Skip to main content

Research

Incident Reporting Map

This map compares major reporting paths contractors may need to evaluate after a cyber, privacy, cloud, supplier, or data incident. It is a triage aid, not a substitute for contract-specific legal review.

Last reviewed: June 29, 2026

How to use this map

Start with facts, not labels. A “cyber incident,” “privacy incident,” “breach,” “ransomware event,” “supplier incident,” “cloud incident,” or “security event” may trigger different reporting obligations depending on the contract and data involved.

Use this page to compare likely reporting paths. Then review the actual contract, clause, agency instruction, privacy law, insurance policy, and subcontract terms.

DFARS 252.204-7012 / DoD cyber incident reporting

Trigger
A cyber incident under DFARS 252.204-7012 involving covered defense information or covered contractor information systems, based on the clause definitions and facts.
Who reports
Contractors and subcontractors when the clause applies. Subcontractors report directly to DoD and provide the incident report number to the prime or higher-tier subcontractor.
Timeline
Rapid reporting within 72 hours of discovery.
Where/how
DoD reporting mechanism associated with DIBNet.
Source authority
DFARS 252.204-7012 and DFARS subpart 204.73.
Contractor action items
Preserve images and monitoring/packet-capture data for at least 90 days, submit malicious software when required, notify prime/higher-tier where applicable, preserve evidence, and support DoD damage assessment.

DoD CMMC-related posture

Trigger
CMMC itself is not the incident-reporting clause. It may affect readiness, assessment evidence, affirmations, and contract eligibility.
Who reports
Reporting follows applicable clauses such as DFARS 252.204-7012, not CMMC alone.
Timeline
Follow the triggered clause or contract requirement.
Where/how
Follow applicable DoD reporting procedures.
Source authority
32 CFR part 170; DFARS 252.204-7021 and 252.204-7025 when included; DFARS 252.204-7012 for reporting.
Contractor action items
Do not assume CMMC status eliminates reporting obligations. Maintain incident-response evidence and update risk posture as needed.

FAR and civilian agency cyber clauses

Trigger
Agency-specific cybersecurity incident, breach, system compromise, unauthorized access, or security event as defined by contract, security attachment, or agency policy.
Who reports
Usually the prime contractor to the agency, with subcontractor notice upstream; exact obligations vary.
Timeline
Varies. Some clauses require prompt notice; others set specific hour/day requirements.
Where/how
Agency-designated contact, portal, contracting officer, COR, security office, or incident mailbox.
Source authority
FAR clauses, agency supplements, contract attachments, task-order terms, and system authorization requirements.
Contractor action items
Maintain a contract-specific reporting matrix. Do not assume DoD timelines apply to civilian agencies.

Privacy and breach notification

Trigger
Unauthorized access, acquisition, use, disclosure, or compromise of personal information, depending on applicable law and contract terms.
Who reports
Contractor, agency, covered entity, business associate, vendor, or prime depending on legal role.
Timeline
Varies by state, sector law, agency term, and contract.
Where/how
Agency customer, affected individuals, regulators, state attorneys general, HHS OCR, education authorities, financial regulators, or others depending on law.
Source authority
State breach laws, Privacy Act-related contract terms, HIPAA, FERPA, GLBA, FTC Act, agency privacy clauses, and contract-specific requirements.
Contractor action items
Identify affected individuals, residency, data elements, encryption status, acquisition/access facts, contractual notice terms, and customer approval requirements.

CIRCIA

Trigger
Covered cyber incidents and ransom payments by covered entities under CISA's final CIRCIA regulations once effective.
Who reports
Covered entities as defined by final regulations.
Timeline
CIRCIA directs reporting of covered cyber incidents within 72 hours and ransom payments within 24 hours, but the regulatory obligations are not effective until the final rule goes into effect.
Where/how
CISA reporting mechanism under the final rule.
Source authority
CIRCIA statute and CISA rulemaking.
Contractor action items
Monitor final-rule status; determine whether the contractor falls within a covered sector/entity definition; align incident intake with likely CIRCIA data needs without stating that final obligations are currently live.

FedRAMP cloud service providers

Trigger
Cloud-service incident that affects or may affect agency customers, authorization boundary, confidentiality, integrity, availability, or customer data as defined by FedRAMP procedures and customer requirements.
Who reports
Cloud service provider and/or agency customer depending on authorization structure; contractors using a CSP may still have separate contract reporting obligations.
Timeline
Follow current FedRAMP incident communication procedures and contract terms.
Where/how
FedRAMP/agency-designated processes and customer communications.
Source authority
FedRAMP official guidance, authorization package requirements, agency contracts.
Contractor action items
Ensure CSP notice timelines support contractor obligations; do not assume CSP reporting satisfies prime or agency reporting duties.

GovRAMP state/local cloud customers

Trigger
Cloud-service incident affecting state, local, tribal, territorial, or education public-sector customer data or systems, depending on customer contract and GovRAMP-related procurement requirements.
Who reports
Service provider, contractor, or customer depending on contract.
Timeline
Varies by contract and customer.
Where/how
Customer-designated incident contacts and GovRAMP-related processes where applicable.
Source authority
Contract terms, GovRAMP program materials, state/local law.
Contractor action items
Use “GovRAMP” for current references; refer to “StateRAMP” only historically. Maintain customer-specific reporting matrix.

Cyber insurance

Trigger
Security incident, privacy breach, claim, extortion demand, business interruption, funds transfer event, or other covered event as defined by policy.
Who reports
Insured contractor, often through broker or carrier notice process.
Timeline
Promptly or as specified by policy.
Where/how
Carrier, broker, breach coach, panel vendor process.
Source authority
Insurance policy.
Contractor action items
Notify early enough to preserve coverage; coordinate with legal and government reporting; do not let insurance vendor selection conflict with contract obligations.

Prime/subcontract reporting

Trigger
Incident affecting flowed-down data, systems, contract performance, customer information, or subcontract requirements.
Who reports
Subcontractor to prime/higher-tier; prime to government where required; subcontractor direct-to-government where specific clauses require.
Timeline
Should be shorter than prime's government deadline; actual terms vary.
Where/how
Contract-designated contacts and escalation paths.
Source authority
Subcontract clauses and flowed-down FAR/DFARS/agency requirements.
Contractor action items
Include incident definitions, timelines, evidence preservation, cooperation, and direct-reporting rules in subcontracts.

Minimum triage fields

Every incident intake should capture:

  • date/time discovered;
  • affected systems;
  • affected contracts/customers;
  • data categories involved;
  • known or suspected unauthorized access/acquisition;
  • ransomware or extortion facts;
  • cloud or supplier involvement;
  • subcontractor involvement;
  • current containment status;
  • evidence preserved;
  • possible reporting deadlines; and
  • decision-maker approvals.

Educational content only. This map is a triage aid and general reference. It does not calculate legal obligations automatically and does not constitute legal advice. Contractors should review the actual contract, clause, and applicable law for each incident.