FAR & DFARS: Procurement Power
All Episodes
DFARS Cyber Flowdowns and CMMC Assessment Rules

DFARS Cyber Flowdowns and CMMC Assessment Rules

0:00|0:00

This episode breaks down Class Deviation 2026-O0025 and its impact on DFARS cybersecurity flowdowns, subcontractor obligations, and incident reporting across the defense supply chain. It also covers CMMC assessment non-duplication rules and the government’s expanded authority to remove risky vendors from covered programs.


Chapter 1

The Class Deviation Rewriting Cybersecurity Flowdowns

Eric Marquette

So if you work anywhere in the defense industrial base, you, uh, you probably noticed the ground shifting under your feet recently. We are looking at Class Deviation 2026 O0025, which basically pulls cybersecurity and supply chain rules out of the old sections and anchors them into a brand new framework, DFARS Part 240.

Paul Netopski

Yeah, and, and look, this isn't just cosmetic renumbering, Eric. This is firsthand testimony, not commentary. Contracting officers are now directed to flow down requirements like DFARS 252.204 7012 and the new assessment clause 252.240 7997 down to every single subcontract tier, unless it's strictly commercial off the shelf items.

Eric Marquette

Wait, pure COTS items are exempt, but everything else gets it?

Paul Netopski

Everything else gets it. But here is the thing that people keep missing in practice. Prime contractors see this mandate and they just, they blindly copy paste the entire cyber clause stack down to machine shops, hardware vendors, people who never touch covered defense information. Scope is being driven by the marking, or in this case, blind paper pushes, not by the actual information flow.

Eric Marquette

Right, right, so a guy making standard bolts gets hit with a hundred and ten NIST controls.

Paul Netopski

Exactly. It breaks down the commercial supply chain because a small vendor looks at a fifty page cyber requirement for a five thousand dollar order and just says, no thanks, we are out.

Eric Marquette

Mm. But there was one really interesting protection buried in the guidance, right? In PGI 240.370 8?

Paul Netopski

Yes! This is an area with issues for sure, but this specific provision is a huge win for operational reality. PGI 240.370 8 explicitly states that when a contractor reports a cyber incident to dibnet.dod.mil, the contracting officer cannot, by itself, treat that report as proof that the contractor failed to maintain adequate security.

Eric Marquette

Wait, say that again? So reporting a breach doesn't automatically mean you failed your contract obligations?

Paul Netopski

Precisely. It removes the fear of instant punitive action just for coming forward. Now, how that incident report flows up the chain, that is where the administrative mechanics get intense. If a fourth tier sub suffers an incident, they report it to DIBNet. DoD gives them an incident report number. That lower tier sub has to pass that specific report number up to the third tier, who passes it to the second tier, all the way up to the prime.

Eric Marquette

Ah, so it's a relay race of tracking numbers, not necessarily dumping the raw compromised data to everyone up the chain.

Paul Netopski

Right. You preserve confidentiality while ensuring the government and the prime have end to end visibility of the threat chain.

Chapter 2

Assessment Rules CMMC Updates and Supply Chain Protections

Eric Marquette

Now, speaking of government visibility, let's talk about assessments. Because contractors have been terrified of getting audited twice, once by a CMMC third party assessor and then again by the Defense Contract Management Agency.

Paul Netopski

And that is where DFARS 240.370 3 comes in. My interpretation of this is very clear, it creates a formal non duplication rule. The Department of Defense is legally prohibited from forcing a contractor to undergo a duplicate Medium or High NIST SP 800 171 assessment if valid assessment results or CMMC results under 32 CFR Part 170 are already on file in SPRS.

Eric Marquette

Unless, what, there's a major threat shift?

Paul Netopski

Unless there is an explicit, documented change in the threat environment or system architecture. Otherwise, once it is verified, the government has to respect the data on file.

Eric Marquette

Okay, so that protects contractors from redundant audits. But what about on the supply chain risk side? Because I saw some pretty intense authority granted under DFARS 252.239 7018 and Title 10 Section 3252.

Paul Netopski

That is where the teeth are, Eric. Under those authorities, senior defense officials can unilaterally exclude a vendor or direct a prime to cut out a specific subcontractor based on all source intelligence regarding supply chain risk. And here is the kicker, that exclusion decision is explicitly immune from bid protests at the GAO or in federal court.

Eric Marquette

Wait, no bid protest allowed? You can't even sue to challenge it?

Paul Netopski

No review in federal court. If national security intelligence indicates your equipment or software poses a risk to a covered system, you are out, period. Which brings us back to what I always tell contractors, you have to focus on the brilliant basics. Compliance isn't about collecting paper promises or filling out spreadsheets. It is 75 percent documentation and 25 percent technical controls, but those technical controls must follow the actual data.

Eric Marquette

So stop drawing your security boundary around the whole company if the sensitive data only lives on two workstations.

Paul Netopski

Follow the data across people, technology, and physical locations. If you map your CUI flow accurately, you lower your compliance burden, you satisfy NIST 800 171, and you survive DFARS Part 240. Built to operate. Designed to last.

Eric Marquette

Know your data, protect the perimeter, and don't panic when the regulations get renumbered. Thanks for breaking it down, Paul.