Gov Contract Finder LogoGov Contract Finder Logo
  • ⭐
    AI Bidding Assistant
    Analyze RFPs and draft faster
    Apps
    Browser ExtensionMobile App
    Features
    Email AlertsInsights & AnalyticsProcurement Officers
    Overview →
    OverviewBrowser ExtensionMobile AppEmail AlertsInsights & AnalyticsAI Bidding Assistant
  • Pricing
  • Contracts
  • Learn
    Knowledge BaseGuidesGlossaryQ&ABlogDocumentation
    Comparisons
    Compare PlatformsSAM.gov Alternative
    Solutions
    Why Gov Contract FinderFor Small BusinessFor Capture TeamsSupport
    Proof
    Customer StoriesData Coverage
    Knowledge BaseGuidesGlossaryQ&ABlogDocumentationSupportWhy Gov Contract FinderFor Small BusinessCompare Platforms
  • Services
  • Login
  • Schedule Demo
Gov Contract Finder LogoGov Contract Finder Logo
  • Product
  • AI Bidding Assistant
  • Browser Extension
  • Mobile App
  • Email Alerts
  • Insights & Analytics
  • Pricing
  • Knowledge Base
  • Guides
  • Glossary
  • Q&A
  • Documentation
  • Blog
  • For Small Business
  • For Capture Teams
  • Compare Platforms
  • Services
  • Workflow Automation
  • Support
  • Contact Us
© Copyright 2026 Gov Contract Finder.
  • Terms Of Service
  • Privacy Policy
  • Editorial Policy
Home / Resources / Cybersecurity & CMMC
Cybersecurity & CMMC

What Do the Latest DoD Security Requirement Changes Mean for Contractors?

Published September 16, 2026

DoD clauses apply to covered contractor systems, current NIST SP 800-171 assessments, SPRS postings, and cloud security controls when cloud services are used.

What Do the Latest DoD Security Requirement Changes Mean for Contractors editorial illustration
Gov Contract Finder Editorial Team
•2 min read•Information as of September 16, 2026

AI-assisted and automatically checked against the linked primary sources.

Get more Gov Contract Finder updates in Google

Open Google source preferences

Which contractors are affected?

According to DFARS 252.204-7012, a covered contractor information system is an unclassified system owned or operated by or for a contractor that processes, stores, or transmits covered defense information. DFARS 252.204-7020 says the assessment requirements apply to covered contractor information systems that are required to comply with NIST SP 800-171. For award consideration, DFARS 252.204-7019 states that if the offeror is required to implement NIST SP 800-171, the offeror must have a current assessment that is not more than 3 years old unless the solicitation sets a shorter period, and that assessment must cover each relevant covered contractor information system tied to the offer, contract, task order, or delivery order. The clauses also connect those assessments to SPRS. DFARS 252.204-7020 distinguishes basic assessments from medium and high assessments, with basic assessments being contractor self-assessments and medium and high assessments being conducted by the Government. DFARS 252.204-7020 also allows rebuttal of Medium and High Assessment summary scores before posting, and gives the contractor 14 business days after completion of each assessment to provide additional information or rebut findings.

[2][3][4]

What changes for assessment requirements?

The cited rules require current NIST SP 800-171 DoD assessments for covered contractor information systems, with summary-level scores posted in SPRS. Basic assessments are contractor self-assessments; medium and high assessments are Government assessments.
Sources: [2] 252.204-7019 Notice of NISTSP 800-171 DoD Assessment Requirements., [3] 252.204-7020 NIST SP 800-171DoD Assessment Requirements.

What should small businesses review?

Small businesses should review whether their work involves covered contractor information systems, whether those systems process, store, or transmit covered defense information, and whether NIST SP 800-171 applies under DFARS 252.204-7012 and 252.204-7020. They should also review their SPRS status, because the clauses require current assessment scores to be posted or submitted for posting. If cloud computing is used to provide information technology services in performance of the contract, DFARS 252.239-7010 adds separate requirements: the contractor must obtain Contracting Officer approval before using cloud services when the offer said cloud was not anticipated, must implement and maintain the required safeguards under the Cloud Computing Security Requirements Guide unless waived, must keep non-DoD-premises Government data in the United States or outlying areas unless written approval says otherwise, and must report cloud-related cyber incidents to DoD.

[3][4][6]

  • The cited DFARS rules apply to covered contractor information systems that must comply with NIST SP 800-171.
  • Award consideration can depend on a current assessment that is not more than 3 years old unless the solicitation sets a shorter period.
  • Basic assessments are contractor self-assessments; medium and high assessments are Government assessments and are tied to SPRS posting.
  • Cloud computing adds separate security, data-location, and cyber incident reporting requirements under DFARS 252.239-7010.
Next Step

Review whether your contracts involve covered contractor information systems, current SPRS assessment status, and any cloud computing use under the cited DFARS clauses.

Important Note

DFARS 252.204-7020 allows the contractor to receive Medium and High Assessment summary scores and rebut them before SPRS posting, and gives 14 business days after each assessment to provide additional information or rebut findings.

Sources & Citations

1. 252.204-7019 Notice of NISTSP 800-171 DoD Assessment Requirements. [Link ↗](government site)Accessed 9/16/2026
2. 252.204-7020 NIST SP 800-171DoD Assessment Requirements. [Link ↗](government site)Accessed 9/16/2026
3. 252.204-7012 Safeguarding Covered Defense Information and Cyber Incident Reporting. | Acquisition.GOV [Link ↗](government site)Accessed 9/16/2026

Tags

#cybersecurity-cmmc#defense-contracting#DFARS#nist-sp-800-171#small business#sprs

Ready to Win Government Contracts?

Use Gov Contract Finder to discover relevant federal opportunities and prepare stronger bids.

Get StartedSchedule Demo

Related Articles

How Should Contractors Plan for Budget Impasses and Continuing Resolutions?

FAR funding clauses control whether performance can start, continue, or stop when appropriations are delayed, and written notices govern liability.

Read more →

How Should Defense Contractors Prepare for Recent CMMC Assessment Changes?

Defense contractors tied to covered contractor information systems must track CMMC status windows, SPRS posting, and continuous-compliance affirmations.

Read more →

How Do DoD Cost and Pricing Policy Changes Affect Defense Proposals?

DoD pricing guidance can change defense proposals by tightening data requests, price-analysis scrutiny, and the support needed to prove fairness.

Read more →