# Safeguarding Covered Defense Information and Cyber Incident Reporting
Short Answer
DFARS 252.204-7012 is the core DoD contract clause for safeguarding covered defense information and reporting cyber incidents. A contractor should care because the clause can turn NIST SP 800-171 implementation, incident reporting, forensic preservation, malware submission, and subcontractor flowdown into contract-performance obligations rather than optional security practices.
Why this matters for government contractors
For defense contractors, this clause is often the legal hinge between a technical cybersecurity program and a procurement obligation. It applies when the clause is included in a DoD contract and the contractor has covered defense information or provides operationally critical support. The clause is not a general cybersecurity statute; it is an acquisition clause with legal force because it is incorporated into the contract.
The most important practical point is that DFARS 252.204-7012 does several things at once. It requires adequate security on covered contractor information systems; it incorporates NIST SP 800-171 as the baseline for protecting covered defense information; it requires rapid reporting of covered cyber incidents to DoD; it requires preservation of images and monitoring data; it creates obligations around malicious software; and it requires flowdown to covered subcontractors. A contractor that treats it only as a list of technical controls misses the contract administration, incident-response, evidence, and supply-chain pieces.
What the clause does
The clause requires contractors to provide “adequate security” for covered defense information on covered contractor information systems. In ordinary contractor terms, that means the system that stores, processes, or transmits covered defense information must be protected using the security requirements in NIST SP 800-171 unless an approved variance or alternative measure applies. The clause also requires contractors to report covered cyber incidents within 72 hours of discovery and to submit reports through the DoD reporting mechanism.
The incident provisions matter because they are not limited to data-breach notification. A “covered cyber incident” is tied to actual or potentially adverse effect on a covered contractor information system, covered defense information, or the contractor’s ability to provide operationally critical support. After reporting, the contractor must preserve and protect images of affected systems and relevant monitoring or packet-capture data for at least 90 days so DoD can request it for forensic or damage-assessment purposes.
How it reaches contractors
DFARS 252.204-7012 reaches contractors through DoD solicitations, contracts, task orders, delivery orders, and covered subcontracts. It is especially important when a contractor receives, generates, stores, processes, or transmits covered defense information, which commonly overlaps with Controlled Unclassified Information but is framed through the DFARS definition. The clause also matters to prime contractors because the flowdown obligation is not a passive “send the clause along” exercise. Primes need a process for deciding which subcontracts involve covered defense information or operationally critical support and for ensuring subcontractors understand reporting and incident-number obligations.
Procurement and cybersecurity significance
The clause affects proposal strategy, system boundary definition, subcontractor vetting, incident-response planning, and compliance evidence. Contractors should be able to identify the covered contractor information system, the covered defense information in scope, the NIST SP 800-171 implementation status, any unresolved POA&M items, and how the incident-response process satisfies DoD reporting and evidence-preservation requirements.
This clause also intersects with enforcement risk. The False Claims Act is not a cybersecurity control, but inaccurate statements about DFARS 252.204-7012 compliance, unsupported NIST SP 800-171 representations, or concealment of material noncompliance can become significant when tied to award, payment, certifications, or claims. Contract remedies, termination risk, past-performance consequences, suspension/debarment concerns, and FCA theories can all be in play depending on the facts.
Relationship to other GovConCyber requirements
DFARS 252.204-7012 is the legal and contractual source that often makes NIST SP 800-171 operationally mandatory for DoD contractors. DFARS 252.204-7019 and 252.204-7020 add the SPRS assessment layer. DFARS 252.204-7021 and 32 C.F.R. Part 170 add the CMMC verification layer. 32 C.F.R. Part 2002 and Executive Order 13556 explain the government-wide CUI program that often supplies the protected-information context. CIRCIA, FedRAMP, agency incident rules, and state breach laws may add separate reporting obligations but do not replace the DoD 72-hour reporting obligation when this clause applies.
What contractors should do
- Confirm whether DFARS 252.204-7012 is in the solicitation, contract, order, or subcontract.
- Identify all covered defense information and the systems that store, process, or transmit it.
- Maintain a system security plan and current evidence of NIST SP 800-171 implementation for covered systems.
- Track POA&M items carefully and avoid overclaiming implementation status.
- Maintain an incident-response procedure that includes DoD reporting within 72 hours of discovery, DC3 submission steps, and preservation of system images and monitoring data.
- Build flowdown review into subcontract formation, supplier onboarding, and incident escalation.
- Coordinate DFARS reporting with CIRCIA, agency, FedRAMP, state, sector, and customer-notice obligations instead of assuming one report satisfies all regimes.
Current status
Current acquisition clause. The clause should be treated as in force when included in a DoD contract. The page should not describe CMMC as replacing DFARS 252.204-7012; CMMC adds verification and contract eligibility layers, while 7012 remains the core safeguarding and incident-reporting clause.
Primary citations
- DFARS 252.204-7012.
- 48 C.F.R. § 252.204-7012.
- NIST SP 800-171 Rev. 2 / Rev. 3, as incorporated by the applicable contract and rule.
- DFARS 252.204-7019; DFARS 252.204-7020; DFARS 252.204-7021.
---
Source type: acquisition_clause. Implementation status: in_force.