What Do the Latest DoD Security Requirement Changes Mean for Contractors?
DoD clauses apply to covered contractor systems, current NIST SP 800-171 assessments, SPRS postings, and cloud security controls when cloud services are used.
AI-assisted and automatically checked against the linked primary sources.
Which contractors are affected?
According to DFARS 252.204-7012, a covered contractor information system is an unclassified system owned or operated by or for a contractor that processes, stores, or transmits covered defense information. DFARS 252.204-7020 says the assessment requirements apply to covered contractor information systems that are required to comply with NIST SP 800-171. For award consideration, DFARS 252.204-7019 states that if the offeror is required to implement NIST SP 800-171, the offeror must have a current assessment that is not more than 3 years old unless the solicitation sets a shorter period, and that assessment must cover each relevant covered contractor information system tied to the offer, contract, task order, or delivery order. The clauses also connect those assessments to SPRS. DFARS 252.204-7020 distinguishes basic assessments from medium and high assessments, with basic assessments being contractor self-assessments and medium and high assessments being conducted by the Government. DFARS 252.204-7020 also allows rebuttal of Medium and High Assessment summary scores before posting, and gives the contractor 14 business days after completion of each assessment to provide additional information or rebut findings.