Two of the DFARS cybersecurity clauses your contracts have cited for five years no longer exist under their old numbers. The self-assessment and SPRS duties they carried are still yours. Anyone auditing a contract file by clause number is about to reach the wrong conclusion.
Here is a quiet problem worth ten minutes of your week. The Revolutionary FAR Overhaul class deviations took effect on February 1, 2026, and among the things they rewired was the numbering of the cybersecurity clauses everyone in the defense industrial base has memorized.
DFARS 252.204-7019 — the provision that told offerors they needed a current NIST SP 800-171 assessment posted in SPRS — was eliminated outright. DFARS 252.204-7020 was renumbered to DFARS 252.240-7997, keeping its title, NIST SP 800-171 DoD Assessment Requirements. On the civilian side, the basic safeguarding clause moved from FAR 52.204-21 to FAR 52.240-93, with the same fifteen requirements inside it.
Practitioner analyses published across the spring and summer agree on what happened next: the self-assessment-and-post-to-SPRS duty did not vanish with 7019. It relocated onto the CMMC clause, DFARS 252.204-7021. At Level 1, that means self-assessing against the fifteen basic safeguarding requirements and posting the result to SPRS. At Level 2, it means all 110 requirements of NIST SP 800-171, posted to SPRS, with an annual affirmation by an authorized company official. DFARS 252.204-7012 — safeguarding plus 72-hour incident reporting — was not touched at all.
Now stack that on top of the Phase 2 pause. Two independent changes landed in the same clause neighborhood within months of each other: the third-party assessment requirement came out of the contract text, and the clause that used to carry the SPRS duty disappeared from the clause list. Read together by someone doing a quick file review, they look like evidence that the cyber requirements have been unwound. They have not been. What changed is who verifies and where it is written.
| The reference you know | Where it lives now | What you still owe |
|---|---|---|
| FAR 52.204-21 — basic safeguarding, 15 requirements | FAR 52.240-93 | The same fifteen requirements, still flowing down to subcontractors that handle FCI. |
| DFARS 252.204-7019 — offeror’s current assessment in SPRS | Eliminated; duty carried by DFARS 252.204-7021 | Self-assess at your contract’s CMMC level and keep a current score posted in SPRS. |
| DFARS 252.204-7020 — DoD assessment requirements | DFARS 252.240-7997 | Government-led medium and high assessments unchanged, including the 14-day window to rebut findings. |
| DFARS 252.204-7012 — safeguarding & incident reporting | Unchanged | NIST SP 800-171 implementation and a 72-hour report on any cyber incident. |
| DFARS 252.204-7021 / -7025 — CMMC level & affirmation | In force; third-party step paused | Level 1 or Level 2 self-assessment plus the annual affirmation. |
One practical wrinkle: contracts awarded before the deviations still carry the old numbers on their face, so for a while you are living with both sets. That is exactly why this is a documentation problem rather than a trivia question.
Federal agencies spent late summer warning that the defense industrial base is being harvested at scale
On August 26, the FBI, the National Security Agency, and the Cyber National Mission Force issued a joint cybersecurity advisory on a China-linked operation tracked as QTFY (also QT and QTCYBER). The advisory names the Defense Industrial Base first among the sectors targeted, alongside communications, government, and higher education, and it publishes the actors’ tactics, infrastructure detail, and indicators of compromise drawn from real incident response. It is still on the Bureau’s current cyber alert list.
The same week, the Justice Department and the FBI seized the domains behind two linked platforms. QScan scanned the internet at scale for vulnerable internet-facing and connected devices. QTRouter then absorbed the compromised devices into an obfuscation network that masked where intrusions actually originated. Reporting on the takedown describes the group as selling this capability to customers including China’s Ministry of State Security and the People’s Liberation Army. The FBI’s San Diego field office and Cyber Division led the disruption with the U.S. Attorney’s Office for the Southern District of California.
Notice the shape of the tradecraft, because it is not the one most compliance programs are built around. It does not begin with a spear-phishing email to a program manager. It begins with an unpatched device that has a public IP address — an edge firewall, a VPN appliance, a camera, a piece of shop-floor equipment someone put on the internet to make remote support easier. Industrial-scale scanning finds it, and the same infrastructure that hides the intrusion is built out of other people’s neglected hardware.
Which is why the advisory’s mitigations read like a requirements list you have already been scored against: inventory and patch internet-facing systems, review public-facing applications, isolate critical systems, and hunt through your logs for the published indicators. Configuration management, vulnerability remediation, boundary protection, and system monitoring are four of the requirement families sitting behind your SPRS number right now.
The industry being “relieved” of CMMC is not asking to be relieved of it
One of the more useful correctives to the idea that the defense industrial base wants the requirement to go away is the industry’s own annual survey. Fielded in May 2026 by Merrill Research across 302 U.S. defense contractors — 195 primes, 118 subcontractors, 11 both — and published in August as the 2026 State of the Defense Industrial Base report, it points in a direction that is easy to miss in the headlines.
Read those numbers next to each other and the actual industry position comes into focus: keep the mandate, make compliance cheaper to achieve — and, quietly, we are markedly less confident than we were that our own numbers would survive scrutiny. As Merrill Research CEO David M. Schneer put it, “Contractors are reporting higher SPRS scores and greater adoption of important cybersecurity capabilities, but confidence in the accuracy of those scores has fallen substantially.”
The report’s own framing is the sentence to keep: the challenge is “not simply how much contractors spend on cybersecurity, but how effectively those investments translate into implemented, sustainable and verifiable security.” That is not a request to remove verification. It is a request for a cheaper, more continuous form of it — which happens to be exactly the direction the Department has been signaling since the review began.
What to do this week
The theme this issue: paperwork moved, obligations didn’t, and the threat never checked the rulemaking calendar.
- Rebuild your clause matrix with both old and new numbers. FAR 52.204-21 / 52.240-93, DFARS 252.204-7019 (gone), 252.204-7020 / 252.240-7997, plus 7012, 7021, and 7025. One page, kept with the contract file.
- Confirm a current SPRS score is posted at the right level. If anyone on your team concluded the obligation ended when 7019 did, correct that this week, in writing.
- Inventory every internet-facing device in or near your CUI boundary. Patch it, monitor it, or take it off the internet — then run the August advisory’s indicators against your logs.
- Decide by October 19 whether to comment on the FAR Overhaul’s second batch. Note that the CUI substance sits in the separate Part 40 rule, not in this batch.
- Put tomorrow’s Cyber AB town hall and the October 29 NIST webinar on a real calendar. Name one person to circulate a one-page summary of each within 48 hours.
Quick hits
- Sep 28, 2026Seventeen days after the review window closed, the Task Force recommendations are still not public.The signaled window has slipped from mid-September to late September or early October, and that window is now at its edge. Tomorrow’s Cyber AB town hall is the next scheduled forum where conclusions could surface. Planning around a date the Department has not committed to is the expensive option.
- Sep 25, 2026Detailed analyses of FAR Overhaul batch two land — and find no new cyber or CUI requirements.Alerts from Wiley and from Bradley Arant Boult Cummings walk all sixteen parts of the four proposed rules published September 18. Neither identifies a new cybersecurity or CUI obligation; the changes are structural, in commercial acquisition (Part 12), negotiation (Part 15), and subcontracting (Part 44). Comments on FAR Case 2026-003 and its companions are due October 19.
- Sep 28, 2026The FAR Part 40 CUI rule is now 67 days past its comment close with no final rule.This is the rule that would extend CUI safeguarding and NIST SP 800-171 across civilian agencies and lift the baseline to Revision 3. It has been open in this briefing since Issue 01. When it lands, it lands without a transition comment period.
- Sep 2, 2026Federal funding is running on a stopgap through December 11, 2026.Final FY2027 decisions were pushed past the midterms. Every pending rule, review, and reform timetable now sits inside a window that ends at a budget deadline — so plan on operating under today’s requirements through year-end rather than a rewritten set.
Not sure where your organization stands?
CUI Vault gives you a live, always-audit-ready picture of your CUI environment and NIST 800-171 posture — so headlines like today’s are a footnote, not a fire drill. Reach out to your NtelSec team to talk through your current gaps.
