---
title: SPRS Self-Assessment Requirements Remain for CMMC Despite DFARS Overhaul Changes
description: DFARS cybersecurity clause changes caused confusion, but government contractors must still complete CMMC Level 1 self-assessments and report results in SPRS.
image: https://info.redstonegci.com/hubfs/RGCI%20-%20SPRS%20Self-Assessment%20Requirements%20Remain%20for%20CMMC%20Despite%20DFARS%20Overhaul%20Changes.png
---

[ PAY INVOICE](https://redstonegci.com/invoice-payment/) [Call Us Today 256-704-9800](tel:2567049800) [info@redstonegci.com](Mailto:info@redstonegci.com)

<http://www.facebook.com/redstonegci> <http://www.twitter.com/RedstoneGCI> <http://www.linkedin.com/company/redstone-government-consulting-inc-> <https://www.youtube.com/channel/UCQv3eAwiPTTQAnoy7hnUwgg>

[![Redstone_Logo](https://info.redstonegci.com/hubfs/redstone%20logo%20version%201%20-%20rgb-1.png)](https://www.redstonegci.com/)

# SPRS Self-Assessment Requirements Remain for CMMC Despite DFARS Overhaul Changes

[Posted by Lynne Nalley, CPA on Mon, Mar 2, 2026 @ 11:03 AM](https://info.redstonegci.com/blog/author/lynne-nalley)

- [Tweet](https://twitter.com/share)

## ![RGCI - SPRS Self-Assessment Requirements Remain for CMMC Despite DFARS Overhaul Changes](https://info.redstonegci.com/hs-fs/hubfs/RGCI%20-%20SPRS%20Self-Assessment%20Requirements%20Remain%20for%20CMMC%20Despite%20DFARS%20Overhaul%20Changes.png?width=1000&name=RGCI%20-%20SPRS%20Self-Assessment%20Requirements%20Remain%20for%20CMMC%20Despite%20DFARS%20Overhaul%20Changes.png)

Recent DFARS class deviations associated with the FAR and DFARS overhaul reorganized several cybersecurity clauses, leading to confusion about government contractor self-assessment requirements. Although certain DFARS provisions were removed or renumbered, government contractors handling Federal Contract Information (FCI) must still conduct CMMC Level 1 self-assessments and post results in Supplier Performance Risk System (SPRS).

## Highlights

- **DFARS Clause Reorganization.** In January 2026, DoD began issuing class deviations on 31 FAR parts and related DFARS as part of the DFARS Revolutionary FAR overhaul. While there are many revisions, a significant change was the relocation of some of the cybersecurity procedures to FAR 40 and DFARS 240 Information Security and Supply Chain Security Requirements and renumbering of the cybersecurity provisions and clauses in the related sections.
- **Provision/Clause Renumbering.** Some of the cybersecurity provisions and clauses were relocated and renumbered under the DFARS Revolutionary FAR overhaul. For example, the clause at FAR 52.204-21 was changed to FAR 52.240-93, and the clause at DFARS 252.204-7020 was changed to DFARS 252.240-7997 and removed the requirement for the basic self-assessment.
- **Self-Assessment Requirement.** Although the NIST SP 800-171 Basic Self-Assessment requirement was removed from DFARS 252.204-7020 when the clause was relocated to DFARS 252.240-7997, contractor self-assessments were not eliminated. A self-assessment is still required for contractors required to comply with CMMC Level 1.
- **CMMC Level 1 Requirements.** Contractors handling Federal Contract Information on DoD contracts are required to comply with CMMC Level 1. This requires contractors to prepare a self-assessment against a minimum of the 15 safeguarding controls in FAR 52.240-93 and post the score in the Supplier Performance Risk System.
- **Operational Impact.** Contractors need to review the DFARS Revolutionary FAR Overhaul class deviations and effective dates to gain an understanding of the changes and the impact on policies, subcontract flowdowns, templates, and flowdown clauses.

---

As part of the [DFARS Revolutionary FAR Overhaul Class Deviations,](https://www.acq.osd.mil/dpap/dars/dfars_far_overhaul_class_deviations.html) the Department of Defense (DoD) adopted the FAR Council’s changes. It began [issuing class deviations to DFARS text with effective dates as early as January 23, 2026](https://info.redstonegci.com/blog/dod-issues-far-and-dfars-revolutionary-overhaul-class-deviations-effective-as-early-as-january-2026). While there are many changes, we are focusing on the class deviation for the revision and renumbering of the cybersecurity-related clauses, which became effective February 1, 2026.

A major change in the FAR and DFARS overhaul is the creation of [FAR Part 40](https://www.acquisition.gov/far-overhaul/far-part-deviation-guide/far-overhaul-part-40) and [DFARS Part 240 Information Security and Supply Chain Security](https://www.acq.osd.mil/dpap/dars/classdev/DFARS_RFO/Part-240/2026-O0025_TAB_A_Deviation_Memo_DFARS_240.pdf). These new parts consolidate some of the cybersecurity, prohibition, and supply chain risk management requirements previously located in FAR Part 4 and DFARS 204 into FAR Part 40 and DFARS Part 240, respectively.

## What Changes are Related to Cybersecurity?

### FAR Clause Changes

- [FAR Clause 52.204-21 Basic Safeguarding of Covered Contractor Information Systems](https://www.acquisition.gov/far/52.204-21) moved to [FAR 52.240-93](https://www.acquisition.gov/far-overhaul/far-part-deviation-guide/far-overhaul-part-52#FAR_52_240_93) with no changes to the clause. 
    - Solicitation Provision moved from [FAR 4.1903](https://www.acquisition.gov/far/4.1903) to [FAR 40.303-2](https://www.acquisition.gov/far-overhaul/far-part-deviation-guide/far-overhaul-part-40#FAR_40_303_2)
    - Implement, at a minimum, the 15 security controls if the contractor is handling Federal Contract Information (FCI)
    - Flow down clause to subcontractors if handling FCI

### DFARS Clause Changes

- [DFARS 252.204‑7019 Notice of NIST SP 800-171 DoD Assessment Requirements](https://www.acquisition.gov/dfars/252.204-7019-notice-nistsp-800-171-dod-assessment-requirements.) has been eliminated.
- [DFARS 252.204-7020](https://www.acquisition.gov/dfars/252.204-7020-nist-sp-800-171dod-assessment-requirements.) has been renumbered to [DFARS 252.240-7997](https://www.acq.osd.mil/dpap/dars/classdev/DFARS_RFO/Part-240/2026-O0025_TAB_A_Deviation_Memo_DFARS_240.pdf) but maintains the same title, “NIST SP 800-171 DoD Assessment Requirements.” 
    - Solicitation Provision moved from [DFARS 204.7304](https://www.acquisition.gov/dfars/204.7304-solicitation-provision-and-contract-clauses.) to [DFARS 240.370-5](https://www.acq.osd.mil/dpap/dars/classdev/DFARS_RFO/Part-240/2026-O0025_TAB_A_Deviation_Memo_DFARS_240.pdf)
    - Requirement for a basic self-assessment of NIST SP 800-171 security controls and post score in [Supplier Performance Risk System (SPRS)](https://www.sprs.csd.disa.mil/) has been removed
    - Medium and High assessments conducted by the Government in accordance with NIST SP 888-171A did not change
- [DFARS 252.204-7012](https://www.acquisition.gov/dfars/252.204-7012-safeguarding-covered-defense-information-and-cyber-incident-reporting.) Safeguarding Covered Defense Information and Cyber Incident Reporting 
    - No change to the requirements
    - Solicitation Provision moved from [DFARS 204.7304](https://www.acquisition.gov/dfars/204.7304-solicitation-provision-and-contract-clauses.) to [DFARS 240.370-5](https://www.acq.osd.mil/dpap/dars/classdev/DFARS_RFO/Part-240/2026-O0025_TAB_A_Deviation_Memo_DFARS_240.pdf)
- [DFARS 252.204-7021](https://www.acquisition.gov/dfars/252.204-7021-contractor-compliance-cybersecurity-maturity-model-certification-level-requirements.) Contractor Compliance with the Cybersecurity Maturity Model Certification Level Requirements 
    - No change to the requirements for CMMC Level 1, 2 and 3
    - Provision moved from [DFARS 204.7504](https://www.acquisition.gov/dfars/204.7504-solicitation-provision-and-contract-clause.) to [DFARS 240.371-5](https://www.acq.osd.mil/dpap/dars/classdev/DFARS_RFO/Part-240/2026-O0025_TAB_A_Deviation_Memo_DFARS_240.pdf)

As a result of the DFARS changes, some companies have circulated article titles claiming, “*government contractors are no longer required to conduct basic self‑assessments or upload their scores into SPRS.”* These article titles unintentionally suggest that the removal or restructuring of prior DFARS clauses (such as 252.204‑7019/7020) has eliminated the Basic Self-Assessment requirement. Government contractors handling covered defense information were required to implement all 110 security controls per [NIST SP 800-171](https://csrc.nist.gov/pubs/sp/800/171/r3/final), complete a Basic Self-Assessment and post the score in SPRS. While DFARS 252.204-7997 removes the NIST SP 800-171 Basic Self-Assessment requirement, it does not eliminate the self-assessment requirement altogether.

## Where Does the Self-Assessment Still Reside?

DFARS 252.204-7021 Contractor Compliance with the Cybersecurity Maturity Model Certification (CMMC) Level Requirements establishes a self-assessment requirement for government contractors. Under this clause, contractors and subcontractors with Department of Defense (DoD) contracts that handle Federal Contract Information (FCI) are required to comply with CMMC Level 1.

CMMC 1 requires contractors to conduct a self-assessment against the 15 basic safeguarding security controls in FAR 52.240-93, and post the resulting score to SPRS. This streamlined self-assessment is advantageous for contractors whose information systems only process FCI. In contrast to the former NIST SP 800‑171 Basic Self‑Assessment, which required evaluating and scoring 110 security controls, CMMC Level 1 imposes a significantly reduced compliance burden. Contractors that handle CUI on DoD contracts will continue to be subject to NIST SP 800-171 assessment requirements under CMMC Level 2.

## Takeaways

Government contractor self-assessments of security controls have not been removed in their entirety. The requirement for a Basic Self‑Assessment using the 110 security controls in NIST 800 SP-171 has been eliminated. But if you have a DoD contract/subcontract and handle FCI, you will need to meet CMMC Level 1, prepare a self-assessment of the 15 security controls in FAR 52.240-93, and post the score in SPRS.

Government contractors should:

- Update internal references from 52.204‑21 to 52.240‑93
- Remove DFARS 252.204-7019 and update references from 252.204-7020 to DFARS 252.240-7997
- Review templates, subcontracts, and flowdowns to ensure the new clause numbers are flowed down if applicable
- Verify that the 15 safeguarding controls are implemented and documented
- Ensure subcontractors handling FCI are also flowing down the updated clause

## Understanding Cybersecurity Compliance Responsibilities

Redstone Government Consulting assists government contractors in understanding how cybersecurity requirements affect their contracts, policies, and operational processes. Our team helps government contractors evaluate contract clauses, review policy documentation, and confirm that purchasing practices and subcontract flowdowns align with applicable cybersecurity requirements. When technical support is needed, Redstone GCI works with established industry partners who provide services such as penetration testing, incident response support, security assessments, and assistance with POA&M development and remediation. Through this coordinated approach, government contractors can address both regulatory obligations and technical cybersecurity requirements while maintaining alignment with their contract compliance responsibilities.

[![Contact Us for a Consultation](https://no-cache.hubspot.com/cta/default/203971/interactive-173774226074.png) ](https://info.redstonegci.com/hs/cta/wi/redirect?encryptedPayload=AVxigLKNXY57w%2FTyt3Lw%2BQiYTgrRenKzYFGfEGgUUYL%2FJ8OLXAdnhJmVbQMKU8jojVE71EvaojRfhLtZke1DCf3mgF%2Br9NrL1C5JGPVbi4iccYdQCOQ1IifPmhbHKKU5qPmebperMtHEN32yba4OVg0jGUMBWaEJuT1k7%2FmNhUFRutj%2FVWXO&webInteractiveContentId=173774226074&portalId=203971)

## Frequently Asked Questions (FAQs)

- **Did the DFARS Revolutionary FAR Overhaul eliminate cybersecurity self-assessments for contractors? ** No. The DFARS overhaul removed the basic self-assessment to comply with the 110 controls in NIST SP 800-171, but it did not eliminate self-assessments entirely. Contractors with DoD contracts handling Federal Contract Information must comply with CMMC Level 1 which requires a self-assessment.
- **Who must complete a CMMC Level 1 self-assessment? **Contractors and subcontractors that handle Federal Contract Information on DoD contracts must comply with CMMC Level 1; which requires a self-assessment of the 15 basic safeguarding controls in FAR 52.240-93. The score is posted in the Supplier Performance Risk System (SPRS).
- **How is the current self-assessment different from the previous NIST SP 800-171 assessment? **Contractors performing DoD contracts must complete a self assessment demonstrating compliance with 15 basic safeguarding controls when processing Federal Contract Information. Prior to this change, contractors that handled FCI had to complete a self-assessment and comply with the 110 security controls in NIST SP 800-171 and this requirement was removed from DFARS 252.240-7997.
- **Why should government contractors review their policies and contracts after these changes? **DoD has issued class deviations accepting 31 sections of the DFARS Revolutionary FAR overhaul beginning in January 2026. These class deviations include effective dates of the FAR and related DFARS changes. It is important to review and understand the changes, effective dates and impact on your contracts. While there are many changes, this blog identifies significant changes related to cybersecurity clauses.

### Written by [Lynne Nalley, CPA](https://info.redstonegci.com/blog/author/lynne-nalley)

![Lynne Nalley, CPA](https://info.redstonegci.com/hubfs/images/Staff_/Lynne-Nalley.png) Lynne is a Director with Redstone Government Consulting, Inc. providing government contract consulting services to our clients primarily related to Commercial Item Determinations and support, Cost Accounting Standards, DFARS Business System Audits, Proposals, and Incurred Cost. Prior to joining Redstone Government Consulting, Lynne served in several capacities with DCAA and DCMA for over 35 years. Professional Experience Lynne began her career working with DCAA in the Honeywell Resident Office, Clearwater, FL in 1984. Lynne’s experience included various positions which involved conducting or reviewing forward proposals or rate audits, financial capability audits, progress payments, accounting and estimating systems, cost accounting standards, claims and disclosure statement reviews. She is an expert in FAR, DFARS, CAS and testified as an expert witness. Lynne assisted in drafting the commercial item guidance for DCAA Headquarters. Lynne was assigned as a Regional Technical Specialist where she provided guidance to 20 field offices on highly complex or technical issues relative to forward pricing, financial capability or progress payment issues. As an Assistant for Quality, she was involved in reviewing and ensuring audit reports were in compliance with policy and GAGAS as well as made NASBA certified presentations to the staff including but not limited to billing reviews, CAS, unallowable cost and progress payments. To enhance her experience in government contracting, Lynne accepted a position with DCMA in 2015 as part of the newly organized DCMA Cadre of Experts in the Commercial Item Group. This included performing reviews of prime contractor’s assertions and/or commercial item determinations as well as performing price analyses. Lynne was a project lead and later became a lead analyst where she engaged with the buying commands on requests and reviewed price analysis reviews performed by a team of 5 analysts. She also assisted the DCMA CPSR team relative to commercial items and co-instructed the Commercial Item Training presented to DCMA. Education Lynne earned a Bachelor of Science Degree in Accounting from the University of Central Florida. Certifications State of Florida Certified Public Accountant State of Alabama Certified Public Accountant Defense Acquisition Workforce Improvement Act (DAWIA) Level III- Auditing DAWIA Level III – Contracting

## About Redstone GCI

Redstone GCI is a consulting firm focused on fulfilling the needs of government contractors in all areas of compliance. With a singular mission to help contractors through the multiple layers of “red tape,” we allow contractors to focus on what they do best – support their mission with the U.S. Government. We are home to a group of consultants made up of GovCon industry professionals, CPAs, attorneys, and retired government audit and acquisition professionals.

Our focus and knowledge of audit and compliance functions administered by DCAA and DCMA will always be at the heart of what we do. However, for the past decade, we’ve strategically grown to support other areas of the government contractor back-office with that same level of focus and expertise. We’ve added expertise in contracts management, subcontract administration, proposal pricing, various software systems, HR and employment law, property administration, manufacturing, data analytics/reporting, Grant specialists, M&A, and many other areas. When we see a trend in the needs of contractors, we act to ensure we can provide the best expertise in the market to fulfill those needs.

One thing our clients can be certain of is that with the Redstone GCI Team in your corner, there is no problem too big and no issue too technical for our team to tackle.

 Topics: [Contracts & Subcontracts Administration](https://info.redstonegci.com/blog/topic/contracts-subcontracts-administration), [Government Regulations](https://info.redstonegci.com/blog/topic/government-regulations), [Federal Acquisition Regulation (FAR)](https://info.redstonegci.com/blog/topic/federal-acquisition-regulation-far), [Cybersecurity](https://info.redstonegci.com/blog/topic/cybersecurity), [Manufacturing Operations Consulting](https://info.redstonegci.com/blog/topic/manufacturing-operations-consulting)

### Search Posts

This is a search field with an auto-suggest feature attached.

- There are no suggestions because the search field is empty.

### Subscribe via E-mail

### Latest Posts

### Posts by category

- [Accounting System Compliance (282)](https://info.redstonegci.com/blog/topic/accounting-system-compliance)
- [Commercial Determination (34)](https://info.redstonegci.com/blog/topic/commercial-determination)
- [Contractor Purchasing System Review (CPSR) (85)](https://info.redstonegci.com/blog/topic/contractor-purchasing-system-review-cpsr)
- [Contracts & Subcontracts Administration (300)](https://info.redstonegci.com/blog/topic/contracts-subcontracts-administration)
- [Cost Accounting Standards (CAS) (60)](https://info.redstonegci.com/blog/topic/cost-accounting-standards-cas)
- [COVID-19 (23)](https://info.redstonegci.com/blog/topic/covid-19)
- [Customer Success Story (2)](https://info.redstonegci.com/blog/topic/customer-success-story)
- [Cybersecurity (28)](https://info.redstonegci.com/blog/topic/cybersecurity)
- [DCAA Audit Support (249)](https://info.redstonegci.com/blog/topic/dcaa-audit-support)
- [Defense Procurement & Acquisition Policy (DPAP) (7)](https://info.redstonegci.com/blog/topic/defense-procurement-acquisition-policy-dpap)
- [Deltek Costpoint (54)](https://info.redstonegci.com/blog/topic/deltek-costpoint)
- [DFARS Business Systems (179)](https://info.redstonegci.com/blog/topic/dfars-business-systems)
- [DOD IG (10)](https://info.redstonegci.com/blog/topic/dod-ig)
- [Employee & Contractor Compensation (22)](https://info.redstonegci.com/blog/topic/employee-contractor-compensation)
- [Employers & Unions (8)](https://info.redstonegci.com/blog/topic/employers-unions)
- [Estimating System Compliance (18)](https://info.redstonegci.com/blog/topic/estimating-system-compliance)
- [Export & Import (19)](https://info.redstonegci.com/blog/topic/export-import)
- [Federal Acquisition Regulation (FAR) (187)](https://info.redstonegci.com/blog/topic/federal-acquisition-regulation-far)
- [Federal Construction Contracting (4)](https://info.redstonegci.com/blog/topic/federal-construction-contracting)
- [Government Compliance Training (59)](https://info.redstonegci.com/blog/topic/government-compliance-training)
- [Government Property Management (18)](https://info.redstonegci.com/blog/topic/government-property-management)
- [Government Regulations (265)](https://info.redstonegci.com/blog/topic/government-regulations)
- [Government Shutdown (9)](https://info.redstonegci.com/blog/topic/government-shutdown)
- [Grants & Cooperative Agreements (2 CFR 200) (32)](https://info.redstonegci.com/blog/topic/grants-cooperative-agreements-2-cfr-200)
- [Human Resources (118)](https://info.redstonegci.com/blog/topic/human-resources)
- [Incurred Cost Proposal Submission (ICP/ICE) (83)](https://info.redstonegci.com/blog/topic/incurred-cost-proposal-submission-icp-ice)
- [Litigation Consulting Support (17)](https://info.redstonegci.com/blog/topic/litigation-consulting-support)
- [Manufacturing Operations Consulting (26)](https://info.redstonegci.com/blog/topic/manufacturing-operations-consulting)
- [Material Management & Accounting System (MMAS) (23)](https://info.redstonegci.com/blog/topic/material-management-accounting-system-mmas)
- [Non-US Government Contractor (3)](https://info.redstonegci.com/blog/topic/non-us-government-contractor)
- [Office of Federal Contract Compliance Programs (31)](https://info.redstonegci.com/blog/topic/office-of-federal-contract-compliance-programs)
- [Organizational Change Management Consulting (17)](https://info.redstonegci.com/blog/topic/organizational-change-management-consulting)
- [Paycheck Protection Program (PPP) Loans (8)](https://info.redstonegci.com/blog/topic/paycheck-protection-program-ppp-loans)
- [Program Management & Project Cost Control (2)](https://info.redstonegci.com/blog/topic/program-management-project-cost-control)
- [Proposal Cost Volume Development & Pricing (79)](https://info.redstonegci.com/blog/topic/proposal-cost-volume-development-pricing)
- [Quickbooks (21)](https://info.redstonegci.com/blog/topic/quickbooks)
- [REAs, Claims & Terminations (10)](https://info.redstonegci.com/blog/topic/reas-claims-terminations)
- [Redstone GCI (50)](https://info.redstonegci.com/blog/topic/redstone-gci)
- [Sequestration (4)](https://info.redstonegci.com/blog/topic/sequestration)
- [Service Contract Act (14)](https://info.redstonegci.com/blog/topic/service-contract-act)
- [Small Business Compliance (121)](https://info.redstonegci.com/blog/topic/small-business-compliance)
- [System Award Management (SAM) (9)](https://info.redstonegci.com/blog/topic/system-award-management-sam)
- [UKG Ready HR Software Consulting (7)](https://info.redstonegci.com/blog/topic/ukg-ready-hr-software-consulting)
- [Unanet (35)](https://info.redstonegci.com/blog/topic/unanet)
- [Vlog (41)](https://info.redstonegci.com/blog/topic/vlog)

### Disclaimer

*Data published on our website, such as our white papers, blogs and other government contracting commentary reflect our interpretations and opinions of current events and regulations, at the time such data is published, and the perspectives/opinions of other professionals in our industry may vary from our own.  Further, our commentary and perspectives do not reflect legal analyses, since we are not attorneys, but rather government contracts and accounting advisors.  We therefore make no representation that the use of our published information will insulate a company from government challenges, nor otherwise ensure a successful defense on any government procurement adverse action.  Readers agree that articles or blog commentary presented within our website shall not be replicated or re-published without requesting before publication in another medium, and our expressed written consent to do so.*

**Redstone Government Consulting**  
501 Madison Street SE, Suite 100  
Huntsville, AL 35801

**Phone: ** [256.704.9800](tel:2567049800)  
**Email Us**[ info@redstonegci.com](mailto:info@redstonegci.com)

**[PAY INVOICE](https://redstonegci.com/invoice-payment/)**  
[PCI DSS compliance documentation](https://redstonegci.com/wp-content/uploads/2016/10/pci_dss_self_assessment_certificate.pdf)

<http://www.facebook.com/redstonegci> <http://www.twitter.com/RedstoneGCI> <http://www.linkedin.com/company/redstone-government-consulting-inc-> <https://www.youtube.com/channel/UCQv3eAwiPTTQAnoy7hnUwgg>

© 2026 Redstone Government Consulting | All Rights Reserved | [Privacy Policy](https://redstonegci.com/privacy-policy/) | [Event Refund / Cancellation Policy](https://redstonegci.com/event-refund-cancellation-policy/)