A community resource for the acquisition workforce not a .gov website
part52.dev Federal Acquisition Clause Monitor
DFARS Clause ACTIVE

252.204-7021

Contractor Compliance With the Cybersecurity Maturity Model Certification Level Requirements.
Search on acquisition.gov · View on eCFR.gov
Effective Date
NOV 2025
Active Deviations
3
Versions
3 (since 2020-11-30)
DEV
This clause is modified by 3 active class deviations
  • 2026-O0043 — DFARS RFO Implementation (Part 4)
    Modified by RFO class deviation
  • 2026-O0028 — DFARS RFO Implementation (Part 12)
  • 2026-O0025 — DFARS RFO Implementation (Part 40)
    Add clause 252.204-7021
View per-deviation details →
252.204-7021 Contractor Compliance With the Cybersecurity Maturity Model Certification Level Requirements.

As prescribed in 204.7504(a), use the following clause:

CONTRACTOR COMPLIANCE WITH THE CYBERSECURITY MATURITY MODEL CERTIFICATION LEVEL REQUIREMENTS (NOV 2025)

(a)
Definitions.
As used in this clause-

Controlled unclassified information
means information the Government creates or possesses, or information an entity creates or possesses for or on behalf of the Government, that a law, regulation, or Governmentwide policy requires or permits an agency to handle using safeguarding or dissemination controls (32 CFR 2002.4(h)).

Current
means—

(1) With regard to Conditional Cybersecurity Maturity Model Certification (CMMC) Status—

(i) Not older than 180 days for Conditional Level 2 (Self) assessments and Conditional Level 2 (certified third-party assessment organization (C3PAO)) assessments, with—

(A) No changes in compliance with the requirements at 32 CFR part 170 since the Conditional CMMC Status date (see 32 CFR 170.16 and 170.17); and

(B) A corresponding affirmation of continuous compliance by an affirming official (see 32 CFR 170.4); and

(ii) Not older than 180 days for Conditional Level 3 (Defense Industrial Base Cybersecurity Assessment Center (DIBCAC)) assessments, with—

(A) No changes in compliance with the requirements at 32 CFR part 170 since the Conditional CMMC Status date (see 32 CFR 170.18); and

(B) A corresponding affirmation of continuous compliance by an affirming official;

(2) With regard to Final CMMC Status—

(i) Not older than 1 year for Final Level 1 (Self), with—

(A) No changes in compliance with the requirements at 32 CFR part 170 since the Final CMMC Status date (see 32 CFR 170.15); and

(B) A corresponding affirmation of continuous compliance, not older than 1 year, by an affirming official;

(ii) Not older than 3 years for Final Level 2 (Self) assessments and Final Level 2 (C3PAO) assessments, with—

(A) No changes in compliance with the requirements at 32 CFR part 170 since the Final CMMC Status date (see 32 CFR 170.16 and 170.17); and

(B) A corresponding affirmation of continuous compliance, not older than 1 year, by an affirming official; and

(iii) Not older than 3 years for Final Level 3 (DIBCAC) assessments, with—

(A) No changes in compliance with the requirements at 32 CFR part 170 since the Final CMMC Status date (see 32 CFR 170.18); and

(B) A corresponding affirmation of continuous compliance, not older than 1 year, by an affirming official; and

(3) With regard to affirmation of continuous compliance (32 CFR 170.22), not older than 1 year with no changes in compliance with the requirements at 32 CFR part 170.

Cybersecurity Maturity Model Certification (CMMC) status
means the result of meeting or exceeding the minimum required score for the corresponding assessment. The potential statuses are as follows:

(1) Final Level 1 (Self).

(2) Conditional Level 2 (Self).

(3) Final Level 2 (Self).

(4) Conditional Level 2 (C3PAO).

(5) Final Level 2 (C3PAO).

(6) Conditional Level 3 (DIBCAC).

(7) Final Level 3 (DIBCAC).

Cybersecurity Maturity Model Certification unique identifier (CMMC UID)
means 10 alpha-numeric characters assigned to each CMMC assessment and reflected in the Supplier Performance Risk System (SPRS) for each contractor information system.

Federal contract information (FCI)
means information, not intended for public release, that is provided by or generated for the Government under a contract to develop or deliver a product or service to the Government. It does not include information provided by the Government to the public, such as on public websites, or simple transactional information, such as information necessary to process payments.

Plan of action and milestones
means a document that identifies tasks to be accomplished. It details resources required to accomplish the elements of the plan, any milestones in meeting the tasks, and scheduled completion dates for the milestones, as defined in National Institute of Standards and Technology Special Publication 800-115 (32 CFR 170.21).

(b)
Framework.
The Cybersecurity Maturity Model Certification (CMMC) is a framework for assessing a contractor's compliance with applicable information security protections (see 32 CFR part 170).

(c)
Duplication.
The CMMC assessments will not duplicate efforts from any other comparable DoD assessment, except for rare circumstances when a reassessment may be necessary, for example, when there are indications of issues with cybersecurity and/or compliance with CMMC requirements.

(d)
Requirements.
The Contractor shall—

(1)(i) Have and maintain for the duration of the contract a current CMMC status at the following CMMC level, or higher: ___
[Contracting Officer insert: CMMC Level 1 (Self); CMMC Level 2 (Self); CMMC Level 2 (C3PAO); or CMMC Level 3 (DIBCAC)]
for all information systems used in performance of the contract, task order, or delivery order that process, store, or transmit FCI or CUI; and

(ii) Consult 32 CFR 170.23 related to the flowdown of the CMMC requirements, and flow down the correct CMMC level to subcontracts and other contractual instruments;

(2) Only process, store, or transmit FCI or CUI on contractor information systems that have a CMMC status at the CMMC level required in paragraph (d)(1) of this clause, or higher;

(3) Complete on an annual basis, and maintain as current, an affirmation, by the affirming official (see 32 CFR 170.4), of continuous compliance with the requirements associated with the CMMC level required in paragraph (d)(1) of this clause in the Supplier Performance Risk System (SPRS) (
https://piee.eb.mil
) for each CMMC UID applicable to each of the contractor information systems that process, store, or transmit FCI or CUI and that are used in performance of the contract;

(4) Ensure all subcontractors and suppliers complete prior to subcontract award, and maintain on an annual basis, an affirmation, by the affirming official (see 32 CFR 170.4), of continuous compliance with the requirements associated with the CMMC level required for the subcontract or other contractual instrument for each of the subcontractor information systems that process, store, or transmit FCI or CUI and that are used in performance of the subcontract; and

(5) If the Contractor has a CMMC Status of Conditional, successfully close out a valid plan of action and milestones (32 CFR 170.21) to achieve a CMMC Status of Final.

(e)
Reporting.
The Contractor shall—

(1) Submit to the Contracting Officer—

(i) The CMMC UID(s) issued by SPRS for contractor information systems that will process, store, or transmit FCI or CUI during performance of the contract; and

(ii) Any changes in the CMMC UIDs generated in SPRS throughout the life of the contract, task order, or delivery order, if applicable;

(2) Enter into SPRS the results of a current self-assessment for each CMMC UID, not covered by a C3PAO assessment or DIBCAC assessment, applicable to each of the contractor information systems that process, store, or transmit FCI or CUI and that are used in performance of the contract; and

(3) Complete in SPRS on an annual basis and maintain as current an affirmation of continuous compliance by the affirming official (see 32 CFR 170.4) for each self-assessment, C3PAO assessment, or DIBCAC assessment required under the contract in SPRS.

(f)
Subcontracts.
The Contractor shall—

(1) Insert the substance of this clause, including this paragraph (f) and excluding paragraph (e)(1), in subcontracts and other contractual instruments, including those for the acquisition of commercial products and commercial services, excluding commercially available off-the-shelf items, if the subcontract or other contractual instrument will contain a requirement to process, store, or transmit FCI or CUI; and

(2) Prior to awarding a subcontract or other contractual instrument, ensure that the subcontractor has a current CMMC certificate or current CMMC status at the CMMC level that is appropriate for the information that is being flowed down to the subcontractor based on the requirements at 32 CFR 170.23.

(End of clause)

[90 FR 43575, Sept. 10, 2025]

Change History

Date Authority Type Summary
detected 2026-03-19 [MOD] CLAUSE_MODIFIED Modified: (1), (2), (3), (4), (5) and 11 more paragraphs updated
View diff
--- 2025-10-24 00:00:00
+++ 2025-11-10 00:00:00
@@ -1,33 +1,131 @@
-252.204-7021 Contractor Compliance with the Cybersecurity Maturity Model Certification Level Requirement.
+252.204-7021 Contractor Compliance With the Cybersecurity Maturity Model Certification Level Requirements.
 
-Link to an amendment published at 90 FR 43575, Sept. 10, 2025.
+As prescribed in 204.7504(a), use the following clause:
 
-As prescribed in 204.7503(a) and (b), insert the following clause:
-
-Contractor Compliance With the Cybersecurity Maturity Model Certification Level Requirement (JAN 2023)
+CONTRACTOR COMPLIANCE WITH THE CYBERSECURITY MATURITY MODEL CERTIFICATION LEVEL REQUIREMENTS (NOV 2025)
 
 (a)
-Scope.
-The Cybersecurity Maturity Model Certification (CMMC) CMMC is a framework that measures a contractor's cybersecurity maturity to include the implementation of cybersecurity practices and institutionalization of processes (see
-https://www.acq.osd.mil/cmmc/index.html
-).
+Definitions.
+As used in this clause-
+
+Controlled unclassified information
+means information the Government creates or possesses, or information an entity creates or possesses for or on behalf of the Government, that a law, regulation, or Governmentwide policy requires or permits an agency to handle using safeguarding or dissemination controls (32 CFR 2002.4(h)).
+
+Current
+means—
+
+(1) With regard to Conditional Cybersecurity Maturity Model Certification (CMMC) Status—
+
+(i) Not older than 180 days for Conditional Level 2 (Self) assessments and Conditional Level 2 (certified third-party assessment organization (C3PAO)) assessments, with—
+
+(A) No changes in compliance with the requirements at 32 CFR part 170 since the Conditional CMMC Status date (see 32 CFR 170.16 and 170.17); and
+
+(B) A corresponding affirmation of continuous compliance by an affirming official (see 32 CFR 170.4); and
+
+(ii) Not older than 180 days for Conditional Level 3 (Defense Industrial Base Cybersecurity Assessment Center (DIBCAC)) assessments, with—
+
+(A) No changes in compliance with the requirements at 32 CFR part 170 since the Conditional CMMC Status date (see 32 CFR 170.18); and
+
+(B) A corresponding affirmation of continuous compliance by an affirming official;
+
+(2) With regard to Final CMMC Status—
+
+(i) Not older than 1 year for Final Level 1 (Self), with—
+
+(A) No changes in compliance with the requirements at 32 CFR part 170 since the Final CMMC Status date (see 32 CFR 170.15); and
+
+(B) A corresponding affirmation of continuous compliance, not older than 1 year, by an affirming official;
+
+(ii) Not older than 3 years for Final Level 2 (Self) assessments and Final Level 2 (C3PAO) assessments, with—
+
+(A) No changes in compliance with the requirements at 32 CFR part 170 since the Final CMMC Status date (see 32 CFR 170.16 and 170.17); and
+
+(B) A corresponding affirmation of continuous compliance, not older than 1 year, by an affirming official; and
+
+(iii) Not older than 3 years for Final Level 3 (DIBCAC) assessments, with—
+
+(A) No changes in compliance with the requirements at 32 CFR part 170 since the Final CMMC Status date (see 32 CFR 170.18); and
+
+(B) A corresponding affirmation of continuous compliance, not older than 1 year, by an affirming official; and
+
+(3) With regard to affirmation of continuous compliance (32 CFR 170.22), not older than 1 year with no changes in compliance with the requirements at 32 CFR part 170.
+
+Cybersecurity Maturity Model Certification (CMMC) status
+means the result of meeting or exceeding the minimum required score for the corresponding assessment. The potential statuses are as follows:
+
+(1) Final Level 1 (Self).
+
+(2) Conditional Level 2 (Self).
+
+(3) Final Level 2 (Self).
+
+(4) Conditional Level 2 (C3PAO).
+
+(5) Final Level 2 (C3PAO).
+
+(6) Conditional Level 3 (DIBCAC).
+
+(7) Final Level 3 (DIBCAC).
+
+Cybersecurity Maturity Model Certification unique identifier (CMMC UID)
+means 10 alpha-numeric characters assigned to each CMMC assessment and reflected in the Supplier Performance Risk System (SPRS) for each contractor information system.
+
+Federal contract information (FCI)
+means information, not intended for public release, that is provided by or generated for the Government under a contract to develop or deliver a product or service to the Government. It does not include information provided by the Government to the public, such as on public websites, or simple transactional information, such as information necessary to process payments.
+
+Plan of action and milestones
+means a document that identifies tasks to be accomplished. It details resources required to accomplish the elements of the plan, any milestones in meeting the tasks, and scheduled completion dates for the milestones, as defined in National Institute of Standards and Technology Special Publication 800-115 (32 CFR 170.21).
 
 (b)
-Requirements.
-The Contractor shall have a current (
-i.e.
-not older than 3 years) CMMC certificate at the CMMC level required by this contract and maintain the CMMC certificate at the required level for the duration of the contract.
+Framework.
+The Cybersecurity Maturity Model Certification (CMMC) is a framework for assessing a contractor's compliance with applicable information security protections (see 32 CFR part 170).
 
 (c)
+Duplication.
+The CMMC assessments will not duplicate efforts from any other comparable DoD assessment, except for rare circumstances when a reassessment may be necessary, for example, when there are indications of issues with cybersecurity and/or compliance with CMMC requirements.
+
+(d)
+Requirements.
+The Contractor shall—
+
+(1)(i) Have and maintain for the duration of the contract a current CMMC status at the following CMMC level, or higher: ___
+[Contracting Officer insert: CMMC Level 1 (Self); CMMC Level 2 (Self); CMMC Level 2 (C3PAO); or CMMC Level 3 (DIBCAC)]
+for all information systems used in performance of the contract, task order, or delivery order that process, store, or transmit FCI or CUI; and
+
+(ii) Consult 32 CFR 170.23 related to the flowdown of the CMMC requirements, and flow down the correct CMMC level to subcontracts and other contractual instruments;
+
+(2) Only process, store, or transmit FCI or CUI on contractor information systems that have a CMMC status at the CMMC level required in paragraph (d)(1) of this clause, or higher;
+
+(3) Complete on an annual basis, and maintain as current, an affirmation, by the affirming official (see 32 CFR 170.4), of continuous compliance with the requirements associated with the CMMC level required in paragraph (d)(1) of this clause in the Supplier Performance Risk System (SPRS) (
+https://piee.eb.mil
+) for each CMMC UID applicable to each of the contractor information systems that process, store, or transmit FCI or CUI and that are used in performance of the contract;
+
+(4) Ensure all subcontractors and suppliers complete prior to subcontract award, and maintain on an annual basis, an affirmation, by the affirming official (see 32 CFR 170.4), of continuous compliance with the requirements associated with the CMMC level required for the subcontract or other contractual instrument for each of the subcontractor information systems that process, store, or transmit FCI or CUI and that are used in performance of the subcontract; and
+
+(5) If the Contractor has a CMMC Status of Conditional, successfully close out a valid plan of action and milestones (32 CFR 170.21) to achieve a CMMC Status of Final.
+
+(e)
+Reporting.
+The Contractor shall—
+
+(1) Submit to the Contracting Officer—
+
+(i) The CMMC UID(s) issued by SPRS for contractor information systems that will process, store, or transmit FCI or CUI during performance of the contract; and
+
+(ii) Any changes in the CMMC UIDs generated in SPRS throughout the life of the contract, task order, or delivery order, if applicable;
+
+(2) Enter into SPRS the results of a current self-assessment for each CMMC UID, not covered by a C3PAO assessment or DIBCAC assessment, applicable to each of the contractor information systems that process, store, or transmit FCI or CUI and that are used in performance of the contract; and
+
+(3) Complete in SPRS on an annual basis and maintain as current an affirmation of continuous compliance by the affirming official (see 32 CFR 170.4) for each self-assessment, C3PAO assessment, or DIBCAC assessment required under the contract in SPRS.
+
+(f)
 Subcontracts.
 The Contractor shall—
 
-(1) Insert the substance of this clause, including this paragraph (c), in all subcontracts and other contractual instruments, including subcontracts for the acquisition of commercial products or commercial services, excluding commercially available off-the-shelf items; and
+(1) Insert the substance of this clause, including this paragraph (f) and excluding paragraph (e)(1), in subcontracts and other contractual instruments, including those for the acquisition of commercial products and commercial services, excluding commercially available off-the-shelf items, if the subcontract or other contractual instrument will contain a requirement to process, store, or transmit FCI or CUI; and
 
-(2) Prior to awarding to a subcontractor, ensure that the subcontractor has a current (
-i.e.,
-not older than 3 years) CMMC certificate at the CMMC level that is appropriate for the information that is being flowed down to the subcontractor.
+(2) Prior to awarding a subcontract or other contractual instrument, ensure that the subcontractor has a current CMMC certificate or current CMMC status at the CMMC level that is appropriate for the information that is being flowed down to the subcontractor based on the requirements at 32 CFR 170.23.
 
 (End of clause)
 
-[85 FR 61520, Sept. 29, 2020, as amended at 88 FR 6589, Jan. 31, 2023]+[90 FR 43575, Sept. 10, 2025]
RFO
Prescription superseded under the RFO

The prescription shown below is from the codified eCFR. The Revolutionary FAR Overhaul relocates this clause's prescription as follows:

  • 204.7504240.371-5 (prescriptive text also revised)
  • 204.7504240.371-5 (prescriptive text also revised)
  • 212.301212.205 (prescriptive text also revised)

See the deviation memorandum for the current prescription authority.

View deviation: 2026-O0043 → · View deviation: 2026-O0028 → · View deviation: 2026-O0025 →

R-DFARS Prescription Source

This clause is prescribed in the R-DFARS by the following deviation:

  • 2026-O0025 — DFARS RFO Implementation (Part 40) (DFARS Part 240)
    Add clause 252.204-7021
204.7504(a)
(a) Unless the requirements at 32 CFR 170.5(d) are met, use the clause at 252.204-7021, Contractor Compliance with the Cybersecurity Maturity Model Certification Level Requirements, as follows:

(1) Until November 9, 2028 in solicitations and contracts, task orders, or delivery orders, including those using FAR part 12 procedures for the acquisition of commercial products and commercial services, except for those solely for the acquisition of commercially available off-the-shelf (COTS) items, if the program office or requiring activity determines that the contractor is required to have a specific CMMC level.

(2) On or after November 10, 2028 in solicitations and contracts, task orders, or delivery orders, including those using FAR part 12 procedures for the acquisition of commercial products and commercial services, except for those solely for the acquisition of COTS items, if the program office or requiring activity determines that the contractor is required to use contractor information systems in the performance of the contract, task order, or delivery order to process, store, or transmit FCI or CUI.
Prescription data sourced from eCFR as of 2026-06-10 03:16 UTC. Cross-references within the prescription are not resolved automatically.

Regulatory Stack

The layers of regulation that govern this clause, from the FAR prescription through agency-specific supplements and any active deviations.

R-DFARS R-DFARS Prescription Per Deviation 2026-O0025 (DFARS Part 240)
2026-O0025: DFARS RFO Implementation (Part 40) — DFARS Part 240

View Deviation 2026-O0025 →

DFARS DFARS Supplement (eCFR) ⚠ May be superseded by RFO 204.7504(a)
(a) Unless the requirements at 32 CFR 170.5(d) are met, use the clause at 252.204-7021, Contractor Compliance with the Cybersecurity Maturity Model Certification Level Requirements, as follows:

(1) Until November 9, 2028 in solicitations and contracts, task orders, or delivery orders, including those using FAR part 12 procedures for the acquisition of commercial products and commercial services, except for those solely for the acquisition of commercially available off-the-shelf (COTS) items, if the program office or requiring activity determines that the contractor is required to have a specific CMMC level.

(2) On or after November 10, 2028 in solicitations and contracts, task orders, or delivery orders, including those using FAR part 12 procedures for the acquisition of commercial products and commercial services, except for those solely for the acquisition of COTS items, if the program office or requiring activity determines that the contractor is required to use contractor information systems in the performance of the contract, task order, or delivery order to process, store, or transmit FCI or CUI.

Search on acquisition.gov · View on eCFR.gov

Version History

Version history is sourced from the codified eCFR. Changes published only as class deviations or by the Revolutionary FAR Overhaul do not appear here until they are incorporated into the eCFR. For RFO-driven changes see the RFO Version tab and any active deviations cited above.

3 versions tracked from 2020-11-30 to 2025-11-10.
NOV 2025 November 10, 2025 CURRENT SUBSTANTIVE
Removed in this version
Added in this version
Unchanged
SEP 2025 (previous)
NOV 2025 (current)
51 added, 27 removed
(a)
(a) Scope. The Cybersecurity Maturity Model Certification (CMMC) CMMC is a framework that measures a contractor's cybersecurity maturity to include the implementation of cybersecurity practices and institutionalization of processes (see https://www.acq.osd.mil/cmmc/index.html).
(a)
(a) Definitions. As used in this clause- Controlled unclassified information means information the Government creates or possesses, or information an entity creates or possesses for or on behalf of the Government, that a law, regulation, or Governmentwide policy requires or permits an agency to handle using safeguarding or dissemination controls (32 CFR 2002.4(h)). Current means—
22 added, 35 removed
(b)
(b) Requirements. The Contractor shall have a current (i.e. not older than 3 years) CMMC certificate at the CMMC level required by this contract and maintain the CMMC certificate at the required level for the duration of the contract.
(b)
(b) Framework. The Cybersecurity Maturity Model Certification (CMMC) is a framework for assessing a contractor's compliance with applicable information security protections (see 32 CFR part 170).
38 added, 3 removed
(c)
(c) Subcontracts. The Contractor shall—
(c)
(c) Duplication. The CMMC assessments will not duplicate efforts from any other comparable DoD assessment, except for rare circumstances when a reassessment may be necessary, for example, when there are indications of issues with cybersecurity and/or compliance with CMMC requirements.
27 added, 5 removed
(1)
(1) Insert the substance of this clause, including this paragraph (c), in all subcontracts and other contractual instruments, including subcontracts for the acquisition of commercial products or commercial services, excluding commercially available off-the-shelf items; and
(1)
(1) Insert the substance of this clause, including this paragraph (f) and excluding paragraph (e)(1), in subcontracts and other contractual instruments, including those for the acquisition of commercial products and commercial services, excluding commercially available off-the-shelf items, if the subcontract or other contractual instrument will contain a requirement to process, store, or transmit FCI or CUI; and
18 added, 9 removed
(2)
(2) Prior to awarding to a subcontractor, ensure that the subcontractor has a current (i.e., not older than 3 years) CMMC certificate at the CMMC level that is appropriate for the information that is being flowed down to the subcontractor. (End of clause)
(2)
(2) Prior to awarding a subcontract or other contractual instrument, ensure that the subcontractor has a current CMMC certificate or current CMMC status at the CMMC level that is appropriate for the information that is being flowed down to the subcontractor based on the requirements at 32 CFR 170.23. (End of clause)
26 added, 5 removed
(i)
[Not present in prior version]
(i)
(i) The CMMC UID(s) issued by SPRS for contractor information systems that will process, store, or transmit FCI or CUI during performance of the contract; and
23 added, 4 removed
(A)
[Not present in prior version]
(A)
(A) No changes in compliance with the requirements at 32 CFR part 170 since the Final CMMC Status date (see 32 CFR 170.18); and
17 added, 5 removed
(B)
[Not present in prior version]
(B)
(B) A corresponding affirmation of continuous compliance, not older than 1 year, by an affirming official; and
22 added, 4 removed
(ii)
[Not present in prior version]
(ii)
(ii) Any changes in the CMMC UIDs generated in SPRS throughout the life of the contract, task order, or delivery order, if applicable;
13 added, 5 removed
(iii)
[Not present in prior version]
(iii)
(iii) Not older than 3 years for Final Level 3 (DIBCAC) assessments, with—
38 added, 4 removed
(3)
[Not present in prior version]
(3)
(3) Complete in SPRS on an annual basis and maintain as current an affirmation of continuous compliance by the affirming official (see 32 CFR 170.4) for each self-assessment, C3PAO assessment, or DIBCAC assessment required under the contract in SPRS.
70 added, 4 removed
(4)
[Not present in prior version]
(4)
(4) Ensure all subcontractors and suppliers complete prior to subcontract award, and maintain on an annual basis, an affirmation, by the affirming official (see 32 CFR 170.4), of continuous compliance with the requirements associated with the CMMC level required for the subcontract or other contractual instrument for each of the subcontractor information systems that process, store, or transmit FCI or CUI and that are used in performance of the subcontract; and
30 added, 5 removed
(5)
[Not present in prior version]
(5)
(5) If the Contractor has a CMMC Status of Conditional, successfully close out a valid plan of action and milestones (32 CFR 170.21) to achieve a CMMC Status of Final.
5 added, 5 removed
(6)
[Not present in prior version]
(6)
(6) Conditional Level 3 (DIBCAC).
150 added, 4 removed
(7)
[Not present in prior version]
(7)
(7) Final Level 3 (DIBCAC). Cybersecurity Maturity Model Certification unique identifier (CMMC UID) means 10 alpha-numeric characters assigned to each CMMC assessment and reflected in the Supplier Performance Risk System (SPRS) for each contractor information system. Federal contract information (FCI) means information, not intended for public release, that is provided by or generated for the Government under a contract to develop or deliver a product or service to the Government. It does not include information provided by the Government to the public, such as on public websites, or simple transactional information, such as information necessary to process payments. Plan of action and milestones means a document that identifies tasks to be accomplished. It details resources required to accomplish the elements of the plan, any milestones in meeting the tasks, and scheduled completion dates for the milestones, as defined in National Institute of Standards and Technology Special Publication 800-115 (32 CFR 170.21).
5 added, 5 removed
(d)
[Not present in prior version]
(d)
(d) Requirements. The Contractor shall—
64 added, 4 removed
(1)(i)
[Not present in prior version]
(1)(i)
(1)(i) Have and maintain for the duration of the contract a current CMMC status at the following CMMC level, or higher: ___[Contracting Officer insert: CMMC Level 1 (Self); CMMC Level 2 (Self); CMMC Level 2 (C3PAO); or CMMC Level 3 (DIBCAC)] for all information systems used in performance of the contract, task order, or delivery order that process, store, or transmit FCI or CUI; and
5 added, 5 removed
(e)
[Not present in prior version]
(e)
(e) Reporting. The Contractor shall—
5 added, 5 removed
(f)
[Not present in prior version]
(f)
(f) Subcontracts. The Contractor shall—
SEP 2025 September 10, 2025 SUBSTANTIVE
Removed in this version
Added in this version
Unchanged
NOV 2020 (previous)
SEP 2025 (current)
4 added, 1 removed
(1)
(1) Insert the substance of this clause, including this paragraph (c), in all subcontracts and other contractual instruments, including subcontracts for the acquisition of commercial items, excluding commercially available off-the-shelf items; and
(1)
(1) Insert the substance of this clause, including this paragraph (c), in all subcontracts and other contractual instruments, including subcontracts for the acquisition of commercial products or commercial services, excluding commercially available off-the-shelf items; and
NOV 2020 November 30, 2020
Earliest version available from the eCFR

Active Class Deviations

DFARS RFO Implementation (Part 4) Modified by RFO class deviation
MODIFIED
DFARS RFO Implementation (Part 12) Modify clause 252.204-7021
MODIFIED
DFARS RFO Implementation (Part 40) Add clause 252.204-7021
MODIFIED
Use with AI assistant
Copy a link and prompt for use with Gemini or another AI assistant.