DFARS 7019

Here's everything you need to know about DFARS 7019: its origins, why the RFO removed it, and how its removal changes compliance requirements.

Until the Revolutionary FAR Overhaul (RFO) removed the clause in 2026, Defense Federal Acquisition Regulation Supplement (DFARS) 252.204-7019 required defense contractors to maintain a current National Institute of Standards and Technology (NIST) SP 800171 cybersecurity assessment and report their score in the Supplier Performance Risk System (SPRS). 

DFARS 7019 required contractors to pass a Basic, Medium, or High assessment at least every three years, with higherlevel assessments conducted by the Department of War (DoW). 

Speak with our team

Origin and Context 

The DoW released DFARS 252.204-7019, titled “Notice of NIST Special Publication 800-171 DoD Assessment Requirements,” in 2020 as part of the DFARS 70 series (7012, 7020 (now DFARS 252.240-7997), 7021, 7025). The series was released in response to adversarial nations stealing controlled unclassified information (CUI) on contractor networks, which falsely claimed to have implemented cybersecurity requirements. That theft compromised several DoW weapon systems. DFARS 7019 built a framework for accountability to ensure contractors actually were compliant, not just claiming to be.   

Why the Revolutionary FAR Overhaul Ended DFARS 7019 

The RFO removed DFARS 7019 in early 2026 in an effort to streamline the Federal Acquisition Regulation (FAR) framework. The clause enforced a “basic self-assessment” of NIST SP 800‑171 and enforced uploading the assessment score to SPRS. However, with Cybersecurity Maturity Model Certification (CMMC) fully operational, DFARS 7019 became redundant. CMMC’s framework within DFARS 7021 covers all required assessments. 

What does the removal of DFARS 7019 change? 

Before the RFO removed DFARS 7019, it was a separate obligation from CMMC with redundant requirements. Now, there is only one assessment obligation under CMMC, aside from government-initiated DFARS 240.7997 medium and high assessments. 

What was DFARS 7019? 

DFARS 7019 held the requirements for contractors to maintain their NIST 800-171 Assessments and report scores in SPRS. It did not require CMMC assessment or reporting.  

Each contractor would need to have a Basic, Medium, or High assessment (defined below) completedat least every three years and ensure that it is properly reported within SPRS. Contracting authorities held the right to adjust the recency requirement from three years to two or one.  

  • Basic:Like the self-assessments and self-attestations that have been taking place since 2018, this assessment required a System Security Plan (SSP) or Plans to be submitted  
  • Medium and High:NIST 800-171 assessments run by the Defense Contract Management Agency (DCMA)  

Interestingly, DFARS 7019 and many of the reporting mechanisms allowed for multiple Commercial and Government Entity (CAGE) codes to apply for a single assessment and SSP within shared systems. A smaller partner company could potentially use another company’s systems exclusively for performing on a contractor, as long as the SSP submitted and assessed accommodates that arrangement.  

DFARS 7019, 7020, 7021, and 7025 differentiations

Contact

Speak With Our Team

Scroll to Top