A community resource for the acquisition workforce not a .gov website
part52.dev Federal Acquisition Clause Monitor
This PGI section supplements: DFARS 204.7500 · FAR 4.7500
The corresponding FAR Part 4 and DFARS Part 204 have been overhauled under the RFO. PGI replacement text is provided in the RFO deviation attachment. View FAR Part 4

Current Content

(a) This subpart prescribes policies and procedures for including the Cybersecurity Maturity Model Certification (CMMC) level requirements in DoD contracts. CMMC is a framework that measures a contractor’s cybersecurity maturity to include the implementation of cybersecurity practices and institutionalization of processes (see https://www.acq.osd.mil/cmmc/index.html)..

(b) This subpart does not abrogate any other requirements regarding contractor physical, personnel, information, technical, or general administrative security operations governing the protection of unclassified information, nor does it affect requirements of the National Industrial Security Program.

Change History

Detected Type Summary
detected 2026-07-30 [PGI] PGI_MODIFIED PGI 204.7500 updated: 1 lines added, 2 lines removed
View diff
--- previous
+++ current
@@ -1,3 +1,2 @@
-(a) This subpart prescribes policies and procedures for including the Cybersecurity Maturity Model Certification (CMMC) level requirements in DoD contracts. CMMC is a framework (see 32 CFR part 170) for assessing a contractor's information security protections.
-(b) This subpart does not abrogate any other requirements regarding contractor physical, personnel, information, technical, or general administrative security operations governing the protection of unclassified information, nor does it affect requirements of the National Industrial Security Program.
-(c) This subpart applies to unclassified contractor information systems.+(a) This subpart prescribes policies and procedures for including the Cybersecurity Maturity Model Certification (CMMC) level requirements in DoD contracts. CMMC is a framework that measures a contractor's cybersecurity maturity to include the implementation of cybersecurity practices and institutionalization of processes (see https://www.acq.osd.mil/cmmc/index.html)..
+(b) This subpart does not abrogate any other requirements regarding contractor physical, personnel, information, technical, or general administrative security operations governing the protection of unclassified information, nor does it affect requirements of the National Industrial Security Program.
Sources: Search on acquisition.gov · View on acq.osd.mil