Skip to content
COOEY
REGULATORY LIBRARY
98 docs in this shelf

The load-bearing documents for a DIB program — CMMC / DFARS regulatory text (eCFR), federal rulemaking, NIST publications and OIRA review — organized as a library. Pick a document; the reader shows the dex dossier: what it says, why it matters, and the concrete obligations it imposes. Originals open at the source.

DIRECTORY_TREE
CMMC / DFARS · eCFR 98
DFARS 252.204 (cyber clauses): 252.204-7011 [Reserved] amended 2018-05-30 2018-05-30 · ecfr-amendment DFARS 252.204 (cyber clauses): 252.204-7004 [Reserved] amended 2018-05-30 2018-05-30 · ecfr-amendment DFARS 252.204 (cyber clauses): 252.204-7009 Limitations on the use or disclosure of third-party contractor reported cyber incident information. amended 2016-12-22 2016-12-22 · ecfr-amendment DFARS 252.204 (cyber clauses): 252.204-7010 Requirement for Contractor To Notify DoD if the Contractor's Activities are Subject to Reporting Under the U.S.-International Atomic Energy Agency Additional Protocol. amended 2016-12-22 2016-12-22 · ecfr-amendment DFARS 252.204 (cyber clauses): 252.204-7011 Alternative Line Item Structure. amended 2016-12-22 2016-12-22 · ecfr-amendment DFARS 252.204 (cyber clauses): 252.204-7012 Safeguarding covered defense information and cyber incident reporting. amended 2016-12-22 2016-12-22 · ecfr-amendment DFARS 252.204 (cyber clauses): 252.204-7005 Oral attestation of security responsibilities. amended 2016-12-22 2016-12-22 · ecfr-amendment DFARS 252.204 (cyber clauses): 252.204-7013 Limitations on the Use or Disclosure of Information by Litigation Support Offerors. amended 2016-12-22 2016-12-22 · ecfr-amendment DFARS 252.204 (cyber clauses): 252.204-7014 Limitations on the Use or Disclosure of Information by Litigation Support Contractors. amended 2016-12-22 2016-12-22 · ecfr-amendment DFARS 252.204 (cyber clauses): 252.204-7015 Notice of Authorized Disclosure of Information for Litigation Support. amended 2016-12-22 2016-12-22 · ecfr-amendment DFARS 252.204 (cyber clauses): 252.204-7006 Billing instructions. amended 2016-12-22 2016-12-22 · ecfr-amendment DFARS 252.204 (cyber clauses): 252.204-7001 [Reserved] amended 2016-12-22 2016-12-22 · ecfr-amendment DFARS 252.204 (cyber clauses): 252.204-7004 Alternate A, System for Award Management. amended 2016-12-22 2016-12-22 · ecfr-amendment DFARS 252.204 (cyber clauses): 252.204-7007 Alternate A, Annual Representations and Certifications. amended 2016-12-22 2016-12-22 · ecfr-amendment DFARS 252.204 (cyber clauses): 252.204-7000 Disclosure of information. amended 2016-12-22 2016-12-22 · ecfr-amendment DFARS 252.204 (cyber clauses): 252.204-7003 Control of government personnel work product. amended 2016-12-22 2016-12-22 · ecfr-amendment DFARS 252.204 (cyber clauses): 252.204-7008 Compliance with safeguarding covered defense information controls. amended 2016-12-22 2016-12-22 · ecfr-amendment DFARS 252.204 (cyber clauses): 252.204-7002 Payment for subline items not separately priced. amended 2016-12-22 2016-12-22 · ecfr-amendment
◂ PREV 3/3
Federal rulemaking 14 NIST publications 15 OIRA · OMB review 2
LAST_SYNC: 2026-08-30 18:00
DOC_VIEWER open original ↗
eCFR rule 2025-11-10 ◆ DEX DOSSIER

DFARS 252.204 (cyber clauses): 252.204-7021 Contractor Compliance With the Cybersecurity Maturity Model Certification Level Requirements. amended 2025-11-10

This DFARS clause requires contractors to represent their CMMC certification level in solicitations and contracts.

DFARS 252.204-7025 mandates that contractors include a representation regarding their Cybersecurity Maturity Model Certification (CMMC) level in solicitations and contracts. This clause ensures that the government is aware of the contractor's cybersecurity posture and compliance level before awarding or continuing a contract.

--- [ Regulatory impact ] ---

DIBs must accurately represent their CMMC level to avoid contract disqualification or non-compliance findings during audits.

Obligations it imposes · 2
  1. Include a representation of CMMC certification level in solicitations and contracts.
  2. Ensure the represented CMMC level matches the actual certification status.
OPEN_ORIGINAL ↗ PERMALINK ⎘ ecfr/496c8b2d-9e9c-4bea-a500-6deb5074891f◈ IRIX document body stays at the source — we index, enrich & link
CONTROL FAMILIES
None identified for this document.
RELATED DOCUMENTS
No related documents yet.