Skip to main content
Compliance Guidance

The 72-Hour Clock: What DFARS 252.204-7012 Actually Requires You to Do

Nearly every defense contractor can recite the 72-hour reporting deadline. Far fewer have the credential required to file the report — and that credential cannot be obtained in 72 hours.

Brandon Hancock, J.D., CMMC-RPPublished September 7, 2026Updated September 7, 20267 min read

Nearly every defense contractor can recite the 72-hour reporting deadline. Far fewer have the credential required to file the report — and that credential cannot be obtained in 72 hours.

The reporting obligation in DFARS 252.204-7012 is not a single act; it is five distinct duties that start at different moments and run on different clocks. Contractors who plan only for the deadline routinely discover, mid-incident, that they cannot submit at all. The clause text is short and worth reading in full — but its operational consequences are not obvious from a first pass.

What Starts the Clock

The clause defines "rapidly report" as "within 72 hours of discovery of any cyber incident." The trigger is discovery, not confirmation, not root-cause analysis, and not a determination that covered defense information was in fact exfiltrated.

That matters because the clause's definition of a cyber incident is deliberately broad: "actions taken through the use of computer networks that result in a compromise or an actual or potentially adverse effect on an information system and/or the information residing therein." Potentially adverse does substantial work. A contractor waiting for certainty before starting the clock has misread the standard.

The duty attaches under paragraph (c)(1) when an incident affects a covered contractor information system, the covered defense information residing on it, or the contractor's ability to perform requirements designated in the contract as operationally critical support. That third branch is often overlooked: it is not about data at all.

Two Things Must Happen, Not One

Paragraph (c)(1) imposes parallel obligations. The contractor must:

1. Conduct a review for evidence of compromise — "identifying compromised computers, servers, specific data, and user accounts," and analyzing not only the systems involved in the incident but "other information systems on the Contractor's network(s) that may have been accessed as a result." 2. Rapidly report the incident to DoD at the DIBNet portal.

The review is not a precondition to reporting. The 72 hours runs regardless of how far the investigation has gotten. Contractors who treat the review as a gate — "we'll report once we know what happened" — invert the clause. Report on time with what you know; the review continues.

The Credential Nobody Provisions in Advance

Paragraph (c)(3) is the paragraph that ends incidents badly. To report at all, "the Contractor or subcontractor shall have or acquire a DoD-approved medium assurance certificate." That is an External Certification Authority (ECA) certificate, and obtaining one involves identity vetting and issuance time measured in weeks — not the hours available once an incident is discovered.

This is a pre-incident provisioning task disguised as a reporting requirement. Two practical consequences follow. First, at least two people should hold a current certificate, so a single vacation or departure does not leave the company unable to file. Second, certificates expire; a lapsed certificate is functionally identical to never having had one.

The Duties That Outlast the Report

Submitting the report does not close the matter. Three obligations follow it:

  • Malicious software (paragraph (d)). When the contractor or a subcontractor discovers and isolates malicious software in connection with a reported incident, it is submitted to the DoD Cyber Crime Center (DC3) per DC3's or the Contracting Officer's instructions. The clause is explicit: do not send malicious software to the Contracting Officer.
  • Media preservation (paragraph (e)). Images of all known affected systems and all relevant monitoring/packet capture data must be preserved for at least 90 days from submission of the report — a window that runs from the filing date, not the incident date, so it is not a routine log retention period. (See our discussion of what your contract requires you to log.)
  • Access for forensics (paragraph (f)). On DoD request, the contractor provides access to additional information or equipment necessary for forensic analysis.

Remediating and reimaging affected systems before images are captured can extinguish evidence the contractor is contractually obligated to hold. Decide in advance who is authorized to pause remediation long enough to preserve.

Subcontractors Report Directly — and Report Back

Paragraph (m) requires the clause to flow down without alteration into subcontracts involving covered defense information or operationally critical support. Subcontractors report their own incidents to DoD; the prime does not report on their behalf. But paragraph (m)(2)(ii) requires subcontractors to "[p]rovide the incident report number, automatically assigned by DoD, to the prime Contractor (or next higher-tier subcontractor) as soon as practicable."

That number is the prime's only reliable evidence that a lower tier met its obligation. If your subcontract flowdown language does not name it, you have no mechanism to confirm compliance. For the broader structure, see cybersecurity flowdown obligations.

What to Confirm This Week

1. Identify who holds a current DoD-approved medium assurance certificate, and when each expires. 2. Write down who declares "discovery" — the clock does not start when a committee agrees. 3. Confirm your incident response plan preserves images before remediation, and names the person authorized to hold remediation. 4. Check that subcontract flowdowns require the DoD-assigned incident report number. 5. Verify whether any of your contracts designate operationally critical support, which creates a reporting trigger independent of data compromise.

Not sure which clauses your work carries? Start with Find My Requirements and the frameworks reference, then build documentation using the program-building tools and checklists. Defense-sector contractors should also review industry-specific requirements.

Key Takeaways

  • Discovery starts the clock, and the definition is broad. "Rapidly report" means within 72 hours of discovery, and a "cyber incident" includes an actual or potentially adverse effect — reporting is not gated on completing the compromise review that paragraph (c)(1)(i) separately requires.
  • You cannot file without a medium assurance certificate. Paragraph (c)(3) requires a DoD-approved (ECA) certificate to submit through DIBNet. Provisioning takes weeks, so treat it as pre-incident infrastructure and hold more than one.
  • The report is the beginning, not the end. Malicious software goes to DC3 (never the Contracting Officer), system images and packet capture data are preserved for at least 90 days from submission, DoD may request equipment for forensics, and subcontractors must hand the DoD-assigned report number up the chain.

This article is educational information about cybersecurity and government contracting requirements. It is not legal advice, and it does not create an attorney-client relationship. Contract-specific obligations depend on the clauses in your award.

Share
BH

Brandon Hancock

J.D. · CMMC Registered Practitioner (RP)

Brandon is the founder and principal advisor of GovConCyber. His advisory approach is shaped by roughly six years as a U.S. Army human intelligence collector, where information accuracy, source protection, classification discipline, need-to-know access, and controlled reporting were daily requirements. He brings that information-discipline mindset to GovConCyber's work helping government contractors understand and comply with federal cybersecurity obligations.

Was this post helpful?