DFARS Cybersecurity

DFARS 252.204-7012 Compliance

The clause that put cybersecurity into your defense contract. We help contractors and suppliers implement the safeguarding requirements it points to, stand up the 72-hour incident reporting path before they need it, and assemble the evidence that shows the obligation was met. Delivered by a North Carolina compliance and cybersecurity firm serving regulated businesses since 2002.

CyberAB RPO #1449 | BBB A+ Since 2003 | CMMC Registered Practitioner
What It Is

What Is DFARS 252.204-7012?

DFARS 252.204-7012, titled Safeguarding Covered Defense Information and Cyber Incident Reporting, is the Defense Federal Acquisition Regulation Supplement clause that obligates a contractor to protect defense information on its own systems and to report cyber incidents to the Department of Defense. It does two distinct things. First, it defines the security standard a contractor owes: adequate security, which the clause resolves to the 110 controls in NIST Special Publication 800-171. Second, it creates an affirmative reporting duty, requiring that a discovered cyber incident affecting covered defense information or the ability to perform operationally critical support be reported to DoD within 72 hours. The clause also carries obligations most contractors discover late: preserving system images after an incident, submitting malicious software to the government, holding cloud providers to a federal security baseline, and flowing the entire clause down to subcontractors. It applies by contract, not by company size, and a small supplier three tiers down the chain carries the same obligation as a prime.

Key Takeaways

  • DFARS 252.204-7012 requires adequate security on contractor systems that hold covered defense information, and it defines adequate security as the 110 controls of NIST SP 800-171.
  • A discovered cyber incident affecting covered defense information must be reported to the Department of Defense within 72 hours through the DoD reporting portal, which requires a medium assurance certificate obtained in advance.
  • The clause also requires preserving affected system images for at least 90 days, submitting malicious software to the government, and holding cloud service providers to a FedRAMP Moderate security baseline.
  • Paragraph (m) flows the entire clause down to subcontractors, so a supplier who never contracted with the government directly still carries the full obligation.
  • The companion clauses 252.204-7019 and 252.204-7020 turn the self-attestation into a posted score in the Supplier Performance Risk System that contracting officers and primes can read.
  • Petronella Technology Group has served regulated businesses from Raleigh since 2002, holds a BBB A+ rating since 2003, and is a CyberAB Registered Provider Organization (RPO #1449) led by a CMMC Registered Practitioner.

Why It Matters

The Clause Was Always in the Contract. What Changed Is Who Checks.

DFARS 252.204-7012 has appeared in defense contracts for years, and for much of that time it functioned as a self-attested promise nobody audited. That is the part that changed. The obligation itself is old; the verification around it is new, and it arrived through companion clauses rather than through any rewrite of 7012.

Ask a supplier when they became subject to the clause and the honest answer is usually that they do not know. It entered through a contract modification, or through a purchase order from a prime that flowed it down, or through a subcontract signed by someone in operations who reasonably assumed the legal language was boilerplate. Nothing about the transaction announced that the company had just accepted a defined cybersecurity standard and a 72-hour reporting clock. The clause is quiet in exactly the way an obligation should not be.

Then DFARS 252.204-7019 and 252.204-7020 arrived and made the self-attestation legible. Together they require a contractor to conduct a NIST SP 800-171 DoD Assessment using the published DoD Assessment Methodology and to post the resulting score in the Supplier Performance Risk System, where a contracting officer can read it before award. A score that was previously a private opinion became a number the government sees. That number is derived from the same 110 controls that 7012 pointed to all along, which is why so many suppliers experienced the scoring requirement as a shock: it did not add a standard, it revealed how far they were from one they had already agreed to.

The gap that opens is rarely one of intent. A machine shop that makes a bracket to a government drawing does not think of itself as holding defense information, but the drawing is the information, and the moment it lands in a shared mailbox or an unmanaged file server the clause is engaged. An engineering firm exchanges technical data packages with a prime through whatever channel the prime uses, without asking whether that channel meets a transmission control. A supplier keeps ten years of contract correspondence in an email archive that has never been scoped. None of that is negligence. It is what happens when a compliance obligation arrives without a corresponding change to how work gets done.

The practical consequence is a business one. Primes now ask about scores during supplier qualification, because their own flowdown obligation makes a weak subcontractor their problem. A contractor who cannot answer the question is not usually disqualified on cybersecurity grounds. They are quietly passed over, and they rarely find out that is why.


The Requirements

What DFARS 252.204-7012 Actually Requires

The clause is short, and most summaries stop at the first requirement. The obligations after it are the ones that generate findings, because they demand capabilities a contractor either has in place before an incident or does not have at all.

Adequate Security via NIST SP 800-171

The core obligation. A contractor must implement the 110 security requirements in NIST Special Publication 800-171 on every covered contractor information system, or document an alternative that an authorized DoD representative has accepted as equally effective. This is where the majority of the work sits, and where the assessment score comes from.

72-Hour Cyber Incident Reporting

When a contractor discovers a cyber incident that affects covered defense information, a covered contractor information system, or its ability to perform operationally critical support, it must rapidly report to the Department of Defense within 72 hours of discovery. The report goes through the DoD reporting portal, which requires a DoD-approved medium assurance certificate. Obtaining that certificate takes time, which is why the clock is the wrong moment to start.

Media Preservation and Protection

Following a reported incident, the contractor must preserve and protect images of all known affected information systems and relevant monitoring and packet capture data for at least 90 days from the report, so the government can request them. Doing this without destroying the evidentiary value of the images is a forensics discipline, not an IT backup task.

Malicious Software Submission

If malicious software is discovered and isolated in connection with a reported incident, the contractor submits it to the DoD Cyber Crime Center. It is explicitly not sent to the contracting officer, and getting that routing wrong is a common procedural error.

Cloud Service Provider Requirements

Where a contractor uses an external cloud service provider to store, process, or transmit covered defense information, the clause requires that provider to meet security requirements equivalent to the FedRAMP Moderate baseline and to comply with the reporting and media preservation obligations. This is the paragraph that drives collaboration platform decisions more than any other.

Subcontractor Flowdown

The clause must be included in subcontracts for operationally critical support or where performance will involve covered defense information. The prime is responsible for the flowdown, and a subcontractor that reports an incident must also provide the incident report number to the prime. Managing this across a supplier base is a third-party risk program, not a paperwork exercise.


Comparison

DFARS 7012 Compared to the Clauses Around It

Three DFARS cybersecurity clauses are routinely confused with one another, and the confusion has a cost: contractors prepare for the wrong one. They are related but not interchangeable, and 7012 is the only one of the three that imposes an operational duty during an incident.

QuestionDFARS 252.204-7012DFARS 252.204-7019DFARS 252.204-7020
What it obligatesProtect covered defense information and report cyber incidents within 72 hoursProvide a current NIST SP 800-171 assessment summary score before awardConduct the assessment using the DoD methodology and post results in SPRS
Underlying standardNIST SP 800-171, all 110 requirementsNIST SP 800-171, scoredNIST SP 800-171 DoD Assessment Methodology
Creates a duty during an incidentYes, this is the only one of the three that doesNoNo
Produces a number the government seesNo, the obligation is a standard rather than a scoreYes, the posted summary level scoreYes, including assessment date and scope
Reaches subcontractorsYes, by required flowdown in paragraph (m)Applies at award to the offerorYes, flowdown for applicable subcontracts
Touches cloud providers directlyYes, FedRAMP Moderate equivalency requiredNoNo
What contractors most often missThe reporting certificate, media preservation, and flowdownThat the score must be current, not merely existentThat a low score is postable and a missing score is not

Common Findings

Where Contractors Fall Short

Across readiness reviews, the same gaps recur. They cluster around the parts of the clause that require a decision to have been made in advance rather than a product to have been purchased.

Finding 1

No DoD medium assurance certificate in place, so the 72-hour reporting path cannot actually be used on the day it is needed

Finding 2

Covered defense information scattered across general email and file shares, which expands the assessment boundary to the entire company

Finding 3

A system security plan that describes an idealized environment rather than the one running today

Finding 4

Flowdown clauses present in subcontracts but no process for confirming a supplier ever acted on them

Finding 5

A collaboration or email platform that cannot meet the encryption and export-control requirements as currently licensed

Finding 6

No documented procedure for preserving system images, so a real incident would destroy the evidence while responding to it

Not Sure Whether the Clause Is in Your Contracts?

A readiness review starts by reading what you actually signed, then measuring the environment against it. Serving Raleigh, Durham, and the Research Triangle since 2002, with nationwide delivery.


Our Approach

How We Take a Contractor Through DFARS 252.204-7012

The sequence matters. Scoping before assessment prevents the most expensive mistake in this work, which is securing an environment larger than the obligation requires.

1

Contract review: read the actual clauses in your awards, modifications, and purchase orders to confirm which obligations you carry and from whom

2

Data and scope definition: identify where covered defense information enters, lives, and leaves, then decide deliberately how much of the environment stays in scope

3

Gap assessment against all 110 requirements using the DoD Assessment Methodology, producing a defensible score rather than an optimistic one

4

Remediation planning: sequence the work by risk and score impact, separating what can be fixed this quarter from what needs a budget cycle

5

Incident readiness: obtain the reporting certificate, write the reporting and media preservation procedure, and rehearse it before it is needed

6

Documentation and monitoring: produce the system security plan and plan of action, post the score, and keep both current as the environment changes


Deliverables

What You Receive

Every engagement produces artifacts a contracting officer, a prime's supplier quality team, or an assessor can read without a guided tour.

Contract Obligation Map

A plain-language summary of which DFARS cybersecurity clauses appear in which of your contracts and what each one commits you to, so the obligation stops being a matter of assumption.

Scoped Environment Boundary

A documented definition of the systems, people, and data flows that hold covered defense information, with a diagram, and the rationale for what was excluded.

Scored Gap Assessment

Every one of the 110 requirements assessed against the DoD methodology, with the resulting summary level score and the specific evidence behind each determination.

System Security Plan and Plan of Action

The two artifacts the clause and its companions require, describing the environment as it exists and the dated, owned plan for closing what remains open.

Incident Reporting Runbook

The reporting path, the certificate, the decision criteria for what constitutes a reportable incident, the media preservation procedure, and the malware submission route.

Flowdown and Supplier Package

The clause language for your subcontracts plus a tracking approach for confirming suppliers received it, acknowledged it, and can answer for it.


Scope and Cost

What Drives the Cost of DFARS Compliance

There is no useful flat price for this work, because two contractors with identical revenue can differ by an order of magnitude in effort. These are the variables that actually move the number.

How much of your environment is in scope. This is the dominant factor and the one most within your control. A contractor who has separated defense information into a defined enclave is assessing a handful of systems. A contractor whose covered information is spread across every mailbox, file share, and laptop is assessing the entire company. The scoping decision made in week one determines the cost of everything after it.

Where you are starting from. An organization with a current asset inventory, centrally managed identities, and existing logging is remediating gaps. An organization without those has to build the foundation the controls assume exists, and that foundation is a project in its own right regardless of the clause.

Your collaboration and email platform. Requirements that touch encryption and export-controlled data interact directly with how your productivity suite is licensed and configured. Whether a migration is needed, and how much data moves, is frequently the single largest line item in a remediation plan.

The state of your documentation. A system security plan and plan of action are required artifacts, not optional ones, and they must describe the environment that actually exists. Writing them from nothing takes longer than updating them, and inheriting a generic template someone sold you is often worse than starting fresh.

Legacy and specialty equipment. Test benches, inspection systems, and shop-floor machines running unsupported operating systems cannot always be patched or joined to a modern identity platform. Each one needs a documented compensating approach, and that analysis is per-device work.

Your subcontractor footprint. Flowdown is your obligation to manage. A contractor with two long-standing suppliers has a modest administrative task. A contractor with sixty vendors touching technical data has a supply chain program to build. For a scoped estimate against your contracts and environment, talk to our team.


Who It Applies To

Which Businesses Carry This Clause

The clause reaches far past the companies most people picture when they hear defense contractor. If your work product ends up in a defense system and you receive technical information to produce it, assume the question applies to you until your contracts say otherwise.

In North Carolina and across the Southeast, the businesses that discover the clause in their contracts are usually precision machine shops and metal fabricators working to controlled drawings, engineering and design firms exchanging technical data packages, electronics manufacturers and printed circuit board houses, composites and specialty materials suppliers, calibration and test laboratories, robotics and autonomous systems developers, aerospace maintenance and repair operations, and the logistics and packaging firms that handle controlled shipments. Software and IT vendors selling into defense programs carry it too, and so do the professional services firms that support them.

Research universities and their spin-outs occupy a particularly awkward position, because a single sponsored research award can bring the clause into an environment built for openness. The Research Triangle has a concentration of exactly these organizations, which is a large part of why we do this work from Raleigh.


From a Client in the Aviation Industry

"Their quick response and service far surpassed anything I imagined."

Raynor Combs, Aviation Industry

Petronella Technology Group is rated 4.7 across 92 verified TrustIndex reviews and 5.0 across 15 Google reviews.


Why Petronella Technology Group

Experience Behind the Work

Petronella Technology Group has operated from Raleigh, North Carolina since 2002 and has held a BBB A+ rating since 2003. The firm is a CyberAB Registered Provider Organization, RPO #1449, and founder Craig Petronella is a CMMC Registered Practitioner and an NC Licensed Digital Forensics Examiner, License #604180-DFE.

That forensics credential is more relevant to this clause than it first appears. DFARS 252.204-7012 does not only ask a contractor to prevent incidents; it asks what they will do during one, when a 72-hour clock is running and images have to be preserved without contaminating them. Those are forensic questions, and answering them under pressure is different from answering them in a policy document. As Craig Petronella details in the CMMC 2.0 Certification Guide, and across a library of 15 published titles including How Hackers Can Crush Your Business, the distance between a written procedure and an executed one is where most programs are found wanting. Our digital forensics practice is the same team that helps clients rehearse the reporting path before they need it.

On the documentation side, our ComplianceArmor platform generates and maintains the system security plan, plan of action, and evidence mapping this work requires, so those artifacts stay current as the environment changes rather than aging into fiction between assessments. Craig also explores compliance and defense-sector security regularly on the Encrypted Ambition podcast.



FAQ

DFARS 252.204-7012 Questions

What is DFARS 252.204-7012 in plain terms?
It is the contract clause that makes cybersecurity a deliverable in defense work. It requires a contractor to protect covered defense information on its own systems by implementing the 110 controls of NIST SP 800-171, and to report a cyber incident affecting that information to the Department of Defense within 72 hours of discovery. It also requires preserving evidence, submitting discovered malware to the government, holding cloud providers to a federal baseline, and passing the same obligations down to subcontractors.
How do I know if the clause applies to my company?
Read your contracts, subcontracts, and purchase orders rather than reasoning about your size or role. The clause applies by contract. Many suppliers acquire it through a flowdown from a prime without any separate notification, so the obligation frequently arrives inside a routine purchase order. If you receive drawings, specifications, or technical data to produce something for a defense program, treat the question as open until the paperwork answers it.
What counts as covered defense information?
Broadly, it is unclassified controlled technical information or other information requiring safeguarding that is marked or otherwise identified in the contract and provided to you in support of contract performance, or collected or developed by you during performance. In practice it is most often the technical drawings, specifications, process instructions, and test data that let you build the thing. If a prime sent it to you so you could do the work, assume it is in scope until you have confirmed otherwise.
What does the 72-hour reporting requirement actually involve?
The clock starts on discovery of the incident, not on confirmation of its severity, and the report is submitted through the DoD reporting portal. Submitting requires a DoD-approved medium assurance certificate, which must be obtained ahead of time and cannot be arranged during an active incident. Reporting is not an admission of fault and does not by itself constitute a breach determination by the government.
Is DFARS 252.204-7012 the same thing as CMMC?
No, though they rest on the same 110 controls. DFARS 252.204-7012 is a contractual obligation to implement NIST SP 800-171 and to report incidents, historically satisfied by self-attestation. CMMC is the separate verification framework built to confirm that implementation. The 7012 obligation stands on its own regardless of where a given contract sits in the CMMC rollout, which is why preparing for 7012 is never wasted effort.
What is the difference between 7012, 7019, and 7020?
7012 imposes the security standard and the incident reporting duty. 7019 requires that a current NIST SP 800-171 assessment summary score be in the Supplier Performance Risk System when an offer is submitted. 7020 governs how that assessment is conducted under the DoD Assessment Methodology and requires the results be posted. Only 7012 creates obligations that activate during an incident.
Can we comply without moving to a government cloud environment?
Sometimes, and the answer depends on your data rather than on a product recommendation. The clause requires cloud providers handling covered defense information to meet FedRAMP Moderate equivalency and to support the reporting and preservation obligations. Where export-controlled technical data is involved, additional constraints usually apply. The right sequence is to scope the data first and let that drive the platform decision, not the reverse.
What happens if our assessment score is low?
A low score is a normal starting position and is far better than no score at all. The methodology is deliberately weighted so that a handful of unimplemented high-value requirements produce a steep deduction, and most contractors start negative. What matters to a contracting officer is that a current score is posted and that a dated plan of action exists showing which requirements are being closed and when.
Do we have to flow the clause down to every supplier?
It flows down to subcontracts for operationally critical support and to those where performance will involve covered defense information. A supplier who never touches that information does not need it. The judgment call is yours to make and to document, and the common failure is not over-inclusion but inserting the clause everywhere while building no way to confirm any supplier acted on it.
How long does it take to get compliant?
It depends far more on scope and starting condition than on company size. A contractor who has separated covered information into a defined enclave and already has centralized identity, logging, and asset management is working through a focused remediation list. A contractor whose covered information is spread across every mailbox and file server is doing infrastructure work before the controls become achievable. The scoping decision made at the beginning changes the timeline more than any other single choice.

Find Out Where You Actually Stand

We read your contracts, scope the environment that holds covered information, measure it against the 110 controls, and give you a defensible plan. Last updated July 29, 2026.