DFARS 252.204-7012: what the clause requires

Defense Federal Acquisition Regulation Supplement (DFARS) clause 252.204-7012, "Safeguarding Covered Defense Information and Cyber Incident Reporting," is the clause that starts most defense cybersecurity obligations. It is the reason a supplier implements the 110 requirements of National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171, posts a score in the Supplier Performance Risk System (SPRS), and reports a breach within 72 hours.

This page sets out what the clause asks for, in plain words. Clause and document titles are given as published, which is why some of them still read "DoD" after the Department of Defense was renamed the Department of War (DoW).

One clause, five obligationsA box labeled DFARS 252.204-7012 with five arrows leading to boxes labeled protect, report, preserve, cloud, and flow down.DFARS 252.204-7012ProtectReportPreserveCloudFlow down
The clause covers protection, reporting, preservation, cloud providers, and the suppliers below you.

Who the clause covers

Two defined terms decide whether the clause reaches you.

Covered defense information. Unclassified controlled technical information or other information that requires safeguarding, and that is either marked and provided to you in support of the contract, or collected, developed, received, transmitted, used, or stored by you in support of the contract. In practice this is the Controlled Unclassified Information (CUI) your customer sends you, plus what you create for them.

Covered contractor information system. An unclassified system that you own or operate, that processes, stores, or transmits covered defense information.

If both apply, the clause applies. It applies to small suppliers too, because the prime contractor must include it in subcontracts.

What the clause requires

Obligation What it means
Adequate security Implement the 110 security requirements of NIST SP 800-171 on covered contractor information systems.
Variance requests If you propose to vary from a requirement, submit a written explanation to the contracting officer showing the requirement does not apply or that an alternative measure gives equivalent protection. DFARS provision 252.204-7008 carries this at the offer stage.
Rapid incident reporting Report a cyber incident to the government through the Defense Industrial Base network portal within 72 hours of discovering it.
Medium assurance certificate Hold a government-approved medium assurance certificate, because you need one to submit the report.
Malicious software Submit malicious software discovered and isolated in connection with a reported incident, as directed.
Media preservation Preserve and protect images of affected systems and relevant monitoring data for at least 90 days from the date you submit the incident report.
Forensic access Provide access to additional information and equipment the government needs for forensic analysis.
Damage assessment Support the government's assessment of what the incident affected.
Cloud providers If an outside cloud service holds covered defense information, require and confirm that it meets security requirements equivalent to the Federal Risk and Authorization Management Program (FedRAMP) Moderate baseline, and that it meets the clause's incident, malware, preservation, forensic, and damage assessment duties.
Flowdown Include the clause in subcontracts where performance involves covered defense information or operationally critical support.

The 72-hour clock, in practice

"Rapidly report" means within 72 hours of discovery. Three details decide whether a company meets that in a real incident.

  1. Get the certificate before you need it. The reporting portal requires a government-approved medium assurance certificate. A company that starts the certificate process during an incident will miss the window.
  2. Report what you know. If you do not have everything the clause asks for inside 72 hours, report the details you have and submit updates as you learn more. Waiting for a complete picture is the wrong trade.
  3. Start preserving immediately. The 90-day preservation period runs from the date you submit the report, so the images and monitoring data have to survive from the moment you discover the incident.

Reporting an incident is not an admission that you failed a requirement. The clause treats reporting as part of doing the work.

Flowdown: why small suppliers get asked

The clause is included in subcontracts when performance involves covered defense information or operationally critical support. Two duties travel with it.

  • A subcontractor notifies the tier above it when it asks the contracting officer to vary from a NIST SP 800-171 requirement.
  • A subcontractor gives the incident report number, which the government assigns automatically, to the tier above it as soon as practicable.

Separately, DFARS clause 252.204-7020 requires a contractor to confirm that its subcontractors have a current assessment posted in SPRS before awarding a subcontract. That is why a supplier with no direct government contract still gets asked for a score. See SPRS score.

Does the July 2026 pause change this?

No. The Department of War (DoW) suspended the CMMC Phase 2 transition on July 13, 2026, and Class Deviation 2026-O0025, Revision 3 carried that into the clause-insertion rules. That suspension affects when and how compliance is verified by a third party. It does not remove DFARS 252.204-7012, the 110 requirements of NIST SP 800-171, the SPRS score, the annual affirmation, or the 72-hour reporting duty.

The practical reading is that the deadline moved and the work did not. CMMC Phase 2 has the full timeline, and Why CMMC was paused, and what actually fixes it has the argument.

Where the AIC CMMC Complete™ kit fits

Analog Informatics Corporation (AIC) builds AIC CMMC Complete™ for Level 1, Level 2, and Level 3. The clause asks for a mix of technical controls, records, and acts that only your organization can perform. The table separates them.

Clause obligation Kit role
Implement NIST SP 800-171 access control, authentication, and audit requirements Performs
Check control state continuously and show what changed Performs
Hold the evidence behind each requirement Records
Track open items as Plan of Action and Milestones (POA&M) entries Records
Keep incident records with status and history, and forward them to ticket systems and a security information and event management (SIEM) system Assists
Submit the report to the government portal within 72 hours Not a kit function
Obtain and maintain the medium assurance certificate Not a kit function
Preserve system images and monitoring data for 90 days Not a kit function
Confirm a cloud provider meets FedRAMP Moderate equivalent requirements Not a kit function
Post and affirm the SPRS score Not a kit function

How to read the kit role:

Kit role Meaning
Performs The kit does the work on the systems and paths it manages.
Assists The kit does part of the work, and a person finishes it.
Records The kit holds the evidence and the history.

How to read availability:

  • The named AIC module ships and works on the systems and paths the kit manages.
  • The module ships. Coverage of systems outside the kit is planned, or stays with the organization.
  • The product does not do this yet.
  • People, facilities, policy, or tools the organization operates. The Assessment Binder can store the record.

An assessment organization, certification body, or regulator decides whether a requirement is satisfied. These pages describe product availability. They are not an assessment result, a certification, or legal advice.

Common questions

Is this the same as CMMC? No. DFARS 252.204-7012 requires you to implement NIST SP 800-171 and report incidents. CMMC is the program that verifies you did, and it arrives through DFARS clause 252.204-7021. Many companies carry the 7012 obligation today without a CMMC certification requirement in the contract yet.

What counts as a cyber incident? Actions that compromise, or that actually or potentially adversely affect, a covered contractor information system or the covered defense information on it, or your ability to perform operationally critical support.

Does the clause apply if we only handle Federal Contract Information? The clause is written around covered defense information. If you handle Federal Contract Information (FCI) and not CUI, your obligations usually sit at CMMC Level 1 instead. See CMMC Level 1.

Can we use a commercial cloud service? Yes, if it meets security requirements equivalent to the FedRAMP Moderate baseline and supports the clause's incident, malware, preservation, forensic, and damage assessment duties. The duty to confirm that is yours, not the provider's.

What if we cannot meet a requirement? Submit a written explanation to the contracting officer showing the requirement does not apply, or that an alternative measure gives equivalent protection. Do not simply record it as met.

How long do we keep incident evidence? At least 90 days from the date you submit the incident report.