Guide
Does FAR 52.204-21 Apply if My Contract Has No CMMC Clause?
Short Answer
FAR 52.204-21 is a contract clause in its own right, separate from CMMC. Under FAR 4.1903, contracting officers include it when the contractor or a subcontractor may have Federal Contract Information in its information system, and the FAR governs acquisition by all executive agencies, not only DoD. When the clause is in a contract, its 15 safeguarding requirements apply whether or not a DFARS CMMC clause is also present. CMMC is DoD's means of verifying them.
Why the Confusion Exists
Many suppliers first meet the 15 safeguards through CMMC, so it is natural to treat them as a CMMC requirement that starts only when a CMMC clause appears. CMMC Level 1 is built directly on the FAR clause, and the two are often described as one thing.
CMMC also reaches contracts one at a time. DoD states the required level through DFARS 252.204-7025 and 252.204-7021, and a contract without those clauses carries no CMMC level. It is easy to read that as meaning the safeguards do not apply either.
The clause can also carry a new number. Under DoD class deviations effective February 1, 2026, a DoD solicitation may show it as FAR 52.240-93, prescribed at FAR 40.303-2 in the overhauled FAR text.
What the Current Authority Says
FAR 4.1902 applies the basic safeguarding subpart to all acquisitions, including acquisitions of commercial products or commercial services, other than commercially available off-the-shelf items, when a contractor's information system may contain Federal Contract Information. FAR 4.1903 tells the contracting officer to insert FAR 52.204-21 in solicitations and contracts when the contractor or a subcontractor at any tier may have Federal Contract Information residing in or transiting through its information system. The test is the information, not CMMC.
Under FAR 1.101, the FAR sets uniform acquisition policies and procedures for all executive agencies. The prescription in FAR 4.1903 is therefore not limited to DoD contracts.
Paragraph (b)(1) of the clause requires the contractor to apply the 15 basic safeguarding requirements to protect covered contractor information systems. Paragraph (c) requires the contractor to include the substance of the clause in subcontracts in which the subcontractor may have Federal Contract Information residing in or transiting through its information system, other than subcontracts for commercially available off-the-shelf items.
The CMMC rule keeps the two apart. 32 CFR 170.5(e) states that the CMMC Program does not alter any separately applicable requirements to protect FCI or CUI, including those in FAR 52.204-21, and that it provides a means of verifying implementation of those requirements. 32 CFR 170.5(d) adds that when DoD waives CMMC for a solicitation or contract, contractors remain obligated to comply with all applicable cybersecurity and information security requirements.
CMMC itself enters a DoD contract through the DFARS. DFARS 204.7504 prescribes DFARS 252.204-7021 and 252.204-7025. Until November 9, 2028, the clause is used when the program office or requiring activity determines that the contractor must have a specific CMMC level. From November 10, 2028, it is used when the contractor will use its information systems to process, store, or transmit FCI or CUI in performance of the contract. Contracts solely for commercially available off-the-shelf items are excluded in both periods.
Under DoD class deviations 2026-O0025 and 2026-O0038, effective February 1, 2026, DoD contracting officers use the overhauled FAR Part 40 and Part 52. There, FAR 40.303-2 prescribes FAR 52.240-93, Basic Safeguarding of Covered Contractor Information Systems, under the same test of Federal Contract Information residing in or moving through the information system. As of October 2026, the codified FAR still carries FAR 4.1903 and FAR 52.204-21.
What This Means
Look for the safeguarding clause itself, not only for CMMC. If FAR 52.204-21 is in your contract, or FAR 52.240-93 in a DoD solicitation under the deviations, its 15 safeguards apply to the covered contractor information systems that process, store, or transmit FCI, whether or not a CMMC clause is present. That holds for a civilian agency contract as well as a DoD one.
What CMMC adds is verification. When a DoD solicitation requires CMMC Level 1, a current self-assessment entered in SPRS and its affirmation by a senior official are conditions of award. Without a CMMC clause, that contract has no CMMC level to meet, but the safeguards still come from the FAR clause.
Whether a given contract includes the clause, and which of your systems handle FCI, are questions you answer from the contract and your own environment.
Related Definitions
Related Questions
Primary Sources
Source Authority
- Primary Authority
- FAR 4.1902
- Program Authority
- 32 CFR 170.15(c)(1)(ii) Table 2
- Framework Version
- CMMC Assessment Guide, Level 1 v2.13 (September 2024)
- Written By
- AssessrLog, from the primary sources listed above
Cite This Page
“Does FAR 52.204-21 Apply if My Contract Has No CMMC Clause?.” AssessrLog, a product of ProfytAI Pte. Ltd.. https://assessrlog.com/cmmc/guides/does-far-52-204-21-apply-without-a-cmmc-clause/
Build the Record Behind This
AssessrLog is the self-serve system of record for your Level 1 self-assessment. Scope your FCI, work all 59 objectives at your own pace, log each determination with its evidence, and hand your official a clean, defensible package. The determination is always yours to make.
