sha3:6483b586f764abf85ff090bb829e4d6b084707d33674f0a9cacca3c55ed55b57IntactDFARS 252.204-7012 / 7019 / 7020 / 7021
DFARS compliance evidence for defense contractors.
DFARS 252.204-7012 safeguarding, 7019 SPRS assessment information, and 7020 government assessment rights remain while the CMMC Phase II rollout is suspended. PolicyCortex keeps one hash-chained evidence base for the NIST SP 800-171 Rev. 2 baseline behind all four clauses, inside your tenant, so the score you report and the package you hand over rest on rows anyone can recompute.
7da8c5a4697d94ea175f50359238d3b5ce5d9348641f1990aa124bdeb020210eprev:662d7371e2d0What the four clauses ask you to prove
Start with the clauses in your contract and the systems handling covered defense information. Flow-down obligations depend on the clause and subcontract scope. 7012 addresses safeguarding and requires reporting covered cyber incidents within 72 hours of discovery. 7019 requires a current NIST SP 800-171 assessment in SPRS where applicable. 7020 addresses government assessment access and support; the Basic assessment is your own. 7021 is the CMMC contract clause, whose Phase II transition the Department suspended on July 13, 2026 while Phase I self-assessments remain.
Every one of them is a question about the same environment. The evidence that answers 7012 is the evidence behind the 7019 score, is the evidence a 7020 assessment examines, is the package a 7021 assessment would receive.
- 7012
- Safeguarding covered defense information under NIST SP 800-171; 72-hour cyber incident reporting to the DoD. Remains active.
- 7019
- A current NIST SP 800-171 assessment in SPRS where required. The Basic assessment score starts at 110; weighted deductions for unmet requirements can make it negative.
- 7020
- Assessment support at Medium and High; Basic is the self-assessment behind the SPRS score.
- 7021
- The CMMC clause. Phase II transition suspended 2026-07-13; Phase I self-assessments remain in place.
- dfars.source
- Department of War release, July 13, 2026 (official release); the site's explainer: what changed and what to do.
- dfars.handoff
- The eMASS and C3PAO handoff package: what the assessor receives and how they verify it by hash.
9ce73b1ebb4608c710cf77b45a49a9119bf552fa40d0e874355b43bae2e27ccdprev:7da8c5a4697dThe evidence behind all four clauses
One evidence base for the NIST SP 800-171 Rev. 2 baseline, projected into every clause. Where each proof files:
- 7012 · safeguards
- Proof of state: the configuration that satisfies each of the 110 requirements, captured from the provider APIs, content hashed, regenerable to any date.
- 7019 · SPRS
- SPRS-relevant evidence carried per requirement, so the score you report is a projection of rows, not a spreadsheet estimate.
- 7020 · assessment
- The chain itself: a government assessor at Medium or High can recompute the records and confirm nothing was edited after the fact.
- 7021 · CMMC
- The same rows as OSCAL 1.1.2 with an eMASS and C3PAO handoff package, for whichever assessment model the reform review settles on.
- Change and agency
- Proof of change and proof of agency: who or what altered a CUI-scope resource, under what authority, and what any machine was permitted to do before it acted.

Exhibit SB-6 · open gaps by control family and severity, each with framework, environment, days open, and owner. Declared, not hidden. Illustrative demo data; the interface is real.
828055987eb84b637b60679f2084921ac13609a894a90154f97c4cdf2dfb5becprev:9ce73b1ebb46How a 7020 assessor verifies the record
A government assessor at Medium or High recomputes the same chain your Basic self-assessment and SPRS score were projected from, so the 7019 number and the 7020 assessment cannot describe two different environments.
Every record PolicyCortex writes for this obligation is content hashed with SHA3-256 and carries the digest of the record before it, so each line commits to the entire history above it. The log is append only: a correction is a new record, never an edit. Verification is a recomputation, not an assertion. Run the chain from the first record forward and it returns one of two answers: intact, or the sequence number of the first record that breaks.
A second party can do that recomputation without our help. The records, the digests, and the chain rule are everything required: no PolicyCortex account, no API of ours in the loop. When a collector was down or a scope was unobserved, the chain carries a declared gap with the interval and the reason, never silently fewer rows. Absence is declared, not inferred.
41602bebef900a84877c938aa447c726c2141472b1dbc0f5d1e72c1426fbe82dprev:828055987eb8Access and scope for the clauses you carry
Read-only onboarding is scoped to the NIST SP 800-171 Rev. 2 baseline behind 7012. Captured evidence supplies the rows behind a 7019 score, with digests that can be recomputed.
Request access so we can review your environment, evidence needs, and onboarding scope. After access is approved, read-only onboarding uses SHADOW mode inside your own tenant. Nothing executes. Policy evaluation, evidence collection, and action gating run where your data already is; there is no telemetry pipeline to PolicyCortex servers and no egress of evidence. You hold the records and can recompute the chain yourself.
- eval.mode
- SHADOW. Watch only; nothing executes.
- eval.onboarding
- Access is reviewed. Scope and onboarding are agreed with your team.
- eval.location
- Your tenant. Azure, AWS, and GCP are observed clouds, including AWS GovCloud, Azure Government, and GCC High.
- eval.egress
- None. No telemetry pipeline to PolicyCortex servers; no evidence leaves the tenant.
- eval.after
- You keep the records. Licensing is annual and the tenant owns the evidence; a delivery engagement is optional.
697df2f518700d3bff4f4ea8b3dff8824e476b33303bc2f002ac968d395119f1prev:41602bebef90Delivery, if you want the record stood up for you
If you want the record stood up for you, the delivery engagement is 30 days at a fixed fee: $15,000 flat for the standard scope, one primary cloud environment. A cleared delivery team collects the evidence, writes the policies and assessment documents, coordinates approved technical remediation, prepares control owners, and stays through assessor review for in-scope follow-up at no additional cost. The independent assessor makes the certification decision. No certification is guaranteed.
- engagement.price
- $15,000 flat for the standard engagement scope. No hourly, no overages.
- engagement.scope
- 30 days. One primary cloud environment. NIST SP 800-171 Rev. 2, 110 requirements.
- engagement.package
- SSP, POA&M, OSCAL 1.1.2 bundle, and the evidence behind them, organized by control objective.
- engagement.review
- In-scope assessor follow-up is included. The C3PAO remains independent and makes the decision.
6483b586f764abf85ff090bb829e4d6b084707d33674f0a9cacca3c55ed55b57prev:697df2f51870Questions assessors and buyers ask
What is the difference between 7012 and 7021?
7012 requires contractors to safeguard covered defense information using NIST SP 800-171 and remains active. 7021 is the CMMC contract clause. The Department suspended the Phase II transition and future CMMC implementation milestones on July 13, 2026, while keeping Phase I self-assessments in place.
What is a good SPRS score?
A fully implemented NIST SP 800-171 Rev. 2 baseline scores 110 under the Basic Assessment methodology. Unmet requirements carry weighted deductions, so a lower score can be positive, zero, or negative. Report the score supported by your implementation evidence and the applicable assessment methodology.
What about 72-hour incident reporting?
DFARS 7012 requires reporting cyber incidents involving CUI within 72 hours. Proof of change and proof of state give the incident record its timeline: what the environment was, what changed it, and when. The report itself is yours to make.
Do the clauses flow down to subcontractors?
Flow-down obligations depend on the specific clause and subcontract scope. DFARS 252.204-7012 requires flow-down for subcontracts involving covered defense information or operationally critical support. Review the clauses in your contract and the information your subcontractors handle before determining their obligations.
Does PolicyCortex make us compliant?
No. It produces the records compliance decisions rest on. The authorizing official, the C3PAO, or the accountable official makes the determination; PolicyCortex hands them evidence they can recompute instead of a narrative they have to believe.
What happens when a collector is down?
The chain carries a declared gap: the stream, the interval, the reason, and when it was declared. Evidence never silently has fewer rows.
Four clauses. One record the assessor can recompute.