FAR 252.204-7012 — Safeguarding Covered Defense Information and Cyber Incident Reporting

This DFARS clause requires DoD contractors to implement NIST SP 800-171 security controls to protect covered defense information and to report cyber incidents to DoD within 72 hours of discovery. It is the direct predecessor to CMMC assessment requirements.

Clause
FAR 252.204-7012
Applies to
DoD contracts involving covered defense information
Flows down to subs
Yes
Primary risk
72-hour incident reporting failures and NIST 800-171 gaps

Key takeaways

  • Read the clause as incorporated in your contract — tailoring and alternates change obligations.
  • Flowdown obligations are your responsibility; a noncompliant subcontractor is your problem.
  • Document compliance contemporaneously; after-the-fact reconstruction rarely satisfies auditors.
  • When a clause is unclear, ask the contracting officer in writing before award, not after.

What the clause requires

You must implement the 110 security requirements in NIST SP 800-171 on any system that processes, stores, or transmits covered defense information, report cyber incidents affecting covered information or systems within 72 hours via the DoD portal, preserve forensic images and malicious software for at least 90 days, and flow the clause down to subcontractors handling covered defense information.

How to comply in practice

Complete and maintain a System Security Plan and Plan of Action and Milestones documenting your NIST 800-171 implementation status, register in the DoD cyber incident reporting portal before you need it, and rehearse your 72-hour reporting process so it isn't built from scratch during an actual incident.

Common mistakes

Contractors treat NIST 800-171 compliance as a one-time checklist rather than a maintained program, and discover during a DIBCAC assessment or incident that their SSP does not reflect actual system configuration.

FAQ

What is covered defense information?

Unclassified controlled technical information and other categories of controlled unclassified information provided by or generated for DoD in performance of the contract.

How fast must I report an incident?

Within 72 hours of discovery, through the DoD-designated cyber incident reporting portal.

Does this flow down to subcontractors?

Yes, to subcontractors at any tier that will process, store, or transmit covered defense information.

Draft a compliant response for $2

RFP Scribe builds your compliance matrix and first draft from the solicitation and your Company Brain.

Get started

Services that help with this

Buy just the piece you need — most start at a few dollars, no subscription required.

Browse all services