FAR & DFARS: Procurement Power
All Episodes
DFARS Renumbering and the End of Self-Attestation

DFARS Renumbering and the End of Self-Attestation

0:00|0:00

Defense contractors are facing a major DFARS renumbering that turns old cybersecurity citations into a compliance hazard, especially when primes accidentally flow down retired clauses to subcontractors. The episode also breaks down how the new rule shifts verification away from basic self-attestation and toward government-led assessments that demand real evidence, not paper promises.


Chapter 1

The Renumbering Trap and Subcontract Flowdown Chaos

Eric Marquette

If you are working in the defense supply chain, you probably think you have a handle on your cybersecurity clauses. You know, the usual numbers you see pasted into every single contract. But, uh, starting February 1st of 2026, the Department of Defense completely flipped the table on how those clauses are numbered and organized.

Paul Netopski

Yeah, they did. Class Deviation 2026 O0025. It is part of what the government calls the Revolutionary FAR Overhaul, moving things into FAR Part 40 and DFARS Part 240. And, look, I am telling you from firsthand testimony, not commentary, people are treating this like an administrative typo. It is not.

Eric Marquette

Wait, so, so when you say they moved things around, give me the actual clause numbers here. What actually vanished?

Paul Netopski

Okay, so legacy FAR 52 point 204 21, which was basic safeguarding, is now FAR 52 point 240 93. DFARS 252 point 204 7020 got renumbered to DFARS 252 point 240 7997. And the big one, DFARS 252 point 204 7019? Retired entirely. Gone. Erased.

Eric Marquette

Retired? Wait, so if a prime contractor just copies and pastes their old template from last year into a new subcontract, what happens?

Paul Netopski

They are flowing down a dead clause. A completely retired legal requirement. I mean, I see prime contractors right now who think this is just cosmetic. They do not build a clause crosswalk, they hand their sub tier suppliers a contract referencing retired 7019, and then they expect those suppliers to know what to do under DFARS 240 point 370 5. It creates absolute chaos down the chain.

Eric Marquette

Subcontracting officers are literally passing down ghost clauses?

Paul Netopski

Precisely. And when a small supplier gets a contract with retired citations, they cannot properly verify the scope of Controlled Unclassified Information. They cannot fulfill mandatory flowdown rules. You have prime contracts legally out of alignment with subcontracts, creating massive legal exposure for everyone involved.

Eric Marquette

Because the sub supplier is trying to comply with a clause that officially no longer exists in defense acquisition regulations.

Paul Netopski

Exactly. You cannot attestation check against a ghost standard.

Chapter 2

Elimination of Basic Self Attestation and Direct Government Verification

Eric Marquette

So that brings us to what I think is the real bombshell hidden inside this new DFARS 252 point 240 7997 clause. Because it is not just about changing numbers, right? Something fundamental about how contractors prove their security actually disappeared.

Paul Netopski

That is the structural surprise that almost everyone is missing. In the old 7020 clause, you had three assessment levels: basic, medium, and high. Basic was your self assessment that you posted to SPRS. In the new 252 point 240 7997 text, the definition of a basic assessment is gone. Completely deleted.

Eric Marquette

Hold on. The DoD removed basic self assessments?

Paul Netopski

They removed the concept entirely from that clause. The new clause defines only Medium and High Assessments, both of which are government led reviews using NIST SP 800 171A assessment procedures.

Eric Marquette

Wait, so let me make sure I understand this correctly. If a contractor is allowed under CMMC rules to self attest for Level 1 or certain Level 2 systems, but their contract includes this new DFARS clause, does CMMC protect them from government auditors showing up?

Paul Netopski

No. Not at all. And that is where contractors get terribly confused. CMMC defines certification requirements, but DFARS clauses define contract enforcement authority. Even if CMMC allows you to self assess on paper, the presence of DFARS 252 point 240 7997 in your contract gives the Department of Defense direct legal authority to step in and validate your security posture anytime they want.

Eric Marquette

Step in how? Like, what does a government Medium or High Assessment actually look like in practice?

Paul Netopski

Under a Medium Assessment, government assessors review your System Security Plan and your evidence. Under a High Assessment, they conduct deep, detailed reviews, validate that controls are functioning, and directly interview your technical staff for clarification. They do not just look at your self reported score; they ask for proof on the spot.

Eric Marquette

Interviewing employees directly. Wow. So if a company put a perfect 110 score in SPRS based on, say, aspirational goals or templates they bought online...

Paul Netopski

They are walking into a trap. Look, compliance in this sector is usually 75% documentation and 25% technical controls. But when the government conducts a High Assessment, those technical controls get tested. If you marked multi factor authentication or centralized logging as implemented on paper, but your engineer tells the government assessor during an interview that it is only half deployed, you are in immediate trouble with the Department of Justice.

Eric Marquette

Because paper promises do not equal real implementation.

Paul Netopski

Proof matters more than promises. The government made this change specifically because of the huge gap between self reported compliance and real world security. They want verification, not self attestation.

Eric Marquette

So if you are a defense supplier listening right now, what is the immediate move? Where should teams focus their energy today?

Paul Netopski

Stop relying on aspirational SPRS scores. Focus on what I call the brilliant basics. That means core technical controls: strict multi factor authentication, end to end encryption, and continuous logging. Make sure your System Security Plan reflects what is actually running in your environment today, not what you hope to deploy next quarter. Because when DFARS 252 point 240 7997 shows up in your flowdowns, an unannounced government review becomes a very real risk.

Eric Marquette

Update your clause crosswalks, fix your subcontracts, and make sure your evidence matches your claims. Paul, thanks for walking us through this.

Paul Netopski

Always a pleasure. Secure, compliant systems, built with purpose.