Last reviewed: June 29, 2026
The first reporting question is “Which obligations might be triggered?”
When a cyber incident occurs, contractors often ask, “Do we have to report this?” The better first question is: Which reporting regimes might apply, and what facts do we need to decide?
A single event can involve multiple reporting paths. For example, a ransomware event affecting a defense contractor's cloud environment could implicate DFARS 252.204-7012, prime-subcontract notice terms, customer notice terms, privacy breach laws, cyber insurance notice, law-enforcement coordination, FedRAMP or cloud-provider procedures, and future CIRCIA analysis if the contractor is a covered entity under the final rule.
The practical goal is not to overreport blindly. It is to build an incident-intake process that can identify potentially triggered obligations before deadlines pass.
DFARS 252.204-7012: the 72-hour DoD reporting rule
For many defense contractors, DFARS 252.204-7012 is the central cyber incident-reporting clause. It requires contractors to provide adequate security for covered contractor information systems, rapidly report cyber incidents to DoD, submit malicious software when discovered and isolated, preserve and protect images and monitoring/packet-capture data for at least 90 days, and support DoD damage assessment activities.
The clause requires rapid reporting within 72 hours of discovery of a cyber incident. Reports are submitted through DoD's reporting mechanism, commonly associated with DIBNet. Subcontractors must also report directly to DoD when the clause applies and provide the automatically assigned incident report number to the prime or next higher-tier subcontractor as soon as practicable.
Contractors should understand that 7012 reporting is not limited to confirmed data exfiltration. The clause uses contract-specific definitions, including “cyber incident,” “covered defense information,” and “covered contractor information system.” Legal, technical, and contract teams should review those definitions before deciding whether a report is required.
CMMC does not replace 7012 reporting
CMMC is an assessment and contract-eligibility framework for DoD contractors and subcontractors that process, store, or transmit FCI or CUI on contractor information systems. CMMC helps assess whether required cybersecurity practices are implemented, but it does not eliminate incident-reporting duties under DFARS 252.204-7012.
A contractor with a CMMC status can still experience a reportable cyber incident. A contractor preparing for CMMC should use incident-response planning as part of readiness: define escalation triggers, preserve evidence, maintain reporting contacts, train subcontractors, and test whether reporting decisions can be made within contractual timelines.
FAR and agency-specific reporting obligations
Outside DoD, contractors may face incident-reporting obligations through FAR clauses, agency supplements, security attachments, system authorization documents, statements of work, task-order terms, privacy clauses, cloud-service requirements, and customer-specific incident procedures. Civilian agency requirements can vary significantly.
Contractors should not assume that the absence of DFARS 252.204-7012 means there is no reporting duty. Review the contract, incorporated policies, agency cybersecurity clauses, system security requirements, privacy terms, and subcontract flowdowns.
CIRCIA status: important, but not yet a live final-rule reporting regime
The Cyber Incident Reporting for Critical Infrastructure Act of 2022 directs CISA to develop regulations requiring covered entities to report covered cyber incidents and ransom payments. CISA's official materials state that CIRCIA's regulatory requirements, including reporting requirements, will not be effective until the final rule goes into effect. As of this review date, CISA had issued a proposed rule and continued stakeholder engagement, including 2026 town hall activity.
Contractors should monitor CIRCIA if they operate in or support critical infrastructure sectors, including the defense industrial base, information technology, communications, financial services, healthcare, transportation, energy, government facilities, water, and other sectors. But GovConCyber copy should not state that CIRCIA final reporting obligations are currently effective unless official sources confirm that the final rule has taken effect.
FedRAMP, GovRAMP, and cloud incident reporting
Cloud incident reporting can involve the cloud service provider, the agency customer, the contractor using the cloud, and authorization-program procedures. FedRAMP provides a government-wide approach for authorizing cloud services used by federal agencies. GovRAMP, formerly StateRAMP, supports cloud security verification for state, local, tribal, and education government customers.
Contractors should determine whether a cloud provider's obligations satisfy the contractor's own obligations. Often they do not. The contractor may remain responsible for notifying its government customer, prime contractor, or DoD even if the cloud provider has its own incident process. Contracts should make cloud-provider notice timelines short enough to support the contractor's reporting deadlines.
Privacy and breach notification
Incidents involving personal information may trigger privacy, breach-notification, sector, agency, and state-law obligations. These may use different triggers from cybersecurity clauses. Some regimes focus on unauthorized acquisition of personal information; some focus on access, use, disclosure, or compromise; some include agency-specific definitions of privacy incident; some require notice to individuals, regulators, consumer reporting agencies, or government customers.
A contractor should triage privacy facts early: what data was involved, whose data it was, where affected individuals reside, whether the data was encrypted, whether acquisition or access occurred, whether misuse is likely, what contract terms require, and which customer must be notified.
State/local contracts and GovRAMP customers
State, local, tribal, territorial, and education contracts may impose their own reporting windows, security procedures, breach definitions, and procurement consequences. For public-sector cloud work, GovRAMP-related customer expectations may also appear in procurement or vendor management requirements. Do not assume federal timelines control state/local work.
Insurance reporting is separate
Cyber insurance policies often require prompt notice, consent before certain expenses, approved vendors, cooperation, and preservation of claim information. Insurance notice does not satisfy government reporting, and government reporting does not satisfy insurance notice. Incident-response playbooks should include both tracks.
Subcontractors and primes
Incident reporting can break down in the supply chain. A subcontractor may detect the incident first, but the prime may own customer communications. A prime may have the contract with the government, but the subcontractor may have the affected system. DFARS 252.204-7012 requires subcontractors to report directly to DoD when applicable, but many other regimes rely on contractual notice up the chain.
Subcontracts should specify:
- reporting triggers;
- reporting timelines shorter than prime deadlines;
- required facts and updates;
- evidence preservation;
- cooperation with government inquiries;
- restrictions on public statements;
- cyber insurance coordination; and
- whether the subcontractor reports directly to the government, to the prime, or both.
A practical incident-intake triage model
At intake, capture enough facts to route the event:
- What happened? Unauthorized access, malware, ransomware, phishing, credential compromise, lost device, misdirected email, cloud misconfiguration, insider misuse, supplier incident, vulnerability exploitation, or other event.
- What systems are involved? Contractor, government, cloud, subcontractor, endpoint, email, production, development, or third-party environment.
- What data may be involved? FCI, CUI, covered defense information, PII, PHI, financial, education, export-controlled, source-selection, proprietary, classified, or operational data.
- Which contracts or customers are implicated? DoD, civilian agency, state/local, prime, subcontract, grant, or commercial support.
- Which clauses and procedures apply? DFARS 7012, agency clauses, privacy terms, cloud procedures, insurance terms, subcontract notice, law enforcement, CIRCIA monitoring.
- What deadlines may be running? 24 hours, 72 hours, “promptly,” “without unreasonable delay,” or customer-specific windows.
- Who decides and who reports? Legal, security, executive, contract manager, prime/subcontract lead, agency customer, insurer, outside counsel.
Educational content only. This page provides general legal information for educational purposes. It does not constitute legal advice and does not create an attorney-client relationship. Contractors should consult qualified legal counsel for contract-specific incident-reporting obligations.