Subcontractor has no SPRS score: what DFARS 252.204-7012 and 252.204-7021 say
Where a subcontract carries DFARS 252.204-7012 and the work involves CUI or covered defense information, whether a current NIST SP 800-171 assessment in SPRS is needed before award depends on the clauses in that subcontract, the information flowed down and the CMMC level it requires (codified 252.204-7020(g)(2); 252.204-7021(f)(2)). A prime cannot see a subcontractor's score in SPRS; it can only ask for it. The SPRS score is a number from an assessment; it is not a CMMC status.
What the register reads
a date to chaseAsk for the SPRS score and the date of the assessment behind it, or confirm the subcontract involves no CUI.
The rule sentences behind it
5 citedDFARS 252.204-7020(g)(2)codified text, eCFR current to 24 Sep 2026; replaced in Department of War (DoD) contracts by 252.240-7997 under Class Deviation 2026-O0025, effective 1 Feb 2026The Contractor shall not award a subcontract or other contractual instrument, that is subject to the implementation of NIST SP 800-171 security requirements, in accordance with DFARS clause 252.204-7012 of this contract, unless the subcontractor has completed, within the last 3 years, at least a Basic NIST SP 800-171 DoD Assessment
DFARS 252.240-7997(g) (DEVIATION 2026-O0025)Class Deviation 2026-O0025, effective 1 Feb 2026The Contractor shall insert the substance of this clause, including this paragraph (g), in all subcontracts and other contractual instruments, including subcontracts for the acquisition of commercial products or commercial services (excluding commercially available off-the-shelf items).
DFARS 252.204-7021(f)(2)codified text, eCFR current to 24 Sep 2026; the same text is carried in Class Deviation 2026-O0025, effective 1 Feb 2026Prior to awarding a subcontract or other contractual instrument, ensure that the subcontractor has a current CMMC certificate or current CMMC status at the CMMC level that is appropriate for the information that is being flowed down to the subcontractor based on the requirements at 32 CFR 170.23.
32 CFR 170.23(a)(2)codified text, eCFR current to 24 Sep 2026If a subcontractor will process, store, or transmit CUI in performance of the subcontract, then a CMMC Status of Level 2 (Self) is the minimum requirement for the subcontractor.
DFARS 252.204-7012(m)(1)codified text, eCFR current to 24 Sep 2026Include this clause, including this paragraph (m), in subcontracts, or similar contractual instruments, for operationally critical support, or for which subcontract performance will involve covered defense information, including subcontracts for commercial products or commercial services, without alteration, except to identify the parties.
The clauses behind it
DFARS 252.204-7012 (b)Security on covered systems: implement NIST SP 800-171The Contractor shall provide adequate security on all covered contractor information systems; for systems that are not part of an IT service or system operated on behalf of the Government, this means implementing the security requirements in NIST SP 800-171 in effect at the time the solicitation is issued (or as authorised by the Contracting Officer).
DFARS 252.204-7012 (m)Subcontract flowdownThe Contractor shall include this clause, without alteration except to identify the parties, in subcontracts (including for commercial products or services) for operationally critical support or whose performance will involve covered defense information, determine whether information retains its identity as covered defense information, and require subcontractors to report cyber incidents to the prime (or next higher-tier subcontractor) and to DoD via dibnet.
A line that raises it
inventedCobalt Ridge Cable Harness | 7RT22 | | | Level 2 (Self) | | yes | no | yes