Compliance & StandardsGlossary

What Is DFARS 252.204-7012?

Also known as: DFARS 7012, Safeguarding Covered Defense Information clause

Definition

DFARS 252.204-7012 is the Defense Department contract clause requiring contractors to protect covered defense information by implementing NIST SP 800-171, to report cyber incidents to DoD within 72 hours, and to flow the same obligations down to subcontractors.

DFARS 252.204-7012 Explained

Titled Safeguarding Covered Defense Information and Cyber Incident Reporting, this clause is the legal hook that put commercial cybersecurity standards into defense contracts. It applies to covered contractor information systems - any system that processes, stores, or transmits covered defense information. Covered defense information is essentially the DoD-relevant subset of Controlled Unclassified Information: controlled technical data, export-controlled information, and other categories identified in the contract or generated in performance of it.

The safeguarding requirement is specific. The clause obligates contractors to provide adequate security, and it defines adequate security for covered contractor information systems as implementing NIST Special Publication 800-171. Where a requirement is not implemented, the contractor must document the deviation and, historically, could notify the contracting officer of an equivalent alternative measure. This is the origin of the System Security Plan and Plan of Action and Milestones artifacts every defense supplier now maintains.

Incident reporting is the operational teeth. On discovery of a cyber incident affecting a covered system or covered defense information, the contractor must conduct a review for compromise and report to DoD within 72 hours through the DIBNet portal. Reporting requires a DoD-approved medium assurance certificate, which must be obtained in advance - companies that wait until an incident occurs routinely blow the 72-hour window on certificate procurement alone. The contractor must also preserve affected images and packet capture for at least 90 days and provide media or access on request.

Cloud usage carries its own condition. If a contractor uses an external cloud service provider to store, process, or transmit covered defense information, that provider must meet security requirements equivalent to the FedRAMP Moderate baseline, and must comply with the same incident reporting, media preservation, and cyber incident damage assessment obligations. This is why defense suppliers gravitate toward government-community cloud offerings or keep controlled workloads on premises, where the equivalency argument is simpler to make and defend.

The clause does not stand alone. DFARS 252.204-7019 and 7020 require contractors to compute a NIST SP 800-171 self-assessment score and post it in the Supplier Performance Risk System, with DoD reserving the right to conduct higher-level assessments. DFARS 252.204-7021 adds the CMMC requirement. Together the family converts a written promise into a scored, reported, and eventually independently verified obligation, and the 7012 clause must be flowed down verbatim to any subcontractor whose work involves covered defense information.

Why It Matters

  • The clause makes NIST SP 800-171 contractually binding, so a control gap is a contract compliance failure rather than an internal IT shortfall.
  • The 72-hour incident reporting window is short enough that unprepared contractors miss it, and a missed report is itself a breach of contract.
  • Cloud services touching covered defense information must meet FedRAMP Moderate equivalency, which eliminates many commercial SaaS and AI tools by default.
  • Mandatory flowdown means primes must police subtier suppliers, and small shops inherit obligations sized for far larger compliance organizations.

In Practice

The most common failure is the medium assurance certificate. A supplier detects ransomware on a Friday, spends the weekend on containment, and starts the DIBNet report Monday morning - only to discover the portal requires an ECA medium assurance certificate that takes days to obtain and validate. Obtain the certificate during onboarding, assign at least two named holders so vacation does not break reporting, and run a tabletop that includes an actual portal login so the 72-hour clock is never spent on credentials.

Frequently Asked Questions

What triggers a 72-hour report under DFARS 252.204-7012?

The clock starts on discovery of a cyber incident that affects a covered contractor information system or the covered defense information residing on it, including incidents affecting the contractor's ability to perform operationally critical support. Discovery, not confirmation of loss, starts the clock, so contractors report on reasonable suspicion and supplement the report as the investigation develops.

Does DFARS 252.204-7012 apply to commercial off-the-shelf suppliers?

The clause is generally not required for acquisitions solely for commercially available off-the-shelf items. However, if a supplier receives or generates covered defense information in performing the work - controlled drawings, export-controlled specifications, or DoD-specific technical data - the clause applies and must be flowed down, even when the underlying item is otherwise commercial.

Working with DFARS 252.204-7012 in a live environment? Our engineers do this every day - and our AI agents automate most of it.