DFARS 252.204-7012

DFARS 252.204-7012: the clause that survived the pause.

DFARS 252.204-7012 — Safeguarding Covered Defense Information and Cyber Incident Reporting — is the contract clause that makes NIST 800-171 binding, requires cyber incidents to be reported to the Department within 72 hours, sets the bar for cloud services holding covered defense information, and obliges you to flow all of it down to your subcontractors. It has been in DoD contracts since 2017, and nothing about the July 2026 CMMC suspension changed it.

Last reviewed

What the clause requires

Four obligations, and most organizations have only implemented the first.

DFARS 252.204-7012 appears in DoD solicitations and contracts wherever covered defense information will be processed, stored or transmitted on a contractor system. It is the mechanism by which a NIST publication becomes something you can be held to commercially, and it does four things at once.

1. Adequate security. You must provide it, and the clause defines it as implementing NIST SP 800-171 — all 110 requirements. This obligation has run since 31 December 2017. It is not new, it is not CMMC, and it does not wait for a certification program to tell you when to start.

2. Rapid incident reporting. Cyber incidents affecting covered defense information, or the contractor’s ability to perform operationally critical support, must be reported to the Department within 72 hours of discovery, through dibnet.dod.mil.

3. Preservation and cooperation. You must preserve and protect images of affected systems for at least 90 days from the report, submit malicious software if you find it, and give the Department access to information and equipment necessary for forensic analysis and damage assessment.

4. Flow-down. The clause must be included in subcontracts for operationally critical support, or where subcontract performance will involve covered defense information — without alteration except to identify the parties.

The 72-hour clock, and what to do before it starts

Three days is not long, and the part people are not ready for is not the investigation.

The clock starts at discovery, not at confirmation, and 72 hours is not enough time to establish what happened. That is by design — the report is a notification, not a conclusion, and it can be updated. Organizations that miss the window usually do so not because they were still investigating, but because of the mechanics.

Reporting through DIBNet requires a DoD-approved medium assurance certificate. That is not something to discover you need on day one of an incident: obtaining one takes time, involves a person who may be on leave, and cannot be rushed in the middle of a response. Get it in advance, make sure more than one person can use it, and put the details in the incident response plan rather than in someone’s memory.

Two more preparations pay for themselves. Decide in advance who has the authority to declare that the threshold is met — ambiguity there is where days go. And reconcile the 72-hour duty with your other reporting clocks: state breach laws, the SEC’s disclosure rules if you are a public company, and whatever your prime contract adds on top. They are not the same deadline, and they are not the same audience.

Cloud services and FedRAMP Moderate equivalency

The requirement that quietly disqualifies a lot of ordinary SaaS.

If you use an external cloud service provider to store, process or transmit covered defense information, the clause requires you to ensure that provider meets security requirements equivalent to the FedRAMP Moderate baseline, and that it complies with the incident reporting, malicious software submission, media preservation, forensic access and damage assessment paragraphs of the clause.

The word doing the work is equivalent. A provider holding an actual FedRAMP Moderate authorization is straightforward. A provider claiming equivalence is a document review — and the responsibility for that judgment is yours, not theirs. Where a service holds no authorization and offers no assessment against the baseline, the honest answer is usually that covered defense information should not be in it.

This is worth auditing directly, because it is the requirement most likely to be failed by accident. Covered defense information reaches file-sharing tools, e-signature platforms, project trackers and email systems that nobody thinks of as “the CUI system”. Each of those is an external service provider inside your boundary.

Flow-down: the obligation you cannot inspect

You are required to pass this down the chain, required to confirm it, and given no right to look.

The clause flows down without alteration to any subcontractor whose performance involves covered defense information, at every tier. CMMC adds a verification layer on top: primes must ensure a subcontractor holds the required status before award, and that it affirms continued compliance annually. Where the subcontractor will handle only Federal Contract Information, Level 1 (Self) is the requirement; where CUI is involved and the prime contract carries a Level 3 requirement, the minimum for the subcontractor is Level 2 with a C3PAO certification.

Read that carefully and the structural problem is plain. You are accountable for security controls operating inside companies you have no contractual right to audit, whose evidence reaches you as a self-attestation, refreshed annually at best. In between, their environment changes — new remote access, a migration that exposes a service, an expired certificate, an acquisition that merges two networks with different standards. None of that is reported to you. All of it is your exposure.

The failures that matter here are not exotic. A supplier stands up a remote desktop gateway during a busy month and leaves it exposed. A test environment holding real drawings gets published to the internet. A domain lapses and is re-registered by someone else. Every one of those is visible from outside, on the day it happens, to anyone looking — and nobody is looking, because the process asks a question once a year.

That gap is what continuous external monitoring closes. It does not replace the attestation, which is contractually required, and it does not require the supplier’s cooperation. Supplier risk management covers how the rating works, and supply chain risk covers the wider chain, including the fourth parties you never contracted with.

The clause family, and how they fit together family

Four clauses do four different jobs, and they get used interchangeably in conversation when they should not be.

ClauseWhat it does
252.204-7012Safeguarding and cyber incident reporting. Imposes NIST 800-171, the 72-hour report, cloud equivalency and flow-down.
252.204-7019Requires a current NIST 800-171 self-assessment score in SPRS as a condition of being considered for award.
252.204-7020Requires the score to be maintained, and gives the government access to conduct a higher-level assessment through DIBCAC.
252.204-7021The CMMC clause. Requires the CMMC status specified in the contract, at award and for its duration, and flows down. This is the clause the phased rollout turns on.

Status as at 23 August 2026.

What the CMMC pause did not suspend

On 13 July 2026 the Department suspended CMMC Phase 2 and the implementation milestones after it, pending a reform review reporting in mid-September 2026. That suspension operates on 252.204-7021 — the certification requirement. 252.204-7012 is untouched. Adequate security, 72-hour reporting, cloud equivalency and flow-down are contract terms in force today, enforceable through the contract rather than through the CMMC program, and they have been since 2017. Any advice that treats the pause as permission to stop is advice about the wrong clause.

A DFARS 7012 readiness check

Eight things to be able to answer today.

  • Do you know which contracts carry the clause?
    And which subcontracts you have flowed it down into?
  • Can you produce a current 800-171 score?
    Posted in SPRS, dated, and matching the environment as it is now.
  • Do you hold a medium assurance certificate for DIBNet?
    Held by more than one named person, before an incident, not during one.
  • Is 72 hours in your incident response plan?
    With a named person authorized to decide the threshold is met.
  • Have you listed every cloud service that touches CDI?
    Including the ones nobody thinks of as systems — e-signature, file transfer, trackers.
  • Can each of those demonstrate FedRAMP Moderate equivalency?
    An authorization, or an assessment you have actually reviewed.
  • Could you preserve system images for 90 days?
    Capacity, process and authority — tested, not assumed.
  • Do you know what your subcontractors look like from outside?
    Their attestation says what was true when they signed it. Continuous monitoring says what is true now.

DFARS 7012 questions.

What is DFARS 252.204-7012?
A DoD contract clause requiring contractors to safeguard covered defense information by implementing NIST SP 800-171, to report cyber incidents within 72 hours, to meet cloud security requirements equivalent to FedRAMP Moderate where covered defense information is held in a cloud service, and to flow those obligations down to subcontractors.
How quickly must a cyber incident be reported?
Within 72 hours of discovery, through dibnet.dod.mil. Reporting requires a DoD-approved medium assurance certificate, which should be obtained in advance.
What is the difference between DFARS 7012 and CMMC?
DFARS 252.204-7012 imposes the security requirement and has done since 2017. CMMC, through DFARS 252.204-7021, is the program that verifies it. The CMMC Phase 2 suspension in July 2026 affects the verification, not the underlying obligation.
Does DFARS 7012 flow down to subcontractors?
Yes, without alteration other than identifying the parties, to any subcontract whose performance will involve covered defense information or operationally critical support, at every tier of the supply chain.
Can we use ordinary commercial cloud services for covered defense information?
Only where the provider meets security requirements equivalent to the FedRAMP Moderate baseline and complies with the clause’s incident reporting, preservation and forensic access provisions. Assessing that equivalence is the contractor’s responsibility, not the provider’s.

You flowed it down. Now verify it.

Book a 30-minute call and we will rate one of your subcontractors from the outside — what their perimeter shows today, not what their attestation said last year.