On September 29th 2020, the Department of Defense (DoD) issued a Defense Federal Acquisition Regulation Supplement (DFARS) interim rule which was titled “Assessing Contractor Implementation of Cybersecurity Requirements (DFARS Case 2019-D041)”. The new rule was highly anticipated, as it was to address the new Cybersecurity Maturity Model Certification (CMMC) that was released earlier this year and discuss the DoD’s implementation of the CMMC in the Defense Industrial Base (DIB). The interim rule added the following contract clauses: 

  1. 252.204-7019 Notice of NIST SP 800-171 DoD Assessment Requirements.
  2. 252.204-7020 NIST SP 800-171 DoD Assessment Requirements.
  3. 252.204-7021 Contractor Compliance with the Cybersecurity Maturity Model Certification Level Requirement. 

Many people were shocked to learn that the new DFARS interim rule also added two new cybersecurity contract clauses on top of the CMMC clause, that will affect new contracts starting November 30th, 2020. There has been a lot of talk about the new interim rule and its requirements, as well as misinformation about the new rule. We want to assure you, the new interim rule is not as scary as it sounds or as some people are making it out to be. With that being said, let’s take a closer look at the new interim rule.

We will only be looking at the contract clauses 252.204-7019/7020 in this post. We will discuss the CMMC clause (252.204-7021) in a future post. If you want to learn more about the CMMC now, please check out this video where we introduce and explain the CMMC in detail: https://www.youtube.com/watch?v=1CKjn5ztXCs 

New DFARS Requirements 

The interim rule also added the following contract clauses: 252.204-7019 “Notice of NIST SP 800-171 DoD Assessment Requirements” and 252.204-7020 “NIST SP 800-171 DoD Assessment Requirements”. These two contract clauses have gone into effect starting November 30th, 2020, and unfortunately, there has been a lot of misinformation being spread about these two clauses. Please read below for an in-depth overview of everything that you should be aware of regarding the two new DFARS clauses 252.204-7019 and 252.204-7020. 

DFARS 252.204-7019 & DFARS 252.204-7020 Requirements: 

Who This Applies to:  

What is the Objective?

The reason for all above requirements is to eventually become CMMC certified for CMMC level 3 (the CMMC maturity level that handles CUI). The CMMC will be rolled out over the next few years until September 30th, 2025. All contracts are expected to have the CMMC after that date.

Our Suggestion

Example Scenarios: 

  1. You are a company that is a sub-contractor that provides a product to a prime contractor of the DoD. The prime contractor has sent you a letter, stating that you must comply with DFARS clauses 252.204-7019/7020 to bid on future contracts with the prime. However, you do not receive, process, store, or create CUI for the prime contractor or the DoD. What should you do?
    • First, you should ensure that you do not handle or create CUI at all. If you are unsure, review your contract or contact the Prime contractor and ask. If you are positive that you do not handle or create CUI, then you should inform the prime contractor that you do not plan on submitting a NIST SP 800-171 DoD Basic Assessment to the SPRS, because you do not handle or create CUI; therefore, these contract clauses do not apply to your organization.
  2. You are a company that is bidding on a contract to become sub-contractor that creates and provides a product to a prime contractor of the DoD. The contract clearly states that the prime will be flowing CUI down to the sub-contractor who is awarded the contract. The prime contractor is being proactive and has contacted you, requesting proof that you are compliant with DFARS clauses 252.204-7019/7020, before the contract is awarded. What should you do?
    • The contract states that your company will be receiving CUI if you are awarded the contract. Therefore, you must comply with DFARS clauses 252.204-7019/7020. You will have to have a NIST SP 800-171 DoD Basic Assessment to the SPRS at the time of contract award. Since the prime is requesting you provide proof before contract award, you will have to communicate with them and inform them of your intentions of getting your Basic Assessment into the SPRS by time of contract award, if you do not have it in there already.

Our hope is to help answer all of your questions regarding the new DFARS interim rule, and the three clauses that have been added. We strongly recommend that you read the interim rule for yourself, which can be found here.

Does your company have the right cybersecurity plan in place? Contact us for more information on how our customizable services may help protect your business.

Posted by Brendan Kenney

Leave a Reply

Your email address will not be published. Required fields are marked *