Gov Contract Finder
Schedule DemoDemoGet RegisteredRegister
HomeGuides

What is the CMMC compliance roadmap under DFARS Subpart 204.75?

DFARS Subpart 204.75 puts CMMC level requirements into DoD contracts and uses SPRS for Level 1 and Level 2 compliance.

advanced1 min readStep-by-step guide
What is the CMMC compliance roadmap under DFARS Subpart 204.75 editorial illustration

Summary

What is the CMMC compliance roadmap under DFARS Subpart 204.75? DFARS Subpart 204.75 puts CMMC level requirements into DoD contracts and uses SPRS for Level 1 and Level 2 compliance.

Source & Authority Information

Published: January 26, 2026
Substantively updated: August 26, 2026
Information as of: 2026-08-26
Gov Contract Finder LogoGov Contract Finder Logo
  • Product
  • AI Bidding Assistant
  • Browser Extension
  • Mobile App
  • Email Alerts
  • Insights & Analytics
  • Pricing
  • Knowledge Base
  • Guides
  • Glossary
  • Q&A
  • Documentation
  • Blog
  • For Small Business
  • For Capture Teams
  • Compare Platforms
  • Services
  • Workflow Automation
  • Support
  • Contact Us
© Copyright 2026 Gov Contract Finder.
  • Terms Of Service
  • Privacy Policy
  • Editorial Policy
Author: Gov Contract Finder Editorial Team
Primary sources:
  • •Subpart 204.75 - CYBERSECURITY MATURITY MODEL CERTIFICATION | Acquisition.GOV(accessed August 26, 2026)
  • •SPRS - CMMC(accessed August 26, 2026)
  • •252.204-7021 Contractor Compliance With the Cybersecurity Maturity Model Certification Level Requirements. | Acquisition.GOV(accessed August 26, 2026)

AI-assisted and automatically checked against the linked primary sources.

Get more Gov Contract Finder updates in Google

Open Google source preferences

How do you follow the CMMC compliance path in DoD contracting?

DFARS Subpart 204.75 prescribes the policies and procedures for including CMMC level requirements in DoD contracts, and it applies to unclassified contractor information systems. Acquisition.gov states that CMMC is a framework for assessing a contractor’s information security protections under 32 CFR part 170. The same subpart also says it does not replace other security obligations, including physical, personnel, information, technical, or general administrative security operations, and it does not affect National Industrial Security Program requirements. For execution, SPRS is the location where vendors certify CMMC Level 1 and Level 2 compliance for the defense acquisition community to review. SPRS also points users to the CMMC Level 1 and Level 2 quick entry guides, the assessment guides, and the official CMMC rule at 32 CFR Part 170. For contract language, DFARS 252.204-7021 is the clause titled Contractor Compliance With the Cybersecurity Maturity Model Certification Level Requirements.

Process

  1. 1
    Check whether the contract includes CMMC requirements

    DFARS Subpart 204.75 prescribes the policies and procedures for including CMMC level requirements in DoD contracts.

  2. 2
    Confirm the scope

    The subpart applies to unclassified contractor information systems and does not replace other required security operations.

  3. 3
    Use SPRS for compliance records

    SPRS is the location for vendors to certify CMMC Level 1 and Level 2 compliance.

  4. 4
    Match the official guidance

    Use the CMMC materials linked through SPRS and the rule at 32 CFR Part 170 when preparing or reviewing the assessment.

Important Note

DFARS Subpart 204.75 does not abrogate other security requirements for protecting unclassified information, and it does not affect National Industrial Security Program requirements.

Quick Answers

  • Do you need CMMC certification for all DoD contracts?
  • How long does CMMC certification take?

Ready to find contracts?

See how Gov Contract Finder helps you discover federal opportunities and organize the work needed to pursue them.

Schedule DemoNeed SAM.gov registration help? →