Transcript
A (0:02)
All right, folks, it is September of 2025, and the regulation that finalizes CMMC guidance for DoD contracting officers and program managers officially goes into effect on November 10th of 2025. And the highlight of the regulation for most people is the final text of DFARS clause 252-204-70 21, the CMMC clause that we've been waiting on for years, which tells contractors which CMMC level they need to achieve specifically to take award of the contract. But the regulation also created DFARS provision 252-204-70. 25, 7025. What the heck is that? I thought 7021 was what we had to worry about. But now that the final rule is done, we can wrap up our Back to Basics series on the DFARS Cyber series of cybersecurity provisions and clauses with this new wacky provision 7025. And that's what we're going to talk about today.
B (1:14)
Yeah, we saw the trend, or we saw how the pattern was. There was always one clause that tells you what's happening and the other clause that tells you what needs to happen for the most part. Right. And so for the CMMC program, for the longest time, we only had 7,021, and it was the one that told us kind of what's happening, but we need to know what needs to happen here. And so that's what 7025 was. All of our guesses as to what number they were going to use were completely off. The numbers have no. There's absolutely no method to the madness when it comes to these numbers, but we have the numbers and it's the ones we have to stick to. And you're going to see them in your contract soon.
A (1:50)
Yep, absolutely. All righty. So we should have a playlist available with the Back to Basic series that you guys can check out. It's been a minute since we've updated it, but we're covering all of the DFARS Cyber series, as we like to call them, the set of solicitation provisions and clauses that govern cybersecurity requirements for defense contractors handling controlled information. So we talked About DFARS provision 7008-7009-7012-7019, 7020. We've gone through all of these, and today we're looking at the new provision 252-204-7025, titled Notice of Cybersecurity Maturity Model Certification Level Requirements. And just like we Talked about with DFARS 252-204-7008 and 7019. The 7025 provision, just like it says in the title, is putting you on notice. It's making you aware of the requirements in a corresponding contract clause. So if you remember from the other episodes that we've done, 7008 makes you aware of 7012, 7019 makes you aware of 7020, 7025 makes you aware of 7021. And like you said, the numbers are completely arbitrary. They get assigned when the rules are, when the final text of the rules are, are put together and the numbering scheme does not indicate what they correspond to. So 7008-7012-7019-7020, 7025, 7021 solicitation provisions and their corresponding contract clauses.
