DFARS 7019 and 7020: The Assessment That Decides Whether You Can Bid
DFARS 252.204-7019 and 252.204-7020 are the pair of clauses that turn "implement NIST 800-171" into "prove it with a score." Two of the five DFARS cyber clauses, they require a current NIST 800-171 DoD Assessment, posted in SPRS, as a condition of a DoD award. 7019 is the solicitation-side notice; 7020 is the contract-side clause. Here is how they work.
Why the pair exists
DFARS 252.204-7012 has required contractors to implement NIST 800-171 since 2016, but it came with no way to check. You signed, you self-attested, and the Government took your word for it.
That gap is what 7019 and 7020 closed. Introduced by a DFARS interim rule effective November 30, 2020, they added a verification layer: a numeric score, calculated with the DoD Assessment Methodology, posted where contracting officers can see it. Since that date, a DoD contract carrying these clauses cannot be awarded to a contractor with no assessment on file.
252.204-7019: the solicitation side
7019 is a solicitation provision, which means it governs what you need before award. Its rule is direct: if you are required to implement NIST 800-171, you must have a current assessment, no more than three years old, posted in SPRS for each covered system relevant to the offer. "Current" is the operative word. A score that has aged past three years is treated as no score at all.
If you have never posted one, you can conduct a Basic Assessment yourself and calculate your SPRS score. But it has to be in SPRS by the time of award. No score, no award, and contracting officers check.
252.204-7020: the contract side
7020 is the contract clause, and it governs what you owe once you are performing. Three obligations come with it.
First, keep your score current in SPRS. Second, provide the Government access to your facilities, systems, and personnel if it decides to conduct a higher-level assessment of your environment. Third, flow the requirement down: you cannot award a subcontract that involves NIST 800-171 unless the subcontractor has its own current Basic Assessment in SPRS. The clause goes into your subcontracts, and your subs post their own scores directly.
Basic, Medium, High: a ladder of confidence, not difficulty
The three assessment types are not three difficulty levels. They are three levels of confidence the Government places in the result, and what separates them is who does the assessing.
A Basic Assessment is your own self-assessment. You review your system security plan against the 110 controls of NIST SP 800-171, score it, and post it. It carries low confidence, because you graded yourself.
A Medium Assessment is conducted by Government personnel. They review your documentation thoroughly and discuss it with you to confirm your self-reported score holds up. Medium confidence.
A High Assessment is the most rigorous, conducted on-site or virtually by Government assessors (DCMA's DIBCAC) using NIST SP 800-171A. They verify, examine, and demonstrate that the controls in your plan are actually implemented, not just described. High confidence.
Most contractors live at Basic. The Government reserves Medium and High for the systems and programs where the data justifies a closer look, and 7020 is what obligates you to open the door when it does.
The requirement that survived the freeze
Here is why this pair matters right now. When the Department of War suspended CMMC Phase 2 in July 2026, it froze third-party certification. It did not touch this. Self-assessments, SPRS scores, and the DoD Assessment regime remain fully in force.
That distinction is easy to miss. A lot of contractors read "CMMC suspended" as "cybersecurity requirements paused," and that is not what happened. 7019 and 7020 still gate your awards. Your score is still checked before every award and option. If you let it lapse past three years because you assumed the pause covered you, you will find out at the worst possible moment: when a contracting officer cannot award you the work.
What to do
Four moves:
Post a current Basic Assessment now if you handle CUI and don't have one. It is the price of eligibility.
Watch the three-year clock. Diary the expiry and reassess before it lapses, not after.
Verify your subcontractors. Before you award to a sub that will touch 800-171 data, confirm their score is in SPRS. Their gap becomes your problem.
Be ready for a Medium or High. If you handle sensitive CUI, assume the Government may come to verify, and keep your evidence in a state you could show tomorrow.
Key Takeaways
7019 and 7020 require a current NIST 800-171 DoD Assessment score in SPRS as a condition of a DoD award. They added the verification that 7012 lacked, effective November 30, 2020.
7019 (solicitation) requires a current score, three years or newer, to be eligible. 7020 (contract) requires you to maintain it, grant access for higher assessments, and flow the requirement to subcontractors.
Basic, Medium, and High are confidence levels, not difficulty levels. Basic is your self-assessment; Medium and High are Government-conducted, with High the most rigorous.
The Phase 2 suspension did not touch this. Self-assessments and SPRS scores still gate awards, and a lapsed score still costs you the award.
No score, no award. Post a current Basic Assessment, watch the three-year clock, and verify your subs.
FAQ
What is the difference between DFARS 7019 and 7020? 7019 is the solicitation provision: to be eligible for award, you need a current NIST 800-171 DoD Assessment score in SPRS. 7020 is the contract clause: once you are performing, you must keep that score current, grant the Government access for a Medium or High assessment if it conducts one, and flow the requirement down to subcontractors who handle NIST 800-171 data.
How current does my SPRS score have to be? Not more than three years old, unless the solicitation specifies a shorter window. A score older than three years is treated as no score at all, which means no award until you post a current one.
What are the Basic, Medium, and High assessments? They are levels of confidence based on who performs the assessment. A Basic Assessment is your own self-assessment (low confidence). A Medium Assessment is a Government-led review of your documentation (medium confidence). A High Assessment is a Government on-site or virtual verification using NIST SP 800-171A (high confidence). Most contractors are at Basic.
Did the CMMC Phase 2 suspension pause 7019 and 7020? No. The July 2026 suspension froze third-party (C3PAO) certification. The self-assessment and SPRS scoring regime under 7019 and 7020 remains fully in force, and a current score still gates every award and option.
Do 7019 and 7020 flow down to subcontractors? Yes. Under 7020, you cannot award a subcontract that involves NIST 800-171 unless the subcontractor has completed at least a current Basic Assessment posted in SPRS, and you must include the substance of the clause in the subcontract. Subcontractors post their own scores directly.
The rules that gate a DoD award do not always announce themselves. A score quietly ages out, a clause changes, a suspension turns out to be narrower than the headline. Federal Cyber Brief tracks what is being bought, who can bid, and what is changing across federal IT and cyber contracting, and sends the parts that matter to your inbox each week. Primary sources only. No noise.
SOURCES
DFARS 252.204-7019, Notice of NIST SP 800-171 DoD Assessment Requirements (acquisition.gov / 48 CFR 252.204-7019). The requirement to have a current assessment (not more than three years old) posted in SPRS to be considered for award; the Basic, Medium, and High assessments; the option to conduct and submit a Basic Assessment.
DFARS 252.204-7020, NIST SP 800-171 DoD Assessment Requirements (acquisition.gov / 48 CFR 252.204-7020). The requirement to provide Government access for a Medium or High assessment; SPRS posting of summary-level scores; the subcontractor flow-down and the requirement that subcontractors have a current Basic Assessment before award.
DFARS 204.7304, Solicitation provision and contract clauses (acquisition.gov). Prescription of the 7019 and 7020 clauses for DoD solicitations and contracts.
NIST SP 800-171 DoD Assessment Methodology, Version 1.2.1 (Office of the Under Secretary of Defense for Acquisition and Sustainment). The definitions of the Basic, Medium, and High assessments and the weighted scoring from a 110-point base.
DFARS Interim Rule, "Assessing Contractor Implementation of Cybersecurity Requirements," 85 FR 61505 (effective November 30, 2020). Introduced DFARS 252.204-7019, 252.204-7020, and 252.204-7021.
NIST SP 800-171A Revision 2. The assessment methods used in the Medium and High assessments.
