DFARS 252.204-7012 (Safeguarding Covered Defense Information and Cyber Incident Reporting)
DFARS 252.204-7012 is a contracting clause used by the U.S. Department of Defense that requires defense contractors to protect certain sensitive but unclassified information on their computer systems and to report cyber incidents. It is part of the Defense Federal Acquisition Regulation Supplement (DFARS), a set of rules that supplement the broader federal acquisition regulations for DoD contracts. Because it is a contract clause, its specific obligations apply to contractors through the terms of their DoD contracts rather than as a general law.
DFARS 252.204-7012 is a Defense Federal Acquisition Regulation Supplement contracting clause, described in the evidence as the oldest of the DFARS 70-series clauses (which also include 252.204-7019, -7020, and -7021), that establishes safeguarding requirements for covered defense information and cyber incident reporting obligations for DoD contractors. The clause defines a 'covered contractor information system' as an unclassified information system that is owned, or operated by or for, a contractor and that processes, stores, or transmits covered defense information. As a DFARS clause, its requirements are imposed on contractors through incorporation into applicable DoD contracts and are directed at protecting covered unclassified information across the defense industrial base; the evidence provided here does not enumerate the specific safeguarding controls, reporting timelines, flow-down provisions, or effective dates, and practitioners should verify the current authoritative text of the clause and any related DFARS 70-series clauses against official sources.
Why it matters
DFARS 252.204-7012 is a foundational mechanism through which the U.S. Department of Defense extends safeguarding and cyber incident reporting obligations across the defense industrial base (DIB). Because the requirements reach contractors through incorporation into applicable DoD contracts rather than as a freestanding statute, the clause functions as the contractual anchor that binds a contractor to protect covered defense information residing on its unclassified systems. For contractors, this means that compliance is not optional and is enforceable through the terms of the contract itself, making familiarity with the clause essential to doing business with the DoD.
Described in the evidence as the oldest of the DFARS 70-series clauses (which also include 252.204-7019, -7020, and -7021), 252.204-7012 established an early and enduring baseline for securing covered unclassified information. Practitioners should be careful not to treat this clause as interchangeable with the other 70-series clauses or with separate authorization regimes such as CMMC, which operate under their own authorities and phased rollout. Each 70-series clause addresses a distinct aspect of the DoD's safeguarding and assessment expectations, and the specific interplay among them should be confirmed against the current authoritative text.
A further common misunderstanding worth flagging is the assumption that satisfying one framework automatically satisfies another. A FedRAMP authorization, for example, does not by itself demonstrate compliance with the contractual obligations imposed by this clause, and compliance with the clause's terms is not the same as being secure. Contractors should verify the specific safeguarding controls, reporting timelines, and flow-down provisions in the current clause text, because the evidence provided here does not enumerate those details.
Who it's relevant to
Inside DFARS 252.204-7012 (Safeguarding Covered Defense Information and Cyber Incident Reporting)
Common questions
Answers to the questions practitioners most commonly ask about DFARS 252.204-7012 (Safeguarding Covered Defense Information and Cyber Incident Reporting).