FAR & DFARS: Procurement Power
All Episodes
DoD Ends Self-Assessments and Tightens Cyber Enforcement

DoD Ends Self-Assessments and Tightens Cyber Enforcement

0:00|0:00

Defense contractors are facing a major shift as the DoD replaces self-reported SPRS scores with government-led validation assessments under new DFARS Part 240 rules. The episode also covers supply chain exclusion authority, unreviewable risk decisions, rapid incident reporting, and the urgency of updating subcontract flowdowns.

Show Notes


Chapter 1

The End of Self Attestation Under Class Deviation 2026 O0025

Eric Marquette

If you are a defense contractor, you might think uploading a self calculated score to the Supplier Performance Risk System was still enough to keep the acquisition team off your back. But on February 1st, 2026, the Department of Defense quietly changed the game.

Paul Netopski

Yeah, they, they basically erased the whole concept of the basic self assessment overnight. Class Deviation 2026 O0025 completely eliminated DFARS 252 point 204 7019. It is just gone.

Eric Marquette

Wait, wait, so 7019 is gone? That was the provision everyone used to submit their self-reported score!

Paul Netopski

Right. Gone. Firsthand testimony here, not commentary. Under the new DFARS 252 point 240 7997, there is no definition of a basic self assessment anymore. None. The government replaced it entirely with mandatory, government led validation assessments. Medium and High.

Eric Marquette

Uh, okay, let me make sure I am following this. So previously, a small contractor could just evaluate their own compliance against NIST SP 800 171, punch a number into SPRS, and move on. Now the clause text literally only recognizes assessments performed by the government?

Paul Netopski

Precisely. The Defense Contract Management Agency, or DIBCAC, conducts these using NIST SP 800 171A assessment procedures. A Medium Assessment is a government review of your evidence. A High Assessment means assessors are in your system, reviewing your System Security Plan, interviewing your team, and validating that controls are actually in place.

Eric Marquette

Mm, but what about CMMC? I hear people saying all the time, well, if CMMC Level 1 or Level 2 allows self attestation for certain contracts, then I am safe, right?

Paul Netopski

That, that is where contractors get horribly confused! CMMC defines your certification requirements, sure. But DFARS clauses define contract enforcement authority. DFARS 252 point 204 7021 for CMMC was left unchanged by the deviation, but DFARS 252 point 240 7997 sits right alongside it in the contract.

Eric Marquette

Ah, so even if your CMMC tier lets you self assess, the contracting officer has explicit contract authority through 7997 to demand proof!

Paul Netopski

Bingo. They can walk in and demand raw evidence for your System Security Plan whenever 7997 is in that contract. CMMC level does not shield you from contract level enforcement. Proof matters now, not promises on paper.

Eric Marquette

Man, for a small prime, that is a massive operational shift. You go from a purely internal documentation exercise to managing live government validation audits where a bad score could pause your awards!

Paul Netopski

It is huge. And look, if your System Security Plan is aspirational rather than operational, you are setting yourself up for severe scrutiny. You have got to get back to the brilliant basics, logging, multi factor authentication, patching, actual technical controls that you can demonstrate on demand.

Chapter 2

Unreviewable Exclusions 72 Hour Reporting and Flowdown Traps

Eric Marquette

Okay, so government audits are one thing, but as I was reading through Part 240, there is something even crazier tucked into DFARS 240 point 271. It deals with supply chain risk exclusions?

Paul Netopski

Oh, this is an area with major issues for sure! Under DFARS 240 point 271 and 10 U.S.C. 3252, agency heads have extraordinary authority to exclude suppliers or order a prime contractor to exclude a sub.

Eric Marquette

Wait, order a prime to terminate a subcontractor?

Paul Netopski

Yes. If there is a joint recommendation from Acquisition and Sustainment and the DoD Chief Information Officer based on a supply chain risk assessment, they can direct you to withhold consent or cut out a specific source.

Eric Marquette

And I am guessing the subcontractor can just file a bid protest with the Government Accountability Office to challenge it?

Paul Netopski

Nope! That is the kicker! If the authorized official determines that disclosing the basis of the action would harm national security, that decision is, by law, not subject to review in a bid protest before the GAO or in any Federal court.

Eric Marquette

Unreviewable? Wow. You could literally lose a subcontract or be barred from a program, and you cannot even protest it in federal court.

Paul Netopski

Zero appeal. That is why tracking your supply chain inputs and foreign vendor dependencies is no longer optional. It is pure survival.

Eric Marquette

And speaking of survival, what happens when something actually goes wrong? The reporting rules got tightened too, right?

Paul Netopski

Right. Rapidly report means within 72 hours of discovery of any cyber incident. You report it to DIBNet at dibnet point dod point mil. Then you take that government assigned incident report number and flow it right up the supply chain.

Eric Marquette

Which brings us to flowdowns in general. What is the trap that primes are falling into right now with these contract updates?

Paul Netopski

The trap is copy pasting old templates! Primes are still flowing down the retired 204 series clauses, like 7019 or old 7020, to their subcontracts. If you flow down outdated clauses instead of the mandatory Part 240 deviation clauses, you are creating immediate compliance exposure for yourself and your subs.

Eric Marquette

So if your subcontracts do not reflect DFARS Part 240 and 252 point 240 7997, you are essentially out of sync with federal acquisition law.

Paul Netopski

Exactly. Look, defense cybersecurity compliance used to be an IT paperwork exercise. You filled out a form, put a score in a database, and called it a day. Now, it is a non negotiable operational gate. If you cannot prove your controls or verify your supply chain, you simply forfeit contract eligibility.

Eric Marquette

Proof over promises. Check your subcontracts, audit your System Security Plan, and stop relying on self attestations.