Skip to main content
Category: CMMC & DIB Assessment

DFARS 252.204-7020

Also known as: NIST SP 800-171 DoD Assessment Requirements, DFARS 7020, 48 CFR 252.204-7020
Simply put

DFARS 252.204-7020 is a clause in the Defense Federal Acquisition Regulation Supplement that applies to defense contractor information systems required to follow the NIST SP 800-171 cybersecurity standards. It generally requires contractors to allow the Department of Defense to come onto their premises to conduct an assessment of how well they meet those standards. It is one of the DFARS clauses associated with verifying contractor cybersecurity, and readers should confirm current requirements against the official regulatory text.

Formal definition

DFARS 252.204-7020, titled 'NIST SP 800-171 DoD Assessment Requirements' and codified at 48 CFR 252.204-7020, is a contract clause that, in most implementations, applies to covered contractor information systems that are required to comply with NIST SP 800-171. The clause generally requires the contractor to provide the Government access to its facilities, systems, and personnel to enable a DoD assessment of the contractor's implementation of NIST SP 800-171 security requirements. It was introduced by an interim rule published in 2020 alongside the related clauses 252.204-7019 and 252.204-7021; note that DFARS 252.204-7012 is a distinct and older clause that predates the 2020 interim rule and should not be treated as part of the same 2020 release. Practitioners should verify flow-down obligations, applicable assessment levels, and current clause text against the authoritative DFARS/CFR sources, as scope and interaction with related requirements may change across revisions.

Why it matters

DFARS 252.204-7020 is a key mechanism by which the Department of Defense verifies, rather than simply trusts, that its contractors have implemented the NIST SP 800-171 security requirements protecting Controlled Unclassified Information. Before the 2020 interim rule introduced this clause alongside 252.204-7019 and 252.204-7021, contractor self-attestation carried significant weight with limited government insight into actual implementation. By generally requiring contractors to provide the government access to their facilities, systems, and personnel for a DoD assessment, the clause shifts the compliance posture from unverified self-reporting toward assessed conformance.

For contractors, the practical significance is that a claim of NIST SP 800-171 compliance may now be subject to government scrutiny, and gaps identified during an assessment can affect eligibility and standing on defense contracts. Practitioners should be careful not to conflate this clause with DFARS 252.204-7012, which is a distinct and older clause predating the 2020 interim rule; the two address related but separate obligations. It is also important to recognize that an assessment under 7020 is not the same as an authorization, and that satisfying assessment requirements does not by itself equate to being secure or to meeting every other contractual cybersecurity obligation.

Readers should treat this entry as a conceptual overview rather than a definitive statement of current obligations. Assessment levels, flow-down expectations to subcontractors, and the interaction of 7020 with other DFARS clauses and emerging verification frameworks may change across regulatory revisions, and the authoritative DFARS and CFR text should be consulted for any compliance or contracting decision.

Who it's relevant to

Defense Contractors and Subcontractors
Organizations operating covered contractor information systems that must comply with NIST SP 800-171 are directly affected, because the clause generally requires them to permit DoD access to facilities, systems, and personnel for an assessment. Contractors should confirm flow-down obligations and the applicable assessment level against the current DFARS text before assuming how the clause reaches subcontractors.
Information System Security Managers and Compliance Officers
Those responsible for demonstrating NIST SP 800-171 implementation need to prepare for the possibility of a government assessment rather than relying solely on self-attestation. They should be careful to distinguish assessment obligations under 7020 from other DFARS requirements, including the separate and older 252.204-7012 clause.
Contracting and Acquisition Officials
Personnel administering defense contracts should understand when 7020 applies, how it relates to the companion clauses 252.204-7019 and 252.204-7021 introduced in the same 2020 interim rule, and that its assessment function does not by itself replace other cybersecurity verification requirements. Current regulatory text should govern any determination.
Auditors and Assessors
Those evaluating contractor cybersecurity should recognize that 7020 concerns DoD's access to conduct an assessment of NIST SP 800-171 implementation, and should not treat an assessment as equivalent to an authorization or as proof that a system is secure. Assessment scope and levels should be confirmed against the authoritative sources.

Inside DFARS 252.204-7020

NIST SP 800-171 DoD Assessment Requirement
DFARS 252.204-7020 generally requires contractors to have completed a current NIST SP 800-171 DoD Assessment for covered contractor information systems that process, store, or transmit Controlled Unclassified Information (CUI) as a condition tied to award and performance. Verify the current clause text against the authoritative source for exact triggering conditions.
Score Submission to SPRS
The clause generally requires that assessment results (a score derived under the DoD Assessment Methodology) be posted to the Supplier Performance Risk System (SPRS), maintained by DoD, so that contracting officers can confirm a current assessment exists prior to award in most implementations.
Assessment Levels
The associated DoD Assessment Methodology describes tiered assessment levels, commonly referred to as Basic, Medium, and High, reflecting the rigor and party performing the review. The Basic level is generally a contractor self-assessment, while Medium and High levels involve DoD assessors. Confirm the specific level requirements and definitions against current DoD guidance.
Flowdown to Subcontractors
The clause generally directs contractors to flow the requirement down to applicable subcontractors whose systems handle covered CUI, and to verify that subcontractors have a current assessment on record before awarding a subcontract. Confirm the precise flowdown conditions in the current clause text.
Government Access for Higher-Level Assessments
For Medium and High assessments, the clause generally addresses providing DoD assessors access necessary to conduct the assessment. Specific procedures and access provisions should be verified against the applicable clause revision and DoD methodology.

Common questions

Answers to the questions practitioners most commonly ask about DFARS 252.204-7020.

Which DFARS clauses were actually created by the September 2020 interim rule, and does that include 252.204-7012?
The September 2020 interim rule established three new DFARS clauses: 252.204-7019, 252.204-7020, and 252.204-7021. Clause 252.204-7012 was not created by that rule; it predates the 2020 interim rule and was issued and amended earlier. A common mistake is grouping all four clauses together as a single 2020 release. When mapping contractual obligations, treat 252.204-7012 as a separate, earlier requirement and verify the current text of each clause against the authoritative DFARS source, because clause language and applicability can change across revisions.
Does submitting a self-assessment score under 252.204-7020 mean my organization is assessed or authorized in the way CMMC or an ATO would provide?
No. A self-assessment reported under 252.204-7020 is a contractor-conducted assessment against the applicable NIST SP 800-171 requirements, generally posted to the government-designated reporting system. It should not be confused with a third-party assessment, a certification, or an Authority to Operate. Assessment and authorization are distinct concepts, and a self-reported score does not by itself demonstrate that a system is secure or externally validated. Readers should confirm current reporting requirements and any assessment-level distinctions against official sources, as these evolve.
Where and how is the assessment score reported under 252.204-7020 submitted?
In most implementations, the clause requires the contractor's NIST SP 800-171 assessment results to be posted to the government-designated reporting repository, and it generally addresses government access to assess a contractor's systems consistent with the applicable methodology. Because the specific system, submission mechanics, and access procedures are governed by the current clause text and DoD guidance, you should verify the exact reporting destination and process against the authoritative DFARS text and any implementing DoD instructions in effect at the time of submission.
How does 252.204-7020 relate to the flowdown obligations to subcontractors?
The clause generally addresses flowdown so that relevant assessment and access expectations extend to subcontractors handling covered information, rather than applying only to the prime contractor. Prime contractors typically must ensure applicable requirements are reflected in subcontracts where the underlying information handling triggers them. Because flowdown wording and applicable thresholds depend on the current clause text and the nature of the information involved, confirm the precise flowdown obligations and any exceptions against the authoritative DFARS language and your contract terms.
How does 252.204-7020 interact with 252.204-7019 and 252.204-7021?
These three clauses were established together in the 2020 interim rule and function as related but distinct requirements: one generally conditions eligibility on having a current assessment on record, one addresses the requirement to conduct and report the assessment and provide government access, and one addresses the phased incorporation of the CMMC framework. They are not interchangeable, and CMMC has continued to evolve across revisions and a phased rollout. Verify which clauses appear in a specific contract and their current text, since applicability and language change over time.
How often should the reported assessment be updated, and does a posted score remain valid indefinitely?
A posted assessment score is generally treated as time-bound rather than permanent, and it may need to be current within a defined period for eligibility purposes. Contractors should not assume a previously posted score remains valid indefinitely, particularly as systems, boundaries, and control implementations change. Because the specific validity period and refresh expectations are set by the applicable clause text and DoD assessment methodology, confirm the current currency requirements against the authoritative sources in effect for your contract.

Common misconceptions

DFARS 252.204-7020 was released in 2020 alongside 252.204-7012, 252.204-7019, and 252.204-7021 as part of a single group of new clauses.
The interim rule published in the Federal Register on September 29, 2020 created clauses 252.204-7019, 252.204-7020, and 252.204-7021. Clause 252.204-7012 is a separate, earlier clause that was first issued as a final rule in 2016 and amended several times since; it was not among the clauses newly created in 2020.
Posting a NIST SP 800-171 assessment score to SPRS means the contractor is fully compliant and secure.
A posted assessment score reflects a point-in-time evaluation against the NIST SP 800-171 requirements under the DoD Assessment Methodology; it is not the same as being fully secure and does not by itself constitute a certification. Compliance with the assessment requirement and actual security are distinct, and scores must be kept current as systems and controls change.
Completing the DoD Assessment under 252.204-7020 satisfies all DoD CUI cybersecurity obligations, including CMMC.
The 7020 assessment requirement is distinct from other authorities. It does not replace the safeguarding and incident-reporting obligations addressed under 252.204-7012, nor does it substitute for CMMC requirements addressed under 252.204-7021. Practitioners should treat these as separate, potentially concurrent obligations and confirm applicability per contract.

Best practices

Confirm the current text of DFARS 252.204-7020 and the associated NIST SP 800-171 DoD Assessment Methodology against authoritative sources before relying on any specific requirement, since clause language and methodology can change across revisions.
Maintain a current NIST SP 800-171 DoD Assessment and ensure the score is accurately posted to SPRS before contract award, treating the score as time-sensitive and updating it as system conditions and control implementation status change.
Distinguish the assessment obligations under 252.204-7020 from the safeguarding and incident-reporting requirements under 252.204-7012 and any CMMC requirements under 252.204-7021, and track each separately per applicable contract.
Verify that subcontractors handling covered CUI have a current assessment on record before subcontract award, and document flowdown of the requirement where applicable.
Retain supporting documentation, including the system security plan and plan of action and milestones, used to derive the assessment score, so results can be substantiated during Medium or High DoD assessments.
Coordinate with the contracting officer to clarify assessment level expectations and access provisions for higher-level assessments, and confirm scope boundaries for which systems handle CUI.