AGILICRYPT™ Check your exposure

Does the government’s encryption rule reach your contracts?

Type your company name. We look it up in the public record of federal contracts and tell you what it shows — and, just as importantly, what it does not.

Tip: use the short form. The record is keyed on the registered legal name, so a trailing LLC, Inc. or Corporation can miss — two words usually find more than five. If nothing comes back, try fewer words, or the name your contracts are actually signed in.

The name you type is sent to USAspending.gov, the US government’s public award database, directly from your browser. It is not sent to us, and we do not log it. There is nothing else on this page — no analytics, no cookies, no trackers.

Plain words used on this page

Encryption
Scrambling information so only the right people can read it.
FIPS certificate
The U.S. government’s official record that a piece of encryption software or equipment was tested by an approved lab.
CUI
Controlled Unclassified Information: sensitive government information, such as some project drawings, that is not secret but must be protected.
Clause
A numbered section of your contract. 252.204-7012 is the Defense Department’s cybersecurity clause.
Prime / subcontractor
The prime holds the contract with the government; a subcontractor works under the prime.
Plan of action
Your company’s written to-do list of security gaps: what the gap is, who fixes it, and by when.

The test that settles it: read your own contract

This search reads the public spending record. Your contract is the actual authority, and you can check it in about two minutes.

Open your contract or subcontract agreement and search the text for 252.204-7012. In a federal prime contract it lives in Section I, Contract Clauses. In a subcontract or purchase order it is usually in the terms and conditions, or in a flow-down attachment.

If 252.204-7012 is there

What the government requires. Your contract treats the government information you receive as CUI. The cybersecurity rules that come with the clause require that information to be protected with encryption that holds a FIPS certificate whenever it is sent or stored outside your company’s protected systems.

What your company must do. Follow those rules — and, where your contract includes CMMC, score itself and have a senior manager sign that it is true, every year. Where some encryption has no certificate, write the gap into your plan of action — which the rules accept only when the problem is small, a real fix is on the way, and the plan shows steps, dates and progress.

What we provide. The proof behind that signature: which of your systems use encryption that holds a certificate, which do not, where a fix stands for each gap, and draft plan entries for you to finish. How it works.

Certificates also change status: on 21 September 2026 every remaining FIPS 140-2 certificate moves to NIST’s “Historical” list. Your systems keep working; what changes is the record behind them.

If you cannot find it, and the only safeguarding clause is FAR 52.204-21

That clause covers Federal Contract Information (non-public information about a government contract), not CUI. It sets fifteen basic security requirements and none of them requires encryption with a FIPS certificate. On that reading, the encryption rule does not reach you through that contract.

Check two things before you rely on it. First, a missing clause is not always an absent one: contracts routinely incorporate clauses by reference rather than printing them, so search for 252.204-7012 across the whole agreement and its attachments, not only Section I. Second, this answers the DoD question only — FedRAMP, CJIS and healthcare-adjacent terms impose FIPS-validated cryptography under their own authority, and CMMC Level 1 still applies to Federal Contract Information.

If you hold several contracts, this is a per-contract answer, not a company-wide one. One contract carrying the clause is enough to put the requirement on the systems that touch its data.

Not sure which clause you are looking at, or cannot find a Section I? Your contracting officer, or the prime’s contracts manager, can tell you in one email — and it is a reasonable thing to ask.

Why this is a contract question

Defense Department contract → your company receives CUI → the contract carries clause 252.204-7012 → which requires the NIST SP 800-171 security rules → which require encryption that holds a FIPS certificate → and, where the contract includes CMMC, your company signs that it meets them.

Under CMMC’s self-check, the person who signs is your own senior manager, not an outside inspector. That is CMMC Level 2 (Self): the Defense Department’s cybersecurity check where your company checks itself, posts its score in SPRS (the Defense Department’s supplier database), and a senior manager signs. Where the CMMC clause is in the contract, the prime above you must collect that signed statement before awarding your subcontract, and every year after. And the government can still come and check.

The part of this that cuts against us, said here rather than left for you to find: the outside CMMC inspections planned for contracts from November 2026 are paused. On 3 September 2026 a Defense Department class deviation (an official instruction to use different contract wording) allowed contracts to ask for CMMC Level 1 or Level 2 (Self) and suspended that step, and a reform task force is expected to report in late September or early October. What did not change: clause 252.204-7012, the NIST SP 800-171 rules and self-assessment all remain in force. Checked 15 September 2026.

What this check cannot tell you

Three limits, stated before you use it rather than after: