FAR 252.204-7012 — Safeguarding Covered Defense Information and Cyber Incident Reporting
This DFARS clause requires DoD contractors to implement NIST SP 800-171 security controls to protect covered defense information and to report cyber incidents to DoD within 72 hours of discovery. It is the direct predecessor to CMMC assessment requirements.
- Clause
- FAR 252.204-7012
- Applies to
- DoD contracts involving covered defense information
- Flows down to subs
- Yes
- Primary risk
- 72-hour incident reporting failures and NIST 800-171 gaps
Key takeaways
- Read the clause as incorporated in your contract — tailoring and alternates change obligations.
- Flowdown obligations are your responsibility; a noncompliant subcontractor is your problem.
- Document compliance contemporaneously; after-the-fact reconstruction rarely satisfies auditors.
- When a clause is unclear, ask the contracting officer in writing before award, not after.
What the clause requires
You must implement the 110 security requirements in NIST SP 800-171 on any system that processes, stores, or transmits covered defense information, report cyber incidents affecting covered information or systems within 72 hours via the DoD portal, preserve forensic images and malicious software for at least 90 days, and flow the clause down to subcontractors handling covered defense information.
How to comply in practice
Complete and maintain a System Security Plan and Plan of Action and Milestones documenting your NIST 800-171 implementation status, register in the DoD cyber incident reporting portal before you need it, and rehearse your 72-hour reporting process so it isn't built from scratch during an actual incident.
Common mistakes
Contractors treat NIST 800-171 compliance as a one-time checklist rather than a maintained program, and discover during a DIBCAC assessment or incident that their SSP does not reflect actual system configuration.
FAQ
What is covered defense information?
Unclassified controlled technical information and other categories of controlled unclassified information provided by or generated for DoD in performance of the contract.
How fast must I report an incident?
Within 72 hours of discovery, through the DoD-designated cyber incident reporting portal.
Does this flow down to subcontractors?
Yes, to subcontractors at any tier that will process, store, or transmit covered defense information.
Draft a compliant response for $2
RFP Scribe builds your compliance matrix and first draft from the solicitation and your Company Brain.
Get startedServices that help with this
Buy just the piece you need — most start at a few dollars, no subscription required.
Compliance & Readability Scan
$2Verify every FAR requirement is addressed in your proposal.
Buy NowRFP Plain-English Summary
$3Translate dense solicitations with FAR references into actionable checklists.
Buy NowContract Modification Writer
$10Generate compliant modification requests with proper FAR citations.
Buy Now