Guides / October 03, 2026
The October 2 DoD Cyber Rule: What Defense Contractors Must Report Now
You find a breach on a Friday night, and your first question is who you must tell. On October 2, 2026, the Defense Department answered part of that with a new rule.
What happened on October 2?
The Defense Department's chief information officer office issued an interim final rule for the Defense Industrial Base Cybersecurity Activities program. (Steptoe) DIB stands for Defense Industrial Base, the companies that supply the military.
The rule took effect right away. Comments are due December 1. (Steptoe) An interim final rule means it is live now while the public still gets to comment.
What is the DIB Cybersecurity Activities program?
It is a voluntary threat information sharing program for defense contractors. About 1,000 cleared contractors take part today. (Steptoe) Cleared means the company holds a facility clearance for classified work.
Each participant signs a standardized Framework Agreement with the government. That agreement sets the terms for sharing cyber threat information both ways.
What does the rule require?
Mandatory cyber incident reporting for program participants. The reporting duties closely mirror the DFARS cyber reporting rule issued in August. (Steptoe) That August rule requires defense contractors to report a cyber incident within 72 hours. It applies when the incident touches covered defense information.
The October rule covers incidents with an actual or potentially bad effect on a covered contractor system. It also covers covered defense information sitting inside that system. (Inside Defense) Covered defense information is unclassified data the Defense Department marked as needing protection.
Participants also must keep records of the incidents they report. The idea is simple: report fast, keep proof.
Why does this matter if I am not in the program?
Because the rule reaches further than the August DFARS rule. The August rule was aimed at procurement contracts. This one relates to contracts, other transactions, and grants where DIB companies take part. (Steptoe)
It also pulls in subcontractors. DIB participants must require their subcontractors to report, even when the subcontractor never joined the program. (Steptoe) A subcontractor on a grant could owe a report under this regime without ever signing up.
What about export-controlled data?
The rule aims partly at apparent compromises of export-controlled information. That is sensitive technical data the government controls for national security reasons.
But the rule does not define export-controlled information precisely. That leaves an open question for contractors. Low-level EAR 99 technical data is one example the legal analysts flagged. (Steptoe) EAR is the Export Administration Regulations.
The report to the Defense Department is mandatory. Companies should also ask whether they owe a separate self-report to the export control agency. That judgment stays with the company.
Does this replace my other reporting duties?
No. The rule says so directly. Reporting under this program does not remove any other cyber incident reporting duty you have. (Steptoe)
Other kinds of CUI go through other channels. CUI stands for Controlled Unclassified Information. Breaches of classified systems are separate too. If you handle several data types, keep a list of which channel covers each one.
What should I do this week?
First, check whether you are a DIB program participant or a subcontractor to one. Read your subcontracts for flow-down reporting language.
Second, line up your reporting access now. The rule explains where to report and how to get the credentials. (Steptoe) You can also name a third-party security provider to report on your behalf.
Third, if the rule affects you, consider filing a comment before December 1. The export-control definition question is exactly the kind of thing comments are for.
Fourth, treat your incident evidence as a standing obligation. Fast reporting is only half the rule. You must be able to show what happened and what you did.
PolicyCortex reads live Azure configuration and maps it to NIST 800-171 controls, so the proof behind your reports stays current.
Sources
- Steptoe, "DoD's New Defense Industrial Base Cybersecurity Rule Aligns with the August DFARS Cyber Reporting Rule" (Oct. 2026)
- Inside Defense, "DOD Establishes Rule Mandating Contractors Report Cyber Incidents" (Oct. 2, 2026)
- DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting
Next step
Report cyber incidents on time, every time. Start keeping your incident evidence audit-ready now.
See how PolicyCortex collects compliance evidence automatically