Procurement reference / DFARS 252.204
Five references. Different evidence and different checkpoints.
A clause number helps locate the requirement. It does not tell you whether another assessment record answers the same question.
Read the incorporated version, the level insertion and the applicable amendments. This page summarizes public texts reviewed September 7, 2026. The permanent clause-family guide provides the organic reference.
01 / Separate the questions
Identify what the evidence must support.
01.1
Safeguarding
7012 addresses adequate security on covered contractor information systems and incident reporting. Read its definitions, information scope and conditions before assigning work.
01.2
NIST assessment
7019 applies its current-assessment condition where the offeror must implement NIST SP 800-171. Current means no more than three years old unless the solicitation specifies less. Verify relevant summary scores in SPRS.
01.3
CMMC status
7025 identifies the level and addresses award eligibility, affirmation and proposal identifiers. 7021 addresses maintaining status during performance. A NIST assessment score does not automatically establish CMMC status.
Official acquisition.gov clause and provision texts, linked below.
02 / Where Deep Fathom fits
Bring the requirement and the evidence question.
A platform evaluation can examine the compliance workflow behind the requirement. The buyer's interpretation, assessment authority and award decision remain separate.
- 01
Locate the source
Record the incorporated version and selected level.
- 02
Check applicability
Identify the information, entity and systems contemplated for performance.
- 03
Review the support
Determine which assessment or affirmation answers the requested representation.
- 04
Preserve questions
Ask the contracting officer about blank insertions or conflicting terms.
03 / Official references
Use the reference that answers the actual question.
| Reference | Supported distinction | Checkpoint or scope |
|---|---|---|
| 7012 | Adequate security and cyber-incident reporting, including 72-hour reporting under its incident provisions. | Covered systems and information during performance. |
| 7019 | Current NIST SP 800-171 DoD Assessment for relevant covered systems when applicable. | Award consideration and SPRS summary-score verification. |
| 7020 | Government assessment access and applicable subcontract assessment checks. | Read paragraph (g), including the COTS exclusion and NIST applicability condition. |
| 7021 | Current CMMC status, annual affirmation and applicable flowdown. | The November 2025 clause distinguishes levels and conditional status. There is no single three-year certificate rule for every level. |
| 7025 | Selected level before award, current status and affirmation, and relevant identifiers in the proposal. | Read the contracting officer's insertion and the rest of the package. |
04 / A package example
A filled level is evidence. An empty blank is a question.
The retained DLA Warren package SPRDL1-26-R-0121 inserts Level 2 (Self) in 7025 on page 35. The retained Hellfire RFQ leaves that insertion blank while using assessment language elsewhere. Those observations support different follow-up questions.
Read the Warren case and solicitation review guide. One notice-action link does not establish the latest package. Follow history and amendments before acting.
05 / Policy and document limits
Read the suspension direction alongside the instrument.
The July 2026 Phase II suspension direction continues Phase I and directs changes to affected solicitations and contracts. Separate 7012 obligations remain. The pause guide explains the review.
This page makes no prevalence claim about all current solicitations. Keyword counts cannot substitute for reading the operative clause or selected level.
Platform evaluation / Compliance evidence
Show the evidence question behind the citation.
Share a public requirement and describe the compliance workflow you need to examine. Our team can demonstrate the relevant platform behavior.
Do not include CUI, credentials, export-controlled data or controlled attachments in this form.
Limitations
- Reviewed September 7, 2026. Incorporated versions and amendments govern the review.
- A NIST assessment and CMMC status are distinct. No universal three-year CMMC certificate rule is asserted.
- Educational reference and platform evaluation are separate from contracting-officer clarification.