Last reviewed: June 29, 2026
How to use this map
Start with facts, not labels. A “cyber incident,” “privacy incident,” “breach,” “ransomware event,” “supplier incident,” “cloud incident,” or “security event” may trigger different reporting obligations depending on the contract and data involved.
Use this page to compare likely reporting paths. Then review the actual contract, clause, agency instruction, privacy law, insurance policy, and subcontract terms.
DFARS 252.204-7012 / DoD cyber incident reporting
- Trigger
- A cyber incident under DFARS 252.204-7012 involving covered defense information or covered contractor information systems, based on the clause definitions and facts.
- Who reports
- Contractors and subcontractors when the clause applies. Subcontractors report directly to DoD and provide the incident report number to the prime or higher-tier subcontractor.
- Timeline
- Rapid reporting within 72 hours of discovery.
- Where/how
- DoD reporting mechanism associated with DIBNet.
- Source authority
- DFARS 252.204-7012 and DFARS subpart 204.73.
- Contractor action items
- Preserve images and monitoring/packet-capture data for at least 90 days, submit malicious software when required, notify prime/higher-tier where applicable, preserve evidence, and support DoD damage assessment.
DoD CMMC-related posture
- Trigger
- CMMC itself is not the incident-reporting clause. It may affect readiness, assessment evidence, affirmations, and contract eligibility.
- Who reports
- Reporting follows applicable clauses such as DFARS 252.204-7012, not CMMC alone.
- Timeline
- Follow the triggered clause or contract requirement.
- Where/how
- Follow applicable DoD reporting procedures.
- Source authority
- 32 CFR part 170; DFARS 252.204-7021 and 252.204-7025 when included; DFARS 252.204-7012 for reporting.
- Contractor action items
- Do not assume CMMC status eliminates reporting obligations. Maintain incident-response evidence and update risk posture as needed.
FAR and civilian agency cyber clauses
- Trigger
- Agency-specific cybersecurity incident, breach, system compromise, unauthorized access, or security event as defined by contract, security attachment, or agency policy.
- Who reports
- Usually the prime contractor to the agency, with subcontractor notice upstream; exact obligations vary.
- Timeline
- Varies. Some clauses require prompt notice; others set specific hour/day requirements.
- Where/how
- Agency-designated contact, portal, contracting officer, COR, security office, or incident mailbox.
- Source authority
- FAR clauses, agency supplements, contract attachments, task-order terms, and system authorization requirements.
- Contractor action items
- Maintain a contract-specific reporting matrix. Do not assume DoD timelines apply to civilian agencies.
Privacy and breach notification
- Trigger
- Unauthorized access, acquisition, use, disclosure, or compromise of personal information, depending on applicable law and contract terms.
- Who reports
- Contractor, agency, covered entity, business associate, vendor, or prime depending on legal role.
- Timeline
- Varies by state, sector law, agency term, and contract.
- Where/how
- Agency customer, affected individuals, regulators, state attorneys general, HHS OCR, education authorities, financial regulators, or others depending on law.
- Source authority
- State breach laws, Privacy Act-related contract terms, HIPAA, FERPA, GLBA, FTC Act, agency privacy clauses, and contract-specific requirements.
- Contractor action items
- Identify affected individuals, residency, data elements, encryption status, acquisition/access facts, contractual notice terms, and customer approval requirements.
CIRCIA
- Trigger
- Covered cyber incidents and ransom payments by covered entities under CISA's final CIRCIA regulations once effective.
- Who reports
- Covered entities as defined by final regulations.
- Timeline
- CIRCIA directs reporting of covered cyber incidents within 72 hours and ransom payments within 24 hours, but the regulatory obligations are not effective until the final rule goes into effect.
- Where/how
- CISA reporting mechanism under the final rule.
- Source authority
- CIRCIA statute and CISA rulemaking.
- Contractor action items
- Monitor final-rule status; determine whether the contractor falls within a covered sector/entity definition; align incident intake with likely CIRCIA data needs without stating that final obligations are currently live.
FedRAMP cloud service providers
- Trigger
- Cloud-service incident that affects or may affect agency customers, authorization boundary, confidentiality, integrity, availability, or customer data as defined by FedRAMP procedures and customer requirements.
- Who reports
- Cloud service provider and/or agency customer depending on authorization structure; contractors using a CSP may still have separate contract reporting obligations.
- Timeline
- Follow current FedRAMP incident communication procedures and contract terms.
- Where/how
- FedRAMP/agency-designated processes and customer communications.
- Source authority
- FedRAMP official guidance, authorization package requirements, agency contracts.
- Contractor action items
- Ensure CSP notice timelines support contractor obligations; do not assume CSP reporting satisfies prime or agency reporting duties.
GovRAMP state/local cloud customers
- Trigger
- Cloud-service incident affecting state, local, tribal, territorial, or education public-sector customer data or systems, depending on customer contract and GovRAMP-related procurement requirements.
- Who reports
- Service provider, contractor, or customer depending on contract.
- Timeline
- Varies by contract and customer.
- Where/how
- Customer-designated incident contacts and GovRAMP-related processes where applicable.
- Source authority
- Contract terms, GovRAMP program materials, state/local law.
- Contractor action items
- Use “GovRAMP” for current references; refer to “StateRAMP” only historically. Maintain customer-specific reporting matrix.
Cyber insurance
- Trigger
- Security incident, privacy breach, claim, extortion demand, business interruption, funds transfer event, or other covered event as defined by policy.
- Who reports
- Insured contractor, often through broker or carrier notice process.
- Timeline
- Promptly or as specified by policy.
- Where/how
- Carrier, broker, breach coach, panel vendor process.
- Source authority
- Insurance policy.
- Contractor action items
- Notify early enough to preserve coverage; coordinate with legal and government reporting; do not let insurance vendor selection conflict with contract obligations.
Prime/subcontract reporting
- Trigger
- Incident affecting flowed-down data, systems, contract performance, customer information, or subcontract requirements.
- Who reports
- Subcontractor to prime/higher-tier; prime to government where required; subcontractor direct-to-government where specific clauses require.
- Timeline
- Should be shorter than prime's government deadline; actual terms vary.
- Where/how
- Contract-designated contacts and escalation paths.
- Source authority
- Subcontract clauses and flowed-down FAR/DFARS/agency requirements.
- Contractor action items
- Include incident definitions, timelines, evidence preservation, cooperation, and direct-reporting rules in subcontracts.
Minimum triage fields
Every incident intake should capture:
- date/time discovered;
- affected systems;
- affected contracts/customers;
- data categories involved;
- known or suspected unauthorized access/acquisition;
- ransomware or extortion facts;
- cloud or supplier involvement;
- subcontractor involvement;
- current containment status;
- evidence preserved;
- possible reporting deadlines; and
- decision-maker approvals.
Educational content only. This map is a triage aid and general reference. It does not calculate legal obligations automatically and does not constitute legal advice. Contractors should review the actual contract, clause, and applicable law for each incident.