DFARS 252.204-7021 is one of the three clauses in the DFARS 70 series. DFARS 7021 is a guiding requirement for use in solicitations and contracts. The DFARS 7021 clause of CMMC requires DoD contractors to maintain their appropriate CMMC level with respect to each contract, while also ensuring any subcontractors are in compliance with the same CMMC level; this will be required for the duration of the contract and must be reassessed every 3 years.
The Cybersecurity Maturity Model Certification (CMMC) is a framework with the objective of securing federal contract information (FCI) and controlled unclassified information (CUI) that is stored, processed, or transmitted by defense contractors and the entire defense industrial base (DIB). CMMC builds on the existing NIST SP 800-171 requirements.
At a minimum, every DoD contractor must meet DFARS 7020 which requires the entity to enter a current assessment score into the Supplier Performance Risk System (SPRS). The SPRS score must be reported annually and is the result of a NIST SP 800-171 gap assessment.
The Cybersecurity Maturity Model Certification 2.0 (CMMC 2.0) requirements are now introduced into the federal regulatory framework with the addition of DFARS 7021.