COMPLIANCE POSTURE

DFARS 252.204-7012

The defense contract clause that requires contractors to implement NIST SP 800-171 on systems holding covered defense information and to report cyber incidents within 72 hours.

Also called Safeguarding Covered Defense Information and Cyber Incident Reporting, the 7012 clause

Last reviewed

What is DFARS 252.204-7012?

DFARS 252.204-7012 — “Safeguarding Covered Defense Information and Cyber Incident Reporting” — is the contract clause that made federal cybersecurity requirements binding on defense contractors rather than advisory. It is short, it is old by the standards of this subject, and it is the source of most of the obligations technology companies discover when they take their first defense subcontract.

The clause does three things. It requires adequate security on covered contractor information systems, defined by reference to the NIST standard for protecting CUI. It requires cyber incident reporting within 72 hours of discovery. And it requires flowdown, so the obligation travels down the supply chain rather than stopping at the prime.

Adequate security means a specific standard

The clause does not leave “adequate” to interpretation. For covered contractor information systems that are not operated on behalf of the government, adequate security means implementing NIST SP 800-171 — the full requirement set, not a selection from it.

Where a requirement is not implemented, the clause anticipates documented deviation rather than silence. What it does not accommodate is a company that signed the clause without reading it and has no plan describing its actual state.

The 72-hour clock

On discovering a cyber incident that affects a covered contractor information system, the covered defense information on it, or the contractor’s ability to provide operationally critical support, the contractor must report to the Department of War within 72 hours of discovery.

Three details matter and are routinely missed:

  • Discovery starts the clock, not confirmation, not root-cause analysis, and not the conclusion of an internal investigation.
  • Reporting requires a medium assurance certificate to access the government reporting portal. Obtaining one takes time you will not have during an incident.
  • Reporting is not an admission. The clause explicitly frames the report as information sharing, and the reporting obligation is separate from any liability question.

The failure mode is almost never unwillingness. It is a company discovering mid-incident that nobody has the credential, nobody knows the portal, and the 72-hour window is being spent on logistics.

Flowdown, and why small vendors get caught

The clause must be included in subcontracts where performance will involve covered defense information or operationally critical support. Primes implement this through their supply-chain teams, which is why a software company with no defense contract of its own receives a questionnaire, a flowdown clause, and a deadline.

At that point the options are to demonstrate compliance, to negotiate scope so that covered information never enters your environment, or to lose the subcontract. The first requires work already done. The second requires product architecture that permits it. The third requires nothing.

The external cloud service requirement

If you use an external cloud service to store, process, or transmit covered defense information, that provider must meet a security requirement equivalent to a defined FedRAMP baseline, and you must require the provider to meet the incident reporting and evidence-preservation obligations.

This one catches companies that did everything else right. A well-implemented security program running on a commercial cloud tier that does not meet the required baseline is still non-compliant. Confirm the specific offering and region your federal deployment uses, not the provider’s brand.

How it connects to everything else

The clause is the contractual anchor. CMMC exists to verify what this clause has required for years. The companion clauses require you to have a current assessment of your implementation and to post the result where the government can see it. The standard defines what implementation means.

Read together, they describe a single obligation viewed from four angles — which is why implementing the standard properly once is the efficient path, and treating each clause as a separate project is not.

COMMON QUESTIONS

What does the 72-hour requirement actually mean?

When you discover a cyber incident affecting a covered contractor information system or the covered defense information on it, you must report it to the Department of War within 72 hours of discovery. The clock starts at discovery, not at confirmation. Companies that have never rehearsed the reporting path are the ones that miss it.

Does the clause flow down to subcontractors?

Yes. The clause requires it to be included in subcontracts for operationally critical support or where performance will involve covered defense information. That is how a small software vendor with no direct defense contract ends up with the same obligation, arriving through a prime rather than a contracting officer.

What is covered defense information?

Unclassified controlled technical information and other information requiring safeguarding or dissemination controls that is either marked and provided to the contractor in support of the contract, or collected and developed by the contractor in performance of it. In practice it overlaps heavily with Controlled Unclassified Information.

Is the cloud provider requirement separate?

Yes, and it is easy to miss. Where a contractor uses an external cloud service to store, process, or transmit covered defense information, the clause requires that provider to meet a defined security requirement equivalent to a specific FedRAMP baseline. Choosing a commercial cloud tier that does not meet it is a compliance failure regardless of how well your own controls are implemented.

HOW GOVEXPRESS SCORES THIS

Compliance Posture

This clause is the contractual hook that makes Compliance Posture enforceable, because signing a contract containing it is a commitment the government can act on rather than a statement on a website.

One of the 12 categories in the Federal Readiness Score. The methodology is public — including the things this platform will never claim.

DFARS 252.204-7012 is one signal. See all of them.

Get your free score