Skip to main content
Category: CMMC & DIB Assessment

DFARS 252.204-7019

Also known as: Notice of NIST SP 800-171 DoD Assessment Requirements, DFARS 7019
Simply put

DFARS 252.204-7019 is a solicitation provision used by the Department of Defense to notify companies bidding on contracts that they must have a current assessment of how well they meet the NIST SP 800-171 cybersecurity requirements. It is a notice included in solicitations rather than an ongoing contract clause, and it points offerors toward the DoD assessment process. Contractors should verify the current text against the official DFARS, as the specific version and requirements may change across revisions.

Formal definition

DFARS 252.204-7019 is a solicitation provision (distinct from a contract clause) that notifies offerors of the DoD assessment requirements tied to NIST SP 800-171, generally requiring that an offeror have a current NIST SP 800-171 assessment on record as a condition of eligibility for award, as reflected in its applicable version. The provision was among the new solicitation provision and contract clauses introduced through the DoD interim rule associated with the NIST SP 800-171 assessment methodology, and per one source is prescribed at DFARS 204.7304(d) in its NOV 2023 version. It is closely related to but should not be conflated with DFARS 252.204-7020 (which addresses DoD access to conduct assessments) or DFARS 252.204-7012 (safeguarding of covered defense information); practitioners should confirm the current prescription, version, and effective dates against the authoritative DFARS and Federal Register text, as the precise interim rule effective date and revision details are not established within this evidence.

Why it matters

DFARS 252.204-7019 is one of the mechanisms through which the Department of Defense moved from self-attestation toward verifiable evidence of a contractor's cybersecurity posture. Before award, an offeror generally must have a current NIST SP 800-171 assessment on record, which shifts the burden onto contractors to demonstrate, rather than simply assert, that they have evaluated their systems against the applicable security requirements. For companies bidding on DoD work involving Controlled Unclassified Information (CUI), a missing or stale assessment can render them ineligible for award, making this provision a gating item in the acquisition process rather than a routine formality.

Because 252.204-7019 is a solicitation provision and not an ongoing contract clause, its role differs from clauses that impose continuing performance obligations. It operates at the point of competition and eligibility, notifying offerors of the assessment expectation and pointing them toward the DoD assessment process. Practitioners frequently confuse it with the related clauses in the same family, and that confusion has practical consequences: treating a provision as a clause, or assuming an assessment posted in the relevant DoD system is permanent, can lead to compliance gaps. An assessment reflects a point-in-time evaluation and should not be treated as a substitute for ongoing security or continuous monitoring.

Compliance officers and contracting personnel should also recognize that having a current assessment does not by itself mean a contractor is secure, nor that it satisfies every DoD cybersecurity obligation. The provision addresses assessment status and eligibility notice; it does not replace the safeguarding requirements found elsewhere in the DFARS. Because the specific version, prescription, and requirements can change across revisions, readers must verify the current text against the authoritative DFARS and the Federal Register rather than relying on any single summary.

Who it's relevant to

Defense contractors and offerors bidding on DoD work
Companies competing for DoD contracts that involve Controlled Unclassified Information generally need a current NIST SP 800-171 assessment on record to be eligible for award. This provision serves as the notice of that expectation, so bidders should ensure their assessment status is current before submitting an offer and verify the applicable requirements against the current DFARS text.
Contract and acquisition personnel
Contracting officers and acquisition staff who assemble DoD solicitations need to understand when this provision applies and how its prescription is stated in the applicable DFARS version. They should distinguish it from the related 252.204-7020 clause on DoD assessment access and the 252.204-7012 safeguarding clause to avoid inserting or citing the wrong instrument.
Compliance officers and information system security managers
Personnel responsible for tracking cybersecurity compliance should treat the assessment referenced by this provision as a point-in-time evaluation, not a permanent credential or a proxy for actual security. They should monitor whether assessments remain current and confirm version and effective-date details against authoritative sources, since these can change across revisions.
Subcontractors and supply chain participants
Companies operating within the DoD supply chain may be affected by assessment expectations that flow down through prime contractors. Because obligations and flow-down requirements can vary, subcontractors should confirm with their prime and against the current DFARS how the assessment requirements apply to their specific situation.

Inside DFARS 252.204-7019

NIST SP 800-171 Assessment Requirement
The clause generally requires an offeror to have a current assessment of its implementation of NIST SP 800-171 security requirements for covered contractor information systems that process, store, or transmit Controlled Unclassified Information (CUI). Verify the specific applicability against the current DFARS text, as coverage depends on whether the corresponding safeguarding clause (DFARS 252.204-7012) applies.
SPRS Score Posting
As a condition tied to eligibility for award, the offeror's assessment results (a summary level score) are generally expected to be posted in the DoD Supplier Performance Risk System (SPRS). The clause is the notice-of-requirements provision that informs offerors of this obligation; confirm the exact submission and timing mechanics against the current authoritative text and DoD guidance.
Assessment Methodology Reference
The assessment is generally to be conducted in accordance with the DoD NIST SP 800-171 Assessment Methodology, which defines how implementation of the requirements is scored. The methodology and its scoring approach are maintained by DoD and may be revised, so practitioners should consult the current version.
Currency of the Assessment
The requirement generally contemplates that the posted assessment be current, and DoD guidance has associated assessments with a limited period of validity. Because such timeframes and conditions can change across revisions and policy updates, verify the applicable currency period against the current official source.
Relationship to the Corresponding Clause
DFARS 252.204-7019 (the notice provision directed at offerors) is generally paired with a related clause addressing the ongoing contractual assessment requirement. It is distinct from the CUI safeguarding clause (252.204-7012) and from any CMMC clause; each has separate scope and should not be treated as interchangeable.

Common questions

Answers to the questions practitioners most commonly ask about DFARS 252.204-7019.

Does submitting a score under DFARS 252.204-7019 mean my company is CMMC certified?
No. DFARS 252.204-7019 concerns the requirement to have a current NIST SP 800-171 assessment score posted in the Supplier Performance Risk System (SPRS), which is a self-assessment mechanism. It should not be conflated with CMMC certification, which is a separate, evolving DoD program administered through its own accreditation structure and typically involves third-party or government assessment depending on the level. A posted self-assessment score does not by itself constitute CMMC certification, and readers should verify current CMMC requirements against the applicable DoD rule and contract terms.
Is a NIST SP 800-171 assessment score I posted in SPRS valid indefinitely?
No. Under DFARS 252.204-7019 the offeror generally must have a summary level score that is not older than a specified period, meaning scores are treated as time-bound rather than permanent. This parallels a broader principle in defense cybersecurity that assessments and authorizations are not one-time events. You should verify the currency window for an acceptable score against the current clause text, because the maximum age and related conditions can be affected by rule revisions and agency interpretation.
Where and how is the assessment score actually submitted under this clause?
DFARS 252.204-7019 works in conjunction with DFARS 252.204-7020, which addresses the mechanics of the assessment and its posting in the Supplier Performance Risk System (SPRS). The clause generally requires that a current summary level score be available in SPRS at the time of offer for solicitations to which it applies. Because submission processes and access procedures for SPRS are administered by DoD and may change, confirm the current method against official DoD and SPRS guidance.
Which contracts or solicitations does DFARS 252.204-7019 apply to?
The clause generally applies to solicitations and contracts involving covered defense information under the applicable DFARS framework, subject to the exceptions stated in the rule. It is oriented toward defense procurements rather than federal civilian acquisitions, which follow separate authorities. Because applicability turns on the specific solicitation terms and any prescribed exceptions, you should confirm whether the clause is incorporated in each individual solicitation rather than assuming uniform coverage.
What must an offeror have in place before submitting an offer under this clause?
In most implementations the offeror needs a current NIST SP 800-171 DoD Assessment summary level score posted in SPRS for the relevant information systems before the offer is submitted, consistent with the conditions in the clause. The assessment is tied to the NIST SP 800-171 requirements applicable to Controlled Unclassified Information environments. Verify the specific timing, scope of systems covered, and any documentation expectations against the current clause and DoD assessment methodology.
How does the assessment score relate to a plan of action and milestones (POA&M)?
The NIST SP 800-171 DoD Assessment methodology associated with this clause generally produces a summary level score that reflects requirements met versus not yet met, with unmet requirements typically tracked in a plan of action and milestones. A posted score is a measure of assessed implementation status, not a statement that all requirements are fully met. Compliance status and security posture are distinct concepts, and readers should confirm the scoring methodology and POA&M treatment against current DoD guidance.

Common misconceptions

DFARS 252.204-7019 is the same thing as CMMC.
The clause addresses a self-assessment against NIST SP 800-171 with a score posted to SPRS, whereas CMMC is a separate, DoD-administered certification program with its own phased rollout and revisions. Meeting the 252.204-7019 posting requirement does not by itself satisfy any CMMC obligation, and the two should not be conflated. Confirm which requirements apply to a given solicitation against its current terms.
A posted SPRS score is a permanent record that satisfies the requirement indefinitely.
The requirement generally contemplates a current assessment, and DoD guidance associates assessments with a limited validity period. A score should be maintained and refreshed as implementation changes or as the applicable timeframe lapses. Verify the current validity conditions in the authoritative text before relying on a prior posting.
Having a posted score means the contractor is fully compliant and secure.
A self-assessment score reflects a point-in-time evaluation of implementation status against NIST SP 800-171 and may include a plan of action for unimplemented requirements; it is not an attestation of complete implementation, and compliance scoring is not equivalent to security. The clause concerns reporting an assessment, not conducting an external authorization or certification.

Best practices

Conduct the NIST SP 800-171 self-assessment using the current DoD NIST SP 800-171 Assessment Methodology, and document how each requirement's implementation status was determined.
Post the summary level score in SPRS before it is needed for award eligibility, and confirm the posting mechanics and timing against the current DFARS text rather than assuming prior practice still applies.
Track the currency of your posted assessment and re-assess when your environment changes or when the applicable validity period lapses, treating the score as a living record rather than a one-time filing.
Maintain supporting documentation, including any plan of action for unimplemented requirements, so the basis for the posted score can be substantiated if reviewed.
Do not assume the 252.204-7019 requirement satisfies CMMC or the 252.204-7012 safeguarding obligations; verify which clauses apply to each solicitation and address them separately.
Confirm effective dates, scoring rules, and validity timeframes against the current Federal Register text and official DoD SPRS and assessment guidance, as these details are subject to revision.