What is DFARS 252.204-7012?
DFARS 252.204-7012 — “Safeguarding Covered Defense Information and Cyber Incident Reporting” — is the contract clause that made federal cybersecurity requirements binding on defense contractors rather than advisory. It is short, it is old by the standards of this subject, and it is the source of most of the obligations technology companies discover when they take their first defense subcontract.
The clause does three things. It requires adequate security on covered contractor information systems, defined by reference to the NIST standard for protecting CUI. It requires cyber incident reporting within 72 hours of discovery. And it requires flowdown, so the obligation travels down the supply chain rather than stopping at the prime.
Adequate security means a specific standard
The clause does not leave “adequate” to interpretation. For covered contractor information systems that are not operated on behalf of the government, adequate security means implementing NIST SP 800-171 — the full requirement set, not a selection from it.
Where a requirement is not implemented, the clause anticipates documented deviation rather than silence. What it does not accommodate is a company that signed the clause without reading it and has no plan describing its actual state.
The 72-hour clock
On discovering a cyber incident that affects a covered contractor information system, the covered defense information on it, or the contractor’s ability to provide operationally critical support, the contractor must report to the Department of War within 72 hours of discovery.
Three details matter and are routinely missed:
- Discovery starts the clock, not confirmation, not root-cause analysis, and not the conclusion of an internal investigation.
- Reporting requires a medium assurance certificate to access the government reporting portal. Obtaining one takes time you will not have during an incident.
- Reporting is not an admission. The clause explicitly frames the report as information sharing, and the reporting obligation is separate from any liability question.
The failure mode is almost never unwillingness. It is a company discovering mid-incident that nobody has the credential, nobody knows the portal, and the 72-hour window is being spent on logistics.
Flowdown, and why small vendors get caught
The clause must be included in subcontracts where performance will involve covered defense information or operationally critical support. Primes implement this through their supply-chain teams, which is why a software company with no defense contract of its own receives a questionnaire, a flowdown clause, and a deadline.
At that point the options are to demonstrate compliance, to negotiate scope so that covered information never enters your environment, or to lose the subcontract. The first requires work already done. The second requires product architecture that permits it. The third requires nothing.
The external cloud service requirement
If you use an external cloud service to store, process, or transmit covered defense information, that provider must meet a security requirement equivalent to a defined FedRAMP baseline, and you must require the provider to meet the incident reporting and evidence-preservation obligations.
This one catches companies that did everything else right. A well-implemented security program running on a commercial cloud tier that does not meet the required baseline is still non-compliant. Confirm the specific offering and region your federal deployment uses, not the provider’s brand.
How it connects to everything else
The clause is the contractual anchor. CMMC exists to verify what this clause has required for years. The companion clauses require you to have a current assessment of your implementation and to post the result where the government can see it. The standard defines what implementation means.
Read together, they describe a single obligation viewed from four angles — which is why implementing the standard properly once is the efficient path, and treating each clause as a separate project is not.