Skip to main content
Category: Contracting & Acquisition

DFARS 252.204-7012 (Safeguarding Covered Defense Information and Cyber Incident Reporting)

Also known as: DFARS 7012, DFARS clause 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting
Simply put

DFARS 252.204-7012 is a contracting clause used by the U.S. Department of Defense that requires defense contractors to protect certain sensitive but unclassified information on their computer systems and to report cyber incidents. It is part of the Defense Federal Acquisition Regulation Supplement (DFARS), a set of rules that supplement the broader federal acquisition regulations for DoD contracts. Because it is a contract clause, its specific obligations apply to contractors through the terms of their DoD contracts rather than as a general law.

Formal definition

DFARS 252.204-7012 is a Defense Federal Acquisition Regulation Supplement contracting clause, described in the evidence as the oldest of the DFARS 70-series clauses (which also include 252.204-7019, -7020, and -7021), that establishes safeguarding requirements for covered defense information and cyber incident reporting obligations for DoD contractors. The clause defines a 'covered contractor information system' as an unclassified information system that is owned, or operated by or for, a contractor and that processes, stores, or transmits covered defense information. As a DFARS clause, its requirements are imposed on contractors through incorporation into applicable DoD contracts and are directed at protecting covered unclassified information across the defense industrial base; the evidence provided here does not enumerate the specific safeguarding controls, reporting timelines, flow-down provisions, or effective dates, and practitioners should verify the current authoritative text of the clause and any related DFARS 70-series clauses against official sources.

Why it matters

DFARS 252.204-7012 is a foundational mechanism through which the U.S. Department of Defense extends safeguarding and cyber incident reporting obligations across the defense industrial base (DIB). Because the requirements reach contractors through incorporation into applicable DoD contracts rather than as a freestanding statute, the clause functions as the contractual anchor that binds a contractor to protect covered defense information residing on its unclassified systems. For contractors, this means that compliance is not optional and is enforceable through the terms of the contract itself, making familiarity with the clause essential to doing business with the DoD.

Described in the evidence as the oldest of the DFARS 70-series clauses (which also include 252.204-7019, -7020, and -7021), 252.204-7012 established an early and enduring baseline for securing covered unclassified information. Practitioners should be careful not to treat this clause as interchangeable with the other 70-series clauses or with separate authorization regimes such as CMMC, which operate under their own authorities and phased rollout. Each 70-series clause addresses a distinct aspect of the DoD's safeguarding and assessment expectations, and the specific interplay among them should be confirmed against the current authoritative text.

A further common misunderstanding worth flagging is the assumption that satisfying one framework automatically satisfies another. A FedRAMP authorization, for example, does not by itself demonstrate compliance with the contractual obligations imposed by this clause, and compliance with the clause's terms is not the same as being secure. Contractors should verify the specific safeguarding controls, reporting timelines, and flow-down provisions in the current clause text, because the evidence provided here does not enumerate those details.

Who it's relevant to

DoD Contractors and Subcontractors in the Defense Industrial Base
Organizations that hold or seek DoD contracts are the primary audience, because the clause's obligations apply to them when incorporated into their contracts. Any contractor whose unclassified information systems process, store, or transmit covered defense information should determine whether their systems meet the clause's definition of a covered contractor information system and confirm the current safeguarding and reporting requirements against the authoritative clause text.
Information System Security Managers and Compliance Officers
Personnel responsible for implementing and demonstrating safeguarding measures need to understand how this clause defines a covered contractor information system and how its requirements interact with the broader DFARS 70-series. They should treat compliance with the clause's contractual terms as distinct from a general assurance of security and should verify specific controls and reporting obligations against current official sources.
Contracts and Acquisition Professionals
Those who draft, negotiate, or administer DoD contracts must recognize that DFARS 252.204-7012 imposes its obligations through incorporation into applicable contracts, and that flow-down provisions may extend requirements to subcontractors. Because the evidence here does not enumerate the specific flow-down terms or effective dates, these professionals should confirm the current clause language and its relationship to related 70-series clauses.
Auditors and Assessors
Professionals evaluating a contractor's posture should distinguish this contractual clause from separate authorization regimes and from other DFARS 70-series clauses, avoiding the assumption that they are interchangeable. Assessment against the clause is not the same as authorization under other DoD frameworks, and the specific controls and timelines being assessed should be drawn from the current authoritative clause text.

Inside DFARS 252.204-7012 (Safeguarding Covered Defense Information and Cyber Incident Reporting)

Safeguarding Requirement for Covered Defense Information
The clause generally requires contractors and subcontractors that process, store, or transmit Covered Defense Information (a category that includes Controlled Unclassified Information relevant to DoD) on covered contractor information systems to apply the security requirements in NIST SP 800-171. Verify the specific NIST SP 800-171 revision referenced by the applicable contract, as the referenced revision can change over time.
Cyber Incident Reporting Obligation
The clause generally requires the contractor to rapidly report cyber incidents affecting covered contractor information systems or Covered Defense Information to DoD through the designated DoD reporting mechanism. Contractors should confirm the current reporting portal, required content, and timeframe against the current authoritative clause text, as these details are set by DoD and may be updated.
Media Preservation and Damage Assessment Support
Following a reported cyber incident, the clause generally requires the contractor to preserve and protect relevant images, packet captures, and monitoring data for a period specified in the clause, and to support DoD damage assessment activities. Confirm the exact preservation period and cooperation obligations in the current clause text.
Flowdown to Subcontractors
The clause generally requires that its substance be flowed down to subcontractors when the subcontractor's performance will involve Covered Defense Information or operationally critical support. This means the safeguarding and reporting obligations extend through the supply chain rather than resting solely with the prime contractor.
Cloud Service Provider Conditions
Where a contractor uses an external cloud service provider to store, process, or transmit Covered Defense Information in performance of the contract, the clause generally imposes conditions on that arrangement, which in most implementations are tied to a defined security baseline for the cloud service. Confirm the specific baseline and equivalency terms against the current clause and associated DoD guidance.
Relationship to Broader DoD Compliance Framework
The clause is a DFARS contract clause issued by DoD that operationalizes safeguarding of unclassified CUI/Covered Defense Information at contractor sites. It is distinct from FISMA obligations for federal agency systems, from FedRAMP authorization of cloud services, and from the Cybersecurity Maturity Model Certification (CMMC) program, though these frameworks reference overlapping control sources such as NIST SP 800-171.

Common questions

Answers to the questions practitioners most commonly ask about DFARS 252.204-7012 (Safeguarding Covered Defense Information and Cyber Incident Reporting).

Does complying with DFARS 252.204-7012 mean my systems are secure?
No. DFARS 252.204-7012 establishes contractual requirements for safeguarding covered defense information and reporting cyber incidents, but meeting those requirements is not the same as being secure. The clause generally requires implementing the security requirements in NIST SP 800-171, yet compliance with a control set reflects a point-in-time adherence to specified safeguards and does not guarantee protection against evolving threats. Treat compliance as a baseline obligation rather than evidence of an adequately secured environment, and confirm your specific obligations against the current clause text.
If a cloud service I use is FedRAMP authorized, does that automatically satisfy DFARS 252.204-7012?
Not automatically. FedRAMP authorization and the requirements under DFARS 252.204-7012 are distinct. The clause addresses the use of external cloud service providers by generally requiring, in most implementations, that a cloud provider meet security requirements equivalent to a specified FedRAMP baseline as a condition, but that condition is one element of the clause and does not by itself demonstrate compliance with the clause as a whole. FedRAMP is a federal civilian authorization program, and DoD contractual obligations may impose additional or different expectations. Verify the specific requirements in the applicable clause version and any flow-down terms.
Which information does DFARS 252.204-7012 apply to?
The clause is generally directed at covered defense information, a category associated with Controlled Unclassified Information handled in connection with DoD contracts. Because scope determinations depend on how the information is marked, identified, or otherwise designated under the contract, contractors should not assume a blanket application to all data on their systems. Classified information is governed by separate authorities and is out of scope for this clause. Confirm the precise categories of covered information against your contract and the current clause text.
What are the incident reporting expectations under DFARS 252.204-7012?
The clause generally requires a contractor to report cyber incidents affecting covered defense information or affecting the contractor's ability to perform certain requirements to the Department of Defense within a specified timeframe, and to preserve related information to support review. This entry does not restate the exact reporting window, submission mechanism, or evidence-preservation obligations, as these are set out in the clause and associated DoD guidance and may be updated. Verify the current reporting deadline, method, and retention expectations against the authoritative clause text before establishing internal procedures.
How does DFARS 252.204-7012 relate to NIST SP 800-171 and CMMC?
DFARS 252.204-7012 generally requires implementation of the security requirements in NIST SP 800-171 as the standard for safeguarding covered defense information. CMMC is a separate DoD initiative addressing assessment and verification of contractor cybersecurity, and it is distinct from the clause's self-implementation model. Because CMMC has been subject to phased rollout and revisions, contractors should not conflate the 7012 clause's requirements with CMMC's assessment expectations. Confirm which requirements apply to your contract against the current clause text and applicable DoD acquisition provisions.
Do the requirements of DFARS 252.204-7012 flow down to subcontractors?
The clause generally contemplates that relevant requirements extend to subcontractors when covered defense information is involved in subcontracted work, meaning prime contractors typically need to include applicable flow-down provisions in their subcontracts. The precise conditions triggering flow-down, and the obligations placed on subcontractors, are defined in the clause itself. This entry does not address contractual drafting or the specific mechanics of flow-down. Verify the current flow-down language and its scope against the authoritative clause text and consult contracting or legal resources for implementation specifics.

Common misconceptions

DFARS 252.204-7012 is the same thing as CMMC, so meeting one automatically satisfies the other.
The clause and CMMC are distinct. DFARS 252.204-7012 generally requires implementation of NIST SP 800-171 and cyber incident reporting as a contractual safeguarding obligation, while CMMC is a separate, phased DoD certification/assessment program. They draw on overlapping control sources but are not interchangeable, and practitioners should confirm which requirements a given contract imposes.
Implementing NIST SP 800-171 under the clause means the contractor is fully secure and compliant with all DoD requirements.
Compliance with the clause's safeguarding requirement is not the same as being secure, nor does it cover every DoD requirement. The clause addresses safeguarding of Covered Defense Information and incident reporting; it does not by itself satisfy separate obligations such as classified system requirements under the NISPOM, FedRAMP for cloud services, or any applicable CMMC assessment. Verify the full set of contract requirements.
The safeguarding and reporting obligations apply only to the prime contractor.
The clause generally requires flowdown to subcontractors whose performance involves Covered Defense Information or operationally critical support. The obligations therefore extend through the supply chain, and primes should confirm that subcontractors have accepted and can meet the flowed-down requirements.

Best practices

Identify and inventory where Covered Defense Information and Controlled Unclassified Information are processed, stored, or transmitted across covered contractor information systems so the scope of the safeguarding obligation is clearly bounded.
Confirm the specific NIST SP 800-171 revision cited by each applicable contract and map your implemented controls against it rather than assuming a single static baseline, since the referenced revision can change.
Establish and test a rapid cyber incident reporting process aligned to the current DoD reporting mechanism and timeframe, and verify the required reporting details against the current authoritative clause text before an incident occurs.
Implement procedures to preserve and protect relevant images, monitoring data, and related evidence following a cyber incident, and confirm the current required preservation period and DoD damage assessment support obligations.
Ensure the clause's substance is flowed down to subcontractors involved with Covered Defense Information or operationally critical support, and obtain confirmation that they can meet the safeguarding and reporting requirements.
Where cloud services are used for Covered Defense Information, verify the required cloud security baseline and equivalency conditions against the current clause and DoD guidance, and do not assume a FedRAMP authorization alone satisfies these DoD conditions.