CMMC
What Does DFARS 252.204-7012 Require of a Defense Contractor?
DFARS 252.204-7012 requires a contractor that handles covered defense information to protect it with the security requirements of NIST SP 800-171, report cyber incidents to DoD within 72 hours of discovery, preserve images of affected systems for at least 90 days, hold cloud providers to FedRAMP Moderate equivalence, and flow the clause down to subcontractors that handle covered defense information. It remains in effect during the CMMC Phase 2 suspension.
Capital Cyber. Sources are listed at the end of the article.
Adequate Security Under NIST SP 800-171
For a contractor's own information systems, paragraph (b)(2) applies the security requirements of NIST SP 800-171. The 2026-07-13 implementing memo on the CMMC suspension says the Department will enforce baseline compliance with NIST SP 800-171 Rev 2. DFARS 252.204-7019 adds that an offeror must have a current assessment, not more than three years old unless the solicitation says less, posted in SPRS to be considered for award.
Cyber Incident Reporting in 72 Hours
When a contractor discovers a cyber incident affecting covered defense information or its ability to perform operationally critical support, it reviews for evidence of compromise and reports to DoD at dibnet.dod.mil within 72 hours of discovery (paragraph (c)). Reporting needs a DoD-approved medium assurance certificate, which is worth getting before an incident, not during one.
Preservation, Malware and Access
The contractor preserves and protects images of affected systems and relevant monitoring and packet capture data for at least 90 days from the report (paragraph (e)), submits any malicious software it isolates (paragraph (d)), and gives DoD access to additional information or equipment needed for a forensic analysis on request (paragraph (f)).
Cloud Providers and Subcontractors
An external cloud provider that stores, processes or transmits covered defense information must meet security requirements equivalent to the FedRAMP Moderate baseline (paragraph (b)(2)(ii)(D)). The clause flows down, without alteration, to subcontracts for operationally critical support or that involve covered defense information (paragraph (m)).
Frequently Asked Questions
4 QUESTIONSHow fast must a cyber incident be reported under DFARS 252.204-7012?
Within 72 hours of discovery, to DoD at dibnet.dod.mil, under paragraph (c) of the clause.
Is DFARS 252.204-7012 affected by the CMMC Phase 2 suspension?
No. The 2026-07-13 implementing memo says the cybersecurity requirements of DFARS 252.204-7012 remain in effect.
How long must incident images be kept?
At least 90 days from the submission of the cyber incident report, under paragraph (e).
How old can my SPRS assessment be?
Not more than three years old, unless the solicitation specifies less, under DFARS 252.204-7019.
Sources
READ 2026-10-08- DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting (acquisition.gov)
- DFARS 252.204-7019, Notice of NIST SP 800-171 DoD Assessment Requirements (acquisition.gov)
- Implementing memo on the suspension of CMMC Phase II, Under Secretary of War for Acquisition and Sustainment, 2026-07-13, cleared 26-P-1023 (PDF)
- NIST SP 800-171 Rev. 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations (csrc.nist.gov)
This article explains the regulations and is not legal advice.
Talk it through in 30 minutes.
A call is a conversation, not a pitch. Tell us how your business runs and we will tell you what we would manage.
Looking for CMMC? Our Compliance Division, Capital Cyber Compliance, delivers it.
