Transcript
A (0:00)
Alrighty folks, it is February of 2026 and this one is a doozy. As of February 1, 2026, defense contractors will no longer be required to conduct basic self assessments and upload their scores into SPRs pursuant to DFARS provision 252-204-7019 and DFARS clause 252-20470 20. In fact, 7019 and 7020 no longer exist at all thanks to a DFARS class deviation. You will now See DFARS clause 252-240-7997 called NIST SP 800171 DoD assessment requirements. No, that is not a joke. That is real. Oh, and on top of that, you won't see far clause 5220421 anymore either because it has a new number, 52240 93. Oh, and all of this happened without any rulemaking at all yet. So what the hell is going on? We'll strap in, grab your coffee, because that's what we're going to talk about this week.
B (1:22)
Foreign.
A (1:25)
Jason, this is the biggest change to DFARS cyber security contract clauses outside of CMMC since 2020. And as far as I can tell, nobody's talking about this yet. Initial thoughts before we journey into the center of the earth here, Jacob the.
B (1:46)
The late great professional wrestler Roddy, Roddy Piper used to always say, one of the best on the mic ever, right? Used to always say, just when they think they know the answers, I change it up and switch the questions, right? And so like this is what's, what's happening right here in front of our eyes. Just when the defense industrial base thinks that they're just scratching the surface on the answers, surprise, the questions are changed. When you were telling me the background and you said February 1st, I thought you were extremely confused because April 1st is April Fool's Day, not February 1st. And I thought this was all a joke. What is happening, dude?
A (2:29)
Yeah, yeah, the. A lot of times the changes, the. The people who lament the changes around cmmc, they tend to overblow what those changes actually are not this time. These are actually legitimate changes that are going to cause.
B (2:42)
This is a big deal, bro.
A (2:44)
Yeah. Yeah. Okay, so real quick, against my instincts to explain everything and then get to the changes. We're going to summarize the changes first. That way you can listen to the context if you want to. So, five things to know here. First, far clause 5220421 has been renumbered to 522-4093. It is still titled Basic Safeguarding of Covered Contractor information systems. The 15 requirements are still the same. They have not changed. The flow down is still the same, still applies to systems that handle federal contract information. All that stuff is the same. But it has a new number 522-4093 that is real. So if you see the new number that is not an error. Second, DFARS provision 252-2047 19 no longer exists. It it has been deleted. Third, DFARS clause 252-204-7020 has two changes to it. It has been renumbered to 252-24-07997. It is still titled NIST SP 800171 DoD Assessment Requirements. However, there is no longer a basic self assessment requirement that has been completely deleted from the text of the clause. Medium and high assessments and everything associated with that process remain unchanged but everything related to basic self assessments and uploading your score to SPRs has now gone away. Fourth, there are no changes to DFARS clause 252-204-7012 or provision 252-204-7008. And fifth, there are no changes to DFars clause 252-204-7021, the CMMC clause or its provision 252-204-7025. Initial thoughts here Jason yeah, so I.
