PARTNERSHIPCUI Vault and Trout Software partner to extend the CUI boundary to the machine.CUI Vault partners with Trout Software.Read the announcement

The clause numbers moved. The obligations moved with them — they didn’t disappear.

Two of the DFARS cybersecurity clauses your contracts have cited for five years no longer exist under their old numbers. The self-assessment and SPRS duties they carried are still yours.

Two of the DFARS cybersecurity clauses your contracts have cited for five years no longer exist under their old numbers. The self-assessment and SPRS duties they carried are still yours. Anyone auditing a contract file by clause number is about to reach the wrong conclusion.

Here is a quiet problem worth ten minutes of your week. The Revolutionary FAR Overhaul class deviations took effect on February 1, 2026, and among the things they rewired was the numbering of the cybersecurity clauses everyone in the defense industrial base has memorized.

DFARS 252.204-7019 — the provision that told offerors they needed a current NIST SP 800-171 assessment posted in SPRS — was eliminated outright. DFARS 252.204-7020 was renumbered to DFARS 252.240-7997, keeping its title, NIST SP 800-171 DoD Assessment Requirements. On the civilian side, the basic safeguarding clause moved from FAR 52.204-21 to FAR 52.240-93, with the same fifteen requirements inside it.

Practitioner analyses published across the spring and summer agree on what happened next: the self-assessment-and-post-to-SPRS duty did not vanish with 7019. It relocated onto the CMMC clause, DFARS 252.204-7021. At Level 1, that means self-assessing against the fifteen basic safeguarding requirements and posting the result to SPRS. At Level 2, it means all 110 requirements of NIST SP 800-171, posted to SPRS, with an annual affirmation by an authorized company official. DFARS 252.204-7012 — safeguarding plus 72-hour incident reporting — was not touched at all.

Now stack that on top of the Phase 2 pause. Two independent changes landed in the same clause neighborhood within months of each other: the third-party assessment requirement came out of the contract text, and the clause that used to carry the SPRS duty disappeared from the clause list. Read together by someone doing a quick file review, they look like evidence that the cyber requirements have been unwound. They have not been. What changed is who verifies and where it is written.

The reference you knowWhere it lives nowWhat you still owe
FAR 52.204-21 — basic safeguarding, 15 requirementsFAR 52.240-93The same fifteen requirements, still flowing down to subcontractors that handle FCI.
DFARS 252.204-7019 — offeror’s current assessment in SPRSEliminated; duty carried by DFARS 252.204-7021Self-assess at your contract’s CMMC level and keep a current score posted in SPRS.
DFARS 252.204-7020 — DoD assessment requirementsDFARS 252.240-7997Government-led medium and high assessments unchanged, including the 14-day window to rebut findings.
DFARS 252.204-7012 — safeguarding & incident reportingUnchangedNIST SP 800-171 implementation and a 72-hour report on any cyber incident.
DFARS 252.204-7021 / -7025 — CMMC level & affirmationIn force; third-party step pausedLevel 1 or Level 2 self-assessment plus the annual affirmation.

One practical wrinkle: contracts awarded before the deviations still carry the old numbers on their face, so for a while you are living with both sets. That is exactly why this is a documentation problem rather than a trivia question.

So what: your clause matrix is probably out of date, and an out-of-date clause matrix is how an organization ends up affirming something nobody verified. Pull every active contract and modification this week, write down which cybersecurity clause numbers each one actually cites, and map each citation to the obligation that is live today. Then confirm a current score is posted in SPRS at the right level. Deleting a clause number has never deleted a duty — it moved it, and the affirmation you sign is still a representation to the government.

Federal agencies spent late summer warning that the defense industrial base is being harvested at scale

On August 26, the FBI, the National Security Agency, and the Cyber National Mission Force issued a joint cybersecurity advisory on a China-linked operation tracked as QTFY (also QT and QTCYBER). The advisory names the Defense Industrial Base first among the sectors targeted, alongside communications, government, and higher education, and it publishes the actors’ tactics, infrastructure detail, and indicators of compromise drawn from real incident response. It is still on the Bureau’s current cyber alert list.

The same week, the Justice Department and the FBI seized the domains behind two linked platforms. QScan scanned the internet at scale for vulnerable internet-facing and connected devices. QTRouter then absorbed the compromised devices into an obfuscation network that masked where intrusions actually originated. Reporting on the takedown describes the group as selling this capability to customers including China’s Ministry of State Security and the People’s Liberation Army. The FBI’s San Diego field office and Cyber Division led the disruption with the U.S. Attorney’s Office for the Southern District of California.

Notice the shape of the tradecraft, because it is not the one most compliance programs are built around. It does not begin with a spear-phishing email to a program manager. It begins with an unpatched device that has a public IP address — an edge firewall, a VPN appliance, a camera, a piece of shop-floor equipment someone put on the internet to make remote support easier. Industrial-scale scanning finds it, and the same infrastructure that hides the intrusion is built out of other people’s neglected hardware.

Which is why the advisory’s mitigations read like a requirements list you have already been scored against: inventory and patch internet-facing systems, review public-facing applications, isolate critical systems, and hunt through your logs for the published indicators. Configuration management, vulnerability remediation, boundary protection, and system monitoring are four of the requirement families sitting behind your SPRS number right now.

So what: the assessment calendar paused this summer. The targeting did not, and the people doing the targeting are explicitly interested in the sector you sell into. This week, produce one list: every device in or adjacent to your CUI boundary that has a public IP address. Confirm each one is patched, monitored, and actually supposed to be exposed, then run the advisory’s indicators against your logs. If you find an internet-facing device sitting inside your CUI boundary, that is the most valuable finding you will make this month — and it is the kind of finding an assessor, a prime, or an adversary would have made for you.

The industry being “relieved” of CMMC is not asking to be relieved of it

One of the more useful correctives to the idea that the defense industrial base wants the requirement to go away is the industry’s own annual survey. Fielded in May 2026 by Merrill Research across 302 U.S. defense contractors — 195 primes, 118 subcontractors, 11 both — and published in August as the 2026 State of the Defense Industrial Base report, it points in a direction that is easy to miss in the headlines.

What the DIB said about itself: 90% said cybersecurity standards should be legally mandated. 74% asked for simpler implementation — not a lower bar. The average self-reported SPRS score reached +51, a five-year high, up from +33 a year earlier. Confidence in the accuracy of those scores fell to 65%, down from 89% the previous year and 94% in 2024. And 1% described themselves as completely prepared for certification.

Read those numbers next to each other and the actual industry position comes into focus: keep the mandate, make compliance cheaper to achieve — and, quietly, we are markedly less confident than we were that our own numbers would survive scrutiny. As Merrill Research CEO David M. Schneer put it, “Contractors are reporting higher SPRS scores and greater adoption of important cybersecurity capabilities, but confidence in the accuracy of those scores has fallen substantially.”

The report’s own framing is the sentence to keep: the challenge is “not simply how much contractors spend on cybersecurity, but how effectively those investments translate into implemented, sustainable and verifiable security.” That is not a request to remove verification. It is a request for a cheaper, more continuous form of it — which happens to be exactly the direction the Department has been signaling since the review began.

So what: don’t build next year’s budget on the assumption that reform lowers the bar. The constituency for lowering it is smaller than the coverage suggests — nine in ten of your peers want the mandate to stay. Build instead for a world where you are asked to demonstrate posture more often, with less notice, and in a form somebody outside your company can verify. That is a different capability from passing one audit every three years, and the organizations sitting in that 1% did not get there in a quarter.

What to do this week

The theme this issue: paperwork moved, obligations didn’t, and the threat never checked the rulemaking calendar.

  • Rebuild your clause matrix with both old and new numbers. FAR 52.204-21 / 52.240-93, DFARS 252.204-7019 (gone), 252.204-7020 / 252.240-7997, plus 7012, 7021, and 7025. One page, kept with the contract file.
  • Confirm a current SPRS score is posted at the right level. If anyone on your team concluded the obligation ended when 7019 did, correct that this week, in writing.
  • Inventory every internet-facing device in or near your CUI boundary. Patch it, monitor it, or take it off the internet — then run the August advisory’s indicators against your logs.
  • Decide by October 19 whether to comment on the FAR Overhaul’s second batch. Note that the CUI substance sits in the separate Part 40 rule, not in this batch.
  • Put tomorrow’s Cyber AB town hall and the October 29 NIST webinar on a real calendar. Name one person to circulate a one-page summary of each within 48 hours.

Quick hits

  • Sep 28, 2026
    Seventeen days after the review window closed, the Task Force recommendations are still not public.
    The signaled window has slipped from mid-September to late September or early October, and that window is now at its edge. Tomorrow’s Cyber AB town hall is the next scheduled forum where conclusions could surface. Planning around a date the Department has not committed to is the expensive option.
  • Sep 25, 2026
    Detailed analyses of FAR Overhaul batch two land — and find no new cyber or CUI requirements.
    Alerts from Wiley and from Bradley Arant Boult Cummings walk all sixteen parts of the four proposed rules published September 18. Neither identifies a new cybersecurity or CUI obligation; the changes are structural, in commercial acquisition (Part 12), negotiation (Part 15), and subcontracting (Part 44). Comments on FAR Case 2026-003 and its companions are due October 19.
  • Sep 28, 2026
    The FAR Part 40 CUI rule is now 67 days past its comment close with no final rule.
    This is the rule that would extend CUI safeguarding and NIST SP 800-171 across civilian agencies and lift the baseline to Revision 3. It has been open in this briefing since Issue 01. When it lands, it lands without a transition comment period.
  • Sep 2, 2026
    Federal funding is running on a stopgap through December 11, 2026.
    Final FY2027 decisions were pushed past the midterms. Every pending rule, review, and reform timetable now sits inside a window that ends at a budget deadline — so plan on operating under today’s requirements through year-end rather than a rewritten set.

Not sure where your organization stands?

CUI Vault gives you a live, always-audit-ready picture of your CUI environment and NIST 800-171 posture — so headlines like today’s are a footnote, not a fire drill. Reach out to your NtelSec team to talk through your current gaps.

This briefing is a general-information summary of publicly reported CMMC and CUI developments. It is not legal advice; consult your compliance counsel before making contractual or certification decisions.
Talk to us about CUI Vault All issues