Skip to main content
Category: Controlled Unclassified Information

Covered Defense Information

Also known as:
Simply put

Covered Defense Information (CDI) is a category of sensitive but unclassified information that defense contractors must protect when it is handled on their systems. It generally covers technical and other controlled information related to defense work that requires safeguarding or limits on how it can be shared. The term is used in Department of Defense contracts to trigger specific cybersecurity obligations for the contractors who handle it.

Formal definition

Covered Defense Information (CDI) is a DFARS term referring to unclassified controlled technical information or other information, as described in the Controlled Unclassified Information (CUI) framework, that requires safeguarding or dissemination controls and is marked or otherwise identified as such. In most implementations the operative definition and associated safeguarding obligations are set out in DFARS clause 252.204-7012 (Safeguarding Covered Defense Information and Cyber Incident Reporting); related clauses such as 252.204-7000 reference the concept in the context of information disclosure rather than establishing the definition itself. CDI applies to unclassified information provided to or developed by a contractor in performance of a covered DoD contract, and its identification depends on marking and applicable dissemination or safeguarding requirements. This entry does not address the specific technical safeguarding controls, incident reporting timelines, contractual flow-down requirements, or the precise categorization of information as CUI, all of which practitioners should verify against the current authoritative text of the applicable DFARS clause and DoD CUI guidance. Note that CDI as a DFARS concept is distinct from, though related to, the broader CUI program and from CMMC assessment requirements, and readers should confirm current scope and revision-specific details.

Why it matters

Covered Defense Information sits at the center of the Department of Defense's efforts to protect sensitive unclassified information that flows to and through its contractor base. When information qualifies as CDI, it generally triggers specific safeguarding and cyber incident reporting obligations for the contractor handling it, primarily through DFARS clause 252.204-7012. Misidentifying what does or does not constitute CDI can leave genuinely sensitive technical information inadequately protected, or conversely impose safeguarding burdens where they do not contractually apply. Because CDI is unclassified, it is easy to underestimate its sensitivity, yet its aggregation and relevance to defense work is precisely why the DoD requires controls on how it is stored, processed, and disseminated.

Who it's relevant to

Defense Contractors and Subcontractors
Organizations performing work on covered DoD contracts are the primary parties responsible for identifying and protecting CDI on their systems. They must determine, based on markings and contract terms, when information qualifies as CDI and what safeguarding and reporting obligations follow, generally under DFARS clause 252.204-7012. Contractors should verify flow-down and safeguarding specifics against the current authoritative text rather than relying on generalized summaries.
Compliance Officers and Contract Managers
Those responsible for interpreting DFARS obligations need to distinguish precisely between clauses, recognizing that the definition of CDI resides in 252.204-7012 while 252.204-7000 references the concept in the context of disclosure. They should also avoid conflating CDI safeguarding with broader CUI program requirements or with CMMC assessment obligations, confirming current scope for each.
Information System Security Personnel
Security practitioners supporting defense contractors must understand which information on their systems constitutes CDI so that appropriate protections and incident response processes can be applied. Because identification depends on marking and applicable safeguarding requirements, close coordination with contract and compliance staff is important. Practitioners should confirm the specific technical controls and incident reporting timelines against the applicable DFARS clause.
Auditors and Assessors
Individuals evaluating a contractor's handling of CDI should ground their assessments in the correct governing clause and current DoD CUI guidance, and should treat compliance with safeguarding obligations as distinct from an overall demonstration of security. They should also recognize that CDI-related obligations under DFARS are related to but separate from CMMC assessment requirements.

Inside CDI

Definitional Source
Covered Defense Information (CDI) is defined in DFARS clause 252.204-7012, which contains the operative definition of the term. Related clauses may reference this definition but do not themselves establish it. Readers should verify the current text of DFARS 252.204-7012 against the official regulation, as clause language and cross-references may be updated.
Controlled Unclassified Information (CUI) Component
CDI generally encompasses unclassified information that requires safeguarding or dissemination controls, consistent with the CUI framework. It is not classified information, which is governed separately under other authorities such as the NISPOM. Practitioners should confirm the specific CUI categories at issue against current DoD and National Archives (as CUI Executive Agent) guidance.
Marking, Identification, or Association with Performance
CDI typically covers information that is either marked or otherwise identified in a contract and provided to a contractor by or on behalf of DoD, or collected, developed, received, transmitted, used, or stored by a contractor in support of contract performance. The precise scope depends on the contract terms and the applicable version of the governing DFARS clause.
Safeguarding and Reporting Nexus
The CDI designation is significant because it generally triggers safeguarding obligations and cyber incident reporting requirements set out in DFARS 252.204-7012, which in most implementations point to security requirements drawn from NIST SP 800-171. The applicability of specific obligations should be confirmed against the current clause and contract.

Common questions

Answers to the questions practitioners most commonly ask about CDI.

Is Covered Defense Information (CDI) the same thing as Controlled Unclassified Information (CUI)?
No, though the terms overlap and are frequently conflated. CUI is the broader government-wide categorization framework maintained by the National Archives (NARA) and applicable across federal civilian, defense, and other agencies. CDI is a DoD-specific term used in the context of DFARS 252.204-7012, and its scope is generally tied to unclassified information that requires safeguarding or dissemination controls in connection with covered defense contracts. In practice, CDI and the DoD's implementation of CUI are closely related, but you should not assume they are interchangeable in every context. Confirm the applicable definition against the current DFARS text and DoD guidance rather than relying on the general CUI framework alone.
Does DFARS clause 252.204-7000 define Covered Defense Information?
No. The definition of Covered Defense Information appears in DFARS clause 252.204-7012, not in 252.204-7000. Clause 252.204-7000 addresses a separate subject and does not itself define CDI. This is a common citation error worth correcting, because the safeguarding and cyber incident reporting obligations that attach to CDI flow from 252.204-7012. When citing the source of the CDI definition, reference 252.204-7012 and verify the current clause text, as DFARS provisions are subject to revision.
How do we determine whether information we handle qualifies as CDI on a given contract?
Determination generally depends on whether the information falls within the categories described in the applicable DFARS 252.204-7012 definition and whether it is provided to, or developed by, the contractor in connection with performance of that contract. In most implementations, contracting officers, program offices, and the requiring activity are responsible for identifying and marking such information, but marking practices vary, so contractors should not assume the absence of markings means information is not covered. This entry does not address contract-specific determinations; confirm the applicable requirements with the contracting officer and against the current clause and contract documents.
What safeguarding obligations are generally associated with handling CDI?
In most cases, contracts incorporating DFARS 252.204-7012 require that CDI residing on or transiting covered contractor information systems be protected in accordance with the security requirements referenced by that clause, which have generally pointed to NIST SP 800-171 for nonfederal systems. The specific applicable revision and any tailoring should be verified, as control baselines and referenced publications change over time. This description addresses the concept only and does not cover implementation specifics or the full set of contractual obligations, which must be confirmed against the current clause text.
What are our reporting responsibilities if CDI is involved in a cyber incident?
Under contracts incorporating DFARS 252.204-7012, contractors are generally required to report cyber incidents affecting covered defense information or the contractor's ability to perform certain requirements, typically within a timeframe specified in the clause and through the designated DoD reporting mechanism. Because reporting timelines, thresholds, and mechanisms are defined in the clause and associated DoD guidance and may be revised, verify the current requirements rather than relying on general summaries. This entry does not provide legal or contractual advice on incident handling.
Does flowing down CDI requirements to subcontractors apply automatically?
In general, DFARS 252.204-7012 contemplates flow-down of applicable requirements to subcontractors when the subcontracted effort involves covered defense information or operationally critical support, subject to the conditions stated in the clause. However, the precise flow-down obligations, exceptions, and any related determinations should be confirmed against the current clause language and the specific contract, as this entry does not cover the contractual or legal specifics of subcontractor obligations.

Common misconceptions

CDI is defined by DFARS clause 252.204-7000.
The operative definition of Covered Defense Information appears in DFARS 252.204-7012. Other clauses may reference the term, but they do not establish its definition. Readers should anchor to 252.204-7012 and verify the current regulatory text.
CDI and classified information are the same category subject to the same controls.
CDI is unclassified information within the CUI space and is handled under DFARS safeguarding and reporting requirements. Classified information is governed by separate authorities (such as the NISPOM) with distinct handling rules, and the two should not be conflated.
Meeting a general compliance checklist automatically means CDI is properly protected.
Compliance and security are not equivalent. Satisfying documentation or clause-flowdown steps does not by itself guarantee that CDI safeguarding and incident-reporting obligations are effectively met; practitioners should confirm actual implementation against the applicable clause and security requirements.

Best practices

Anchor CDI determinations to the definition in DFARS 252.204-7012 and verify the current regulatory text rather than relying on secondary or referencing clauses.
Identify whether information marked or provided under a specific contract, or generated in support of performance, falls within the CDI scope, and confirm ambiguous cases against contract terms and current DoD/CUI guidance.
Distinguish CDI (unclassified CUI-space information under DFARS) from classified information governed by separate authorities, and route each to the correct handling regime.
Map applicable safeguarding requirements, generally drawn from NIST SP 800-171 in most implementations, to the systems that process, store, or transmit CDI, and verify the applicable revision.
Establish and rehearse the cyber incident reporting process tied to DFARS 252.204-7012 so reporting obligations for CDI are met within required timeframes as stated in the current clause.
Treat compliance documentation as necessary but not sufficient, and validate that CDI protections are actually implemented and maintained, confirming specifics against current official sources.