DFARS 252.204-7019 & 7020: SPRS Assessment Requirements
These two clauses require contractors to assess themselves against NIST SP 800-171, post the score to SPRS, and allow DoD to conduct higher-level assessments. Both have been in effect since November 2020.
DFARS 252.204-7019 and 7020 were published in November 2020 as an interim step toward CMMC — establishing self-assessment and SPRS score posting requirements before the full certification framework was in place.
DFARS 252.204-7019: Notice of Assessment Requirement
This clause requires contractors to have a current NIST SP 800-171 assessment posted in SPRS before contract award. Specifically:
- ✓The assessment must be conducted using DoD's self-assessment methodology or by DoD directly
- ✓The resulting score (ranging from -203 to 110) must be posted in SPRS before the contractor can be considered for contract award
- ✓Scores must remain current — DoD considers a self-assessment older than three years to be outdated
DFARS 252.204-7020: Assessment Access Requirement
This clause extends 7019 by giving DoD the explicit right to conduct a higher-level assessment:
- ✓DoD DIBCAC (Defense Industrial Base Cybersecurity Assessment Center) can conduct medium or high-confidence assessments of a contractor's NIST SP 800-171 compliance
- ✓DoD can access the contractor's facilities and systems for assessment purposes
- ✓A DIBCAC high-confidence assessment can be used in lieu of a C3PAO assessment for CMMC Level 2 purposes
SPRS before CMMC
Ready to start your CMMC journey?
Book a free 30-minute call with Rick to get a straight answer on where you stand and what to do next.
More in DFARS & Legal
