Buy 1 Get 2 Free Special on Cyber Regulations: DoD Interim Rule Unveils 3 New Clauses Geared at Cybersecurity Assessments
Client Alert | 1 min read | 09.29.20
The Department of Defense (DoD) has released its eagerly anticipated Interim Rule amending the Defense Federal Acquisition Regulation Supplement (DFARS) to implement two major initiatives: the National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171 DoD Assessment Methodology and the Cybersecurity Maturity Model Certification (CMMC). The Interim Rule introduces the related clauses DFARS 252.204-7019, Notice of NIST SP 800-171 DoD Assessment Requirements and DFARS 252.204-7020, NIST SP 800-171 DoD Assessment Requirements; as well as the separate clause DFARS 252.204-7021, Cybersecurity Maturity Model Certification Requirements.
-7019 requires contractors to have a current NIST SP 800-171 DoD Assessment in order to be considered for award, which may have been met where contractors have had a recent Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) Assessment. Relatedly, -7020 requires contractors to provide the Government with access to their facilities and systems for higher-level Assessments, in addition to ensuring that subcontractors handling Covered Defense Information (CDI) have made their Assessments available to the Government.
-7021 implements the long-expected CMMC framework, where contractors must receive a third-party certification that they have met one of five specified cybersecurity levels – and maintain that certification for the duration of their contracts. The CMMC clause will begin appearing in select solicitations later this year, and eventually in all solicitations above the micro-purchase threshold by October 1, 2025, excluding those exclusively for commercially available off-the-shelf (COTS) items.
The Interim Rule goes into effect on November 30, 2020, with comments due the same day.
Contacts

Partner and Crowell Global Advisors Senior Director
- Washington, D.C.
- D | +1.202.624.2698
- Washington, D.C. (CGA)
- D | +1 202.624.2500
Insights
Client Alert | 4 min read | 08.14.26
License to Hack? The White House Greenlights Private-Sector Offensive Cyber Operations
On August 12, 2026, the White House released a National Security Presidential Memorandum (NSPM), marking a seismic shift in U.S. cybersecurity policy and establishing a framework to authorize private-sector companies to conduct offensive cyber operations—historically strictly prohibited by federal law—against foreign Cyber-Enabled Transnational Criminal Organizations (CE-TCOs). It builds on an executive order issued in March 2026 that directed federal agencies to develop plans to combat cyber-crimes against Americans.
Client Alert | 4 min read | 08.13.26
Supreme Court Confirms Contractual Loss of Bargain Without Repudiatory Breach
Client Alert | 7 min read | 08.12.26
Developments in Canadian Investment Treaty Practice: New FIPA Between Canada and UAE in Force
Client Alert | 6 min read | 08.11.26
