
DFARS Renumbering and the End of Self-Attestation
Defense contractors are facing a major DFARS renumbering that turns old cybersecurity citations into a compliance hazard, especially when primes accidentally flow down retired clauses to subcontractors. The episode also breaks down how the new rule shifts verification away from basic self-attestation and toward government-led assessments that demand real evidence, not paper promises.
Chapter 1
The Renumbering Trap and Subcontract Flowdown Chaos
Eric Marquette
If you are working in the defense supply chain, you probably think you have a handle on your cybersecurity clauses. You know, the usual numbers you see pasted into every single contract. But, uh, starting February 1st of 2026, the Department of Defense completely flipped the table on how those clauses are numbered and organized.
Paul Netopski
Yeah, they did. Class Deviation 2026 O0025. It is part of what the government calls the Revolutionary FAR Overhaul, moving things into FAR Part 40 and DFARS Part 240. And, look, I am telling you from firsthand testimony, not commentary, people are treating this like an administrative typo. It is not.
Eric Marquette
Wait, so, so when you say they moved things around, give me the actual clause numbers here. What actually vanished?
Paul Netopski
Okay, so legacy FAR 52 point 204 21, which was basic safeguarding, is now FAR 52 point 240 93. DFARS 252 point 204 7020 got renumbered to DFARS 252 point 240 7997. And the big one, DFARS 252 point 204 7019? Retired entirely. Gone. Erased.
Eric Marquette
Retired? Wait, so if a prime contractor just copies and pastes their old template from last year into a new subcontract, what happens?
Paul Netopski
They are flowing down a dead clause. A completely retired legal requirement. I mean, I see prime contractors right now who think this is just cosmetic. They do not build a clause crosswalk, they hand their sub tier suppliers a contract referencing retired 7019, and then they expect those suppliers to know what to do under DFARS 240 point 370 5. It creates absolute chaos down the chain.
Eric Marquette
Subcontracting officers are literally passing down ghost clauses?
Paul Netopski
Precisely. And when a small supplier gets a contract with retired citations, they cannot properly verify the scope of Controlled Unclassified Information. They cannot fulfill mandatory flowdown rules. You have prime contracts legally out of alignment with subcontracts, creating massive legal exposure for everyone involved.
Eric Marquette
Because the sub supplier is trying to comply with a clause that officially no longer exists in defense acquisition regulations.
Paul Netopski
Exactly. You cannot attestation check against a ghost standard.
Chapter 2
Elimination of Basic Self Attestation and Direct Government Verification
Eric Marquette
So that brings us to what I think is the real bombshell hidden inside this new DFARS 252 point 240 7997 clause. Because it is not just about changing numbers, right? Something fundamental about how contractors prove their security actually disappeared.
Paul Netopski
That is the structural surprise that almost everyone is missing. In the old 7020 clause, you had three assessment levels: basic, medium, and high. Basic was your self assessment that you posted to SPRS. In the new 252 point 240 7997 text, the definition of a basic assessment is gone. Completely deleted.
Eric Marquette
Hold on. The DoD removed basic self assessments?
Paul Netopski
They removed the concept entirely from that clause. The new clause defines only Medium and High Assessments, both of which are government led reviews using NIST SP 800 171A assessment procedures.
Eric Marquette
Wait, so let me make sure I understand this correctly. If a contractor is allowed under CMMC rules to self attest for Level 1 or certain Level 2 systems, but their contract includes this new DFARS clause, does CMMC protect them from government auditors showing up?
Paul Netopski
No. Not at all. And that is where contractors get terribly confused. CMMC defines certification requirements, but DFARS clauses define contract enforcement authority. Even if CMMC allows you to self assess on paper, the presence of DFARS 252 point 240 7997 in your contract gives the Department of Defense direct legal authority to step in and validate your security posture anytime they want.
Eric Marquette
Step in how? Like, what does a government Medium or High Assessment actually look like in practice?
Paul Netopski
Under a Medium Assessment, government assessors review your System Security Plan and your evidence. Under a High Assessment, they conduct deep, detailed reviews, validate that controls are functioning, and directly interview your technical staff for clarification. They do not just look at your self reported score; they ask for proof on the spot.
Eric Marquette
Interviewing employees directly. Wow. So if a company put a perfect 110 score in SPRS based on, say, aspirational goals or templates they bought online...
Paul Netopski
They are walking into a trap. Look, compliance in this sector is usually 75% documentation and 25% technical controls. But when the government conducts a High Assessment, those technical controls get tested. If you marked multi factor authentication or centralized logging as implemented on paper, but your engineer tells the government assessor during an interview that it is only half deployed, you are in immediate trouble with the Department of Justice.
Eric Marquette
Because paper promises do not equal real implementation.
Paul Netopski
Proof matters more than promises. The government made this change specifically because of the huge gap between self reported compliance and real world security. They want verification, not self attestation.
Eric Marquette
So if you are a defense supplier listening right now, what is the immediate move? Where should teams focus their energy today?
Paul Netopski
Stop relying on aspirational SPRS scores. Focus on what I call the brilliant basics. That means core technical controls: strict multi factor authentication, end to end encryption, and continuous logging. Make sure your System Security Plan reflects what is actually running in your environment today, not what you hope to deploy next quarter. Because when DFARS 252 point 240 7997 shows up in your flowdowns, an unannounced government review becomes a very real risk.
Eric Marquette
Update your clause crosswalks, fix your subcontracts, and make sure your evidence matches your claims. Paul, thanks for walking us through this.
Paul Netopski
Always a pleasure. Secure, compliant systems, built with purpose.