DFARS 252.204-7020
DFARS 252.204-7020 is a clause in the Defense Federal Acquisition Regulation Supplement that applies to defense contractor information systems required to follow the NIST SP 800-171 cybersecurity standards. It generally requires contractors to allow the Department of Defense to come onto their premises to conduct an assessment of how well they meet those standards. It is one of the DFARS clauses associated with verifying contractor cybersecurity, and readers should confirm current requirements against the official regulatory text.
DFARS 252.204-7020, titled 'NIST SP 800-171 DoD Assessment Requirements' and codified at 48 CFR 252.204-7020, is a contract clause that, in most implementations, applies to covered contractor information systems that are required to comply with NIST SP 800-171. The clause generally requires the contractor to provide the Government access to its facilities, systems, and personnel to enable a DoD assessment of the contractor's implementation of NIST SP 800-171 security requirements. It was introduced by an interim rule published in 2020 alongside the related clauses 252.204-7019 and 252.204-7021; note that DFARS 252.204-7012 is a distinct and older clause that predates the 2020 interim rule and should not be treated as part of the same 2020 release. Practitioners should verify flow-down obligations, applicable assessment levels, and current clause text against the authoritative DFARS/CFR sources, as scope and interaction with related requirements may change across revisions.
Why it matters
DFARS 252.204-7020 is a key mechanism by which the Department of Defense verifies, rather than simply trusts, that its contractors have implemented the NIST SP 800-171 security requirements protecting Controlled Unclassified Information. Before the 2020 interim rule introduced this clause alongside 252.204-7019 and 252.204-7021, contractor self-attestation carried significant weight with limited government insight into actual implementation. By generally requiring contractors to provide the government access to their facilities, systems, and personnel for a DoD assessment, the clause shifts the compliance posture from unverified self-reporting toward assessed conformance.
For contractors, the practical significance is that a claim of NIST SP 800-171 compliance may now be subject to government scrutiny, and gaps identified during an assessment can affect eligibility and standing on defense contracts. Practitioners should be careful not to conflate this clause with DFARS 252.204-7012, which is a distinct and older clause predating the 2020 interim rule; the two address related but separate obligations. It is also important to recognize that an assessment under 7020 is not the same as an authorization, and that satisfying assessment requirements does not by itself equate to being secure or to meeting every other contractual cybersecurity obligation.
Readers should treat this entry as a conceptual overview rather than a definitive statement of current obligations. Assessment levels, flow-down expectations to subcontractors, and the interaction of 7020 with other DFARS clauses and emerging verification frameworks may change across regulatory revisions, and the authoritative DFARS and CFR text should be consulted for any compliance or contracting decision.
Who it's relevant to
Inside DFARS 252.204-7020
Common questions
Answers to the questions practitioners most commonly ask about DFARS 252.204-7020.