Problem briefContract obligations
What contract and security commitments must we support?
Record contract and customer requirements as assigned work with evidence that remains available through handoffs and review.
Requirement to review
Assign each contract requirement and track its evidence.
- 01 Requirement Recorded
- 02 Owner Assigned
- 03 Work Tracked
- 04 Evidence Recorded
- 05 Review Supported
01Source requirement
Review the governing requirement.
These pages explain the source requirement and its practical implications. A contracting officer defines solicitation requirements. Assessors, customers, and counsel make their own determinations.
- 01
Obligations often originate in more than one place: a prime flowdown, the award, the statement of work, a security addendum, or a representation made during the pursuit.
DFARS 252.204-7012 official sourceDFARS 252.204-7020 official sourceDFARS 252.204-7021 official source
- 02
Where DFARS 252.204-7021 applies, contractors must flow down the correct CMMC level to covered subcontracts and verify the required current status before award.
- 03
For NIST SP 800-171 assessment requirements that flow down under DFARS 252.204-7020, the subcontractor provisions include a current Basic Assessment condition for covered contractor information systems.
BoundaryResponsibility
Prepare the record for review.
Deep Fathom organizes the requirement, work, and evidence record. Counsel and the contracting parties determine the meaning and enforceability of contract language.
02Decision guides
Answer the buyer question before the decision.
Short, source-backed answers for teams reviewing a requirement, making a representation, or committing time to a pursuit.
03Platform workflow
Assign the work. Keep evidence with the requirement.
Deep Fathom records requirements, accountable owners, work, evidence, and decisions so the team can prepare for the next review.
- Record requirements as accountable work with an owner and due date.
- Associate evidence and affected system scope with each commitment.
- Give security, program, and contract teams one record for review of changes and open work.
Review contract requirements
Review contract commitments before performance begins.
Tell our team about the award, flowdown, customer commitment, or handoff. We will show how Deep Fathom can assign the work and retain the evidence for the requirements involved.
- The contract, flowdown, or representation in question
- The teams responsible for carrying it into performance
- The work, evidence, and review date that need a record
Request a platform evaluation
Reviewed by our teamProvide the details listed at left. Our team will review them, clarify what the platform can support, and recommend an evaluation step.
Do not include CUI, credentials, or export-controlled data.
05Related reading
Related resources
SourcesReviewed
Read the governing material.
- DFARS 252.204-7012Safeguarding covered defense information and cyber-incident reporting clause.Official source ↗
- DFARS 252.204-7020NIST SP 800-171 DoD assessment requirements, including Basic Assessment and subcontract provisions.Official source ↗
- DFARS 252.204-7021Current CMMC status, annual affirmation, and CMMC flowdown requirements where the clause applies.Official source ↗
- NIST SP 800-171 Rev. 2The 110 security requirements incorporated by reference into 32 CFR part 170 and assessed at CMMC Level 2.Official source ↗
- NIST SP 800-171 Rev. 3The current NIST publication. DFARS 252.204-7012 points at the revision in effect at time of solicitation, while CMMC assessments are conducted against Revision 2.Official source ↗
- NIST SP 800-171AAssessment procedures, including the assurance case: a body of evidence organized into an argument that a claim about a system is true.Official source ↗