Compliance with DFARS 252.204-7012 & NIST 800-171; Expect 2019 to be the year of audit and enforcement

By Eric Noonan • November 29, 2018

On November 6th, 2018, DoD’s Acting Principal Director for Defense Pricing and Contracting (DPC) issued a memorandum titled, “Guidance for Assessing Compliance and Enhancing Protections Required by DFARS Clause 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting” that is expected to be transformative in the enforcement of compliance throughout the acquisition process.

While the implementation of DFARS and NIT 800-171 requirements have been mandatory since December 2017, many Department of Defense (DoD) contractors haven’t yet felt the sting of an audit and efforts were largely contained to completing checklists from government contracting officers or Primes. The DoD telegraphed a transition to enforcement and the impacts of non-compliance with guidance made available to the public for comment in Federal Register, Volume 83 Issue 79 (Tuesday, April 24, 2018). All comments were considered and integrated, when appropriate, into the final documents and as expected 2019 will be a game changer for non-compliant Prime and subcontractors.

The November 6th, 2018 memorandum references two new guidance documents providing for enforcement of DFARS 252.204-7012 & NIST 800-171 across the entire supply chain:

“DoD Guidance for Reviewing System Security Plans and the NIST SP 800-171 Security Requirements Not Yet Implemented”

“Guidance for Assessing Compliance of and Enhancing Protections for a Contractor’s Internal Unclassified Information System”

This new set of guidance empowers acquisition officers to enforce compliance throughout the entire acquisition lifecycle, both before and after contract award. Changes include:

  • A standard for the data content and format to be used in NIST SP 800-171 System Security Plans
  • Adding cybersecurity measures in addition to those found in NIST SP 800-171
  • Creating an “Acceptable” (Go/No Go threshold) rating, which can require “must-have” NIST 800-171 requirements to be in place before an award can be made
  • Incorporates 800-171 compliance as a technical evaluation factor, which often becomes part of the weighted score for contract awards
  • Conducting on-site assessments, using NIST SP 800-171A: Assessing Security Requirements for Controlled Unclassified Information
  • Requiring a contractor to complete a new form titled: ‘Contractor’s Record of Tier 1 Level Suppliers Receiving/Developing Covered Defense Information
  • Requesting a contractor’s plan to track flow down of Covered Defense Information
  • Requesting a contractor’s plan to assess the compliance of their own suppliers

With the ability to request a contractor’s plan to track flow down of Covered Defense Information (CDI) and request the contractor’s plan to assess the compliance of their own suppliers, Prime contractors are expected to document and demonstrate enforcement of their own supply chain’s compliance.

In 2019 Prime and Subcontractors can expect to be audited against actual implementation the DFARS 252.204-7012 & NIST 800-171 security requirements. For those taking a wait and see approach to the impact of your ability to do business with the DoD without implementing NIST 800-171; you just got your answer, 2019 will be a year of reckoning for non-compliant Prime and subcontractors.

If you have delayed documenting your SSP, POA&Ms or actually implementing the NIST 800-171 requirements, CyberSheath can lead your efforts to achieve compliance by conducting a gap assessment of your compliance with NIST 800-171, writing the required System Security Plan (SSP) and leading your implementation efforts. Contact Us today to get started!

CyberSheath Blog

How to Safeguard Your Company from Phishing

Email is so ubiquitous in our everyday lives that it can be a challenge to always be on guard when receiving messages. Each day it’s not unheard of for each member of your team to have hundreds of messages land in their inbox. How do you make sure that none…

3 Tools to Help Defend Your IT Infrastructure from Threats

With the continually evolving threat landscape and the prevalence of team members working from home, it is more important than ever to be proactive with how your company is protecting itself from cyberattacks.  CyberSheath can help. We offer services to build on all the great work you have already done…

DNS Filtering for Additional Protection of IT Systems

Phase one of securing your IT infrastructure should include protecting your endpoints and safeguarding your employees from phishing attempts. After you have implemented these controls, the next logical step is to launch a DNS filtering solution.   What is DNS filtering and why do you need it? Domain name server…

Our Trusted Partners

Tenable Microsoft Siemplify KnowBe4 ConnectWise DUO