SK Written by Sarika Krishnan with Robert LabardeeSenior Program Manager and Founder and CEO

DFARS 252.204-7012 and NIST 800-171

Lightbridge Cloud defines DFARS 252.204-7012 as the Department of Defense contract clause that requires defense contractors to safeguard covered defense information and report cyber incidents within 72 hours. It points to NIST SP 800-171, a framework of 110 security controls across 14 families, as the standard those contractors must meet.

DFARS 252.204-7012 is the DoD clause that requires safeguarding and 72-hour incident reporting.

DFARS 252.204-7012 is a clause in the Defense Federal Acquisition Regulation Supplement. When the Department of Defense places it in a contract or subcontract, the contractor must provide adequate security for covered defense information stored on or passing through its systems, and must report a cyber incident to DoD. That reporting deadline is commonly cited as within 72 hours of discovering the incident.

The clause does not invent its own security standard. It points to NIST SP 800-171 as the baseline a contractor must implement to count as having adequate security. Covered defense information, the data the clause protects, includes controlled unclassified information that supports the performance of a defense contract. For that broader category, see our guide on controlled unclassified information.

Lightbridge Cloud is an independent advisory firm. This guide describes the requirements as the regulations actually state them, because a contractor's obligations turn on the specific clauses written into its contract. Verify the current clause text and the exact reporting window against the official source at acquisition.gov, since DFARS provisions are revised over time.

NIST SP 800-171 organizes 110 controls into 14 security families.

NIST SP 800-171 is the National Institute of Standards and Technology publication that defines how to protect controlled unclassified information on nonfederal systems. It is widely cited as 110 controls grouped into 14 families, each covering one dimension of security. An organization meets the standard by implementing the controls that apply to its environment and documenting a plan for any that are not yet in place. These are the families, summarized.

Access Control

Limits who can reach systems that hold controlled unclassified information, covering account management, least privilege, separation of duties, and remote access. It is one of the largest families by control count in NIST SP 800-171.

Awareness and Training

Requires that users and administrators understand the security risks tied to their roles and the policies that apply, including insider-threat awareness for staff who handle covered information.

Audit and Accountability

Calls for creating, protecting, and reviewing audit logs so a contractor can trace user activity, detect misuse, and support an investigation if covered defense information is exposed.

Configuration Management

Establishes baseline configurations, change control, and restrictions on what software runs, so systems that process controlled unclassified information stay in a known and hardened state.

Identification and Authentication

Verifies the identity of users, processes, and devices before granting access, and is where multifactor authentication and credential management requirements live.

Incident Response and the remaining families

Incident Response, Maintenance, Media Protection, Personnel Security, Physical Protection, Risk Assessment, Security Assessment, System and Communications Protection, and System and Information Integrity complete the 14 families and the 110 controls.

The exact control count and wording change between revisions of the publication, so confirm them against the current revision published by NIST before scoping a program.

DFARS, NIST 800-171, SPRS, and CMMC form a single ladder.

These four terms are often used interchangeably, but they sit at different rungs. The clause creates the obligation, the standard defines what good looks like, the SPRS score measures how far an organization has implemented it, and CMMC adds verification on top of the same baseline. Reading them as a ladder is the clearest way to plan a program.

The clause: DFARS 252.204-7012

The contractual trigger. When this clause appears in a defense contract or subcontract, it obligates the contractor to provide adequate security for covered defense information and to report a cyber incident to DoD, commonly cited as within 72 hours of discovery.

The standard: NIST SP 800-171

The technical baseline the clause requires. Adequate security is defined as implementing the 110 controls across 14 families that protect controlled unclassified information on nonfederal systems.

The score: SPRS self-assessment

A standardized methodology produces a numeric assessment score that contractors record in the Supplier Performance Risk System. It signals how completely the 110 controls are implemented, with a documented plan for any that are not yet met.

The certification: CMMC

The Cybersecurity Maturity Model Certification operationalizes NIST SP 800-171 by adding independent verification. Depending on the level, it ranges from a self-assessment to a third-party assessment, moving from self-attested compliance toward verified compliance.

CMMC phase-in dates and level definitions are still evolving. Verify the current rule against the DoD CIO and OUSD Acquisition and Sustainment before relying on any specific date or threshold. Lightbridge Cloud frames its CMMC work as readiness and advisory, not as certification.

The SPRS self-assessment score signals NIST 800-171 implementation to contracting officers.

Under the DoD assessment methodology, a contractor scores its own implementation of the 110 NIST SP 800-171 controls and records the result in the Supplier Performance Risk System, known as SPRS. The score is a standardized signal: it tells a contracting officer how completely the controls are in place and where a plan of action and milestones still covers gaps. Because officers can view the score, it factors into eligibility for awards that carry the safeguarding clause.

The scoring rules, including how individual controls are weighted and any maximum or minimum values, are set by the DoD methodology and are revised periodically. Treat any specific number as something to verify against the current official methodology rather than a fixed figure. Lightbridge Cloud helps organizations assess honestly against the controls, document a defensible plan, and prepare the evidence behind a score rather than inflate it.

DFARS and NIST 800-171 sit alongside ITAR, EAR, and DCAA obligations.

Information security is one regime among several for a defense contractor. ITAR and EAR govern export-controlled technical data, administered by the State Department Directorate of Defense Trade Controls and the Commerce Department Bureau of Industry and Security. A control that protects controlled unclassified information may also touch export-controlled data, so the regimes overlap in practice even though they are written and enforced separately.

Contract accounting is its own track. Many defense awards require an accounting system that satisfies the Defense Contract Audit Agency, and that finance work lives on the Lightbridge ERP practice: see its guide on DCAA-compliant accounting. Map each regime to its own authoritative source, the NARA CUI Registry for CUI categories, DDTC and BIS for export control, and DCSA for industrial security, because no single framework covers all of them.

Lightbridge Cloud builds DFARS and NIST 800-171 readiness as an independent advisor.

Lightbridge Cloud is an independent, vendor-neutral advisory firm. Its DFARS and NIST SP 800-171 work is readiness and advisory: assessing the gap against the 110 controls across 14 families, helping write a realistic plan of action and milestones, preparing the SPRS self-assessment, and charting the path toward CMMC. Lightbridge does not claim to be CMMC certified or FedRAMP authorized, and it operates to recognized security controls as a matter of practice rather than asserting an awarded certification.

What keeps the guidance honest is independence. Lightbridge sells advisory and engineering, not a partner-tier product quota, so a recommendation follows what an organization's environment actually needs. For contractors weighing where to start, our CMMC compliance readiness service and the companion controlled unclassified information guide are the right entry points.

This guide is general information, not legal, audit, or accounting advice. Regulations such as DFARS, NIST SP 800-171, CMMC, ITAR, EAR, and DCAA requirements change over time. Verify any specific clause, date, threshold, or score against the official source, including acquisition.gov, NIST, the DoD CIO and OUSD Acquisition and Sustainment, the NARA CUI Registry, DCSA, and DDTC or BIS, and consult qualified counsel for your situation. Any product or platform names mentioned are trademarks of their respective owners; Lightbridge Cloud is independent and is not affiliated with, endorsed by, or a partner tier of any vendor.

DFARS and NIST 800-171: frequently asked questions

What is DFARS 252.204-7012 in simple terms?
DFARS 252.204-7012 is a Defense Federal Acquisition Regulation Supplement clause that the Department of Defense places in contracts. In simple terms, it requires a defense contractor to safeguard covered defense information on its systems and to report a cyber incident to DoD, a deadline commonly described as within 72 hours of discovery. The clause points to NIST SP 800-171 as the security standard a contractor must meet. Lightbridge Cloud helps organizations build readiness against this clause as an independent advisor, not as a reseller of any vendor product. Verify the current clause text against acquisition.gov, since DFARS provisions are revised over time.
What is NIST SP 800-171 and how many controls does it have?
NIST SP 800-171 is a National Institute of Standards and Technology publication that defines how to protect controlled unclassified information on nonfederal systems and organizations. It is widely cited as 110 security controls organized across 14 control families, ranging from Access Control to System and Information Integrity. The exact control count and wording change between revisions of the publication, so confirm the figure against the current revision published by NIST before scoping a program. Lightbridge Cloud uses the framework to assess gaps and plan remediation without steering an organization toward any single tool.
What is a SPRS score and why does it matter?
A SPRS score is the result of the NIST SP 800-171 self-assessment that a contractor records in the Supplier Performance Risk System. Using a standardized scoring methodology, an organization evaluates how completely it has implemented the 110 controls and documents a plan for any control not yet met. Contracting officers can view the score, so it factors into eligibility for awards that carry the safeguarding clause. The exact scoring rules and any maximum or minimum thresholds should be verified against the current DoD methodology, because they are revised periodically.
How do DFARS and NIST 800-171 ladder up to CMMC?
The pieces stack. DFARS 252.204-7012 is the contract clause that creates the obligation. NIST SP 800-171 is the standard of 110 controls that defines adequate security. The SPRS self-assessment score measures how completely those controls are implemented. CMMC, the Cybersecurity Maturity Model Certification, then operationalizes the same NIST SP 800-171 baseline by adding verification, which depending on the assessment level ranges from a self-assessment to an independent third-party assessment. CMMC does not replace the underlying controls: it confirms them. Phase-in dates and level definitions are still evolving, so verify the current rule with the DoD CIO and OUSD Acquisition and Sustainment.
What is covered defense information and controlled unclassified information?
Covered defense information is the category named in DFARS 252.204-7012 and includes controlled unclassified information that supports the performance of a defense contract. Controlled unclassified information, or CUI, is the broader government-wide category for unclassified information that still requires safeguarding under law, regulation, or policy. The authoritative list of CUI categories is the National Archives CUI Registry maintained by NARA. Our companion guide on controlled unclassified information explains the category in depth and how it triggers safeguarding duties.
Who has to comply with DFARS 252.204-7012?
The clause generally applies to defense contractors and their subcontractors at any tier when the contract involves covered defense information, and the obligation flows down through the supply chain. That reach means a small subcontractor can inherit the same safeguarding and reporting duties as a prime. Applicability turns on the specific clauses in a given contract, so the contract itself and acquisition.gov are the authoritative sources. Lightbridge Cloud helps contractors and subcontractors map which obligations actually apply to their environment before they invest in controls they may not need.
How does this relate to ITAR, EAR, and DCAA accounting requirements?
DFARS and NIST SP 800-171 address information security, but defense contractors often face parallel regimes. ITAR and EAR govern export-controlled technical data, administered by the State Department Directorate of Defense Trade Controls and the Commerce Department Bureau of Industry and Security respectively, and a control that protects CUI may also touch export-controlled data. Separately, contract accounting can require a DCAA-compliant accounting system. For that finance side, see the Lightbridge ERP guide on DCAA-compliant accounting. Verify each regime against its own authoritative source, since they are administered by different agencies.
How does Lightbridge Cloud support DFARS and NIST 800-171 readiness?
Lightbridge Cloud is an independent, vendor-neutral advisory firm. It supports DFARS and NIST SP 800-171 work as readiness and advisory: assessing the gap against the 110 controls, helping document a plan of action, and preparing for the SPRS self-assessment and the path toward CMMC. Lightbridge does not claim to be CMMC certified or FedRAMP authorized and does not sell a partner-tier product line, so recommendations are driven by fit rather than commission. Our CMMC compliance readiness service describes that scope in detail.

From understanding the clause to passing the assessment.

When the question shifts from what DFARS and NIST 800-171 require to whether your environment is ready, Lightbridge Cloud runs a vendor-neutral gap assessment and helps you build a defensible plan.