The Significant Changes to SPRS Scores and DEFARS Clauses You Need to Know
As of February 1, 2026, major changes to DEFARS clauses and SPRS scores have been implemented, including the deletion of basic self-assessment requirements and renumbering of key clauses. This blog post outlines these changes and their implications for defense contractors.
As of February 1, 2026, the landscape of cybersecurity compliance for defense contractors has undergone a significant transformation. This blog post will explore the recent changes to the Defense Federal Acquisition Regulation Supplement (DEFARS) clauses and the implications for contractors in the defense industrial base.
Overview of Changes
The changes that took effect on February 1, 2026, are substantial and have been implemented without any formal rulemaking process. Here are the key updates:
-
Renumbering of FAR Clause 5220421
The FAR clause 5220421 has been renumbered to 5224093. Despite the change in number, the title remains the same: "Basic safeguarding of covered contractor information systems." Importantly, the 15 requirements outlined in this clause have not changed, and the flowdown requirements still apply to systems handling federal contract information. -
Deletion of DEFARS Provision 2522047019
DEFARS Provision 2522047019 has been completely deleted from the regulations. This marks a significant shift in the compliance landscape for defense contractors. -
Changes to DEFARS Clause 2522047020
DEFARS Clause 2522047020 has been renumbered to 2522407997 and is now titled "NIST SP80171 DOD Assessment Requirements." A critical change here is the removal of the basic self-assessment requirements, which means that contractors will no longer need to conduct basic self-assessments or upload their scores to the Supplier Performance Risk System (SPRS). However, medium and high assessments remain unchanged. -
No Changes to Certain DEFARS Clauses
There are no changes to DEFARS Clause 2522047012 or Provision 2522047025. Additionally, DEFARS Clause 2522047021, which pertains to the Cybersecurity Maturity Model Certification (CMMC), remains unchanged.
Implications of the Changes
These changes represent a significant shift in the compliance requirements for defense contractors. The removal of basic self-assessment requirements means that contractors will no longer have to self-report their cybersecurity posture in the same way as before. This could lead to a variety of outcomes:
- Increased Compliance Burden: Without the basic self-assessment, contractors may face a more complex compliance landscape, as they will need to focus on medium and high assessments without the foundational self-assessment process.
- Potential for Confusion: The renumbering of clauses and the deletion of provisions may lead to confusion among contractors who are accustomed to the previous numbering system. Familiarity with the new numbers will take time.




















