Covered Defense Information
Covered Defense Information (CDI) is a category of sensitive but unclassified information that defense contractors must protect when it is handled on their systems. It generally covers technical and other controlled information related to defense work that requires safeguarding or limits on how it can be shared. The term is used in Department of Defense contracts to trigger specific cybersecurity obligations for the contractors who handle it.
Covered Defense Information (CDI) is a DFARS term referring to unclassified controlled technical information or other information, as described in the Controlled Unclassified Information (CUI) framework, that requires safeguarding or dissemination controls and is marked or otherwise identified as such. In most implementations the operative definition and associated safeguarding obligations are set out in DFARS clause 252.204-7012 (Safeguarding Covered Defense Information and Cyber Incident Reporting); related clauses such as 252.204-7000 reference the concept in the context of information disclosure rather than establishing the definition itself. CDI applies to unclassified information provided to or developed by a contractor in performance of a covered DoD contract, and its identification depends on marking and applicable dissemination or safeguarding requirements. This entry does not address the specific technical safeguarding controls, incident reporting timelines, contractual flow-down requirements, or the precise categorization of information as CUI, all of which practitioners should verify against the current authoritative text of the applicable DFARS clause and DoD CUI guidance. Note that CDI as a DFARS concept is distinct from, though related to, the broader CUI program and from CMMC assessment requirements, and readers should confirm current scope and revision-specific details.
Why it matters
Covered Defense Information sits at the center of the Department of Defense's efforts to protect sensitive unclassified information that flows to and through its contractor base. When information qualifies as CDI, it generally triggers specific safeguarding and cyber incident reporting obligations for the contractor handling it, primarily through DFARS clause 252.204-7012. Misidentifying what does or does not constitute CDI can leave genuinely sensitive technical information inadequately protected, or conversely impose safeguarding burdens where they do not contractually apply. Because CDI is unclassified, it is easy to underestimate its sensitivity, yet its aggregation and relevance to defense work is precisely why the DoD requires controls on how it is stored, processed, and disseminated.
Who it's relevant to
Inside CDI
Common questions
Answers to the questions practitioners most commonly ask about CDI.