FAR and DFARS › DFARS Part 204: Administrative and Information Matters › Subpart 204.75
DFARS 204.7504 Solicitation provision and contract clause.
The codified text (eCFR, as of 2026-10-02). Under the Revolutionary FAR Overhaul ↗, agencies follow class deviations with new text for many parts while the formal rules go through the Federal Register: check the solicitation and your contract's clauses, which rule.
In plain English
This section tells contracting officers when to include the CMMC compliance clause (252.204-7021) and the related notice provision (252.204-7025) in solicitations and contracts. It sets different inclusion rules before and after November 10, 2028, and generally excludes contracts solely for COTS items. If your contract includes the clause, you must meet the specified CMMC level.
Applies to: Solicitations and contracts, task orders, or delivery orders where the program office or requiring activity makes the stated determination
What it requires
- Comply with the Cybersecurity Maturity Model Certification Level Requirements when the clause at 252.204-7021 is included in your contract
Key terms: CMMC level · 252.204-7021 · 252.204-7025 · COTS items · FCI
Written by AI from this section's text. A guide, not legal advice: the text below rules.
The text
(a) Unless the requirements at 32 CFR 170.5(d) are met, use the clause at 252.204-7021, Contractor Compliance with the Cybersecurity Maturity Model Certification Level Requirements, as follows:
(1) Until November 9, 2028, in solicitations and contracts, task orders, or delivery orders, including those using FAR part 12 procedures for the acquisition of commercial products and commercial services, except for those solely for the acquisition of commercially available off-the-shelf (COTS) items, if the program office or requiring activity determines that the contractor is required to have a specific CMMC level.
(2) On or after November 10, 2028, in solicitations and contracts, task orders, or delivery orders, including those using FAR part 12 procedures for the acquisition of commercial products and commercial services, except for those solely for the acquisition of COTS items, if the program office or requiring activity determines that the contractor is required to use contractor information systems in the performance of the contract, task order, or delivery order to process, store, or transmit FCI or CUI.
(b) Use the provision at 252.204-7025, Notice of Cybersecurity Maturity Model Certification Level Requirements, in solicitations that include the clause at 252.204-7021.
Sections it refers to
- 252.204-7021 Contractor Compliance With the Cybersecurity Maturity Model Certification Level Requirements.
- 252.204-7025 Notice of Cybersecurity Maturity Model Certification Level Requirements.
Sections that refer to it
- 204.7503 Procedures.
- 212.301 Solicitation provisions and contract clauses for the acquisition of commercial products and commercial services.
- 252.204-7021 Contractor Compliance With the Cybersecurity Maturity Model Certification Level Requirements.
- 252.204-7025 Notice of Cybersecurity Maturity Model Certification Level Requirements.
← 204.7503 Procedures. · 204.7600 Scope of subpart. →
Rule changes for DFARS Part 204
- Defense Federal Acquisition Regulation Supplement: Assessing Contractor Implementation of Cybersecurity Requirements (DFARS Case 2019-D041) ↗ · final rule 2025-09-10 · effective 2025-11-10
- Defense Federal Acquisition Regulation Supplement: Inapplicability of Additional Defense-Unique Laws and Certain Non-Statutory DFARS Clauses to Commercial Item Contracts (DFARS Case 2018-D074) ↗ · final rule 2024-11-15 · effective 2024-11-25
- Defense Federal Acquisition Regulation Supplement; Technical Amendments ↗ · final rule 2024-09-26 · effective 2024-10-01
- Defense Federal Acquisition Regulation Supplement: Data Universal Numbering System to Unique Entity Identifier Transition (DFARS Case 2022-D023) ↗ · final rule 2024-09-26 · effective 2024-10-01
- Defense Federal Acquisition Regulation Supplement: Modification of Notification of Intent To Transport Supplies by Sea (DFARS Case 2020-D026) ↗ · final rule 2024-09-26 · effective 2024-10-01
- Defense Federal Acquisition Regulation Supplement: Assessing Contractor Implementation of Cybersecurity Requirements (DFARS Case 2019-D041) ↗ · proposed 2024-08-15 · comments due 2024-10-15
- Defense Federal Acquisition Regulation Supplement; Technical Amendments ↗ · final rule 2024-07-29 · effective 2024-07-29
- Defense Federal Acquisition Regulation Supplement: Modification of Notification of Intent To Transport Supplies by Sea (DFARS Case 2020-D026) ↗ · proposed 2024-03-26 · comments due 2024-05-28
Source: eCFR, 48 CFR chapters 1 and 2 (GPO GovInfo bulk data) ↗. Plain words for the terms: glossary.