Skip to main content
Lightbridge Cloud A Lightbridge.ai company
SK Written by Sarika Krishnan with Robert LabardeeSenior Program Manager and Founder and CEO

DFARS 252.204-7012 and NIST 800-171

Lightbridge Cloud defines DFARS 252.204-7012 as the Department of Defense contract clause that, when included in a contract involving covered defense information, requires the contractor to safeguard that information and report to DoD within 72 hours of discovery a cyber incident affecting a covered contractor information system or the covered defense information residing therein, or affecting the contractor's ability to perform contract requirements designated as operationally critical support and identified in the contract. It points to the contractually applicable revision of NIST SP 800-171. Under Revision 2, that framework has 110 security requirements across 14 families; they form the minimum baseline when that revision applies, subject to the clause's authorized alternatives and nonapplicability determinations.

DFARS 252.204-7012 sets safeguarding and 72-hour reporting duties under a contract containing the clause.

DFARS 252.204-7012 is a clause in the Defense Federal Acquisition Regulation Supplement. When the Department of Defense places it in a contract or subcontract involving covered defense information, the contractor must provide adequate security for that information stored on or passing through its systems, and must report to DoD within 72 hours of discovery a cyber incident affecting a covered contractor information system or the covered defense information residing therein, or affecting the contractor's ability to perform contract requirements designated as operationally critical support and identified in the contract.

The clause does not invent its own security standard. It points to NIST SP 800-171 as a minimum baseline, subject to authorized alternatives and nonapplicability determinations, and may require additional measures where reasonably necessary. Adequate security is therefore broader than implementing the 110 requirements alone. Covered defense information, the data the clause protects, means unclassified controlled technical information or other information described in the Controlled Unclassified Information (CUI) Registry that requires safeguarding or dissemination controls pursuant to and consistent with applicable law, regulations, and Governmentwide policies, and is either (1) marked or otherwise identified in the contract, task order, or delivery order and provided to the contractor by or on behalf of the Department of Defense in connection with contract performance, or (2) collected, developed, received, transmitted, used, or stored by or on behalf of the contractor in support of contract performance. For that broader category, see our guide on controlled unclassified information.

Lightbridge Cloud is an independent advisory firm. This guide describes the requirements as the regulations actually state them, because a contractor's obligations turn on the specific clauses written into its contract. Verify the current clause text and the exact reporting window against the official source at acquisition.gov, since DFARS provisions are revised over time.

NIST SP 800-171 Revision 2 organizes 110 security requirements into 14 security families.

NIST SP 800-171 is the National Institute of Standards and Technology publication that defines how to protect controlled unclassified information on nonfederal systems. The count is revision-specific: Revision 2 has 110 security requirements grouped into 14 families, while Revision 3 has 97 security requirements grouped into 17 families. Use the revision specified by the contract. An organization can identify the requirements applicable to its environment and use a POA&M to document unmet requirements and remediation milestones, but a POA&M documents deficiencies; it does not make unmet requirements compliant. Where a POA&M is permitted under CMMC, it supports only Conditional status, never Final status. These are the Revision 2 families, summarized.

Access Control

Limits who can reach systems that hold controlled unclassified information, covering account management, least privilege, separation of duties, and remote access. It is one of the largest families by requirement count in NIST SP 800-171.

Awareness and Training

Requires that users and administrators understand the security risks tied to their roles and the policies that apply, including insider-threat awareness for staff who handle covered information.

Audit and Accountability

Calls for creating, protecting, and reviewing audit logs so a contractor can trace user activity, detect misuse, and support an investigation if covered defense information is exposed.

Configuration Management

Establishes baseline configurations, change control, and restrictions on what software runs, so systems that process controlled unclassified information stay in a known and hardened state.

Identification and Authentication

Verifies the identity of users, processes, and devices before granting access, and is where multifactor authentication and credential management requirements live.

Incident Response and the remaining families

Incident Response, Maintenance, Media Protection, Personnel Security, Physical Protection, Risk Assessment, Security Assessment, System and Communications Protection, and System and Information Integrity complete the 14 families and 110 security requirements specified in Revision 2.

Requirement counts and wording differ between revisions of the publication, so confirm the contractually applicable revision against the current publication from NIST before scoping a program.

DFARS, NIST 800-171, SPRS, and CMMC form a single ladder.

These four terms are often used interchangeably, but they sit at different rungs. The clause creates the obligation, the applicable standard defines what good looks like, the SPRS score measures how far an organization has implemented it, and CMMC applies level-specific requirements and assessment paths. Reading them as a ladder is the clearest way to plan a program.

The clause: DFARS 252.204-7012

The contractual trigger. When this clause appears in a defense contract or subcontract involving covered defense information, it obligates the contractor to provide adequate security for that information and to report to DoD within 72 hours of discovery a cyber incident affecting a covered contractor information system or the covered defense information residing therein, or affecting the contractor's ability to perform contract requirements designated as operationally critical support and identified in the contract.

The standard: NIST SP 800-171

The technical baseline the clause requires, using the revision specified by the contract. Under Revision 2, the clause requires the 110 security requirements at a minimum, subject to authorized alternatives and nonapplicability determinations, and may require additional measures where reasonably necessary; adequate security is broader than those requirements alone.

The score: SPRS self-assessment

A standardized methodology produces a numeric assessment score that contractors record in the Supplier Performance Risk System. It signals how completely the 110 security requirements in NIST SP 800-171 Revision 2 are implemented, where that is the applicable baseline; a POA&M records gaps and milestones but does not make unmet requirements compliant.

The certification: CMMC

CMMC uses level-specific requirements and assessment paths. Level 1 is based on FAR 52.204-21; Level 2 uses NIST SP 800-171 Revision 2 and may use self-assessment or an authorized C3PAO assessment depending on the contract; Level 3 adds selected NIST SP 800-172 requirements and is assessed by DCMA's DIBCAC, not a C3PAO. Final Level 2 (C3PAO) status covering the Level 3 scope is a mandatory prerequisite before that DIBCAC Level 3 assessment.

CMMC phase-in dates and level definitions are still evolving. Verify the current rule against the DoD CIO and OUSD Acquisition and Sustainment before relying on any specific date or threshold. Lightbridge Cloud frames its CMMC work as readiness and advisory, not as certification.

The SPRS self-assessment score signals NIST 800-171 implementation to contracting officers.

Under the DoD assessment methodology, a contractor scores its own implementation of the 110 NIST SP 800-171 Revision 2 security requirements, where that is the applicable baseline, and records the result in the Supplier Performance Risk System, known as SPRS. The score is a standardized signal: it tells a contracting officer how completely the security requirements are in place and where a plan of action and milestones still covers gaps. A POA&M identifies deficiencies and does not make unmet requirements compliant. For acquisitions using DFARS 252.204-7019, a current assessment posted in SPRS can be an award condition, and DFARS 252.204-7020 establishes related assessment and access obligations. DFARS 252.204-7012 establishes safeguarding and qualifying-incident reporting obligations; it is not the source of that SPRS award condition.

The scoring rules, including how individual requirements are weighted and any maximum or minimum values, are set by the DoD methodology and are revised periodically. Treat any specific number as something to verify against the current official methodology rather than a fixed figure. Lightbridge Cloud helps organizations assess honestly against the security requirements, document a defensible plan, and prepare the evidence behind a score rather than inflate it.

Before a formal self-assessment, our free NIST 800-171 / CMMC Level 2 Readiness Assessment gives a directional readiness tier across all 14 NIST SP 800-171 Revision 2 security families in about 10 minutes. It is a planning tool, not the SPRS methodology described above.

DFARS and NIST 800-171 sit alongside ITAR, EAR, and DCAA obligations.

Information security is one regime among several for a defense contractor. ITAR and EAR govern export-controlled technical data, administered by the State Department Directorate of Defense Trade Controls and the Commerce Department Bureau of Industry and Security. A control that protects controlled unclassified information may also touch export-controlled data, so the regimes overlap in practice even though they are written and enforced separately.

Contract accounting is its own track. Many defense awards require an accounting system that satisfies the Defense Contract Audit Agency, and that finance work lives on the Lightbridge ERP practice: see its guide on DCAA-compliant accounting. Map each regime to its own authoritative source, the NARA CUI Registry for CUI categories, DDTC and BIS for export control, and DCSA for industrial security, because no single framework covers all of them.

Lightbridge Cloud builds DFARS and NIST 800-171 readiness as an independent advisor.

Lightbridge Cloud is an independent, vendor-neutral advisory firm. Its DFARS and NIST SP 800-171 work is readiness and advisory: assessing the gap against the 110 security requirements across 14 families in Revision 2 when that is the contractually applicable revision, helping write a realistic plan of action and milestones, preparing the SPRS self-assessment, and charting the path toward the applicable CMMC assessment path. Lightbridge does not claim to be CMMC certified or FedRAMP authorized; its role here is readiness advisory.

What keeps the guidance honest is independence. Lightbridge sells advisory and engineering, not a partner-tier product quota, so a recommendation follows what an organization's environment actually needs. For contractors weighing where to start, our CMMC compliance readiness service and the companion controlled unclassified information guide are the right entry points. Control 3.13.11 alone trips up many contractors: see our guide on FIPS 140-2 and 140-3 validated cryptography for why "AES-256 encrypted" is not the same claim as FIPS validated.

This guide is general information, not legal, audit, or accounting advice. Regulations such as DFARS, NIST SP 800-171, CMMC, ITAR, EAR, and DCAA requirements change over time. Verify any specific clause, date, threshold, or score against the official source, including acquisition.gov, NIST, the DoD CIO and OUSD Acquisition and Sustainment, the NARA CUI Registry, DCSA, and DDTC or BIS, and consult qualified counsel for your situation. Any product or platform names mentioned are trademarks of their respective owners; Lightbridge Cloud is independent and is not affiliated with, endorsed by, or a partner tier of any vendor.

DFARS and NIST 800-171: frequently asked questions

What is DFARS 252.204-7012 in simple terms?
DFARS 252.204-7012 is a Defense Federal Acquisition Regulation Supplement clause that the Department of Defense places in contracts. In simple terms, when a contract containing it involves covered defense information, it requires the contractor to safeguard that information on its systems and to report to DoD within 72 hours of discovery a cyber incident affecting a covered contractor information system or the covered defense information residing therein, or affecting the contractor's ability to perform contract requirements designated as operationally critical support and identified in the contract. The clause points to NIST SP 800-171 as a minimum baseline, subject to authorized alternatives and nonapplicability determinations, and may require additional measures where reasonably necessary. Lightbridge Cloud helps organizations build readiness against this clause as an independent advisor, not as a reseller of any vendor product. Verify the current clause text against acquisition.gov, since DFARS provisions are revised over time.
What is NIST SP 800-171 and how many security requirements does it have?
NIST SP 800-171 is a National Institute of Standards and Technology publication that defines how to protect controlled unclassified information on nonfederal systems and organizations. The count is revision-specific: Revision 2 has 110 security requirements organized across 14 security families, ranging from Access Control to System and Information Integrity, while Revision 3 has 97 security requirements across 17 families. Use the revision specified by the contract and confirm its wording against the current NIST publication before scoping a program. Lightbridge Cloud uses the framework to assess gaps and plan remediation without steering an organization toward any single tool.
What is a SPRS score and why does it matter?
A SPRS score is the result of the NIST SP 800-171 self-assessment that a contractor records in the Supplier Performance Risk System. Using a standardized scoring methodology, an organization evaluates how completely it has implemented the 110 security requirements in NIST SP 800-171 Revision 2, where that is the applicable baseline, and documents a plan for any requirement not yet met. A POA&M records deficiencies and remediation milestones; it does not make unmet requirements compliant. For acquisitions using DFARS 252.204-7019, a current assessment posted in SPRS can be an award condition, while DFARS 252.204-7020 establishes related assessment and access obligations. DFARS 252.204-7012 establishes safeguarding and incident-reporting duties, not that SPRS award condition. The exact scoring rules and any maximum or minimum thresholds should be verified against the current DoD methodology, because they are revised periodically.
How do DFARS and NIST 800-171 ladder up to CMMC?
The pieces stack. When included in a contract involving covered defense information, DFARS 252.204-7012 creates safeguarding and qualifying-incident reporting obligations. NIST SP 800-171 is the applicable technical standard; under Revision 2, it has 110 security requirements across 14 families. The SPRS self-assessment score measures how completely those requirements are implemented, and DFARS 252.204-7019 and 252.204-7020 govern the current-assessment and related assessment/access mechanisms used for applicable awards. CMMC has level-specific requirements and assessment paths: Level 1 is based on FAR 52.204-21, Level 2 uses NIST SP 800-171 Revision 2 and may involve self-assessment or a C3PAO, and Level 3 adds selected NIST SP 800-172 requirements and is assessed by DCMA's DIBCAC, not a C3PAO. Final Level 2 (C3PAO) status covering the Level 3 scope is a mandatory prerequisite before that DIBCAC Level 3 assessment. CMMC does not replace the underlying requirements for the applicable level. Phase-in dates and level definitions are still evolving, so verify the current rule with the DoD CIO and OUSD Acquisition and Sustainment.
What is covered defense information and controlled unclassified information?
Covered defense information is unclassified controlled technical information or other information described in the Controlled Unclassified Information (CUI) Registry that requires safeguarding or dissemination controls pursuant to and consistent with applicable law, regulations, and Governmentwide policies, and is either (1) marked or otherwise identified in the contract, task order, or delivery order and provided to the contractor by or on behalf of the Department of Defense in connection with contract performance, or (2) collected, developed, received, transmitted, used, or stored by or on behalf of the contractor in support of contract performance. Controlled unclassified information, or CUI, is the broader government-wide category for unclassified information that still requires safeguarding under law, regulation, or policy. The authoritative list of CUI categories is the National Archives CUI Registry maintained by NARA. Our companion guide on controlled unclassified information explains the category in depth and how it triggers safeguarding duties.
Who has to comply with DFARS 252.204-7012?
The clause generally applies to defense contractors and their subcontractors when the DFARS clause is included in the applicable contract. Paragraph (m) requires flow-down to subcontracts for operationally critical support or for which subcontract performance will involve covered defense information; either condition independently triggers flow-down. That reach means a small subcontractor can inherit the same safeguarding and reporting duties as a prime. Applicability turns on the specific clauses in a given contract, so the contract itself and acquisition.gov are the authoritative sources. Lightbridge Cloud helps contractors and subcontractors map which obligations actually apply to their environment before they invest in controls they may not need.
How does this relate to ITAR, EAR, and DCAA accounting requirements?
DFARS and NIST SP 800-171 address information security, but defense contractors often face parallel regimes. ITAR and EAR govern export-controlled technical data, administered by the State Department Directorate of Defense Trade Controls and the Commerce Department Bureau of Industry and Security respectively, and a control that protects CUI may also touch export-controlled data. Separately, contract accounting can require a DCAA-compliant accounting system. For that finance side, see the Lightbridge ERP guide on DCAA-compliant accounting. Verify each regime against its own authoritative source, since they are administered by different agencies.
How does Lightbridge Cloud support DFARS and NIST 800-171 readiness?
Lightbridge Cloud is an independent, vendor-neutral advisory firm. It supports DFARS and NIST SP 800-171 work as readiness and advisory: assessing the gap against the 110 security requirements in Revision 2 when that is the contractually applicable revision, helping document a plan of action, and preparing for the SPRS self-assessment and the applicable CMMC assessment path. Lightbridge does not claim to be CMMC certified or FedRAMP authorized and does not sell a partner-tier product line, so recommendations are driven by fit rather than commission. Our CMMC compliance readiness service describes that scope in detail.

From understanding the clause to passing the assessment.

When the question shifts from what DFARS and NIST 800-171 require to whether your environment is ready, Lightbridge Cloud runs a vendor-neutral gap assessment and helps you build a defensible plan.