
- Level 3 (Expert) adds controls beyond NIST 800-171 for the most sensitive programs and requires a government-led assessment.
Implementation Timeline
The rollout runs in four phases:6Department of Defense CIO. About CMMC
- Phase 1 (November 2025 through November 2026) focuses on Level 1 and Level 2 self-assessments. The DoD may include Level 2 C3PAO or Level 3 requirements in select procurements.
- Phase 2 (November 2026 through November 2027) is when Level 2 contracts begin requiring third-party certification by C3PAOs. Self-assessment alone will no longer satisfy most CUI-related contracts.
- Phase 3 (November 2027 through November 2028) broadens enforcement across all applicable DoD contracts and tightens supply-chain compliance.
- Phase 4 (November 2028 onward) brings full implementation, with CMMC requirements in all relevant solicitations and no exceptions for non-compliance.
Contractors handling CUI who plan to bid on DoD work in 2026 should be preparing for a C3PAO assessment now, even though Phase 1 technically allows self-assessment for most contracts. Assessor capacity is limited, and waiting until Phase 2 begins could mean missing solicitation deadlines. The CMMC clause (252.204-7021) flows down to subcontractors handling FCI or CUI, excluding only commercially available off-the-shelf items.7eCFR. 48 CFR 252.204-7021 – Contractor Compliance With the Cybersecurity Maturity Model Certification Level Requirements
Domestic Sourcing: Specialty Metals
DFARS enforces strict domestic sourcing for certain materials used in defense products. The most prominent restriction, implemented through DFARS clauses 252.225-7008 and 252.225-7009, generally requires specialty metals incorporated into items delivered to the DoD to be melted or produced in the United States or a qualifying country.8eCFR. 48 CFR 252.225-7009 – Restriction on Acquisition of Certain Articles Containing Specialty Metals Specialty metals include specific types of steel, titanium alloys, and zirconium alloys. The qualifying country list covers 28 nations with reciprocal defense procurement agreements, including Australia, Canada, Japan, the United Kingdom, and most NATO members.9Acquisition.GOV. DFARS 252.225-7002 Qualifying Country Sources as Subcontractors
Several exceptions apply. Specialty metals in commercial off-the-shelf end items, subsystems, and assemblies are generally exempt, though raw mill products and standalone forgings or castings do not qualify unless incorporated into a COTS item. A de minimis exception covers noncompliant specialty metals that make up less than 2 percent of the total weight of all specialty metals in the end item, but it does not extend to high-performance magnets. Electronic components are exempt entirely, and the government can waive the restriction when compliant metals are not available in the needed quality, quantity, or form. Prime contractors carry responsibility for verifying compliance throughout their supply chains.8eCFR. 48 CFR 252.225-7009 – Restriction on Acquisition of Certain Articles Containing Specialty Metals
Counterfeit Electronic Parts Prevention
Counterfeit components in defense systems can cause catastrophic failures, and DFARS addresses the risk head-on. Clause 252.246-7008 sets a mandatory sourcing hierarchy for electronic parts. Contractors have to obtain parts first from the original manufacturer, authorized suppliers, or suppliers that buy exclusively from those authorized channels.10eCFR. 48 CFR 252.246-7008 – Sources of Electronic Parts
Only when parts are unavailable through those preferred channels can a contractor turn to “contractor-approved suppliers,” and even then the contractor must follow established counterfeit-prevention industry standards, accept full responsibility for the parts’ authenticity, and make the selection subject to government review.10eCFR. 48 CFR 252.246-7008 – Sources of Electronic Parts Compliance typically falls apart when contractors skip the preferred-source step and go straight to a secondary-market supplier. That exposure exists even if the parts turn out to be genuine.
What Happens If You Don’t Comply
The consequences of failing DFARS obligations range from losing a single contract to facing multimillion-dollar fraud liability.
Contract Termination for Default
Under FAR 49.4, the government can terminate a contract entirely or partially when a contractor fails to perform any provision, including DFARS-mandated cybersecurity or sourcing requirements.11Acquisition.GOV. FAR Subpart 49.4 – Termination for Default A default termination is far worse than a convenience termination. It can make the contractor liable for excess reprocurement costs, and it poisons future proposals because past performance is a standard evaluation factor.
False Claims Act Liability
The larger financial risk comes from the Department of Justice. In October 2021, the DOJ launched its Civil Cyber-Fraud Initiative, which uses the False Claims Act to pursue contractors that misrepresent their cybersecurity compliance. When you submit an SPRS score or certify CMMC compliance in connection with a contract, that representation can become the basis for a False Claims Act case if it turns out to be inaccurate.
Enforcement has accelerated. In 2025 alone, the DOJ settled cybersecurity-related False Claims Act cases against defense contractors for failures including not implementing NIST 800-171 controls, not maintaining a compliant system security plan, and submitting inflated SPRS assessment scores. One settlement reached $4.6 million. These cases frequently originate from whistleblower complaints under the False Claims Act’s qui tam provisions, meaning a disgruntled employee or subcontractor can trigger an investigation. The DOJ has signaled that this pace will continue into 2026 and beyond.
Suspension and Debarment
Contractors that show a pattern of non-compliance risk suspension or debarment from all federal contracting, not just the contract at issue. It is less common than termination or financial penalties, but it is the most severe long-term consequence: a debarred company is locked out of the entire federal marketplace.
Where To Start If You’re New To DFARS
Companies entering the defense supply chain for the first time often underestimate how deeply DFARS reaches into their operations. A few priorities matter most.
Read every DFARS clause in your contract or subcontract carefully. The clause matrix at DFARS Part 252 identifies which clauses flow down, and your prime contractor’s subcontract should call out the specific ones that apply to you.
Treat cybersecurity as a contract requirement, not an IT project. The NIST 800-171 controls require a documented system security plan, access controls, audit logging, incident response procedures, and more. Building these from scratch takes months, and cutting corners creates False Claims Act exposure the moment you submit an SPRS score. If your contract involves CUI, begin the CMMC assessment process early. Phase 1 allows self-assessment for most Level 2 contracts through November 2026, but Phase 2 will require third-party certification, and the pool of accredited C3PAOs is still growing.
Finally, domestic sourcing obligations catch many new entrants off guard. If your deliverables incorporate specialty metals or electronic parts, you need traceability documentation for your entire supply chain. An otherwise compliant product can create a contract breach if a subcontractor three tiers down sourced a titanium alloy from a non-qualifying country.