Most defense contractors store covered defense information somewhere they do not own. DFARS 252.204-7012 has a specific paragraph about that, and it asks for more than a vendor's assurance.
If you process, store, or transmit covered defense information in a cloud service you did not build, DFARS 252.204-7012(b)(2)(ii)(D) puts two obligations on you — not on your provider. The clause requires the contractor to "require and ensure" that the cloud service provider meets security requirements equivalent to the FedRAMP Moderate baseline, and that the provider complies with paragraphs (c) through (g) of the clause. Those are separate commitments, and the second one is the one that gets skipped.
First, Figure Out Which Cloud Rule Applies
The clause splits cloud into two regimes, and they are not interchangeable.
If the system is part of an IT service or system operated on behalf of the Government, paragraph (b)(1)(i) routes you to DFARS 252.239-7010, Cloud Computing Services — a different clause with a different security baseline and its own terms.
If the system is your own environment — your Microsoft 365 tenant, your engineering file share, your ERP instance — you are in paragraph (b)(2), where NIST SP 800-171 governs your system and (b)(2)(ii)(D) governs the external cloud provider you hand covered defense information to. Getting this threshold question wrong means applying the wrong baseline to the wrong system. Our Find My Requirements tool walks the same branch.
"Require and Ensure" Is a Verb Pair
The clause does not say select a provider that claims equivalency. It says require and ensure. In contract terms, that means two things:
- Require — the obligation is written into your agreement with the provider, so equivalency and incident cooperation are contractual duties you can enforce, not marketing assertions on a trust page.
- Ensure — you hold evidence sufficient to support the representation you are making to the Government. A vendor questionnaire, a SOC 2 report scoped to something else, or a sales engineer's email is not the same thing as documentation mapped to the FedRAMP Moderate baseline.
DoD's Chief Information Officer has published guidance specifically on this question — Federal Risk and Authorization Management Program Moderate Equivalency for Cloud Service Provider's Cloud Service Offerings — and it is worth reading in full before you rely on any provider's equivalency claim. A provider that is already FedRAMP Moderate or High authorized removes the question entirely; "equivalent" is the harder path, and the contractor carries the proof.
The Part Almost Nobody Negotiates: Paragraphs (c) Through (g)
Read (b)(2)(ii)(D) to the end. The provider must also comply with the clause's incident machinery:
- (c) Cyber incident reporting — review for evidence of compromise and rapidly report to DoD at DIBNet, where "rapidly report" means within 72 hours of discovery. See our walkthrough of the 72-hour report's mechanics.
- (d) Malicious software — isolated malware goes to the DoD Cyber Crime Center (DC3), not to the contracting officer.
- (e) Media preservation and protection — images of affected systems and relevant monitoring and packet capture data preserved for at least 90 days from submission of the incident report.
- (f) Forensic access — on request, DoD gets access to additional information or equipment needed for forensic analysis.
- (g) Damage assessment — if DoD elects to conduct one, the information gathered under (e) is produced.
Ask an honest question about your current provider: if DoD asked for 90 days of packet capture from that tenant tomorrow, could you produce it? If the answer is no, the gap is contractual, not technical, and it exists today.
What to Do This Quarter
1. Inventory every external cloud service that touches covered defense information — including the ones adopted without IT's involvement. 2. Check authorization status first. FedRAMP Moderate or High authorized is the clean answer. 3. Pull the contract for anything claiming equivalency and confirm the equivalency and (c)–(g) obligations actually appear in it. 4. Collect the evidence and file it with your system security plan, because that is where an assessor will look. 5. Flow it down. Paragraph (m) requires the clause in subcontracts involving covered defense information, and your subcontractors have cloud providers too — see flowdown obligations.
This is also a scoping exercise. An external cloud service that handles covered defense information does not sit outside your boundary because someone else runs it; see CMMC Level 2 asset categories and our compliance checklists for how to document it.
Key Takeaways
- The obligation is yours, not the vendor's. DFARS 252.204-7012(b)(2)(ii)(D) tells the contractor to require and ensure — a provider's compliance page does not discharge it.
- Equivalency is only half the paragraph. The provider must also comply with paragraphs (c) through (g): 72-hour reporting, malware submission to DC3, 90-day media preservation, forensic access, and damage assessment support.
- Confirm which cloud rule applies before anything else. Systems operated on behalf of the Government run through DFARS 252.239-7010; your own environments run through (b)(2) and NIST SP 800-171.
GovConCyber publishes educational information about government contractor cybersecurity requirements. It is not legal advice, and it does not create an attorney-client relationship.