DFARS 252.204-7012 Compliance
The clause that put cybersecurity into your defense contract. We help contractors and suppliers implement the safeguarding requirements it points to, stand up the 72-hour incident reporting path before they need it, and assemble the evidence that shows the obligation was met. Delivered by a North Carolina compliance and cybersecurity firm serving regulated businesses since 2002.
What Is DFARS 252.204-7012?
DFARS 252.204-7012, titled Safeguarding Covered Defense Information and Cyber Incident Reporting, is the Defense Federal Acquisition Regulation Supplement clause that obligates a contractor to protect defense information on its own systems and to report cyber incidents to the Department of Defense. It does two distinct things. First, it defines the security standard a contractor owes: adequate security, which the clause resolves to the 110 controls in NIST Special Publication 800-171. Second, it creates an affirmative reporting duty, requiring that a discovered cyber incident affecting covered defense information or the ability to perform operationally critical support be reported to DoD within 72 hours. The clause also carries obligations most contractors discover late: preserving system images after an incident, submitting malicious software to the government, holding cloud providers to a federal security baseline, and flowing the entire clause down to subcontractors. It applies by contract, not by company size, and a small supplier three tiers down the chain carries the same obligation as a prime.
Key Takeaways
- DFARS 252.204-7012 requires adequate security on contractor systems that hold covered defense information, and it defines adequate security as the 110 controls of NIST SP 800-171.
- A discovered cyber incident affecting covered defense information must be reported to the Department of Defense within 72 hours through the DoD reporting portal, which requires a medium assurance certificate obtained in advance.
- The clause also requires preserving affected system images for at least 90 days, submitting malicious software to the government, and holding cloud service providers to a FedRAMP Moderate security baseline.
- Paragraph (m) flows the entire clause down to subcontractors, so a supplier who never contracted with the government directly still carries the full obligation.
- The companion clauses 252.204-7019 and 252.204-7020 turn the self-attestation into a posted score in the Supplier Performance Risk System that contracting officers and primes can read.
- Petronella Technology Group has served regulated businesses from Raleigh since 2002, holds a BBB A+ rating since 2003, and is a CyberAB Registered Provider Organization (RPO #1449) led by a CMMC Registered Practitioner.
The Clause Was Always in the Contract. What Changed Is Who Checks.
DFARS 252.204-7012 has appeared in defense contracts for years, and for much of that time it functioned as a self-attested promise nobody audited. That is the part that changed. The obligation itself is old; the verification around it is new, and it arrived through companion clauses rather than through any rewrite of 7012.
Ask a supplier when they became subject to the clause and the honest answer is usually that they do not know. It entered through a contract modification, or through a purchase order from a prime that flowed it down, or through a subcontract signed by someone in operations who reasonably assumed the legal language was boilerplate. Nothing about the transaction announced that the company had just accepted a defined cybersecurity standard and a 72-hour reporting clock. The clause is quiet in exactly the way an obligation should not be.
Then DFARS 252.204-7019 and 252.204-7020 arrived and made the self-attestation legible. Together they require a contractor to conduct a NIST SP 800-171 DoD Assessment using the published DoD Assessment Methodology and to post the resulting score in the Supplier Performance Risk System, where a contracting officer can read it before award. A score that was previously a private opinion became a number the government sees. That number is derived from the same 110 controls that 7012 pointed to all along, which is why so many suppliers experienced the scoring requirement as a shock: it did not add a standard, it revealed how far they were from one they had already agreed to.
The gap that opens is rarely one of intent. A machine shop that makes a bracket to a government drawing does not think of itself as holding defense information, but the drawing is the information, and the moment it lands in a shared mailbox or an unmanaged file server the clause is engaged. An engineering firm exchanges technical data packages with a prime through whatever channel the prime uses, without asking whether that channel meets a transmission control. A supplier keeps ten years of contract correspondence in an email archive that has never been scoped. None of that is negligence. It is what happens when a compliance obligation arrives without a corresponding change to how work gets done.
The practical consequence is a business one. Primes now ask about scores during supplier qualification, because their own flowdown obligation makes a weak subcontractor their problem. A contractor who cannot answer the question is not usually disqualified on cybersecurity grounds. They are quietly passed over, and they rarely find out that is why.
What DFARS 252.204-7012 Actually Requires
The clause is short, and most summaries stop at the first requirement. The obligations after it are the ones that generate findings, because they demand capabilities a contractor either has in place before an incident or does not have at all.
Adequate Security via NIST SP 800-171
The core obligation. A contractor must implement the 110 security requirements in NIST Special Publication 800-171 on every covered contractor information system, or document an alternative that an authorized DoD representative has accepted as equally effective. This is where the majority of the work sits, and where the assessment score comes from.
72-Hour Cyber Incident Reporting
When a contractor discovers a cyber incident that affects covered defense information, a covered contractor information system, or its ability to perform operationally critical support, it must rapidly report to the Department of Defense within 72 hours of discovery. The report goes through the DoD reporting portal, which requires a DoD-approved medium assurance certificate. Obtaining that certificate takes time, which is why the clock is the wrong moment to start.
Media Preservation and Protection
Following a reported incident, the contractor must preserve and protect images of all known affected information systems and relevant monitoring and packet capture data for at least 90 days from the report, so the government can request them. Doing this without destroying the evidentiary value of the images is a forensics discipline, not an IT backup task.
Malicious Software Submission
If malicious software is discovered and isolated in connection with a reported incident, the contractor submits it to the DoD Cyber Crime Center. It is explicitly not sent to the contracting officer, and getting that routing wrong is a common procedural error.
Cloud Service Provider Requirements
Where a contractor uses an external cloud service provider to store, process, or transmit covered defense information, the clause requires that provider to meet security requirements equivalent to the FedRAMP Moderate baseline and to comply with the reporting and media preservation obligations. This is the paragraph that drives collaboration platform decisions more than any other.
Subcontractor Flowdown
The clause must be included in subcontracts for operationally critical support or where performance will involve covered defense information. The prime is responsible for the flowdown, and a subcontractor that reports an incident must also provide the incident report number to the prime. Managing this across a supplier base is a third-party risk program, not a paperwork exercise.
DFARS 7012 Compared to the Clauses Around It
Three DFARS cybersecurity clauses are routinely confused with one another, and the confusion has a cost: contractors prepare for the wrong one. They are related but not interchangeable, and 7012 is the only one of the three that imposes an operational duty during an incident.
| Question | DFARS 252.204-7012 | DFARS 252.204-7019 | DFARS 252.204-7020 |
|---|---|---|---|
| What it obligates | Protect covered defense information and report cyber incidents within 72 hours | Provide a current NIST SP 800-171 assessment summary score before award | Conduct the assessment using the DoD methodology and post results in SPRS |
| Underlying standard | NIST SP 800-171, all 110 requirements | NIST SP 800-171, scored | NIST SP 800-171 DoD Assessment Methodology |
| Creates a duty during an incident | Yes, this is the only one of the three that does | No | No |
| Produces a number the government sees | No, the obligation is a standard rather than a score | Yes, the posted summary level score | Yes, including assessment date and scope |
| Reaches subcontractors | Yes, by required flowdown in paragraph (m) | Applies at award to the offeror | Yes, flowdown for applicable subcontracts |
| Touches cloud providers directly | Yes, FedRAMP Moderate equivalency required | No | No |
| What contractors most often miss | The reporting certificate, media preservation, and flowdown | That the score must be current, not merely existent | That a low score is postable and a missing score is not |
Where Contractors Fall Short
Across readiness reviews, the same gaps recur. They cluster around the parts of the clause that require a decision to have been made in advance rather than a product to have been purchased.
Finding 1
No DoD medium assurance certificate in place, so the 72-hour reporting path cannot actually be used on the day it is needed
Finding 2
Covered defense information scattered across general email and file shares, which expands the assessment boundary to the entire company
Finding 3
A system security plan that describes an idealized environment rather than the one running today
Finding 4
Flowdown clauses present in subcontracts but no process for confirming a supplier ever acted on them
Finding 5
A collaboration or email platform that cannot meet the encryption and export-control requirements as currently licensed
Finding 6
No documented procedure for preserving system images, so a real incident would destroy the evidence while responding to it
Not Sure Whether the Clause Is in Your Contracts?
A readiness review starts by reading what you actually signed, then measuring the environment against it. Serving Raleigh, Durham, and the Research Triangle since 2002, with nationwide delivery.
How We Take a Contractor Through DFARS 252.204-7012
The sequence matters. Scoping before assessment prevents the most expensive mistake in this work, which is securing an environment larger than the obligation requires.
Contract review: read the actual clauses in your awards, modifications, and purchase orders to confirm which obligations you carry and from whom
Data and scope definition: identify where covered defense information enters, lives, and leaves, then decide deliberately how much of the environment stays in scope
Gap assessment against all 110 requirements using the DoD Assessment Methodology, producing a defensible score rather than an optimistic one
Remediation planning: sequence the work by risk and score impact, separating what can be fixed this quarter from what needs a budget cycle
Incident readiness: obtain the reporting certificate, write the reporting and media preservation procedure, and rehearse it before it is needed
Documentation and monitoring: produce the system security plan and plan of action, post the score, and keep both current as the environment changes
What You Receive
Every engagement produces artifacts a contracting officer, a prime's supplier quality team, or an assessor can read without a guided tour.
Contract Obligation Map
A plain-language summary of which DFARS cybersecurity clauses appear in which of your contracts and what each one commits you to, so the obligation stops being a matter of assumption.
Scoped Environment Boundary
A documented definition of the systems, people, and data flows that hold covered defense information, with a diagram, and the rationale for what was excluded.
Scored Gap Assessment
Every one of the 110 requirements assessed against the DoD methodology, with the resulting summary level score and the specific evidence behind each determination.
System Security Plan and Plan of Action
The two artifacts the clause and its companions require, describing the environment as it exists and the dated, owned plan for closing what remains open.
Incident Reporting Runbook
The reporting path, the certificate, the decision criteria for what constitutes a reportable incident, the media preservation procedure, and the malware submission route.
Flowdown and Supplier Package
The clause language for your subcontracts plus a tracking approach for confirming suppliers received it, acknowledged it, and can answer for it.
What Drives the Cost of DFARS Compliance
There is no useful flat price for this work, because two contractors with identical revenue can differ by an order of magnitude in effort. These are the variables that actually move the number.
How much of your environment is in scope. This is the dominant factor and the one most within your control. A contractor who has separated defense information into a defined enclave is assessing a handful of systems. A contractor whose covered information is spread across every mailbox, file share, and laptop is assessing the entire company. The scoping decision made in week one determines the cost of everything after it.
Where you are starting from. An organization with a current asset inventory, centrally managed identities, and existing logging is remediating gaps. An organization without those has to build the foundation the controls assume exists, and that foundation is a project in its own right regardless of the clause.
Your collaboration and email platform. Requirements that touch encryption and export-controlled data interact directly with how your productivity suite is licensed and configured. Whether a migration is needed, and how much data moves, is frequently the single largest line item in a remediation plan.
The state of your documentation. A system security plan and plan of action are required artifacts, not optional ones, and they must describe the environment that actually exists. Writing them from nothing takes longer than updating them, and inheriting a generic template someone sold you is often worse than starting fresh.
Legacy and specialty equipment. Test benches, inspection systems, and shop-floor machines running unsupported operating systems cannot always be patched or joined to a modern identity platform. Each one needs a documented compensating approach, and that analysis is per-device work.
Your subcontractor footprint. Flowdown is your obligation to manage. A contractor with two long-standing suppliers has a modest administrative task. A contractor with sixty vendors touching technical data has a supply chain program to build. For a scoped estimate against your contracts and environment, talk to our team.
Which Businesses Carry This Clause
The clause reaches far past the companies most people picture when they hear defense contractor. If your work product ends up in a defense system and you receive technical information to produce it, assume the question applies to you until your contracts say otherwise.
In North Carolina and across the Southeast, the businesses that discover the clause in their contracts are usually precision machine shops and metal fabricators working to controlled drawings, engineering and design firms exchanging technical data packages, electronics manufacturers and printed circuit board houses, composites and specialty materials suppliers, calibration and test laboratories, robotics and autonomous systems developers, aerospace maintenance and repair operations, and the logistics and packaging firms that handle controlled shipments. Software and IT vendors selling into defense programs carry it too, and so do the professional services firms that support them.
Research universities and their spin-outs occupy a particularly awkward position, because a single sponsored research award can bring the clause into an environment built for openness. The Research Triangle has a concentration of exactly these organizations, which is a large part of why we do this work from Raleigh.
From a Client in the Aviation Industry
"Their quick response and service far surpassed anything I imagined."
Raynor Combs, Aviation Industry
Petronella Technology Group is rated 4.7 across 92 verified TrustIndex reviews and 5.0 across 15 Google reviews.
Experience Behind the Work
Petronella Technology Group has operated from Raleigh, North Carolina since 2002 and has held a BBB A+ rating since 2003. The firm is a CyberAB Registered Provider Organization, RPO #1449, and founder Craig Petronella is a CMMC Registered Practitioner and an NC Licensed Digital Forensics Examiner, License #604180-DFE.
That forensics credential is more relevant to this clause than it first appears. DFARS 252.204-7012 does not only ask a contractor to prevent incidents; it asks what they will do during one, when a 72-hour clock is running and images have to be preserved without contaminating them. Those are forensic questions, and answering them under pressure is different from answering them in a policy document. As Craig Petronella details in the CMMC 2.0 Certification Guide, and across a library of 15 published titles including How Hackers Can Crush Your Business, the distance between a written procedure and an executed one is where most programs are found wanting. Our digital forensics practice is the same team that helps clients rehearse the reporting path before they need it.
On the documentation side, our ComplianceArmor platform generates and maintains the system security plan, plan of action, and evidence mapping this work requires, so those artifacts stay current as the environment changes rather than aging into fiction between assessments. Craig also explores compliance and defense-sector security regularly on the Encrypted Ambition podcast.
Explore the Rest of the Requirement
NIST SP 800-171 Compliance
Controlled Unclassified Information
NIST and DFARS Compliance Overview
CMMC Compliance Guide
NIST 800-171A Assessment
CMMC and SPRS Self-Score
Free SPRS Score Calculator
CMMC Enclave Design
System Security Plan Requirement
Plan of Action Requirement
FIPS Validated Cryptography
CMMC Incident Response
NIST 800-161 Supply Chain Risk
NIST for Federal Contractors
CMMC and GCC High
NIST 800-88 Media Sanitization
DFARS 252.204-7012 Questions
What is DFARS 252.204-7012 in plain terms?
How do I know if the clause applies to my company?
What counts as covered defense information?
What does the 72-hour reporting requirement actually involve?
Is DFARS 252.204-7012 the same thing as CMMC?
What is the difference between 7012, 7019, and 7020?
Can we comply without moving to a government cloud environment?
What happens if our assessment score is low?
Do we have to flow the clause down to every supplier?
How long does it take to get compliant?
Find Out Where You Actually Stand
We read your contracts, scope the environment that holds covered information, measure it against the 110 controls, and give you a defensible plan. Last updated July 29, 2026.