Register:DFARS 252.2046 recordsSHA3-256 chainedSealed Amended head sha3:6483b586f764abf85ff090bb829e4d6b084707d33674f0a9cacca3c55ed55b57Intact

DFARS 252.204-7012 / 7019 / 7020 / 7021

DFARS compliance evidence for defense contractors.

DFARS 252.204-7012 safeguarding, 7019 SPRS assessment information, and 7020 government assessment rights remain while the CMMC Phase II rollout is suspended. PolicyCortex keeps one hash-chained evidence base for the NIST SP 800-171 Rev. 2 baseline behind all four clauses, inside your tenant, so the score you report and the package you hand over rest on rows anyone can recompute.

Request AccessBook a call

Access is reviewed. Scope and onboarding are agreed with your team.

REC 0000OBLIGATIONsha3-2567da8c5a4697d94ea175f50359238d3b5ce5d9348641f1990aa124bdeb020210eprev:662d7371e2d0

What the four clauses ask you to prove

Start with the clauses in your contract and the systems handling covered defense information. Flow-down obligations depend on the clause and subcontract scope. 7012 addresses safeguarding and requires reporting covered cyber incidents within 72 hours of discovery. 7019 requires a current NIST SP 800-171 assessment in SPRS where applicable. 7020 addresses government assessment access and support; the Basic assessment is your own. 7021 is the CMMC contract clause, whose Phase II transition the Department suspended on July 13, 2026 while Phase I self-assessments remain.

Every one of them is a question about the same environment. The evidence that answers 7012 is the evidence behind the 7019 score, is the evidence a 7020 assessment examines, is the package a 7021 assessment would receive.

7012
Safeguarding covered defense information under NIST SP 800-171; 72-hour cyber incident reporting to the DoD. Remains active.
7019
A current NIST SP 800-171 assessment in SPRS where required. The Basic assessment score starts at 110; weighted deductions for unmet requirements can make it negative.
7020
Assessment support at Medium and High; Basic is the self-assessment behind the SPRS score.
7021
The CMMC clause. Phase II transition suspended 2026-07-13; Phase I self-assessments remain in place.
dfars.source
Department of War release, July 13, 2026 (official release); the site's explainer: what changed and what to do.
dfars.handoff
The eMASS and C3PAO handoff package: what the assessor receives and how they verify it by hash.
REC 0001EVIDENCEsha3-2569ce73b1ebb4608c710cf77b45a49a9119bf552fa40d0e874355b43bae2e27ccdprev:7da8c5a4697d

The evidence behind all four clauses

One evidence base for the NIST SP 800-171 Rev. 2 baseline, projected into every clause. Where each proof files:

7012 · safeguards
Proof of state: the configuration that satisfies each of the 110 requirements, captured from the provider APIs, content hashed, regenerable to any date.
7019 · SPRS
SPRS-relevant evidence carried per requirement, so the score you report is a projection of rows, not a spreadsheet estimate.
7020 · assessment
The chain itself: a government assessor at Medium or High can recompute the records and confirm nothing was edited after the fact.
7021 · CMMC
The same rows as OSCAL 1.1.2 with an eMASS and C3PAO handoff package, for whichever assessment model the reform review settles on.
Change and agency
Proof of change and proof of agency: who or what altered a CUI-scope resource, under what authority, and what any machine was permitted to do before it acted.
Exhibit SB-6gap analysis, as shipped
The PolicyCortex gap analysis: open compliance gaps stacked by control family and severity, each with framework, environment, days open, and owner

Exhibit SB-6 · open gaps by control family and severity, each with framework, environment, days open, and owner. Declared, not hidden. Illustrative demo data; the interface is real.

REC 0002VERIFICATIONsha3-256828055987eb84b637b60679f2084921ac13609a894a90154f97c4cdf2dfb5becprev:9ce73b1ebb46

How a 7020 assessor verifies the record

A government assessor at Medium or High recomputes the same chain your Basic self-assessment and SPRS score were projected from, so the 7019 number and the 7020 assessment cannot describe two different environments.

Every record PolicyCortex writes for this obligation is content hashed with SHA3-256 and carries the digest of the record before it, so each line commits to the entire history above it. The log is append only: a correction is a new record, never an edit. Verification is a recomputation, not an assertion. Run the chain from the first record forward and it returns one of two answers: intact, or the sequence number of the first record that breaks.

A second party can do that recomputation without our help. The records, the digests, and the chain rule are everything required: no PolicyCortex account, no API of ours in the loop. When a collector was down or a scope was unobserved, the chain carries a declared gap with the interval and the reason, never silently fewer rows. Absence is declared, not inferred.

REC 0003EVALUATIONsha3-25641602bebef900a84877c938aa447c726c2141472b1dbc0f5d1e72c1426fbe82dprev:828055987eb8

Access and scope for the clauses you carry

Read-only onboarding is scoped to the NIST SP 800-171 Rev. 2 baseline behind 7012. Captured evidence supplies the rows behind a 7019 score, with digests that can be recomputed.

Request access so we can review your environment, evidence needs, and onboarding scope. After access is approved, read-only onboarding uses SHADOW mode inside your own tenant. Nothing executes. Policy evaluation, evidence collection, and action gating run where your data already is; there is no telemetry pipeline to PolicyCortex servers and no egress of evidence. You hold the records and can recompute the chain yourself.

eval.mode
SHADOW. Watch only; nothing executes.
eval.onboarding
Access is reviewed. Scope and onboarding are agreed with your team.
eval.location
Your tenant. Azure, AWS, and GCP are observed clouds, including AWS GovCloud, Azure Government, and GCC High.
eval.egress
None. No telemetry pipeline to PolicyCortex servers; no evidence leaves the tenant.
eval.after
You keep the records. Licensing is annual and the tenant owns the evidence; a delivery engagement is optional.
REC 0004DELIVERYsha3-256697df2f518700d3bff4f4ea8b3dff8824e476b33303bc2f002ac968d395119f1prev:41602bebef90

Delivery, if you want the record stood up for you

If you want the record stood up for you, the delivery engagement is 30 days at a fixed fee: $15,000 flat for the standard scope, one primary cloud environment. A cleared delivery team collects the evidence, writes the policies and assessment documents, coordinates approved technical remediation, prepares control owners, and stays through assessor review for in-scope follow-up at no additional cost. The independent assessor makes the certification decision. No certification is guaranteed.

engagement.price
$15,000 flat for the standard engagement scope. No hourly, no overages.
engagement.scope
30 days. One primary cloud environment. NIST SP 800-171 Rev. 2, 110 requirements.
engagement.package
SSP, POA&M, OSCAL 1.1.2 bundle, and the evidence behind them, organized by control objective.
engagement.review
In-scope assessor follow-up is included. The C3PAO remains independent and makes the decision.

Every term of the engagement, on its own page.

REC 0005QUESTIONSsha3-2566483b586f764abf85ff090bb829e4d6b084707d33674f0a9cacca3c55ed55b57prev:697df2f51870

Questions assessors and buyers ask

What is the difference between 7012 and 7021?

7012 requires contractors to safeguard covered defense information using NIST SP 800-171 and remains active. 7021 is the CMMC contract clause. The Department suspended the Phase II transition and future CMMC implementation milestones on July 13, 2026, while keeping Phase I self-assessments in place.

What is a good SPRS score?

A fully implemented NIST SP 800-171 Rev. 2 baseline scores 110 under the Basic Assessment methodology. Unmet requirements carry weighted deductions, so a lower score can be positive, zero, or negative. Report the score supported by your implementation evidence and the applicable assessment methodology.

What about 72-hour incident reporting?

DFARS 7012 requires reporting cyber incidents involving CUI within 72 hours. Proof of change and proof of state give the incident record its timeline: what the environment was, what changed it, and when. The report itself is yours to make.

Do the clauses flow down to subcontractors?

Flow-down obligations depend on the specific clause and subcontract scope. DFARS 252.204-7012 requires flow-down for subcontracts involving covered defense information or operationally critical support. Review the clauses in your contract and the information your subcontractors handle before determining their obligations.

Does PolicyCortex make us compliant?

No. It produces the records compliance decisions rest on. The authorizing official, the C3PAO, or the accountable official makes the determination; PolicyCortex hands them evidence they can recompute instead of a narrative they have to believe.

What happens when a collector is down?

The chain carries a declared gap: the stream, the interval, the reason, and when it was declared. Evidence never silently has fewer rows.

Four clauses. One record the assessor can recompute.

Register colophonRecomputable by a second party
SeqLabelSHA3-256Prev
REC 0000OBLIGATION7da8c5a4697d662d7371e2d0
REC 0001EVIDENCE9ce73b1ebb467da8c5a4697d
REC 0002VERIFICATION828055987eb89ce73b1ebb46
REC 0003EVALUATION41602bebef90828055987eb8
REC 0004DELIVERY697df2f5187041602bebef90
REC 0005QUESTIONS6483b586f764697df2f51870

The record headers on this page are SHA3-256 digests of this page's own copy, chained in sequence from a fixed genesis value. Edit one word of any record's copy above and every digest after it changes. Head of chain: sha3:6483b586f764. The product does the same thing to your evidence.

Photograph: Joshua Stevens, NASA Earth Observatory, with Landsat data from the U.S. Geological Survey, Public domain (NASA, 17 U.S.C. 105). Source