By
OCD Tech
January 18, 2021
•
5
min read

On September 30, 2020, the DoD revealed a new set of proposed clauses for the Defense Federal Acquisition Regulation Supplement-known as the DFARS-in an interim rule (DFARS Case 2019-D041). These new clauses seek to close the gap between security and compliance for the Defense Industrial Base (DIB). The interim rule introduces the CMMC requirement, which had been expected for well over a year, but the additional clauses this interim rule introduced were widely unexpected.Before explaining the new clauses, it is relevant to address the existing -7012 clause. Since December 2017, this clause has mandated compliance with NIST 800-171 for companies handling DoD Controlled Unclassified Information (CUI). The -7012 clause is approved for use in all DoD contracts (with a few exceptions) and is found in contracts that do not contain CUI. The new set of clauses in the DFARS can be viewed as an expansion of the -7012 clause to create more stringent guidelines for the DIB.-7019 Clause: Notice of NIST SP 800-171 DoD Assessment RequirementsAll companies who handle DoD CUI must complete a self-assessment using the DoD Assessment Methodology and generate a score. Companies must then input that score and the date at which they plan to remediate all gaps to the Supplier Performance Risk System (SPRS). At the time of contract award for a DoD contract containing the new -7019 clause, a DoD contracting officer will simply verify a score has been uploaded. At this time there is no baseline score requirement, which means that any score is sufficient to meet the -7019-clause requirement.-7020 Clause: NIST SP 800-171 DoD Assessment RequirementsAlong with the -7012 and -7019 clauses, this new clause is approved for inclusion in all DoD contracts. This new clauserequires a contractor to provide the Government with access to its facilities, systems, and personnel when it is necessary for DoD to conduct or renew a higher-level Assessment. The higher-level assessments are the Medium and High assessments. The self-assessment conducted as part of the -7019 clause is called a Basic Assessment.
Additionally, this rule requires that contractors flow down their requirements established in -7019 to their subcontractors4-7021 Clause: Cybersecurity Maturity Model Certification (CMMC) RequirementsThis new DFARS clause establishes CMMC into the federal regulatory framework. This requires CMMC to be included in all contracts, task orders, and solicitations (with few exceptions). The level of CMMC required will be determined by the DoD and inserted into the Request for Proposal. Contractors must maintain the appropriate CMMC level for the duration of any contract and flow down necessary requirements to subcontractors. The CMMC certification at the appropriate level is required at time of contract award.
[wpforms id="10486" title="false" description="false"]

Audit. Security. Assurance.
IT Audit | Cybersecurity | IT Assurance | IT Security Consultants – OCD Tech is a technology consulting firm serving the IT security and consulting needs of businesses in Boston (MA), Braintree (MA) and across New England. We primarily serve Fortune 500 companies including auto dealers, financial institutions, higher education, government contractors, and not-for-profit organizations with SOC 2 reporting, CMMC readiness, IT Security Audits, Penetration Testing and Vulnerability Assessments. We also provide dark web monitoring, DFARS compliance, and IT general controls review.
Contact Info
OCD Tech
25 BHOP, Suite 407, Braintree MA, 02184
844-623-8324
https://ocd-tech.com
Follow Us
Videos
Check Out the Latest Videos From OCD Tech!
Services
SOC Reporting Services
– SOC 2 ® Readiness Assessment
– SOC 2 ®
– SOC 3 ®
– SOC for Cybersecurity ®
IT Advisory Services
– IT Vulnerability Assessment
– Penetration Testing
– Privileged Access Management
– Social Engineering
– WISP
– General IT Controls Review
IT Government Compliance Services
– CMMC
– DFARS Compliance
– FTC Safeguards vCISO