DFARS 252.204-7021
DFARS 252.204-7021 is a contract clause used by the U.S. Department of Defense (DoD) to require certain contractors and subcontractors to hold a Cybersecurity Maturity Model Certification (CMMC) at the level specified in their contract. When this clause appears in a solicitation or contract, it generally means the contractor must achieve and maintain the required CMMC certification to be eligible for award and to continue performing the work. It is the mechanism that carries CMMC obligations into defense contracts, and its specific requirements should be confirmed against the current official clause text.
DFARS 252.204-7021 is a contract clause within the Defense Federal Acquisition Regulation Supplement, issued through DoD rulemaking, that incorporates Cybersecurity Maturity Model Certification (CMMC) requirements into covered DoD contracts and subcontracts involving Federal Contract Information and Controlled Unclassified Information (CUI). It generally obligates a contractor to have a current CMMC certificate at the level required by the contract, to maintain that certification for the duration of performance, and to report changes affecting its status to the contracting officer; in the current (NOV 2025) version of the clause, the reporting requirement appears at paragraph (e)(1)(ii). The clause first became effective under the DoD interim rule published in late 2020 (the NOV 2020 version); a later rule revised the clause text and tied it to a phased CMMC rollout, so readers should not treat any single date as the clause's original effective date. This entry describes the clause's function and does not cover CMMC assessment levels, the phased implementation timeline, tailoring, or contract-specific applicability, all of which must be verified against the current authoritative DFARS text and associated CMMC rules. Note that CMMC certification under this clause is distinct from, and does not substitute for, other DFARS obligations such as those under 252.204-7012.
Why it matters
DFARS 252.204-7021 is the contractual mechanism that turns the Cybersecurity Maturity Model Certification (CMMC) program from a policy framework into an enforceable condition of doing business with the Department of Defense. Without a clause like this in a contract, CMMC requirements would remain aspirational; when the clause is present, holding the required CMMC certification generally becomes a prerequisite for award and for continued performance. For contractors and subcontractors handling Federal Contract Information or Controlled Unclassified Information (CUI), the presence of this clause can determine eligibility to compete for and retain defense work.
Who it's relevant to
Inside DFARS 252.204-7021
Common questions
Answers to the questions practitioners most commonly ask about DFARS 252.204-7021.