· DFARS  · 6 min read

DFARS 252.204-7019 and 7020: The SPRS Self-Assessment Cycle

DoD removed DFARS 252.204-7019 and renumbered 252.204-7020, but the NIST SP 800-171 assessment and SPRS scoring cycle continues under CMMC and current contract clauses, so contractors need a clear, defensible approach to scoring, posting, and flowdown.

DoD removed DFARS 252.204-7019 and renumbered 252.204-7020, but the NIST SP 800-171 assessment and SPRS scoring cycle continues under CMMC and current contract clauses, so contractors need a clear, defensible approach to scoring, posting, and flowdown.

DoD changed the DFARS stack that anchored SPRS self-assessments on February 1, 2026. DFARS 252.204-7019 dropped out, and DFARS 252.204-7020 moved under a new number. The SPRS cycle did not go away. You still need an accurate NIST SP 800-171 assessment and a defendable score in the Supplier Performance Risk System when the solicitation or clause set calls for it.

DFARS 252.204-7019 set the SPRS posting rule

DFARS 252.204-7019, Notice of NIST SP 800-171 DoD Assessment Requirements, tied proposal eligibility to current assessment results in SPRS. DFARS used NIST SP 800-171 as the baseline and told offerors to post the current DoD Assessment result for the system that supports the contract. The clause framed a Basic self-assessment as current for a three-year window unless the solicitation or contract stated a shorter period. Acquisition officials used SPRS during source selection to confirm the posting.

That requirement created a cycle. You scored your environment against 800-171, recorded the score and required metadata, and posted it to SPRS before offer submission. When you changed scope, closed POA&M items, or crossed the currency window, you updated the posting. You aligned the posting to the CAGE code and the enclave that supported the work.

DFARS 252.204-7020 defined DoD Medium and High assessments

DFARS 252.204-7020, NIST SP 800-171 DoD Assessment Requirements, addressed government-led reviews. The clause required contractors to give DoD access to facilities, systems, and personnel to conduct Medium or High assessments. It also forced prime contractors to ensure applicable subcontractors had a current result in SPRS before subcontract award.

This structure created two enforcement touchpoints. Contracting officers could verify you posted a current score. The Defense Contract Management Agency or another DoD team could perform an onsite or virtual Medium or High assessment and update the score in SPRS. The flowdown language put the same expectation on suppliers that touch the same Controlled Unclassified Information.

SPRS score content and update cadence

SPRS holds a composite score and key dates that tell a contracting officer how recent and how defensible your assessment is. You map a score to a system or enclave and a System Security Plan (SSP), and you include the SSP date, the assessment date, and a target date to complete open POA&M items. You also identify the CAGE code that aligns to the work.

The three-year currency window in DFARS 252.204-7019 defined the refresh cycle for Basic assessments under that clause set. Medium and High assessments by DoD teams could update the score and reset the clock. Contract language can set a shorter window. You should plan updates around material SSP changes, enclave boundary changes, POA&M closures that move the score, and solicitation requirements. Use SPRS scoring mechanics and SSP documentation practices that you can defend during a Medium or High review.

February 2026 changes to 7019 and 7020

DoD issued changes effective February 1, 2026 that removed DFARS 252.204-7019 and renumbered 252.204-7020 to 252.240-7997. Practitioner briefings describe a refocus of the clause language on DoD-led assessments and continued use of SPRS for results, with the standalone Basic self-assessment posting obligation no longer housed in the old 7019 and 7020 slots. Treat each active solicitation and award as the source of truth. Pull the current clause text on Acquisition.gov and confirm what your contract requires before you change internal processes.

The practical effect for most contractors looks straightforward. You still need an accurate 800-171 assessment, a score that matches the state of your controls, and timely updates that reflect POA&M progress. You still need flowdown language and a way to verify supplier status when the work involves CUI. Contracting officers still rely on SPRS to see assessment status.

SPRS self-assessment under CMMC today

CMMC aligns the assessment model to NIST SP 800-171 for Level 2 work. DFARS 252.204-7021 ties eligibility to CMMC. DoD uses SPRS as the system of record for assessment results. You should expect solicitations and awards that reference CMMC to direct you to maintain an SPRS score that matches your claimed posture and assessment status.

Plan the cycle around your assessment events.

  • Use your CMMC readiness or formal assessment to drive an SPRS update that reflects the implemented controls and open POA&M items.
  • Align the SPRS scope to the enclave that processes CUI for the work, and keep the SSP and diagrams current.

The same logic applies to your supply chain. When the prime contract includes CUI, require applicable subcontractors to show a current assessment and score in SPRS before award, and require updates when their scope or posture changes. Document the check and keep it with your subcontract file. If a DoD team schedules a Medium or High assessment, prepare to walk through control implementation evidence in the enclave that supports the contract. Keep POA&M items grounded in 800-171 requirements and move them with real remediation, not paper adjustments. If you need a method to plan and prove POA&M burn-down, see our guidance on POA&M management.

Prime and subcontract implementation steps

Treat this as an operational process, not a one-time event.

  • For primes, standardize how you scope enclaves, map CAGE codes, and post to SPRS. Build a pre-award check that confirms currency against the contract requirement.
  • For subs, include the clause set in the solicitation and purchase order, and require an SPRS screenshot or letter that shows the current score and dates before award.

Tie procurement to the security program. Your security team owns the control implementation, SSP updates, and POA&M burn-down. Your contracts team owns clause interpretation and flowdown. Your capture team owns pre-award checks and proposal assertions. Run a short gate where all three groups confirm the exact clause requirements and the current SPRS posting before bid or award.

Microsoft platform context

Microsoft documents how Azure and Microsoft 365 offerings support contractors that must address DFARS cybersecurity clauses, including the clauses that reference NIST SP 800-171 assessments and SPRS. Use those platform capabilities to implement controls, collect evidence, and produce the documentation that supports your assessment and score. A cloud platform does not confer compliance by itself, and no vendor can guarantee your outcome. Your program, your controls, and your documentation drive your score and your eligibility. Microsoft publishes an overview for DFARS customers that helps you align features and artifacts to clause requirements.

What to watch next

Monitor the clause text on Acquisition.gov and your solicitations. Expect SPRS to remain the system of record for 800-171 assessment results tied to contract eligibility and performance. Keep your SSPs and POA&Ms current. Train capture and subcontracts staff on clause reading and evidence expectations. Align your assessment calendar to real contract milestones and DoD reviews.

If you need a refresher on DFARS 252.204-7012 and its incident reporting and cloud requirements that sit alongside these assessment clauses, review our post on DFARS 252.204-7012. If you need a control-level view of CMMC Level 2 against NIST SP 800-171, see our Level 2 mapping.

Sources

DFARS 252.204-7019 — Notice of NIST SP 800-171 DoD Assessment Requirements (Acquisition.gov) DFARS 252.204-7020 — NIST SP 800-171 DoD Assessment Requirements (Acquisition.gov) DFARS compliance offerings for Azure and Microsoft 365 (Microsoft)

Want a structured starting point?

Our 27-question CMMC technical readiness self-survey covers tenant, identity, endpoint, data protection, audit logging, documentation, and the 72-hour DFARS reporting plan. The score is produced in your browser from your answers alone. Nothing is verified or stored.

Back to Blog

Related Posts

View All Posts »
Incident Response Playbooks for DFARS 7012 Reporting

Incident Response Playbooks for DFARS 7012 Reporting

A DFARS 252.204-7012 playbook directs fast triage, evidence preservation, DIBNet reporting, and DC3 malware submission, mapped to NIST SP 800-171 incident response controls and grounded in your Microsoft cloud footing.