Skip to main content
Category: CMMC & DIB Assessment

DFARS 252.204-7021

Also known as: DFARS 7021, DFARS 252.204-7021 CMMC clause
Simply put

DFARS 252.204-7021 is a contract clause used by the U.S. Department of Defense (DoD) to require certain contractors and subcontractors to hold a Cybersecurity Maturity Model Certification (CMMC) at the level specified in their contract. When this clause appears in a solicitation or contract, it generally means the contractor must achieve and maintain the required CMMC certification to be eligible for award and to continue performing the work. It is the mechanism that carries CMMC obligations into defense contracts, and its specific requirements should be confirmed against the current official clause text.

Formal definition

DFARS 252.204-7021 is a contract clause within the Defense Federal Acquisition Regulation Supplement, issued through DoD rulemaking, that incorporates Cybersecurity Maturity Model Certification (CMMC) requirements into covered DoD contracts and subcontracts involving Federal Contract Information and Controlled Unclassified Information (CUI). It generally obligates a contractor to have a current CMMC certificate at the level required by the contract, to maintain that certification for the duration of performance, and to report changes affecting its status to the contracting officer; in the current (NOV 2025) version of the clause, the reporting requirement appears at paragraph (e)(1)(ii). The clause first became effective under the DoD interim rule published in late 2020 (the NOV 2020 version); a later rule revised the clause text and tied it to a phased CMMC rollout, so readers should not treat any single date as the clause's original effective date. This entry describes the clause's function and does not cover CMMC assessment levels, the phased implementation timeline, tailoring, or contract-specific applicability, all of which must be verified against the current authoritative DFARS text and associated CMMC rules. Note that CMMC certification under this clause is distinct from, and does not substitute for, other DFARS obligations such as those under 252.204-7012.

Why it matters

DFARS 252.204-7021 is the contractual mechanism that turns the Cybersecurity Maturity Model Certification (CMMC) program from a policy framework into an enforceable condition of doing business with the Department of Defense. Without a clause like this in a contract, CMMC requirements would remain aspirational; when the clause is present, holding the required CMMC certification generally becomes a prerequisite for award and for continued performance. For contractors and subcontractors handling Federal Contract Information or Controlled Unclassified Information (CUI), the presence of this clause can determine eligibility to compete for and retain defense work.

Who it's relevant to

Prime Contractors Bidding on DoD Work
Primes responding to solicitations that include DFARS 252.204-7021 generally must hold the required CMMC certification at the specified level to be eligible for award. They should confirm which CMMC level applies to a given procurement and where the contract falls in the phased rollout, since these factors determine what certification must be in place before performance begins.
Subcontractors Handling FCI or CUI
The clause reaches subcontractors and lower-tier suppliers that handle Federal Contract Information or Controlled Unclassified Information as part of defense work. Subcontractors should verify the CMMC level flowed down to them under their subcontract, which may differ from the prime's level, and confirm their obligations against the governing clause text rather than assuming they mirror the prime's requirements.
Contracting Officers and Acquisition Staff
Contracting officers rely on this clause as the vehicle that carries CMMC obligations into covered contracts and as the recipient point for contractor reports of changes to certification status. They are positioned to confirm that the correct clause version and CMMC level are incorporated into a solicitation consistent with the phased rollout and applicable DoD rules.
Compliance Officers and ISSMs
Those responsible for maintaining a contractor's security and compliance posture must ensure that required CMMC certification is achieved before award and sustained throughout performance, and that changes affecting status are reported as the clause requires. They should treat certification as an ongoing obligation rather than a one-time milestone, and keep CMMC obligations under this clause distinct from separate DFARS requirements such as those under 252.204-7012.

Inside DFARS 252.204-7021

CMMC Requirement Flow-Down
The clause is the DFARS mechanism that operationalizes the Cybersecurity Maturity Model Certification (CMMC) program in DoD contracts. It generally obligates a contractor to maintain a current CMMC certificate or self-assessment at the level required by the specific solicitation or contract for information systems that process, store, or transmit covered defense information or Controlled Unclassified Information (CUI). Practitioners should confirm the required CMMC level and assessment type against the applicable solicitation, because these are set at the contract level rather than by the clause text itself.
Applicable CMMC Level
The clause references a CMMC level that must be achieved and maintained, but the specific level required is determined by the contracting activity in the individual procurement rather than fixed within the clause. The reader should verify the level and any tailoring in the governing solicitation.
Ongoing Maintenance of Certification/Status
The clause is generally understood to require that the applicable CMMC status be maintained for the duration of the contract, not merely established at award. This reflects the broader principle that compliance status is a continuing obligation rather than a one-time milestone.
Subcontractor Flow-Down
Consistent with DoD's approach to protecting CUI across the supply chain, the clause is designed to extend applicable CMMC requirements to subcontractors when they will process, store, or transmit covered information. Prime contractors should confirm the specific flow-down obligations and the level required of each subcontractor against the current clause text and contract terms.
Reporting / Notification Obligation
The current (NOV 2025) version of the clause includes a reporting requirement at paragraph (e)(1)(ii). Practitioners should read the current clause text to confirm exactly what must be reported and to whom, because the specific triggers and mechanics should be verified against the authoritative published version.
Relationship to Other DFARS Cyber Clauses
This clause is distinct from DFARS 252.204-7012 (safeguarding covered defense information and cyber incident reporting) and from DFARS 252.204-7019/7020 (NIST SP 800-171 assessment requirements). It should not be treated as a substitute for those separate obligations, which may apply concurrently.

Common questions

Answers to the questions practitioners most commonly ask about DFARS 252.204-7021.

Does DFARS 252.204-7021 impose the same requirements as DFARS 252.204-7012?
No. These are distinct clauses that should not be treated as interchangeable. DFARS 252.204-7012 generally addresses safeguarding covered defense information and cyber incident reporting, and it references implementation of NIST SP 800-171 security requirements. DFARS 252.204-7021 addresses the Cybersecurity Maturity Model Certification (CMMC) requirement and the contractor's obligation to have and maintain the applicable CMMC certificate for the relevant level. Because the two clauses can appear together in a contract, practitioners should read each on its own terms rather than assuming one satisfies the other. Confirm the precise obligations against the current official text of each clause, as the requirements and cross-references may be tailored or revised.
Is DFARS 252.204-7021 a new clause that first became effective in 2025?
No. The clause was introduced under the interim rule effective November 30, 2020 (the NOV 2020 version). A 2025 date associated with the clause reflects revised clause text becoming mandatory rather than the clause first coming into existence. It is a common mistake to describe the clause as newly created in 2025. Because CMMC has been implemented in phases and the clause text has been revised, readers should verify which version of the clause applies to a given solicitation or contract and consult the current authoritative regulatory text rather than relying on a single effective date.
Where in the clause is the reporting-related requirement located?
In the current (NOV 2025) version of the clause, the reporting requirement appears at paragraph (e)(1)(ii). Paragraph designations have shifted across revisions of the clause, so a citation that was accurate for an earlier version may not point to the same provision in the current text. When citing a specific obligation, confirm both the clause version and the exact paragraph in the authoritative regulatory source, because tailoring and revisions can change paragraph structure.
How should a contractor determine which CMMC level applies under this clause?
The applicable CMMC level is generally identified in the solicitation or contract rather than selected by the contractor. Practitioners should review the specific requirements stated in the applicable solicitation and confirm them against the current authoritative clause text and associated DoD guidance, because the level and its assessment expectations may be tailored to the contract and may differ across CMMC phases and revisions. This entry does not resolve contract-specific level determinations, which the reader must verify against the governing documents.
Does having a required CMMC certificate at award mean the contractor has no ongoing obligations?
No. The clause generally contemplates that the contractor have and maintain the applicable CMMC certificate, which implies obligations do not end at award. It is a common error to treat certification as a one-time, permanent status. Practitioners should track the currency of their certificate and any continuing affirmation or maintenance expectations described in the current clause text and related DoD guidance, and should not assume compliance is static. Confirm the specific maintenance obligations against the authoritative sources applicable to the contract version.
How does this clause interact with the flowdown of requirements to subcontractors?
The clause generally addresses situations where CMMC requirements extend beyond the prime contractor, so practitioners should not assume subcontractor obligations are out of scope. The specific flowdown expectations, including which subcontractors are affected and at what level, are stated in the clause text and associated guidance and may vary by contract and clause version. Because these details can change across revisions and be tailored to the acquisition, verify the precise flowdown language in the current authoritative clause and confirm any contract-specific interpretation with the contracting activity. This entry does not provide contractual or legal advice on individual flowdown determinations.

Common misconceptions

The clause first became effective in 2025, so it is a brand-new requirement.
The clause has existed since the DoD interim rule effective November 30, 2020 (the NOV 2020 version). The 2025 date refers to a revised version of the clause text becoming mandatory, not to the clause's first effective date. Practitioners should confirm which version applies to a given contract.
Achieving the required CMMC status at award satisfies the clause for the life of the contract.
The clause is generally understood to require that the applicable CMMC status be maintained throughout performance, not established only once. Like an ATO, a certification is time-bound and subject to ongoing obligations rather than being permanent.
Complying with DFARS 252.204-7012 or completing a NIST SP 800-171 self-assessment automatically satisfies this clause.
This clause is separate from 252.204-7012 and from the 7019/7020 assessment clauses. Meeting one does not automatically satisfy the others; the applicable CMMC requirement is distinct and may apply in addition to those obligations.

Best practices

Identify the specific CMMC level and assessment type required by each solicitation or contract, since these are set at the procurement level and not fixed within the clause itself.
Confirm which version of the clause applies to your contract, distinguishing the original NOV 2020 clause from the revised NOV 2025 text, and verify the exact wording against the authoritative published DFARS.
Read the reporting requirement in the current clause (at paragraph (e)(1)(ii) of the NOV 2025 version) carefully to confirm what must be reported, to whom, and under what triggers.
Treat CMMC status as a continuing obligation to be maintained throughout performance rather than a one-time gate at award, and align it with continuous monitoring practices.
Map and manage subcontractor flow-down, confirming the applicable level required of each subcontractor that will process, store, or transmit covered information.
Track this clause separately from DFARS 252.204-7012 and 252.204-7019/7020, and confirm which combination of obligations applies rather than assuming one satisfies the others.