DFARS 252.204-7012: what the clause requires
Defense Federal Acquisition Regulation Supplement (DFARS) clause 252.204-7012, "Safeguarding Covered Defense Information and Cyber Incident Reporting," is the clause that starts most defense cybersecurity obligations. It is the reason a supplier implements the 110 requirements of National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171, posts a score in the Supplier Performance Risk System (SPRS), and reports a breach within 72 hours.
This page sets out what the clause asks for, in plain words. Clause and document titles are given as published, which is why some of them still read "DoD" after the Department of Defense was renamed the Department of War (DoW).
Who the clause covers
Two defined terms decide whether the clause reaches you.
Covered defense information. Unclassified controlled technical information or other information that requires safeguarding, and that is either marked and provided to you in support of the contract, or collected, developed, received, transmitted, used, or stored by you in support of the contract. In practice this is the Controlled Unclassified Information (CUI) your customer sends you, plus what you create for them.
Covered contractor information system. An unclassified system that you own or operate, that processes, stores, or transmits covered defense information.
If both apply, the clause applies. It applies to small suppliers too, because the prime contractor must include it in subcontracts.
What the clause requires
| Obligation | What it means |
|---|---|
| Adequate security | Implement the 110 security requirements of NIST SP 800-171 on covered contractor information systems. |
| Variance requests | If you propose to vary from a requirement, submit a written explanation to the contracting officer showing the requirement does not apply or that an alternative measure gives equivalent protection. DFARS provision 252.204-7008 carries this at the offer stage. |
| Rapid incident reporting | Report a cyber incident to the government through the Defense Industrial Base network portal within 72 hours of discovering it. |
| Medium assurance certificate | Hold a government-approved medium assurance certificate, because you need one to submit the report. |
| Malicious software | Submit malicious software discovered and isolated in connection with a reported incident, as directed. |
| Media preservation | Preserve and protect images of affected systems and relevant monitoring data for at least 90 days from the date you submit the incident report. |
| Forensic access | Provide access to additional information and equipment the government needs for forensic analysis. |
| Damage assessment | Support the government's assessment of what the incident affected. |
| Cloud providers | If an outside cloud service holds covered defense information, require and confirm that it meets security requirements equivalent to the Federal Risk and Authorization Management Program (FedRAMP) Moderate baseline, and that it meets the clause's incident, malware, preservation, forensic, and damage assessment duties. |
| Flowdown | Include the clause in subcontracts where performance involves covered defense information or operationally critical support. |
The 72-hour clock, in practice
"Rapidly report" means within 72 hours of discovery. Three details decide whether a company meets that in a real incident.
- Get the certificate before you need it. The reporting portal requires a government-approved medium assurance certificate. A company that starts the certificate process during an incident will miss the window.
- Report what you know. If you do not have everything the clause asks for inside 72 hours, report the details you have and submit updates as you learn more. Waiting for a complete picture is the wrong trade.
- Start preserving immediately. The 90-day preservation period runs from the date you submit the report, so the images and monitoring data have to survive from the moment you discover the incident.
Reporting an incident is not an admission that you failed a requirement. The clause treats reporting as part of doing the work.
Flowdown: why small suppliers get asked
The clause is included in subcontracts when performance involves covered defense information or operationally critical support. Two duties travel with it.
- A subcontractor notifies the tier above it when it asks the contracting officer to vary from a NIST SP 800-171 requirement.
- A subcontractor gives the incident report number, which the government assigns automatically, to the tier above it as soon as practicable.
Separately, DFARS clause 252.204-7020 requires a contractor to confirm that its subcontractors have a current assessment posted in SPRS before awarding a subcontract. That is why a supplier with no direct government contract still gets asked for a score. See SPRS score.
The related clauses
| Clause | What it adds |
|---|---|
| DFARS 252.204-7008 | At the offer stage, requires a written explanation for any NIST SP 800-171 control you propose to vary from. |
| DFARS 252.204-7012 | This clause. Safeguarding plus cyber incident reporting. |
| DFARS 252.204-7019 | You must have a current assessment, generally not more than three years old, posted in SPRS to be considered for award. |
| DFARS 252.204-7020 | Government access for a Medium or High assessment, subcontractor confirmation, and flowdown. |
| DFARS 252.204-7021 | The Cybersecurity Maturity Model Certification (CMMC) requirement clause. |
Does the July 2026 pause change this?
No. The Department of War (DoW) suspended the CMMC Phase 2 transition on July 13, 2026, and Class Deviation 2026-O0025, Revision 3 carried that into the clause-insertion rules. That suspension affects when and how compliance is verified by a third party. It does not remove DFARS 252.204-7012, the 110 requirements of NIST SP 800-171, the SPRS score, the annual affirmation, or the 72-hour reporting duty.
The practical reading is that the deadline moved and the work did not. CMMC Phase 2 has the full timeline, and Why CMMC was paused, and what actually fixes it has the argument.
Where the AIC CMMC Complete kit fits
Analog Informatics Corporation (AIC) builds AIC CMMC Completeâ„¢ for Level 1, Level 2, and Level 3. The clause asks for a mix of technical controls, records, and acts that only your organization can perform. The table separates them.
| Clause obligation | Kit role |
|---|---|
| Implement NIST SP 800-171 access control, authentication, and audit requirements | Performs |
| Check control state continuously and show what changed | Performs |
| Hold the evidence behind each requirement | Records |
| Track open items as Plan of Action and Milestones (POA&M) entries | Records |
| Keep incident records with status and history, and forward them to ticket systems and a security information and event management (SIEM) system | Assists |
| Submit the report to the government portal within 72 hours | Not a kit function |
| Obtain and maintain the medium assurance certificate | Not a kit function |
| Preserve system images and monitoring data for 90 days | Not a kit function |
| Confirm a cloud provider meets FedRAMP Moderate equivalent requirements | Not a kit function |
| Post and affirm the SPRS score | Not a kit function |
How to read the kit role:
| Kit role | Meaning |
|---|---|
| Performs | The kit does the work on the systems and paths it manages. |
| Assists | The kit does part of the work, and a person finishes it. |
| Records | The kit holds the evidence and the history. |
How to read availability:
An assessment organization, certification body, or regulator decides whether a requirement is satisfied. These pages describe product availability. They are not an assessment result, a certification, or legal advice.
Common questions
Is this the same as CMMC?
No. DFARS 252.204-7012 requires you to implement NIST SP 800-171 and report incidents. CMMC is the program that verifies you did, and it arrives through DFARS clause 252.204-7021. Many companies carry the 7012 obligation today without a CMMC certification requirement in the contract yet.
What counts as a cyber incident?
Actions that compromise, or that actually or potentially adversely affect, a covered contractor information system or the covered defense information on it, or your ability to perform operationally critical support.
Does the clause apply if we only handle Federal Contract Information?
The clause is written around covered defense information. If you handle Federal Contract Information (FCI) and not CUI, your obligations usually sit at CMMC Level 1 instead. See CMMC Level 1.
Can we use a commercial cloud service?
Yes, if it meets security requirements equivalent to the FedRAMP Moderate baseline and supports the clause's incident, malware, preservation, forensic, and damage assessment duties. The duty to confirm that is yours, not the provider's.
What if we cannot meet a requirement?
Submit a written explanation to the contracting officer showing the requirement does not apply, or that an alternative measure gives equivalent protection. Do not simply record it as met.
How long do we keep incident evidence?
At least 90 days from the date you submit the incident report.
Related pages
- SPRS score: how the number is calculated and posted
- CMMC Level 2: all 110 requirements, row by row
- NIST SP 800-171
- C3PAO: who performs a Level 2 certification assessment
- Secure enclaves: narrowing what the clause reaches
- Detect, respond, remediate
- Logging and SIEM
- AIC CMMC Completeâ„¢ and pricing
- Glossary
Sources
- DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting
- DFARS 252.204-7019, Notice of NIST SP 800-171 DoD Assessment Requirements
- DFARS 252.204-7020, NIST SP 800-171 DoD Assessment Requirements
- NIST SP 800-171 Rev. 2
- Defense Industrial Base cyber incident reporting portal
- External Certification Authority program, for the medium assurance certificate
- FedRAMP documents and templates
- Department of War announcement on the CMMC Phase II pause