POA&M Discipline: The Gap Disqualifying Contractors

Most defense contractors know they are supposed to have a Plan of Action and Milestones. Fewer understand what it does inside the CMMC framework. Almost none are managing it with the rigor the current enforcement environment demands.

A POA&M is not a compliance placeholder. Under the 2025 DFARS final rule, it is a time-bound legal instrument that determines whether your organization qualifies for Conditional CMMC Level 2 status, how long that status remains valid, and whether your SPRS record will satisfy a contracting officer's pre-award verification check.

Managed poorly, a POA&M does not protect your compliance posture. It documents the gap that disqualifies you.

This blog covers how POA&Ms function within the current CMMC Level 2 framework, the 180-day remediation clock, what third-party assessors examine, and the specific management failures that are moving contractors from conditional eligibility to disqualified, quietly, before they reach evaluation.

What a POA&M Is and Why It Matters Now

A Plan of Action and Milestones identifies security control deficiencies, describes the remediation steps required to close each gap, assigns ownership, and establishes target completion dates. In the context of CMMC Level 2, a POA&M is the mechanism that allows a contractor to receive Conditional status when the full 110-point SPRS threshold has not yet been achieved.

The CMMC Level 2 Assessment Guide and DoD guidance establish a specific scoring framework that governs how POA&Ms interact with certification status. A fully compliant environment earns a score of 110. Unmet controls produce deductions, and scores can fall as low as negative 203 for organizations with widespread deficiencies. Organizations scoring between approximately 88 and 109 points may qualify for Conditional CMMC Level 2 status, provided that each deficiency is documented in an approved POA&M and all items are closed within 180 days of the assessment.

Final CMMC Level 2 certification requires a score of 110 with all POA&M items closed. Conditional status is not equivalent to Final status for all contracting purposes. Requiring activities with higher-risk programs may mandate Final certification as an award condition regardless of POA&M documentation.

The 180-day window is a hard deadline. Organizations that do not close all POA&M items within 180 days of their assessment lose Conditional status and may be required to initiate a new assessment cycle. For organizations managing active contracts or pursuing new awards, losing Conditional status mid-cycle is both an operational and a competitive problem.

Three POA&M Failures That Are Disqualifying Contractors

Treating POA&Ms as Documentation Rather Than Execution Plans

The most common POA&M failure is treating the document as a compliance artifact rather than an active management tool. Organizations create a POA&M during their self-assessment, assign general completion dates, and file it. Nobody owns the remediation milestones. Nobody tracks progress. Nobody confirms when items are actually closed.

When a C3PAO assessor or contracting officer reviews the POA&M, they are not looking for a list of acknowledged deficiencies. They are looking for evidence that remediation is actively underway: documented progress updates, completed control implementations verified against assessment objectives, and accurate status flags that distinguish open items from closed ones.

A POA&M created six months ago and never updated since is not a compliant POA&M. It is evidence of a compliance program that exists on paper but not in practice. Under the False Claims Act framework that governs SPRS self-attestation, that distinction has legal consequences, not just compliance ones.

Missing the 180-Day Closure Deadline Without Escalation

The 180-day remediation clock begins at the time of assessment. For self-assessed organizations, it starts when the assessment is recorded in SPRS. For C3PAO-assessed organizations, it starts when the formal assessment findings are documented.

Many contractors are missing this deadline not because the remediation work is impossible, but because the deadline is not being tracked as a hard constraint. POA&M items slip due to competing operational priorities, IT resource constraints, or administrative neglect. By the time the deadline approaches, the organization faces a choice between seeking an extension, which requires documented justification and is not guaranteed, or losing Conditional status entirely.

The cost of a new assessment, ranging from $50,000 to more than $100,000 for a C3PAO engagement plus internal labor, is entirely avoidable. The disqualification risk during the gap period is not. Organizations that have gone through this once rarely repeat the mistake.

Incomplete or Inaccurate POA&M Entries

CMMC Level 2 assessment methodology evaluates 110 security requirements across 320 assessment objectives drawn from NIST SP 800-171A Rev. 3. A compliant POA&M must address each deficiency at the assessment objective level, not just at the control level.

This distinction is frequently misunderstood. A contractor may document a deficiency under a NIST control heading without recognizing that the deficiency maps to multiple specific assessment objectives, each of which may require a distinct remediation action. A POA&M entry that addresses the control heading but not the specific objective is incomplete. The associated SPRS score deduction remains in effect until the specific objective is demonstrably closed.

This level of specificity requires that the people maintaining the POA&M understand NIST SP 800-171A assessment methodology, not just the high-level control framework. For small and mid-sized contractors that assigned POA&M ownership to general IT staff or operations personnel without compliance training, this is a gap that surfaces at exactly the wrong moment: formal assessment.

What Assessors Actually Look For

Third-party C3PAO assessors approach POA&M review with a defined methodology. Understanding what they are looking for is the most direct path to avoiding preventable findings.

Building a POA&M Management System That Holds Up

The organizations that consistently pass CMMC Level 2 assessments without surprises manage their POA&M as a live operational document, not a static compliance artifact. The difference between those two approaches is visible in the first five minutes of an assessor review.

The Legal Dimension

POA&M management is not just a compliance operations issue. It sits at the intersection of SPRS self-attestation requirements and False Claims Act exposure.

Under the CMMC framework, an Affirming Official, typically a senior company executive, certifies that the SPRS assessment accurately reflects the organization's compliance status. A POA&M that misrepresents the status of open items, overstates remediation progress, or attributes closed status to items still deficient is a false attestation. Under 31 U.S.C. § 3729, knowing submission of false or fraudulent claims to the federal government exposes the organization and the certifying official to treble damages and civil penalties.

The Department of Justice Civil Cyber-Fraud Initiative has demonstrated consistent willingness to pursue enforcement actions against contractors who misrepresent cybersecurity compliance. MORSE Corporation paid $4.6 million to resolve false SPRS scoring allegations. Raytheon Technologies paid $8.3 million following whistleblower complaints about cybersecurity misrepresentations. The legal risk is not theoretical.

For the Affirming Official signing the SPRS entry, POA&M accuracy is a personal legal accountability, not a documentation preference.

Frequently Asked Questions

What is the minimum SPRS score required to maintain Conditional CMMC Level 2 status?

Current DoD guidance indicates that organizations scoring approximately 88 to 109 points may qualify for Conditional status, provided all deficiencies are documented in approved POA&Ms and closed within 180 days of the assessment. Organizations below this threshold are generally not eligible for Conditional status. Final certification requires a score of 110 with all POA&M items closed. Specific threshold application may vary by program, and contracting officers retain discretion on how Conditional status is treated for their requirements.

Can I extend the 180-day POA&M remediation window?

Extensions are not automatically available. DoD guidance does not establish a formal extension process for the 180-day closure deadline, and organizations that miss the deadline risk losing Conditional status. If unforeseen circumstances are delaying remediation, document the situation clearly and consult with a qualified compliance advisor about available options. The safest path is to build sufficient buffer into your remediation planning so that extensions are never needed.

How specific do POA&M entries need to be?

Entries should map to specific NIST SP 800-171A assessment objectives, not just high-level control numbers. Each entry should identify the deficient objective, describe the remediation action required, assign a named owner, establish a target completion date, and indicate current status. Entries that address only the control-level heading without identifying which assessment objectives are unmet will be flagged as incomplete during formal assessment review.

Does a subcontractor need its own POA&M?

Yes. Any subcontractor that processes, stores, or transmits CUI on a contractor-owned information system is independently subject to CMMC Level 2 requirements, including the POA&M obligation for any unmet controls. Prime contractors are responsible for ensuring that CUI-handling subcontractors meet these requirements. A subcontractor that cannot demonstrate a current, accurate POA&M for any open deficiencies creates award eligibility risk for the prime.

A POA&M that nobody is actively managing is not a compliance asset. It is a documented record of unresolved deficiencies that an assessor, a contracting officer, or a DOJ investigator can read. The organizations that treat POA&M discipline as an operational priority, not a compliance formality, are the ones that reach Final status on schedule and hold it. Contact us today to learn more about how Atlantic Digital helps defense contractors build POA&M management systems that satisfy assessor scrutiny, protect SPRS status, and support contract eligibility across the Defense Industrial Base.

Building a CMMC-Ready Capture Strategy Before the RFP

Most defense contractors used to treat CMMC compliance the way they treated past performance: something to organize after the award. That window has closed.

Under the CMMC 2.0 final rule, which became enforceable on November 10, 2025, contracting officers are verifying SPRS assessment status before evaluation begins. Compliance posture is a pre-proposal filter now, not a post-award action item.

For BD and capture professionals, this creates a strategic problem that has nothing to do with cybersecurity. Your pipeline is built around pursuit timelines, bid/no-bid decisions, and proposal schedules. None of those systems were designed to account for a compliance gate that can disqualify your organization before a single evaluator reads your technical approach.

This blog translates the CMMC enforcement timeline into a capture calendar: what BD and capture leaders need to confirm at 180 days, 90 days, and 30 days before an anticipated RFP release, and what happens to your pipeline when those checks are skipped.

Why Compliance Is Now a Capture Variable

The CMMC 2.0 final rule did something prior cybersecurity regulations did not: it tied contract eligibility directly to a verifiable, externally accessible record.

Your SPRS entry is not a self-declaration buried in a representations and certifications form. It is a date-stamped record in a DoD database that a contracting officer can pull before your proposal is scored. Under DFARS 252.204-7021, contractors handling Controlled Unclassified Information must hold a qualifying CMMC Level 2 status, recorded in SPRS, no older than 12 months, and affirmed by a senior company official. If the entry is expired, missing, or reflects an unresolved Conditional status, the contracting officer has grounds to exclude your organization before evaluation begins.

For capture managers, the compliance question is no longer a proposal section to fill out. It is a go/no-go variable that belongs on your pursuit tracker alongside ceiling value and incumbency.

The Capture Compliance Calendar

180 Days Before Anticipated RFP Release

This is the earliest point in the pursuit cycle where compliance posture should be formally reviewed. At 180 days, you have enough lead time to address most gaps without compressing your proposal schedule.

Confirm CUI scope. Determine whether the anticipated contract will involve Controlled Unclassified Information. This is not always obvious from a Sources Sought notice or early market research. Review the program description, the requiring activity, and any draft PWS language for CUI indicators. If the program involves technical data, export-controlled information, or operational specifications, treat CUI as in scope until you can confirm otherwise.

Validate current SPRS status. Pull your organization's SPRS record and confirm the assessment date, the affirming official, and whether the entry reflects Final or Conditional status. A Conditional status requires all open POA&M items to be closed within 180 days of the assessment. If your entry is more than 10 months old, start the re-assessment process now. Waiting until the RFP drops leaves no recovery window.

Identify the applicable assessment pathway. Not all Level 2 contracts require the same assessment type. Programs involving export-controlled CUI, and those subject to DLA clause RD005, generally require C3PAO third-party certification. Lower-risk programs may permit self-assessment. Confirming which pathway applies at 180 days determines whether you are managing an internal readiness effort or coordinating an external assessment engagement. That difference in lead time is significant, and confusing the two is expensive.

90 Days Before Anticipated RFP Release

At 90 days, your capture strategy is taking shape. Teaming conversations are active. Win themes are developing. Compliance gaps at this stage are proposal risks, not correctable deficiencies.

Resolve open POA&Ms. Any POA&M items still open 90 days before an anticipated RFP represent a direct threat to proposal eligibility. If your SPRS record reflects Conditional status, the 180-day remediation clock is already running. Missing that window means you do not achieve Final status, and Final status is the threshold for award on programs requiring full CMMC Level 2 compliance.

Brief teaming partners on compliance requirements. If your capture strategy involves subcontractors who will access CUI, their compliance posture is your problem under DFARS flowdown requirements. Primes are accountable for the cybersecurity posture of their supply chain. A sub with an expired SPRS entry or an unresolved Conditional status can create award eligibility issues for the entire team. Ask the question at 90 days. The conversation is easier then than it is during proposal review.

Prepare your compliance representations. The representations and certifications section requires accurate statements about cybersecurity compliance. Under the False Claims Act, knowing misrepresentations tied to material contract requirements create legal exposure for the certifying official and the company. At 90 days, your compliance team and BD lead should align on what will be represented. That representation must be supportable by your current SPRS record, not by your intentions.

30 Days Before Anticipated RFP Release

At 30 days, your compliance posture is what it is. This is not the time to identify gaps. It is the time to confirm that your documentation, your SPRS record, and your proposal representations are fully aligned.

Confirm annual affirmation currency. SPRS entries require annual affirmation by a qualifying senior official. If your last affirmation is approaching the 12-month mark, complete the re-affirmation before the RFP drops. An expired affirmation at proposal submission is an avoidable disqualifier.

Standardize questionnaire response language. Many prime contractors issue cybersecurity questionnaires as part of their teaming qualification process. These questionnaires are not standardized. They may reference legacy DFARS clause numbers, current CMMC requirements, or a mix of both. Maintain a current, reviewed response library that accurately describes your compliance posture. An inconsistent answer in a questionnaire that conflicts with your representations and certifications is a red flag that can follow you into post-award scrutiny.

Document your assessment evidence. If a contracting officer or prime requests verification of your SPRS status, you should be able to produce underlying assessment documentation within 24 hours. Your System Security Plan, assessment scoring workbook, POA&M status, and affirmation record should be organized and accessible. This is not a pre-proposal requirement. It is a baseline readiness condition for any organization pursuing DoD work.

What BD Leaders Need to Know About CMMC Enforcement Timing

The CMMC rollout is phased, and enforcement is accelerating. Phase 1, which began November 10, 2025, permits contracting officers to include CMMC requirements in solicitations at their discretion. Enforcement is not universal today. It is expanding.

Requiring activities with higher-risk programs are moving faster than the baseline timeline suggests. DLA contracts involving export-controlled CUI are already subject to RD005 requirements, which tie C3PAO certification to contract eligibility for that CUI category. Organizations pursuing DLA work, naval systems programs, or contracts involving technical data packages should treat C3PAO certification timelines as a near-term capture constraint, not a future planning item.

The practical implication for capture strategy is that compliance investment should be sequenced against your pursuit calendar. Organizations that have not achieved Final CMMC Level 2 status should prioritize that effort based on the programs in their active pipeline, not based on an arbitrary compliance deadline. Every contract you pursue before achieving Final status carries proposal eligibility risk.

The Pipeline Risk of Deferring Compliance

Contractors who defer CMMC readiness in favor of proposal activity are making a specific bet: that the programs they pursue will not enforce CMMC requirements before they are ready. That bet is getting harder to win.

As CMMC clauses appear in more solicitations and contracting officers build verification into their pre-award processes, the compliance gate is moving earlier in the acquisition cycle. An organization that is not CMMC-ready is not competing for every DoD contract. It is competing for the subset of contracts where enforcement has not yet reached. That subset shrinks every quarter.

Organizations that treat CMMC readiness as an investment in pipeline access, rather than a regulatory obligation, are making a different strategic calculation. They are buying into a larger addressable market and reducing qualification uncertainty in every pursuit they run. That is a business development argument. BD leaders should be making it at the executive level now.

Frequently Asked Questions

Does CMMC Level 2 apply to every DoD contract?

No. CMMC Level 2 applies to contracts involving processing, storing, or transmitting Controlled Unclassified Information on contractor-owned systems. Contracts involving only Federal Contract Information fall under CMMC Level 1, which requires annual self-assessment. The determination of which level applies is based on the contract's CUI scope, defined by the requiring activity and reflected in solicitation language.

Can a subcontractor's compliance gap affect a prime's eligibility for award?

Yes. Prime contractors are responsible for ensuring that subcontractors who will access CUI meet applicable CMMC requirements. DFARS flowdown provisions require primes to include cybersecurity compliance requirements in subcontracts where CUI will be shared. A subcontractor with an expired SPRS entry or an unresolved compliance gap represents an award risk for the entire team.

How long does it take to achieve Final CMMC Level 2 status?

The timeline depends on your current SPRS score and the number of open POA&M items. Organizations close to the 110-point threshold with well-documented controls may close gaps and achieve Final status within 90 to 120 days. Organizations with significant control gaps or incomplete SSP documentation should plan for a longer runway, six months to a year for a structured readiness and remediation effort before engaging a C3PAO.

What should a BD director do if they are not sure whether a target program will include CMMC requirements?

Treat CUI as in scope until you have confirmed otherwise through program research, industry days, or direct engagement with the requiring activity. If the program involves technical data, export-controlled information, or operationally sensitive specifications, assume CMMC Level 2 applies and validate your posture accordingly. The cost of preparing unnecessarily is far lower than the cost of being excluded from evaluation after investing in a pursuit.

Compliance posture is a capture variable now. BD teams that build it into their pursuit process from the start will qualify for more programs, compete with stronger representations, and close proposals without last-minute eligibility questions. Contact us today to learn more about how Atlantic Digital helps capture and BD teams align compliance posture with pursuit strategy across the Defense Industrial Base.

Subcontractor Flowdowns: Who Owns the Compliance Gap?

A prime contractor can hold a current CMMC Level 2 certification, maintain an accurate SPRS record, and affirm compliance annually, and still find themselves exposed because of a subcontractor two tiers down in their supply chain. DFARS 252.204-7021 requires that CMMC requirements flow down to all subcontractors that will process, store, or transmit Controlled Unclassified Information. The clause is clear on the obligation. What it leaves underspecified is who bears the consequence when a sub falls short.

That ambiguity is where most prime contractors are currently operating. They know they have flowdown obligations. Many have added CMMC language to their subcontract templates. Fewer have built a verification process that actually confirms sub compliance before award, during performance, and at contract renewal. The gap between having flowdown language in a subcontract and having defensible evidence that subs have met their requirements is where liability accumulates.

This blog is for prime contractors, capture managers, and subcontract administrators who are managing the compliance dimension of their supply chain and need to understand what the flowdown requirement actually demands, where legal exposure sits when a sub is non-compliant, and what a defensible prime-side verification process looks like. The regulatory framework is clear enough. The operational execution is where most organizations have work to do.

What DFARS 252.204-7021 Actually Requires of Primes

DFARS 252.204-7021 is the operative CMMC clause. It requires contractors to have a qualifying CMMC level at the time of contract award, maintain that status through the performance period, and flow the requirement to subcontractors at the appropriate level. The flowdown applies to any subcontractor that will process, store, or transmit CUI as part of their performance on the contract.

The prime's obligation is not simply to include CMMC language in the subcontract. The obligation is to ensure that covered subcontractors actually meet the applicable CMMC level. That is a material distinction. A prime who includes a CMMC clause and takes no further steps to verify sub compliance has satisfied the paperwork requirement but has not satisfied the substantive one.

The contracting officer's relationship is with the prime. When the government identifies a compliance gap in the supply chain, the prime is the accountable party. A sub's failure to maintain CMMC compliance does not transfer liability away from the prime. It creates a compliance deficiency in the prime's performance that the contracting officer will address through the prime.

Determining Which Subs Are in Scope

Not every subcontractor on a DoD contract is subject to CMMC flowdown requirements. The requirement applies to subcontractors who will process, store, or transmit CUI as part of their contract performance. A sub providing commercial off-the-shelf hardware with no CUI access is not in scope. A sub providing managed IT services that touch the prime's CUI environment almost certainly is.

Scope determination is a judgment the prime makes at the time of subcontract award, and it must be documented. A prime who cannot demonstrate that they made a deliberate, documented determination about which subs are in scope, and what CMMC level applies to each, has a defensibility problem if the government later questions the supply chain compliance posture.

The complexity increases in layered supply chains. A sub's sub may also handle CUI, and the flowdown obligation extends to them as well. Primes who are managing multi-tier subcontract relationships need a supply chain mapping process that identifies CUI touchpoints at each tier, not just at the first tier.

Where the Legal Exposure Sits

The False Claims Act is the sharpest instrument in this space. Under 31 U.S.C. §3729, contractors who knowingly submit false or fraudulent claims to the government, or who knowingly fail to disclose facts that would affect payment eligibility, face treble damages and civil penalties. The Department of Justice's Civil Cyber-Fraud Initiative has made clear that cybersecurity misrepresentations in DoD contracting, including compliance posture misrepresentations by primes on behalf of their supply chain, fall within its enforcement scope.

A prime who certifies compliance with DFARS 252.204-7021 while knowing that a covered sub does not meet the applicable CMMC level is not in a defensible position. The certification is a representation to the government that the contract is being performed in compliance with its terms. A non-compliant sub making that representation false is a known condition that the prime has an obligation to address.

The exposure is not limited to formal fraud enforcement. Primes who discover mid-performance that a sub is non-compliant face a compliance disclosure question. DFARS 252.204-7012 requires contractors to report cyber incidents. A sub's compliance gap that results in a CUI breach triggers reporting obligations that flow up to the prime and to DoD through the DCISE portal at DC3. A prime who was not in a position to detect the sub's gap because they had no verification process in place is in a difficult position when the disclosure conversation happens.

What a Defensible Prime-Side Verification Process Looks Like

Defensibility in this context means being able to demonstrate to a contracting officer, an inspector general, or a DOJ investigator that the prime took reasonable steps to ensure sub compliance, documented those steps, and acted on what it found. Reasonable steps are not the same as perfect oversight. They are a systematic, documented process that a reasonable organization would use to manage supply chain compliance risk.

Pre-Award Verification

Before awarding a subcontract to a covered sub, the prime should verify the sub's current SPRS record. SPRS is a government system accessible to contractors, and a sub's CMMC status is verifiable there. A pre-award SPRS check, documented in the subcontract file, is the minimum standard for defensible prime-side verification.

Pre-award verification should also include a review of the sub's System Security Plan scope to confirm that the CUI environment the sub will be operating in as part of this contract is within the assessed boundary. A sub whose CMMC assessment covered a different system environment than the one they will be using on your contract has a scope gap that their certification does not resolve.

Contractual Requirements

The subcontract should specify not just the applicable CMMC level but the maintenance requirements: annual affirmation currency, SPRS record maintenance, and the obligation to notify the prime of any material change to compliance posture during the performance period. A sub whose certification lapses during performance has an obligation under a well-drafted subcontract to notify the prime. That notification obligation gives the prime the information it needs to manage the situation before it becomes a government-level problem.

Periodic Verification During Performance

Pre-award verification is not sufficient for contracts with multi-year performance periods. SPRS records can lapse. Certifications expire. Organizational changes at the sub level can create compliance gaps. Primes should build SPRS re-verification into their subcontract management calendar at intervals appropriate to the contract risk level. Annual re-verification is a reasonable baseline for covered subs on active CUI-bearing contracts.

The verification process does not need to be an audit. A documented SPRS check, a written inquiry to the sub confirming affirmation currency, and a file note recording the outcome is a proportionate and defensible approach for most subcontract relationships. The key is that it is systematic and documented, not reactive and ad hoc.

The Teaming Dimension

Flowdown compliance is increasingly a teaming consideration, not just a performance consideration. Prime contractors evaluating teaming partners for new pursuits are adding SPRS status checks to their due diligence process. A potential teammate whose CMMC credentials are conditional, lapsed, or unverifiable is a risk the prime must weigh against the capabilities that teammate brings.

For smaller contractors who operate primarily as subs or teammates, CMMC compliance is now a qualification threshold that determines whether they appear on primes' approved teaming lists. A sub who cannot produce a current SPRS record when a prime asks for it before submitting a proposal is a sub who will be replaced by one who can. The teaming market is sorting itself on compliance posture, and that process is accelerating as the CMMC phase-in continues.

For primes building pursuit teams, the compliance verification conversation should happen at the teaming agreement stage, not after proposal submission. A late discovery that a key teammate's CMMC status is inadequate for the contract's requirements creates a proposal problem that is far more disruptive than a pre-teaming compliance check would have been. Atlantic Digital's CMMC strategy experts work with both primes and subs to align supply chain compliance posture before it becomes a pursuit liability.

Frequently Asked Questions

Does DFARS 252.204-7021 flowdown apply to all subcontractors on a DoD contract?

No. The flowdown requirement applies to subcontractors who will process, store, or transmit CUI as part of their performance on the contract. Subs with no CUI access or handling are not in scope. Primes are responsible for making and documenting the scope determination for each subcontractor relationship, and that determination should be made at the time of subcontract award.

What level of CMMC is required for a covered subcontractor?

The applicable CMMC level for a sub is determined by the nature of the information they handle and the requirements of the prime contract. A sub handling CUI that is not export-controlled would generally fall under Level 2 requirements. A sub handling export-controlled CUI may face more stringent requirements. The prime is responsible for ensuring that the correct level flows down and that the sub actually meets it.

What should a prime do if a sub's CMMC certification lapses during performance?

The prime should address it immediately. A well-drafted subcontract includes a notification obligation and remediation timeline for compliance lapses. The prime should document the discovery, notify the sub of the obligation to restore compliance, establish a remediation timeline, and assess whether the lapse creates a disclosure obligation under DFARS 252.204-7012. Depending on the nature of the lapse and the contract's requirements, the prime may also need to consult with the contracting officer.

Is a prime liable under the False Claims Act for a subcontractor's CMMC non-compliance?

The False Claims Act analysis turns on what the prime knew and what representations they made to the government. A prime who certified compliance with DFARS 252.204-7021 while knowing a covered sub was non-compliant faces real FCA exposure. A prime who had a reasonable verification process in place, acted on what they found, and documented their steps is in a far stronger defensive position. The obligation is not perfect sub compliance at all times. It is reasonable steps to verify and address it.

Contact us today to learn more about how Atlantic Digital can help you build a supply chain compliance verification process that protects your prime position and your pipeline.

What the FAR Overhaul Means for Your DoD Contracts

The Federal Acquisition Regulation is being restructured at a scale not seen in decades. The Revolutionary FAR Overhaul is renumbering, consolidating, and in some cases eliminating clauses that have anchored DoD contracts since the 1990s. For defense contractors, this is not an administrative housekeeping exercise.

It is a compliance event with direct consequences for active contracts, pending solicitations, and CMMC readiness posture.

Most organizations are aware something is changing. The problem is they are managing it reactively. Unfamiliar clause numbers appear in new solicitations. Primes and contracting officers give contradictory guidance. Compliance decisions get made without a clear crosswalk between legacy requirements and what replaced them. That gap is generating real risk right now, before the overhaul is even fully implemented.

This blog covers what changed, what it means for contracts already in hand, and what BD and compliance leaders need to address before the next renewal cycle.

What the Revolutionary FAR Overhaul Actually Is

The RFO is a multi-year restructuring of the FAR and DFARS clause numbering system. Parts of FAR Part 52 are being reorganized under new part numbers, and several DFARS clauses governing cybersecurity and information safeguarding have been renumbered or replaced through class deviations issued by the Office of the Under Secretary of Defense for Acquisition and Sustainment.

The driving rationale is to streamline acquisition, reduce redundancy, and align the regulatory structure with how modern DoD contracting actually operates. The practical effect for contractors is a compliance environment where legacy clause numbers and new clause numbers both appear in active solicitations simultaneously, and do not always map to each other cleanly.

This is not a one-time event with a single effective date. The overhaul is rolling out in phases. Contractors will encounter a mixed regulatory environment for the foreseeable future, which means the organizations that build a tracking system now will spend far less time cleaning up confusion later.

The Clauses That Matter Most Right Now

Three clause transitions are generating the most immediate confusion across the Defense Industrial Base.

FAR 52.204-21 to FAR 52.240-93

FAR 52.204-21 is the basic safeguarding clause requiring contractors to apply 15 foundational security controls to systems that process, store, or transmit Federal Contract Information. Under the RFO, this clause is renumbered to FAR 52.240-93 via class deviation.

The underlying technical requirements are unchanged. The same 15 controls apply. What changes is the clause number appearing in solicitations and contract modifications. Contractors who maintain compliance checklists, SSP documentation, or internal control matrices tied to FAR 52.204-21 need to update those references. They also need to verify that questionnaire responses citing the old number are being evaluated correctly by contracting officers who may or may not be current on the renumbering. Not every contracting officer is.

DFARS 252.204-7019: Functionally Superseded

DFARS 252.204-7019 previously required contractors to complete a NIST SP 800-171 self-assessment and upload a score to SPRS as a condition of contract award. That standalone requirement has been absorbed into the CMMC framework.

For new solicitations where CMMC clauses apply, 252.204-7019 is no longer prescribed as a separate requirement. Self-assessments now support CMMC Level 1 or Level 2 status under DFARS 252.204-7021. But 252.204-7019 may still appear on legacy contracts that predate the CMMC final rule. Organizations managing a mixed contract portfolio need to know which regime governs each award and respond to compliance inquiries accordingly.

DFARS 252.204-7020: Renumbered via Class Deviation

DFARS 252.204-7020 previously governed medium and high NIST SP 800-171 assessments and associated SPRS reporting. It has been renumbered to DFARS 252.240-7997 through class deviation. Its remaining assessment concepts are now aligned with CMMC Level 2 assessment types.

Contractor-performed basic assessments previously addressed under 7020 are now handled under DFARS 252.204-7021, which remains unchanged. The concept of a standalone basic assessment no longer exists under the new structure.

DFARS 252.204-7021: Unchanged

This is the clause that matters most for CUI-handling contractors. DFARS 252.204-7021 establishes CMMC Level 2 certification requirements and links assessment outcomes to SPRS records. It has not been renumbered or modified through the RFO process. When this clause appears in a solicitation, the compliance requirements are current and enforceable as written.

What This Means for Contracts Already in Hand

The RFO creates three specific risk vectors for existing contracts.

Questionnaire misalignment. Prime contractors are sending cybersecurity questionnaires using a mix of legacy and updated clause numbers. Subcontractors who answer based on the wrong reference, or who do not recognize that FAR 52.240-93 and FAR 52.204-21 represent the same underlying requirements, risk submitting inconsistent or incomplete responses. In a compliance-first award environment, that inconsistency can disqualify a bid.

SPRS record validity. For contractors whose SPRS entries were made under the legacy 7019 framework, the question is whether those records still satisfy current assessment requirements. Self-assessments that predate the CMMC final rule and have not been affirmed under DFARS 252.204-7021 may not pass a contracting officer verification check for new awards or renewals.

Contract modification gaps. As contracting officers issue modifications to update clause references in existing awards, some modifications will reference new numbers, some will reference old ones. Organizations without a clause-by-clause tracking system for their active portfolio will struggle to demonstrate compliance when a discrepancy surfaces during an audit or pre-award review.

The SPRS Connection

The RFO does not change SPRS requirements. But the clause restructuring affects how SPRS records are evaluated.

Under the current framework, SPRS scores and CMMC Level 2 status are distinct data points. A legacy NIST self-assessment score in SPRS is not automatically equivalent to a current CMMC Level 2 conditional or final status. Contracting officers verifying pre-award compliance are looking for a current SPRS entry that reflects assessment status under DFARS 252.204-7021, not a legacy self-assessment submitted under 7019.

Organizations that have not updated their SPRS records since the CMMC final rule took effect on November 10, 2025, may have technically accurate NIST scores that no longer satisfy award eligibility requirements. Annual affirmation is mandatory. SPRS entries must be current, meaning no older than one year, and must reflect the contractor's compliance posture under the applicable CMMC level.

What Defense Contractors Should Do Now

Frequently Asked Questions

If my existing contract still references DFARS 252.204-7019, do I still have to comply with it?

Yes. Legacy contracts that include 252.204-7019 remain binding until they are modified. The fact that the clause is no longer prescribed for new solicitations does not remove it from existing awards. Comply with the clause as written until a modification updates or removes it.

Does the FAR overhaul change what security controls I need to implement?

For most contractors, the underlying technical requirements are unchanged. FAR 52.240-93 carries the same 15 basic safeguarding requirements as FAR 52.204-21. The CMMC Level 2 framework still maps to the 110 controls in NIST SP 800-171. What changes is clause numbering, enforcement mechanism, and documentation structure, not the controls themselves.

How do I know whether my SPRS entry is still valid under the current framework?

A valid SPRS entry under current requirements must reflect CMMC Level 2 assessment status under DFARS 252.204-7021, must be no older than 12 months, and must have been affirmed by a qualifying senior official. Legacy NIST self-assessment scores that predate the November 2025 final rule should be reviewed by a qualified compliance advisor to determine whether a new assessment is required.

What is the risk if I submit a questionnaire response with the wrong clause number?

At minimum, it creates confusion and may trigger follow-up from the prime or contracting officer. In a competitive proposal environment, inconsistent or outdated compliance representations can disqualify a bid. In more serious cases, a knowingly inaccurate representation tied to a material contract requirement creates potential False Claims Act exposure for the certifying official.

The FAR overhaul is not a future problem. For contractors with active DoD awards, it is a current one. The organizations that build a systematic response now will compete in the next procurement cycle from a position of documented, defensible compliance. Contact us today to learn more about how Atlantic Digital helps defense contractors manage the FAR overhaul, validate SPRS entries, and maintain compliant posture across their active contract portfolio.

The POA&M Window: How 180 Days Can Save a Contract

Most defense contractors know they need a Plan of Action and Milestones. Far fewer understand that the POA&M is not just a remediation document. Under CMMC Level 2, it is an active eligibility mechanism with a hard timeline attached to it. The 180-day window is not administrative guidance. It is the difference between conditional certification that keeps you in the running and a lapsed posture that removes you from it.

The logic is straightforward in regulation and genuinely complicated in practice. A contractor who cannot achieve a perfect 110-point NIST SP 800-171 score at the time of assessment may still qualify for conditional CMMC Level 2 status, provided the deficiencies are documented in an approved POA&M and remediated within 180 days. That window opens at the point of assessment. What happens inside it determines whether the conditional status converts to final certification or expires without resolution.

This blog is for compliance leads, BD directors, and program managers who understand the POA&M requirement at a surface level and need to understand it operationally. The 180-day window is a compliance tool, a pipeline management tool, and a legal risk management tool simultaneously. Treating it as only one of those is how organizations lose contracts they were otherwise positioned to win.

How Conditional Status Works Under CMMC Level 2

The CMMC Level 2 assessment process scores contractors against 110 security requirements drawn from NIST SP 800-171. A fully implemented environment earns a score of 110. Deficiencies reduce that score, with penalties ranging by requirement.

Contractors scoring between approximately 88 and 109 may qualify for conditional CMMC Level 2 status if all deficiencies are documented in an approved POA&M submitted at the time of assessment. The conditional status is recorded in SPRS and is visible to contracting officers. It signals that the organization has been assessed, has identified gaps, and is actively remediating them.

Conditional status is not the same as final certification. A contracting officer evaluating a solicitation sees the conditional designation and must make a program-level determination about whether that status satisfies the contract's CMMC requirement. Some programs accept conditional status during the current phase-in period. Others require final certification. The acceptability of conditional status is a contract-by-contract determination, and it is not guaranteed.

Final CMMC Level 2 certification requires a score of 110 with all POA&M items closed and verified. The 180-day window is the timeframe within which that closure must occur. A contractor who enters conditional status and allows the window to pass without closing all POA&M items does not retain conditional status indefinitely. The certification posture degrades, and the SPRS record no longer reflects a current, valid compliance position.

What the 180-Day Window Requires Operationally

One hundred and eighty days sounds like a long time. In practice, it compresses quickly once you account for what remediation actually involves.

POA&M items at the time of a Level 2 assessment are not uniform. Some represent documentation gaps that can be closed in days. Others represent technical control deficiencies that require infrastructure changes, vendor procurement, configuration work, and validation. A POA&M that includes a multi-factor authentication gap for a legacy system, a missing system boundary definition, and three incomplete policy documents is not a 30-day project. It is a coordinated remediation program.

The 180-day clock runs regardless of internal resource constraints, competing priorities, or contract demands. A contractor who enters the window in the middle of a major contract performance period faces a real tension between the work that generates revenue today and the remediation work that preserves eligibility tomorrow. Organizations that have not anticipated that tension before they enter the window are the ones who miss the deadline.

The POA&M itself must be structured to support verification, not just documentation. Each item needs a clear description of the deficiency, a defined remediation action, a responsible owner, a milestone schedule, and an anticipated completion date within the 180-day window. A POA&M that lists deficiencies without milestones is not an approved POA&M in the sense the CMMC framework requires. It is a list.

The Reassessment at the Close of the Window

When POA&M items are closed, the closure must be verified. For organizations pursuing third-party certification, that typically means re-engaging the C3PAO to validate that remediated controls are fully implemented. That re-engagement requires scheduling, documentation preparation, and evidence production. None of those activities happen instantly.

A contractor who closes the last POA&M item on day 175 and then begins the scheduling process for verification is cutting it closer than is strategically sound. The practical target for POA&M closure is 120 to 130 days into the window, which leaves sufficient time for evidence organization and assessor scheduling before the deadline.

The Pipeline Consequence of a Missed Window

The consequence of missing the 180-day window is not a fine or a penalty. It is a compliance posture problem that affects every active and pending contract simultaneously.

When conditional status lapses without conversion to final certification, the Supplier Performance Risk System record no longer reflects a current valid status. Contracting officers verifying compliance before award will find an incomplete picture. For contracts that were awarded under conditional status and require final certification within the performance period, a missed window can trigger compliance verification scrutiny from the contracting officer and, in some cases, affect payment or contract continuity.

For BD teams managing an active pipeline, a lapsed POA&M window creates an eligibility gap at exactly the wrong time. The contracts that were in pursuit when the window opened may now be in evaluation when the window closes. A compliance posture problem that surfaces during source selection is far more damaging than one addressed during the assessment period.

Prime contractors managing subcontractor compliance under DFARS 252.204-7021 flowdown requirements are also watching this. A sub whose conditional status has lapsed is a supply chain risk that primes are increasingly unwilling to accept. Teaming conversations now routinely include SPRS status verification, and a contractor who cannot show a current, clean record will find those conversations shorter.

Managing the Window as a Business Discipline

The contractors who navigate the 180-day window successfully treat POA&M management as a program, not a task. The distinction matters.

A task is something that gets completed and then set aside. A program has governance, ownership, milestones, and escalation paths. For a POA&M window that affects contract eligibility, the program model is the only one that reliably produces closure before the deadline.

Effective POA&M programs assign each item to a named owner who is accountable for milestone completion, not just aware of the requirement. They build milestone reviews into the compliance calendar at 30, 60, 90, and 120 days. They identify at intake which items are likely to require external vendor engagement and initiate those procurement processes immediately, because vendor timelines are the most common source of slippage.

Executive visibility is not optional. The Affirming Official who will sign the final certification needs to understand where the POA&M program stands at each milestone review. A compliance lead who is managing a difficult remediation item and has not escalated it to executive attention by day 90 has waited too long. The 180-day window is short enough that late escalation often cannot produce a resolution in time.

For contractors using a GRC platform, POA&M tracking should be integrated into the same system that manages control evidence and SPRS records. Manual tracking in spreadsheets is a reliable source of milestone slippage, particularly when personnel change during the remediation period. Atlantic Digital's CMMC strategy experts work with contractors at every stage of the POA&M lifecycle, from structured gap analysis through final certification readiness.

Frequently Asked Questions

What SPRS score is required to qualify for conditional CMMC Level 2 status?

Contractors scoring between approximately 88 and 109 may qualify for conditional CMMC Level 2 status if all deficiencies below the 110-point threshold are documented in an approved POA&M at the time of assessment. A score below 88 does not qualify for conditional status under current CMMC guidance. Final certification requires a score of 110 with all POA&M items closed and verified.

Can a solicitation be won under conditional CMMC Level 2 status?

It depends on the contract. During the current CMMC phase-in period, some programs accept conditional status as satisfying the Level 2 requirement. Others require final certification before award or within a defined period after award. Contractors should verify the specific CMMC requirement in each solicitation and not assume conditional status will be universally accepted.

What happens if a POA&M item cannot be closed within 180 days?

A POA&M item that cannot be closed within the 180-day window presents a certification risk. Depending on the nature of the item and the program's requirements, the contractor may need to engage the contracting officer to discuss the situation. Prevention is significantly more effective than remediation after the fact. Contractors who identify at intake that an item may be at risk of missing the deadline should escalate immediately and explore whether additional resources or a different technical approach can accelerate closure.

How does POA&M management connect to the False Claims Act?

An approved POA&M is part of the compliance record that supports the Affirming Official's attestation in SPRS. A POA&M that documents deficiencies without genuine remediation progress, or that is used to maintain a conditional status that the organization has no realistic path to converting, creates a misrepresentation risk. The Department of Justice's Civil Cyber-Fraud Initiative treats inaccurate SPRS representations as potential False Claims Act violations, and the POA&M is part of that record.

Contact us today to learn more about how Atlantic Digital can help you build a POA&M program that converts conditional status to final certification before the window closes.

CMMC Flowdown Requirements for Defense Subcontractors

Defense subcontractors are being removed from teams quietly and without warning. Not because they failed a proposal review. Not because their pricing was out of range. Because a prime contractor reviewed their compliance posture and decided the risk was not worth carrying.

CMMC flowdown is the mechanism driving this shift. Prime contractors who hold DoD contracts subject to CMMC requirements are legally obligated to flow those requirements down to subcontractors who will handle Controlled Unclassified Information in the performance of the work. The obligation is not discretionary. What is discretionary is how aggressively primes choose to enforce it and how early in the teaming process they ask the question.

For subcontractors who have not been paying attention, that question is arriving earlier than expected. The firms that cannot answer it are finding themselves replaced before the proposal is submitted.


How Flowdown Works Under DFARS

The legal foundation for CMMC flowdown is DFARS 252.204-7021, the clause that implements CMMC Level 2 requirements in DoD contracts. That clause does not only apply to the prime contractor. It requires primes to include the substance of the clause in all subcontracts and other contractual instruments that involve performance of work that requires handling CUI.

This is mandatory flowdown. The prime does not have the option to decide whether to pass CMMC requirements to a sub. If the sub will handle CUI as part of the subcontract, the prime must include the CMMC clause. The sub is then legally bound by the same CMMC requirements as the prime for the portion of work it performs.

DFARS 252.204-7012, the clause covering adequate security for covered defense information and cyber incident reporting, also flows down. Subcontractors who receive covered defense information are required to provide adequate security on their information systems and report cyber incidents to the DoD within 72 hours. Both clauses together create a compliance framework that extends through the entire supply chain, not just to the prime.

What varies is the CUI scope. Not every subcontract involves CUI. A subcontractor providing a purely commercial product or service that does not require access to technical data, export-controlled information, or other CUI categories may not fall within scope. But the determination of whether CUI is involved is made based on what the sub will actually do in performance, not based on their historical relationship with the prime or their industry category.


What Primes Are Adding Beyond the Legal Minimum

The DFARS flowdown requirements define the legal floor. Many prime contractors are operating well above it.

As CMMC enforcement has accelerated, large prime contractors have been revising their subcontractor qualification processes. Cybersecurity questionnaires that were once a formality have become substantive evaluations. Some primes are requiring subcontractors to demonstrate active SPRS records, minimum SPRS scores, or documented CMMC Level 2 status before they will consider them for teaming. Others are incorporating cybersecurity representations into teaming agreements and NDAs, creating contractual obligations that attach before a proposal is even written.

The practical effect is that CMMC compliance has become a qualification criterion at the teaming stage, not the contract award stage. Subcontractors who have not done this work cannot answer a prime's cybersecurity questionnaire accurately. The firms that are winning teaming spots are the ones that can answer quickly, accurately, and with documentation to back it up.

Primes are doing this for a straightforward reason: their own contract eligibility depends on the security posture of their supply chain. If a subcontractor handling CUI is compromised, the prime bears reporting obligations, reputational consequences, and potential contract liability. Vetting the sub's compliance posture before award is basic risk management.


The Specific Obligations Subcontractors Need to Understand

Subcontractors who receive a subcontract containing DFARS 252.204-7021 are bound by the same CMMC Level 2 requirements as the prime for the systems and work covered by that subcontract. The DoD's CMMC program overview outlines the full framework. In practice, that means:

The scope of these obligations is limited to the CUI that the subcontractor handles in connection with the specific subcontract. A subcontractor's entire information environment does not necessarily fall within scope. But the scoping determination requires deliberate analysis. It is not automatically limited to a single system or project folder simply because the work is defined as limited in scope.


How Subcontractors Are Getting Cut Out

The supply chain displacement happening right now is not usually the result of a formal compliance audit. It is the result of a question that gets asked during teaming discussions, before the proposal goes in, and the answer is not good enough.

The cybersecurity questionnaire gap

Prime contractors are distributing cybersecurity questionnaires to prospective teaming partners with increasing frequency and specificity. These questionnaires ask about SPRS scores, CMMC assessment status, System Security Plan completion, POA&M management, and incident response capabilities. Subcontractors who have not done this work cannot answer these questions accurately. Subcontractors who guess or inflate their answers create legal exposure for themselves and a reliability problem for the prime.

The missing SPRS record

An SPRS record is required for contractors subject to DFARS 252.240-7997 when their subcontract involves CUI. If a subcontractor's SPRS record is blank, expired, or reflects a score well below the threshold for conditional Level 2 status, that is a visible and verifiable compliance gap. Primes who check SPRS before finalizing their team will see it.

The contract flowdown trap

Some subcontractors accept subcontract terms that include DFARS compliance clauses without fully understanding what they are agreeing to. The clause is in the boilerplate. They sign. They perform the work. Then, when the prime asks for a CMMC status update before option year renewal, or when a program office requests compliance verification, they realize their systems do not meet the requirements they contractually committed to. At that point, the path forward involves either rapid remediation, a significant contract risk conversation with the prime, or both.

The supply chain tier problem

Compliance gaps do not only affect direct subcontractors to large primes. They affect companies several tiers down the supply chain. A precision machining firm, a specialized testing laboratory, or a software maintenance contractor may receive a subcontract from a mid-tier integrator who holds a prime contract with DoD. If CUI flows through to that lower-tier sub, the compliance obligation flows with it. The fact that the sub does not have a direct relationship with the DoD agency does not change the regulatory requirement.


What Subcontractors Need to Do Now

The supply chain compliance environment is not getting easier. The firms that establish a defensible CMMC posture now will hold their teaming relationships. The ones that treat this as someone else's problem will continue to lose spots on proposals they should be winning. Atlantic Digital's industry partner network includes subcontractors at every tier of the defense supply chain working through exactly this process.

Audit your existing subcontracts for DFARS clauses

Review every active subcontract for the presence of DFARS 252.204-7012 and 252.204-7021. If those clauses are present, the work you perform under those subcontracts may already carry CMMC obligations. Understanding the existing scope of your compliance requirements is the first step before addressing gaps.

Establish or update your SPRS record

If you do not have a current SPRS record, you cannot demonstrate compliance to a prime contractor or a contracting officer. Completing a self-assessment and uploading your results to SPRS is the minimum viable step. The assessment must be accurate, the score must reflect your actual implementation status, and the affirmation must be signed by a qualified senior executive.

Define your CUI boundary

Scope is everything in CMMC compliance. Work with a CMMC strategy advisor to define precisely which of your information systems are within scope for CUI based on your actual subcontract work. A narrow, well-defined boundary that is rigorously defended is better than a broad boundary that is poorly managed. Get the scoping right first before investing in controls that may not be required.

Prepare for the questionnaire

Develop a standard set of answers to the cybersecurity questionnaire questions your primes are likely to ask. These answers need to be accurate, supported by documentation, and deliverable quickly. A prime that asks on Tuesday and does not hear back by Friday has their answer. Preparation is a competitive advantage.


Frequently Asked Questions

As a subcontractor, am I subject to CMMC if I do not have a direct contract with DoD?

Yes, if your subcontract requires you to handle CUI and your prime contractor flows down DFARS 252.204-7021, you are subject to the same CMMC Level 2 requirements as the prime for that portion of work. The requirement applies based on the nature of the information you handle, not on whether you have a direct contractual relationship with a DoD agency.

How do I know if my subcontract work actually involves CUI?

Review the subcontract statement of work and any contract data requirements lists associated with the effort. Look for references to technical data, export-controlled information, proprietary government information, or any information marked with a CUI designation. If you are uncertain, ask the prime contractor directly. The prime has an obligation to tell you whether CUI will be involved in your performance and, if so, to include the appropriate flowdown clauses.

Can I lose an existing subcontract if I am not CMMC compliant?

A prime contractor who discovers that a subcontractor handling CUI does not meet CMMC requirements has a compliance problem of their own. Depending on the contract terms and the nature of the gap, this can lead to remediation requirements, contract modifications, or in serious cases, termination of the subcontract. The risk is real and is being actively managed by primes as CMMC enforcement matures.

Do I need a C3PAO assessment as a subcontractor or will a self-assessment work?

Whether you need a self-assessment or a C3PAO third-party assessment depends on the specific requirements of the prime contract and the solicitation. Many subcontracts under programs that allow self-assessment at the prime level will also allow self-assessment for subs. However, programs that require C3PAO certification at the prime level will generally require the same for subcontractors who handle CUI. Review the prime's subcontract terms and, when in doubt, ask directly.

Contact us today to learn more about how Atlantic Digital helps defense subcontractors establish CMMC compliance, build defensible SPRS records, and maintain their teaming relationships as flowdown enforcement tightens across the supply chain.

CMMC Conditional Status: When the POA&M Clock Runs Out

Getting a conditional CMMC Level 2 status feels like progress. In many ways it is. It means your organization completed an assessment, your gaps are documented, and you have a legitimate path toward final certification. But conditional status has a built-in expiration mechanism that most contractors underestimate, and when that mechanism activates, the consequences go straight to contract eligibility.

The 180-day remediation window attached to conditional status is not a grace period in the colloquial sense. It is a hard deadline tied directly to your SPRS record. Miss it without closing your Plans of Action and Milestones, and your conditional status degrades. That degradation is visible to contracting officers. It affects award decisions. In the current enforcement environment, it can cost you a contract before you even submit a proposal.

Understanding exactly how conditional status works, what happens when POA&Ms go unresolved, and what a defensible remediation program looks like is not optional reading for contractors under CMMC Level 2 requirements. It is table stakes.

What Conditional Status Actually Means

Under the CMMC Level 2 framework, a contractor achieves conditional status when an assessment identifies deficiencies but those deficiencies are documented in approved POA&Ms. This applies to both self-assessments and third-party C3PAO assessments.

To qualify for conditional status, all identified deficiencies must be captured in POA&Ms at the time of assessment. No undocumented gaps. No informal remediation plans. Every open finding needs a corresponding POA&M entry with a realistic remediation timeline, a named owner, and a description of the compensating controls in place while the gap is being closed.

The CMMC Assessment Guide Level 2 specifies that organizations with a score between approximately 88 and 109 on the NIST SP 800-171 point scale may qualify for conditional Level 2 status if all deficiencies are captured in approved POA&Ms. Organizations below that threshold are not eligible for conditional status regardless of their POA&M documentation. Final Level 2 certification requires a score of 110, meaning all 110 NIST SP 800-171 requirements are fully implemented and all POA&Ms are closed.

Conditional status is recorded in SPRS. Contracting officers reviewing SPRS entries can see whether a supplier holds conditional or final status, when the assessment was conducted, and whether the annual affirmation requirement has been met. None of that is hidden.

The 180-Day Window: What the Timeline Actually Requires

The 180-day remediation window begins at the time of the conditional assessment. Within that window, organizations are expected to close the POA&Ms that supported the conditional status, re-assess the relevant controls, and update their SPRS record to reflect final certification.

In practice, 180 days is not much time. Consider what actually has to happen: remediation work on the open controls, internal validation that the remediation holds, documentation updates to the System Security Plan, preparation for re-assessment, the re-assessment itself, and finally the SPRS update. For organizations with multiple open findings across different control domains, compressing all of that into six months while also running normal business operations requires serious project management discipline.

The most common failure mode is not organizations that ignore their POA&Ms. It is organizations that genuinely intend to remediate but lose the thread. A remediation task gets assigned but the owner does not have adequate support. An infrastructure project runs over schedule and pushes the related security control past the deadline. Leadership attention shifts to a proposal effort and the compliance program loses momentum. Six months later, nothing is closed and the window has expired.

When that happens, the SPRS record reflects a conditional status with an expired remediation timeline. That is a flag for any contracting officer who pulls the record.

What Happens When the Clock Runs Out

Expired POA&Ms do not automatically terminate a CMMC certification. But they do create documented evidence of a compliance gap that your organization represented it would close and did not. That matters in several ways.

Contract award risk

Contracting officers are required to verify SPRS records before award. An expired conditional status does not carry a formal prohibition on award, but it creates a basis for the contracting officer to question whether your organization can meet the contract's cybersecurity requirements. In a competitive bid environment, that question is often resolved in favor of the competitor with a clean SPRS record.

Annual affirmation exposure

DFARS 252.204-7021 requires annual affirmation by a senior company executive that the organization's CMMC status is current and accurate. Affirming conditional status with expired POA&Ms requires the affirming official to certify a record they know to be deficient. That affirmation is not a formality. It has False Claims Act implications. The Department of Justice's Civil Cyber-Fraud Initiative has made clear that cybersecurity misrepresentation on federal contracts can carry treble damages and civil penalties under 31 U.S.C. 3729.

C3PAO re-assessment scope

If your conditional status expires and you subsequently pursue final certification through a C3PAO, the scope of that assessment is not limited to the controls you documented as open. The assessor evaluates your full environment. Organizations that allowed drift in areas outside their original POA&Ms because they were focused on closing documented gaps sometimes discover broader findings during re-assessment than they anticipated.

What a Defensible Remediation Program Looks Like

A POA&M is a compliance document. A remediation program is a managed project. The difference between those two things is what determines whether your conditional status resolves into final certification or expires into liability.

Assign ownership that means something

Every POA&M item needs an owner with the authority and resources to actually close it. Assigning a POA&M to a job title rather than a person, or to a person without budget authority, is assigning it to nobody. The owner needs to understand what done looks like for that specific control, have access to the systems and tools required, and have a supervisor who is tracking progress.

Build a remediation calendar tied to the 180-day window

Work backwards from the remediation deadline. Every POA&M item should have a projected completion date that leaves buffer before the window closes. High-complexity items — anything requiring infrastructure changes, new tooling procurement, or external vendor support — should be scheduled first, not last. The items that take the longest are the ones that need to start immediately.

Document compensating controls precisely

The POA&M requires documentation of compensating controls for each open finding. These are not generic statements about your security program. They are specific, verifiable controls that reduce the risk of the open gap while remediation is underway. Vague compensating controls that cannot be demonstrated to an assessor are not compliant POA&M entries. Write them so an outside evaluator can verify them independently.

Build a pre-closure validation step

Before you formally close a POA&M item and update your SPRS record, verify that the control is actually implemented correctly. An internal validation step that checks the implementation against the NIST SP 800-171A assessment objective for that control reduces the risk of discovering a gap during formal re-assessment. This is especially important for access control, audit logging, and configuration management controls where implementation details determine whether the control passes or fails.

Track program status at the executive level

The annual affirmation requirement puts a senior executive on the hook for the accuracy of the SPRS record. That executive should have real-time visibility into remediation progress, not a summary assembled the week before affirmation is due. A compliance dashboard or regular status briefing that connects POA&M closure rates to the 180-day deadline turns the executive affirmation from a signature exercise into a governance decision.

The Role of Your vCISO in POA&M Management

For most small and mid-sized defense contractors, internal resources are not sufficient to drive a disciplined POA&M remediation program while simultaneously managing ongoing security operations, preparing for proposals, and handling normal business demands. This is exactly where vCISO services provide measurable value.

An experienced vCISO brings structured project management to the remediation program, keeps the executive team informed about timeline risks before they become timeline failures, translates technical remediation requirements into actionable assignments for IT staff, and provides the documentation discipline that makes both conditional status and final certification defensible. They also provide continuity. Internal staff turnover is one of the most common reasons POA&M programs fall apart mid-cycle. A vCISO relationship provides continuity of knowledge and process that does not leave with an individual employee.

Frequently Asked Questions

Can I hold conditional CMMC Level 2 status and still win contracts?

Yes, conditional status is a recognized CMMC Level 2 designation and satisfies the requirement in contracts that specify Level 2. However, the contracting officer has discretion in how they evaluate your SPRS record, and an expired conditional status or approaching remediation deadline creates risk in competitive evaluations. Final certification is a stronger competitive position.

What happens if I cannot close all my POA&Ms within 180 days?

You should engage your advisory team well before the deadline if you are at risk of missing it. In some cases, extensions or phased remediation approaches may be available, but these require proactive communication and documentation. Allowing the deadline to pass without action and without communication creates a much more difficult situation than addressing it in advance.

How do I know if my current SPRS entry accurately reflects my POA&M status?

Your SPRS record should reflect the current state of your assessment, including whether your status is final or conditional and when the assessment was conducted. If your record does not accurately reflect your current posture, you have an affirmation problem. The affirming official must certify that the record is accurate. Reviewing your SPRS entry against your actual POA&M status is a basic governance step that should happen at least quarterly.

Do POA&Ms from a self-assessment have the same 180-day requirement as those from a C3PAO assessment?

The 180-day remediation timeline and the requirement to close POA&Ms before achieving final status apply regardless of whether the underlying assessment was a self-assessment or a C3PAO third-party assessment. The documentation and management discipline required is the same. The primary difference is that a C3PAO assessment provides independent validation of control implementation, which carries more weight in the contracting community than a self-assessment.

Contact us today to learn more about how Atlantic Digital's CMMC strategy team helps defense contractors build disciplined POA&M programs and move from conditional to final CMMC Level 2 certification before the clock runs out.

FAR CUI Rule: Who It Applies to Beyond Defense Contractors

The federal government's handling of Controlled Unclassified Information is about to change for a much wider population of contractors than most people assume. The draft FAR CUI Rule, published in the Federal Register as rule 2024-30437, would extend CUI safeguarding obligations to commercial contractors who hold federal contracts but have never operated under DFARS or CMMC frameworks. Many of those firms have no idea the rule is coming for them.

The assumption that CUI requirements only apply to traditional defense contractors is one of the most expensive misconceptions circulating inside the broader federal supply chain right now. If your organization holds federal contracts and handles information the government has marked or designated as CUI, the rule may apply to you regardless of your industry, your agency customer, or your current compliance posture.

Understanding who actually falls in scope, what the compliance triggers are, and how much lead time you realistically have is not a compliance exercise. It is a business decision.


What the FAR CUI Rule Actually Does

The FAR CUI Rule is a proposed regulation that would incorporate CUI safeguarding requirements directly into the Federal Acquisition Regulation. That matters because FAR applies government-wide. It is not limited to defense contracts or DoD agencies. When this rule takes effect, any federal contractor receiving or generating CUI in the performance of a government contract would be subject to its requirements.

The rule builds on the CUI program established by Executive Order 13556, which directed the National Archives and Records Administration to develop a unified framework for handling sensitive but unclassified government information. That framework, codified at 32 CFR Part 2002, defines what CUI is, how it must be marked, and how it must be protected. The FAR rule operationalizes those requirements in the contracting context.

Under the proposed rule, contractors would be required to implement security controls from NIST SP 800-171 Rev. 3 for systems that process, store, or transmit CUI. They would also be required to report cyber incidents to the relevant federal agency and, in some cases, provide access to affected systems for forensic review. For contractors already operating under DFARS 252.204-7012, much of this will look familiar. For everyone else, it is new territory.


Who Is Actually in Scope

Scope under the FAR CUI Rule is determined by whether your organization receives or generates CUI in the course of performing a federal contract. That is a broader category than it appears.

CUI is not defined by the agency you work with or the contract dollar value. It is defined by the nature of the information. CUI categories span a wide range of sensitive government data, including law enforcement information, export-controlled technical data, proprietary business information submitted to the government, personally identifiable information collected under federal programs, and financial information related to federal operations. The CUI Registry maintained by NARA provides the authoritative list of categories. If any of that information passes through your organization as part of contract performance, you likely handle CUI whether or not anyone has told you that explicitly.

Several contractor populations are particularly likely to be caught off-guard:

The contracting officer defines the scope of CUI in each contract. But the absence of a formal CUI designation does not mean the information you handle is outside scope. The rule creates obligations tied to the nature of the information, not solely to whether someone has stamped it correctly.


The Compliance Trigger Most Contractors Miss

The most important thing to understand about the FAR CUI Rule is that the compliance trigger is not the rule's effective date. It is the first contract award after the rule takes effect that includes the new FAR clause.

Once that clause appears in a contract, the obligations it creates are live. Contractors who have not built CUI-compliant systems and processes before that point face an immediate gap between their contractual commitments and their actual security posture. That is not a theoretical problem. Under the False Claims Act, knowingly certifying compliance you cannot demonstrate can expose your organization and its executives to significant legal liability.

The compliance clock actually starts well before contract award. Building a CUI-compliant environment takes time. Scoping your information systems, identifying where CUI resides, implementing the applicable NIST SP 800-171 Rev. 3 controls, documenting everything in a System Security Plan, and establishing ongoing monitoring and incident reporting capabilities is not a sprint. For most small and mid-sized organizations encountering these requirements for the first time, six to twelve months is a realistic estimate of the implementation timeline, and that is if leadership prioritizes it from the start.

Waiting for the final rule to act is, in practice, waiting until you are already behind. Atlantic Digital's government contracting advisory team works with organizations at exactly this stage — before the clause appears, while there is still time to prepare.


How This Differs from the CMMC Framework

Defense contractors familiar with CMMC may wonder how the FAR CUI Rule relates to the compliance program they are already managing. The short answer is that these are parallel frameworks with overlapping technical requirements but different legal authorities.

CMMC applies to contractors operating under DFARS. It is DoD-specific and implemented through the DFARS clause structure. The FAR CUI Rule would apply across all federal agencies through the FAR. A contractor working exclusively with civilian agencies would not currently be subject to CMMC, but could be fully within scope of the FAR CUI Rule.

For contractors who operate in both spaces, there is good news. The technical controls in both frameworks trace back to NIST SP 800-171, though with an important distinction: CMMC Level 2 currently aligns to Revision 2, while the FAR CUI Rule references Revision 3, which introduced updated assessment procedures and clarified several control requirements. Organizations that have already built CMMC-compliant systems will have a significant head start on FAR CUI Rule compliance. The scoping methodology, SSP documentation, incident reporting infrastructure, and control implementation work they have already done maps directly to the FAR CUI Rule's requirements.

But that overlap also creates a false sense of security for firms that have been quietly relying on their CMMC work as a proxy for broader federal compliance. If your FAR contracts include CUI that sits outside your CMMC assessment boundary, you may have a gap you have not yet identified. Atlantic Digital's CMMC strategy experts can help you assess where those boundaries align and where they do not.


What to Do Before the Final Rule Drops

The comment period on the proposed rule has closed. A final rule is expected, and the contracting community should assume it is coming. These are the steps that separate organizations that will absorb the rule cleanly from those that will scramble.

Conduct a CUI inventory across your federal contracts

Review every active federal contract and identify whether you receive, generate, or handle information that falls within a CUI category. If your contracts are exclusively with DoD and you have already completed CMMC scoping, extend that exercise to any civilian agency work you hold.

Confirm your system boundaries

Identify every information system that touches CUI. Cloud environments, collaboration platforms, file storage systems, email, and any third-party tools used in contract performance should all be evaluated. Boundaries that were appropriate for DFARS compliance may not capture the full scope of CUI under the FAR rule.

Assess your NIST SP 800-171 Rev. 3 posture

If you have not already implemented the 110 controls in NIST SP 800-171 Rev. 3, now is the time to begin. If you have, verify that your System Security Plan is current and that your SPRS score reflects your actual implementation status, not an aspirational one.

Build your incident reporting infrastructure

The FAR CUI Rule includes cyber incident reporting requirements. Contractors need to know who their reporting contact is at the relevant agency, what the reporting timeline is, and how to preserve forensic evidence of a security event. These processes should be documented and tested before a contract clause requires them.

Evaluate your subcontractor obligations

If you are a prime contractor who flows down FAR clauses to subcontractors, you have an obligation to understand whether those subs are positioned to comply. A non-compliant subcontractor handling CUI on your prime contract creates exposure for your organization as well as theirs.


Frequently Asked Questions

Does the FAR CUI Rule apply if I only work with civilian agencies, not DoD?

Yes. The FAR applies government-wide. If the final rule incorporates CUI safeguarding requirements into the FAR, those requirements will apply to contracts with any federal agency, not just DoD. Civilian agency contractors who handle CUI are within scope.

How do I know if the information I handle qualifies as CUI?

CUI is defined by the CUI Registry maintained by NARA. If the information falls within a listed category and you received it from or generated it for the federal government under a contract, it is likely CUI. When in doubt, review your contract language and consult with your contracting officer about whether a CUI designation applies to your work.

If I am already CMMC Level 2 certified, am I compliant with the FAR CUI Rule?

CMMC Level 2 certification demonstrates compliance with NIST SP 800-171 Rev. 2 within your assessed boundary. If that boundary covers all the systems where CUI resides, your technical controls will largely satisfy the FAR CUI Rule requirements. However, CMMC is a DoD-specific program. The FAR CUI Rule has its own clause structure, reporting requirements, and contract implementation mechanisms. Certified organizations should still review their contracts and confirm that their system boundaries and incident reporting processes align with the FAR rule requirements.

What is the False Claims Act exposure for contractors who fall out of compliance?

The Department of Justice's Civil Cyber-Fraud Initiative has pursued enforcement actions against contractors who misrepresented their cybersecurity posture on federal contracts. If a contractor certifies compliance with CUI safeguarding requirements in a contract and that certification is knowingly false, it may constitute a false claim under 31 U.S.C. 3729. Penalties can include treble damages and per-claim statutory fines. Multiple settlements have already been reached in cases involving cybersecurity misrepresentation.


Contact us today to learn more about how Atlantic Digital helps defense and federal contractors prepare for CUI compliance obligations before the final rule takes effect.

NIST SP 800-171 Scoping: Where Contractors Go Wrong

Ask most defense contractors what drives up their CMMC readiness costs and they will tell you it is the controls. The remediation. The tooling. The assessment fees. Those answers are not wrong, but they are downstream of the real problem.

The single most expensive mistake in CMMC Level 2 readiness happens before a single control is implemented. It happens at the boundary. Specifically, it happens when an organization draws the wrong line around which systems, people, and processes touch Controlled Unclassified Information.

NIST SP 800-171 compliance applies to the systems that process, store, or transmit CUI. Define that environment too broadly and you spend the next eighteen months remediating systems that never needed to be in scope. Define it too narrowly and you certify a boundary that does not reflect reality, creating compliance gaps on active contracts and exposure under the False Claims Act.

Scoping is not a technical task. It is a strategic decision with financial and legal consequences. Most organizations treat it like an IT exercise. That is where the trouble starts.

What Scoping Actually Means Under NIST SP 800-171

NIST SP 800-171 establishes 110 security requirements across 14 control families. Those requirements apply to nonfederal systems and organizations that process, store, or transmit CUI. The operative question in scoping is: which systems in your environment meet that definition?

The answer requires two things your organization needs to have done before the boundary conversation begins: a CUI registry that identifies what CUI you receive, where it comes from, and what form it takes; and a data flow map that traces where CUI moves once it enters your environment, which systems touch it, which personnel handle it, and where it comes to rest.

Without both, the boundary you draw is a guess. An educated guess, maybe, but a guess that your assessor will test against evidence. Systems your SSP excludes will be examined. If CUI flows through them and they are out of scope, you have a finding.

Industry data consistently shows that poor scoping and inadequate data discovery can inflate total CMMC readiness costs by 20 to 30 percent. That figure does not account for the cost of a failed assessment or a remediation window that delays contract award.

How Contractors Over-Scope and What It Costs

Over-scoping is the more common error, and it tends to be invisible until the bill arrives.

It typically happens when an organization defaults to including its entire enterprise IT environment in the assessment boundary. The logic sounds reasonable: we handle CUI somewhere in this network, so we should include all of it. In practice, this means applying all 110 NIST SP 800-171 requirements to systems that have no contact with CUI whatsoever, finance platforms, HR systems, marketing tools, general productivity infrastructure.

The cost compounds quickly. Every system in scope requires documented controls. Every gap in those controls requires remediation or a Plan of Action and Milestones (POA&M). Every POA&M extends your path to a final CMMC Level 2 score of 110. A C3PAO assessing a bloated environment takes longer, costs more, and finds more findings because there are simply more surfaces to examine.

The fix is not to exclude everything. It is to invest in network segmentation and architectural isolation that genuinely separates CUI-handling systems from the broader enterprise. An enclave approach, where CUI flows only through a defined, controlled environment, reduces scope legitimately and durably. That investment almost always costs less than remediating an over-scoped enterprise.

How Contractors Under-Scope and Why It Is More Dangerous

Under-scoping is less common but significantly more consequential. It tends to happen in one of three ways.

The 'mostly administrative' exclusion

A system handles CUI occasionally, when someone emails a contract document through a shared inbox, or when a program manager saves a deliverable to a general file share. Because the system is 'mostly used for other things,' it gets excluded from scope. The boundary is drawn around the purpose of the system, not the data that actually flows through it. Under NIST SP 800-171 and DFARS 252.204-7012, the data is what determines scope, not the system's primary function.

The inherited compliance assumption

An organization uses a cloud platform that holds FedRAMP authorization and assumes that means their CUI environment is covered. FedRAMP authorization establishes that the cloud service provider meets a defined security baseline. It does not mean the contractor's configuration of that service, their access controls, their data handling practices, or their boundary documentation meets NIST SP 800-171. The contractor's obligations do not transfer to the provider.

The subcontractor blind spot

A prime contractor scopes their own environment carefully but does not account for CUI that flows to subcontractors or teaming partners during contract performance. If CUI touches a subcontractor's systems, that subcontractor's environment is in scope for NIST SP 800-171 requirements and CMMC obligations under DFARS 252.204-7021 flowdown. A prime with a clean certification and an unvetted subcontractor has a compliance gap whether or not the gap shows up on their own assessment.

The Four Scoping Errors and What They Cost

TABLE 1. COMMON NIST SP 800-171 SCOPING ERRORS AND DOWNSTREAM COSTS

Scoping ErrorWhat It Looks LikeWhat It Costs
Over-scopingIncluding all enterprise IT systems regardless of CUI contactAssessment scope inflated 30-50%; unnecessary remediation investment; longer C3PAO timelines
Under-scopingExcluding systems that transmit or process CUI because they are 'mostly administrative'Compliance gaps in active controls; contract risk; potential False Claims Act exposure
CUI not identifiedOrganization does not know where CUI lives or how it flows through the environmentBoundary cannot be drawn; SSP is incomplete; assessment fails or is delayed
Boundary driftScope defined at assessment; CUI flows into new systems post-assessment without reviewCertification covers a boundary that no longer reflects reality; annual affirmation becomes a liability

Scoping as a Strategic Decision

The organizations that manage CMMC readiness costs most effectively are not the ones that find the cheapest assessor or the fastest path to a passing score. They are the ones that make deliberate scoping decisions early, with executive involvement, and then build their compliance architecture around a defined and defensible boundary.

That means the scoping conversation belongs in the boardroom, not just the server room. A CEO or COO deciding how to structure a compliance investment needs to understand that boundary definition is a lever. A well-segmented CUI enclave can reduce assessment scope by half. That reduction translates directly into lower remediation costs, shorter assessment timelines, and a more manageable annual compliance burden.

It also means that scoping decisions need to be documented with the same rigor as the controls themselves. Your System Security Plan must describe the boundary, justify what is included and excluded, and reflect the actual flow of CUI through your environment. An SSP that describes a boundary your assessor cannot verify is not a compliance document. It is a liability.

One practical benchmark worth knowing: DoD data projects the three-year CMMC Level 2 compliance cost for a small business at approximately $487,000, with the largest variable being internal labor and sustainment. Organizations that scope precisely and maintain that scope through disciplined boundary management consistently come in below that benchmark. Those that do not consistently exceed it.

Where to Start

Conduct a CUI discovery exercise before drawing any boundary. Identify every contract that requires CUI handling, every system that touches it, and every person with access. This is not an IT project. It requires input from contracts, program management, IT, and legal.

Map data flows, not just system inventories. A static list of systems is not a boundary. You need to trace how CUI enters your environment, where it moves, where it is stored, and how it exits. Email, collaboration platforms, shared drives, removable media, and third-party portals all need to be accounted for.

Evaluate network segmentation before committing to an assessment scope. If CUI currently flows across your enterprise environment, architectural changes that isolate it may be the highest-ROI investment you make before engaging a C3PAO.

Document the boundary in your SSP with the specificity your assessor will need. System names, data flows, boundary justifications, and exclusion rationale all belong in the SSP. Vague boundary descriptions are the first thing a thorough assessor will challenge.

Build a boundary review into your annual affirmation process. CUI environments change. New contracts, new tools, new personnel, new subcontractors. A boundary that was accurate at certification may not be accurate twelve months later. Annual affirmation under DFARS 252.204-7021 requires that your SPRS status reflect your current posture. That requirement has teeth.

Frequently Asked Questions

How do we know which systems are in scope for NIST SP 800-171?

Any system that processes, stores, or transmits CUI is in scope. That determination requires a CUI identification exercise first: know what CUI you receive, in what form, and under which contracts. Then trace its flow through your environment. Systems that CUI touches are in scope. Systems that CUI never reaches, and can be architecturally isolated from systems that do, can be excluded with documented justification in your SSP.

Can we reduce our CMMC assessment scope after we have already started remediation?

Yes, but scope reduction is most cost-effective before remediation begins. If you have already invested in remediating systems that should not have been in scope, the remediation is done. Going forward, you can implement segmentation to prevent those systems from re-entering scope in future assessment cycles. Engage a qualified advisor before finalizing any boundary change to ensure the exclusion is documentable and defensible.

Does using Microsoft 365 GCC High mean our environment is automatically NIST SP 800-171 compliant?

No. GCC High provides a platform that supports NIST SP 800-171 compliance, but the contractor is responsible for configuring that platform correctly, controlling access, managing CUI data flows, and documenting compliance in an SSP. The provider's authorization does not transfer compliance status to the contractor. This is one of the most common inherited compliance assumptions in the Defense Industrial Base and one of the most frequently cited gaps in C3PAO assessments.

What happens if our boundary was wrong when we submitted our SPRS score?

If your SPRS score reflects a boundary that excluded systems that should have been in scope, your self-attestation may be inaccurate. Under the False Claims Act, knowing submission of a materially false compliance attestation carries significant legal exposure. The appropriate step is to reassess with an accurate boundary, update your SPRS record, and document the correction. Engaging legal counsel before making that update is advisable if the gap is material.

Scoping is where CMMC readiness is won or lost, and most organizations do not treat it with the seriousness it deserves until the cost overruns are already in motion. Getting the boundary right at the start is the highest-leverage decision in the entire compliance process. Contact us today to learn more.

DFARS 252.204-7012: What It Still Requires in 2026

There is a version of the compliance conversation happening inside defense contracting organizations right now that goes something like this: CMMC covers our cybersecurity obligations, so we just need to get our CMMC Level 2 assessment done and we are covered. It is a reasonable assumption. It is also wrong.

DFARS 252.204-7012 has not been replaced by CMMC. It has not been absorbed into DFARS 252.204-7021. It has not been modified under the Revolutionary FAR Overhaul. The clause is in effect exactly as written, and it imposes obligations that CMMC does not address.

Contractors conflating the two frameworks are leaving real compliance gaps in active contracts, gaps that carry cyber incident reporting liability, cloud security exposure, and potential False Claims Act risk.

What DFARS 252.204-7012 Actually Covers

DFARS 252.204-7012 is titled Safeguarding Covered Defense Information and Cyber Incident Reporting. Its scope is broader than the name suggests.

The clause applies when a contractor's information system processes, stores, or transmits Covered Defense Information (CDI), or when the contractor provides operationally critical support. CDI is defined to include Controlled Unclassified Information (CUI) that is collected, developed, received, transmitted, used, or stored by or on behalf of a contractor in performance of a contract.

When the clause applies, it imposes four distinct requirements:

•       Adequate security. The contractor must apply security requirements in NIST SP 800-171 to all covered contractor information systems. This is the same technical baseline that CMMC Level 2 maps to. The difference is in how compliance is validated and enforced.

•       Cyber incident reporting. The contractor must report cyber incidents to the DoD within 72 hours of discovery via the DCISE portal at DC3. This is a standalone obligation under 7012 with no equivalent provision in CMMC.

•       Malicious software submission. If malicious software is discovered and isolated in connection with a reported cyber incident, the contractor must submit it to the DoD Cyber Crime Center (DC3).

•       Media preservation and protection. Following a cyber incident, the contractor must preserve images of all known affected systems and relevant monitoring and packet capture data for at least 90 days, available for potential DoD forensic analysis.

•       Cloud service provider requirements. Any cloud service used to process, store, or transmit CDI must meet security requirements equivalent to FedRAMP Moderate, or a higher standard agreed upon with the contracting officer.

None of these obligations disappear when a contractor achieves CMMC Level 2 certification. They are parallel requirements under a separate clause.

How 7012 and CMMC Relate to Each Other

CMMC Level 2, enforced through DFARS 252.204-7021, establishes whether a contractor holds a qualifying assessment status to handle CUI on a given program. It draws on the same 110 security requirements from NIST SP 800-171 that 7012 references.

But the two clauses serve different functions. CMMC is an assessment and certification framework. It answers the question: has this contractor's security posture been evaluated against a defined standard, and is that status recorded in SPRS? DFARS 252.204-7012 is an operational obligation framework. It answers the question: when a contractor handles CDI or supports critical operations, what must they do and what must they report?

Achieving CMMC Level 2 certification demonstrates that your controls are in place. DFARS 252.204-7012 governs what you are required to do when something goes wrong, or when you move CDI into the cloud, regardless of your CMMC status.

TABLE 1. DFARS 252.204-7012 VS. CMMC LEVEL 2: KEY DISTINCTIONS

DFfffARS 252.204-7f012CMMC Level 2 / DFARS 252.204-7021vv
TriggerReceipt or transmission of Covered Defense Information on contractor IT systemsProcessing, storing, or transmitting CUI on contractor IT systems
Core requirementAdequate security aligned to NIST SP 800-171; cyber incident reporting; media preservationQualifying CMMC Level 2 assessment status recorded in SPRS; annual affirmation
Incident reportingRequired. 72-hour window to report to DoD.Not separately addressed. 7012 governs.
Cloud requirementCloud providers must meet FedRAMP Moderate or equivalentNo separate cloud provision. 7012 governs.
Media preservationRequired for 90 days following cyber incidentNot addressed
Status in 2026Unchanged. Fully in effect.Unchanged. Phased enforcement through 2028.

Where Contractors Are Getting the Scope Wrong

The most common scoping error is assuming that if CMMC applies to a program, 7012 does not need separate attention. In practice, the clauses appear together in solicitations precisely because they cover different ground.

Three specific areas where conflation creates compliance risk:

Cloud environments

Many contractors have moved workloads to Microsoft 365 GCC High, Azure Government, or AWS GovCloud. These environments support CMMC evidence collection and can help demonstrate NIST SP 800-171 control implementation. But DFARS 252.204-7012 independently requires that any cloud service processing CDI meet FedRAMP Moderate or equivalent. The contractor is responsible for verifying and documenting that requirement, not assuming it is satisfied by the cloud provider's general compliance posture. That verification needs to be explicit in your System Security Plan.

Incident reporting timelines

CMMC does not establish a cyber incident reporting requirement. DFARS 252.204-7012 does, and the 72-hour window runs from discovery, not from the time an investigation is complete or a root cause is identified. Contractors that treat incident response as a compliance exercise rather than an operational one routinely miss this window. The consequence is not a CMMC finding. It is a contract violation with potential False Claims Act exposure under DFARS.

Subcontractor flowdown

DFARS 252.204-7012 requires prime contractors to flow the clause down to subcontractors when CDI will be processed, stored, or transmitted on subcontractor systems, or when the subcontract involves operationally critical support. This flowdown obligation exists independently of CMMC flowdown requirements under 252.204-7021. A prime that manages CMMC flowdown carefully but ignores 7012 flowdown is still out of compliance with its prime contract.

The False Claims Act Exposure Is Real

The Department of Justice Civil Cyber-Fraud Initiative has made clear that misrepresentations about cybersecurity compliance in federal contracting are actionable under the False Claims Act (31 U.S.C. § 3729 et seq.). That exposure is not limited to CMMC attestations.

A contractor that certifies compliance with contract terms, including DFARS 252.204-7012, while operating a cloud environment that does not meet FedRAMP Moderate, or that fails to report a cyber incident within 72 hours, has made a potentially material misrepresentation to the government. The fact that CMMC certification is in order does not resolve that exposure.

Compliance officers and program managers on active DoD contracts should be asking whether their contract compliance certifications accurately reflect 7012 obligations, not just CMMC status.

Practical Steps for Active Contracts

•       Review every active DoD contract for the presence of DFARS 252.204-7012. If CDI is in scope, confirm that your System Security Plan explicitly addresses each of the clause's five requirement areas.

•       Verify your cloud service providers against the FedRAMP Moderate baseline or document an equivalent standard agreed upon with your contracting officer. Do not assume compliance based on the provider's general certifications.

•       Confirm your incident response plan includes the 72-hour reporting window, names the DCISE portal at DC3 (dc3.mil) as the reporting destination, and assigns clear ownership for that obligation. Test the process before you need it.

•       Audit your subcontract agreements for 7012 flowdown. If a subcontractor is handling CDI and the clause is not flowed down, that is a prime contract compliance gap, not a subcontractor problem.

•       Do not treat CMMC certification as a substitute for 7012 compliance documentation. Both need to be current, accurate, and defensible.

Frequently Asked Questions

Does achieving CMMC Level 2 certification satisfy DFARS 252.204-7012?

No. CMMC Level 2 certification confirms that your security posture has been assessed against NIST SP 800-171 requirements and that status is recorded in SPRS. DFARS 252.204-7012 imposes separate obligations, including 72-hour cyber incident reporting, media preservation, malicious software submission, and FedRAMP Moderate requirements for cloud services. These are independent contract requirements that remain in effect regardless of CMMC status.

Has DFARS 252.204-7012 been changed under the Revolutionary FAR Overhaul?

No. As of the current class deviations implementing the FAR overhaul, DFARS 252.204-7012 and its companion provision DFARS 252.204-7008 are unchanged. The overhaul restructured and renumbered several related clauses, including provisions tied to NIST self-assessments and CMMC, but 7012 remains in its current form and fully in effect.

What is the difference between CUI and Covered Defense Information under 7012?

Covered Defense Information (CDI) is the term used in DFARS 252.204-7012 and is defined to include CUI as well as other unclassified information marked or identified in the contract that requires safeguarding. In most current DoD contracts, CDI and CUI overlap substantially, but the 7012 definition is contractually specific. Review your contract's definition of CDI against what your organization actually processes.

If a cyber incident occurs, what specifically must be reported and to whom?

Under DFARS 252.204-7012, contractors must report cyber incidents to the DoD within 72 hours of discovery using the DCISE portal, operated by the DoD Cyber Crime Center (DC3) at dc3.mil. The report must include a description of the technique or method used in the incident, a description of the CDI compromised, any identified compromised systems, and other details defined in the clause. Contractors should also preserve system images and relevant monitoring data for at least 90 days pending potential DoD forensic review. DFARS 252.204-7012 is not a legacy requirement waiting to be replaced. It is an active contract obligation governing how your organization handles incidents, manages cloud environments, and flows compliance requirements to subcontractors. Getting CMMC right matters. Getting 7012 right matters just as much. Contact us today to learn more.