Subcontractor CMMC Tracker
Findings · finding 2 of 12

Subcontractor SPRS score older than three years: what DFARS 252.240-7997 says

Two dates, two rules. The SPRS assessment date is read against the codified award clause, 252.204-7020(g)(2), which looks for an assessment completed within the last 3 years; the deviation clause that replaces it in Department of War (DoD) contracts, 252.240-7997, flows down and carries no age of its own. The CMMC status date is read against 252.204-7021, which reads a Final Level 2 status as current when not older than 3 years, a Final Level 1 status when not older than 1 year and a conditional status when not older than 180 days (32 CFR 170.15 and 170.16 set the same periods). Confirm which deviation your contracting officer's agency has adopted.

What the register reads

a date to chase

Ask for the date of the latest assessment and of the CMMC status in SPRS, system by system.

Three texts, side by side

Where the codified text and the deviation differ, both are shown and neither is called the answer. Confirm which deviation your contracting officer's agency has adopted.

The rule sentences behind it

6 cited
DFARS 252.204-7020(g)(2)codified text, eCFR current to 24 Sep 2026; replaced in DoD contracts by 252.240-7997 under Class Deviation 2026-O0025, effective 1 Feb 2026

The Contractor shall not award a subcontract or other contractual instrument, that is subject to the implementation of NIST SP 800-171 security requirements, in accordance with DFARS clause 252.204-7012 of this contract, unless the subcontractor has completed, within the last 3 years, at least a Basic NIST SP 800-171 DoD Assessment

Threshold read: no subcontract award without an assessment completed within the last 3 years. Source
DFARS 252.240-7997(g) (DEVIATION 2026-O0025)Class Deviation 2026-O0025, effective 1 Feb 2026

The Contractor shall insert the substance of this clause, including this paragraph (g), in all subcontracts and other contractual instruments, including subcontracts for the acquisition of commercial products or commercial services (excluding commercially available off-the-shelf items).

Threshold read: the deviation clause flows down; it carries no award sentence or age of its own. Source
DFARS 252.204-7021, "current" (2)(ii)codified text, eCFR current to 24 Sep 2026; the same text is carried in Class Deviation 2026-O0025, effective 1 Feb 2026

Not older than 3 years for Final Level 2 (Self) assessments and Final Level 2 (C3PAO) assessments, with (A) No changes in compliance with the requirements at 32 CFR part 170 since the Final CMMC Status date (see 32 CFR 170.16 and 170.17); and (B) A corresponding affirmation of continuous compliance, not older than 1 year, by an affirming official

Threshold read: Final Level 2: not older than 3 years, affirmation not older than 1 year. Source
32 CFR 170.16(a)(1)codified text, eCFR current to 24 Sep 2026

To maintain compliance with the requirements for a CMMC Status of Level 2 (Self), the OSA must conduct a Level 2 self-assessment every three years and submit the results in SPRS, within three years of the CMMC Status Date associated with the Conditional Level 2 (Self).

Threshold read: Level 2 (Self) assessment: every three years. Source
DFARS 252.204-7021, "current" (2)(i)codified text, eCFR current to 24 Sep 2026; the same text is carried in Class Deviation 2026-O0025, effective 1 Feb 2026

Not older than 1 year for Final Level 1 (Self), with (A) No changes in compliance with the requirements at 32 CFR part 170 since the Final CMMC Status date (see 32 CFR 170.15); and (B) A corresponding affirmation of continuous compliance, not older than 1 year, by an affirming official

Threshold read: Final Level 1: not older than 1 year. Source
32 CFR 170.15(a)(1)codified text, eCFR current to 24 Sep 2026

To maintain compliance with the requirements for the CMMC Status of Final Level 1 (Self), the OSA must conduct a Level 1 self-assessment on an annual basis and submit the results in SPRS, or its successor capability.

Threshold read: Level 1 (Self) assessment: annual. Source

The clauses behind it

DFARS 252.204-7012 (b)Security on covered systems: implement NIST SP 800-171

The Contractor shall provide adequate security on all covered contractor information systems; for systems that are not part of an IT service or system operated on behalf of the Government, this means implementing the security requirements in NIST SP 800-171 in effect at the time the solicitation is issued (or as authorised by the Contracting Officer).

What an assessor asks to see: A System Security Plan (SSP) describing how each NIST SP 800-171 requirement is met; An SPRS self-assessment score; Implementation evidence for the 110 NIST SP 800-171 security requirements
Where subcontractors usually fall short: Missing or stale SSP; No SPRS score submitted; Claiming full implementation without supporting artefacts
Source: DFARS 252.204-7012
CMMC L2 CA.L2-3.12.1Security Control Assessment 5 points in the score

Assess the security controls in place periodically to determine whether they are effective as implemented.

What an assessor asks to see: Assessment plan defining scope, method and frequency; Completed assessment results per control; Evidence assessments cover effectiveness and not just presence
Where subcontractors usually fall short: Assessment confirms a control exists without testing whether it works; Scope excludes parts of the CUI environment; No defined periodicity so assessments lapse
Source: CMMC 2.0 Level 2 (NIST SP 800-171 Rev 2)

A line that raises it

invented

Delmar Tool and Die | 1GD49 | 97 | 2023-09-26 | Level 2 (Self) | 2026-01-15 | yes | no | yes

See it in the specimen