How Should Defense Contractors Prepare for Recent CMMC Assessment Changes?
Defense contractors tied to covered contractor information systems must track CMMC status windows, SPRS posting, and continuous-compliance affirmations.
AI-assisted and automatically checked against the linked primary sources.
Which contractors are affected?
According to DFARS 252.204-7012, the affected population is contractors handling “covered defense information” on a “covered contractor information system,” meaning an unclassified system owned or operated by or for a contractor that processes, stores, or transmits that information. DFARS 252.204-7019 applies when an offeror is required to implement NIST SP 800-171 and requires a current assessment for each covered contractor information system relevant to the offer, contract, task order, or delivery order. DFARS 252.204-7020 says the NIST SP 800-171 assessment clause applies to covered contractor information systems required to comply with NIST SP 800-171. The newer DFARS 252.204-7021 adds CMMC compliance requirements and assigns a CMMC unique identifier for each assessment that is reflected in SPRS. Taken together, the clauses point to contractors whose systems support DoD work involving covered defense information and whose compliance must be shown through the applicable NIST SP 800-171 or CMMC assessment record.