CMMC Ready Now
Back to Knowledge Center
DFARS & Legal5 min read

DFARS 252.204-7019 & 7020: SPRS Assessment Requirements

These two clauses require contractors to assess themselves against NIST SP 800-171, post the score to SPRS, and allow DoD to conduct higher-level assessments. Both have been in effect since November 2020.

DFARS 252.204-7019 and 7020 were published in November 2020 as an interim step toward CMMC — establishing self-assessment and SPRS score posting requirements before the full certification framework was in place.

DFARS 252.204-7019: Notice of Assessment Requirement

This clause requires contractors to have a current NIST SP 800-171 assessment posted in SPRS before contract award. Specifically:

  • The assessment must be conducted using DoD's self-assessment methodology or by DoD directly
  • The resulting score (ranging from -203 to 110) must be posted in SPRS before the contractor can be considered for contract award
  • Scores must remain current — DoD considers a self-assessment older than three years to be outdated

DFARS 252.204-7020: Assessment Access Requirement

This clause extends 7019 by giving DoD the explicit right to conduct a higher-level assessment:

  • DoD DIBCAC (Defense Industrial Base Cybersecurity Assessment Center) can conduct medium or high-confidence assessments of a contractor's NIST SP 800-171 compliance
  • DoD can access the contractor's facilities and systems for assessment purposes
  • A DIBCAC high-confidence assessment can be used in lieu of a C3PAO assessment for CMMC Level 2 purposes

SPRS before CMMC

If you have not yet posted a SPRS score, you are likely already out of compliance with contracts issued after November 2020 that include these clauses. Even before CMMC certification, having an honest, current SPRS score posted is a baseline requirement.

Ready to start your CMMC journey?

Book a free 30-minute call with Rick to get a straight answer on where you stand and what to do next.