Skip to main content
Third-Party Risk Intake Template for DIB ContractorsIdentity & Access Management
5 min readFor Compliance Officers

Third-Party Risk Intake Template for DIB Contractors

You're about to onboard a new subcontractor. They'll handle Controlled Unclassified Information (CUI) and connect to your network. Under DFARS 252.204-7012, their security posture becomes your compliance responsibility.

Most intake forms ask the wrong questions or bury critical requirements. You need a form that makes NIST SP 800-171 expectations clear from day one.

Purpose of the Template

This intake template sets baseline security expectations for any third party handling CUI, accessing your systems, or joining your supply chain under a DoD contract. It covers:

The template isn't a full security questionnaire. It's a pre-qualification tool to identify compliance gaps before signing a statement of work.

Prerequisites

Before using this template with a subcontractor:

  1. Confirm CUI Scope. If the third party won't handle CUI or connect to systems processing it, standard vendor due diligence may suffice. This template assumes CUI exposure.

  2. Review Prime Contract Clauses. DFARS 252.204-7012 and 252.204-7019 impose specific flow-down obligations. Your template must reflect what your prime expects from you.

  3. Establish Risk Tolerance. Decide if you'll accept a partner with a documented Plan of Action and Milestones (POA&M) or require full implementation of all 110 controls before contract execution.

  4. Designate an Intake Owner. Someone on your compliance or contracts team must review responses, flag gaps, and escalate risks before procurement commits.

The Template

Copy everything below the line. Customize the bracketed fields.


THIRD-PARTY SECURITY INTAKE FORM
[Your Organization Name]
Effective Date: [Date]

Instructions: Complete all sections. Incomplete submissions will delay vendor approval. If you have questions about any requirement, contact [compliance point of contact] before submitting.

1. ORGANIZATION INFORMATION

  • Legal Entity Name: _______________
  • CAGE Code (if applicable): _______________
  • Primary Contact Name and Title: _______________
  • Security/Compliance Contact: _______________
  • Email: _______________
  • Phone: _______________

2. SCOPE OF ENGAGEMENT

Will your organization:

  • Receive, store, or process Controlled Unclassified Information (CUI)?
  • Access [Your Organization]'s network or information systems?
  • Host CUI in your own IT environment (cloud or on-premises)?
  • Provide IT services (hosting, managed services, software development) involving CUI?

If you checked any box above, continue. If none apply, skip to Section 6.

3. NIST 800-171 COMPLIANCE STATUS

Select your current status:

  • Full implementation of all 110 security requirements in NIST SP 800-171 Rev 2
  • Partial implementation with documented Plan of Action and Milestones (POA&M)
  • Not yet assessed
  • Not applicable (we will not handle CUI)

If you selected "Full implementation," provide:

  • Date of most recent self-assessment: _______________
  • Assessment performed by (internal team/third party): _______________

If you selected "Partial implementation," attach your current POA&M showing:

  • Open security requirements
  • Estimated completion dates
  • Compensating controls (if any)

4. INCIDENT RESPONSE OBLIGATIONS

Do you acknowledge the requirement to report cyber incidents involving CUI to [Your Organization] within the timeframes specified in DFARS 252.204-7012 (72 hours for medium-impact events)?

  • Yes, we acknowledge and can meet this requirement
  • No, we need to discuss alternative arrangements

Provide your incident response contact:

  • Name: _______________
  • 24/7 Contact Method: _______________

5. SYSTEM BOUNDARY AND DATA HANDLING

Describe the environment where you will process CUI:

  • Dedicated on-premises enclave
  • Cloud environment (specify provider and region): _______________
  • Shared infrastructure with logical segmentation
  • Other (describe): _______________

Will CUI leave your controlled environment at any point (backups to third-party storage, disaster recovery sites, international data transfers)?

  • No
  • Yes (describe): _______________

6. FLOW-DOWN ACKNOWLEDGMENT

By signing below, you acknowledge:

  1. You will flow down DFARS 252.204-7012 requirements to any of your subcontractors who will handle CUI on your behalf.
  2. You will notify [Your Organization] within 30 days of any material change to your security posture, system architecture, or compliance status.
  3. You will permit [Your Organization] or its authorized representatives to review your security controls upon reasonable notice.

Authorized Signature:

Name: _______________
Title: _______________
Date: _______________


Customization Options

Adjust the CUI Threshold. If your contracts involve only Federal Contract Information (FCI) under FAR 52.204-21, simplify Section 3 to reference basic safeguarding requirements.

Add Cybersecurity Maturity Model Certification Requirements. Once 32 CFR Part 170 enforcement begins, insert a question in Section 3 about the vendor's target CMMC level and certification status. For Level 2 and above, request their Cyber AB certificate number.

Include System Security Plan Boundary Language. If you've documented a specific enclave architecture in your SSP, add a question about whether the vendor's systems will interconnect with that boundary. This flags potential authorization boundary changes early.

Tailor Incident Reporting Timelines. DFARS 252.204-7012 specifies 72 hours for reporting to DoD. Your internal SLA with subcontractors may be tighter. If you need notification within 24 hours to meet your own 72-hour obligation, state that explicitly.

Request Encryption Specifics. For vendors hosting CUI in cloud environments, add a question about FIPS 140-2 validated cryptographic modules. If they're using a commercial cloud provider, ask whether they're using the provider's validated modules or their own.

Validation Steps

After receiving a completed form:

1. Cross-check CAGE Codes. Verify the vendor's CAGE code is active in the System for Award Management. Suspended or excluded entities can't flow down requirements they're barred from holding.

2. Review POA&Ms for Deal-breakers. Not all open security requirements carry equal risk. Decide which gaps you'll accept before the contract is signed.

3. Validate Incident Response Contacts. Send a test email to the provided incident contact. If it bounces or goes to a general inbox, push back. You need a named contact for coordination during a breach.

4. Document Your Decision. If you accept a vendor with a POA&M, record that risk acceptance in your risk register. During your next assessment, you'll need to explain why you allowed a non-compliant partner into your supply chain.

5. Set a Review Cadence. Compliance status changes. Schedule annual re-validation of high-risk vendors. For lower-risk partners, trigger re-validation when renewing the contract or expanding the scope of work.

This template won't catch every supply chain risk, but it will prevent surprises about a subcontractor's compliance status before your C3PAO assessment starts.

You Might Also Like