Transcript
A (0:02)
All right, folks, it is July of 2025. We are in the back half of the year, and we are continuing with our Back to Basics series on the DFARS Cyber series of solicitation provisions and clauses that make up all of the cyber security stuff you got to do as a defense contractor. And today we are picking up where we left off with DFARS clause 252-204-70 20 NIST special publication 800171 DoD assessment requirements. That's what we're going to talk about today.
B (0:40)
Well, hold on. I think when we talked about 7:19, we talked about assessment requirements, and I think one of the most common questions in which we get is 1719, 7020. You know, sounds kind of like the same thing to me. And I know you and I know that they're two different things, but I think you're going to dig a little bit more into why exactly they're separate but related.
A (1:00)
Yeah. So when you read through this collection of solicitations and clauses, the thing to remember is that the solicitation provision is making you aware of the requirements in the clauses. It doesn't always seem that straightforward. So when you sort of read through them, it can feel a little bit repetitive. But just like we talked about early on, we talked about The DFARS provision 252-204-7008 is making you aware of the requirements in DFARS clause 7012. Like we talked about previously, everything in DFARS provision 252-204-7019 is making you aware of the requirements in the clause, the corresponding clause 7020. So that's the general way that these go together. But just to review very quickly, the DFARS Cyber series is a set of five solicitation provisions and contract clauses that govern cybersecurity requirements for defense contractors handling controlled unclassified information. So you got the provision 7008, the clause 7012, the provision 7019, and the clause 7020. We also have DFARS 7009, which we have not gotten to yet, not often talked about, and eventually the CMMC program will add two more items to this list for a total of seven things. Our favorite number it will be DFARS clause 252-204-70 21 and a provision that we don't know the number of yet as of this conversation, but we should know towards the end of this year when the final CMMC clause rule, as we call it, is published.
B (2:41)
And so would you say Kind of if we wanted to sandwich them together. Right. 77,008 and 7,012 are the ones that are telling you to implement things and 7019 and 7020 are the ways that are going to validate that you have implemented those things, right?
A (2:57)
Yeah, yeah, that's exactly right. That's probably the best way to kind of describe them at a high level. And we'll get into how the DoD describes that position from the rule that was published in 2020. But just very, very quickly, at the the highest possible level here, The DFARS clause 252-204-7020 applies to contractor information systems that are subject to NIST SP 800171 requirements pursuant to DFARS clause 252, 204, 7012, which why we're sort of doing these in a sequence. The provision 7008 said, hey, you're going to bid on this work and then it's going to come with this clause 7012. So be aware that you have requirements. The clause 7012 as we talked about in that episode, says, hey, when you handle this specific type of data, you got all these cybersecurity obligations that you have to meet. You know, implementing NIST SB800171 using FedRAMP moderate equivalent or better, flowing it down to subcontractors, on and on and on. And then you've got 7019 saying, hey, you also have obligations for making sure that you conduct a basic self assessment, calculate a score according to our methods, upload that score and make yourself and your facilities available to us. Because that's what 7020 is going to tell you. 7020 tells you that. And then you've got the CMMC clause and provision that are going to say, hey, you need to go out and get an external auditor to actually validate that these scores are correct, and so on and so forth. Everything revolves around whether or not DFAR 7012 applies to you. 7019, 70207021 and so on all orbit around proving that you have actually implemented and complied with DFAR 7012.
