Guides / September 27, 2026
What Is DFARS 252.204-7012 in Plain English?
Defense contracts come with fine print. This clause is the cyber security part. Here is what it says in plain words.
What is DFARS 252.204-7012?
It is a contract clause from the Defense Department. Its full name is Safeguarding Covered Defense Information and Cyber Incident Reporting. (DFARS 252.204-7012)
DFARS stands for Defense Federal Acquisition Regulation Supplement. It is the Defense Department's add-on to the government-wide buying rules.
The clause has two jobs. It tells you how to protect sensitive data. It tells you how to report a cyber incident.
The Defense Department uses it in nearly all solicitations and contracts. The only exception is contracts solely for off-the-shelf items. (DFARS 204.7304) COTS stands for commercially available off-the-shelf, meaning products sold as-is to the public.
Who has to follow it?
Any contractor with the clause in its contract. That includes the prime contractor and every subcontractor down the chain.
It covers any unclassified company system that stores, processes, or transmits covered defense information. (DFARS 252.204-7012) Covered defense information is unclassified data that needs protection, like controlled technical drawings or CUI registry data. (DFARS 252.204-7012) CUI stands for Controlled Unclassified Information.
Company size does not matter. A ten-person shop follows the same rule as a giant prime.
What does "adequate security" mean here?
It means meeting the requirements in NIST SP 800-171. (DFARS 252.204-7012)
NIST stands for the National Institute of Standards and Technology. SP 800-171 is its guide for protecting unclassified information on nonfederal systems.
You use the version in effect when the solicitation was issued. (DFARS 252.204-7012) Your contracting officer can approve a different version or an alternate control. (DFARS 252.204-7012)
The clause also expects common sense. If your risk calls for extra measures, add them and note them in your system security plan. (DFARS 252.204-7012)
What must you do after a cyber incident?
First, review what was hit. Look for compromised computers, servers, data, and user accounts. (DFARS 252.204-7012) Check other systems on your network that the attacker may have reached. (DFARS 252.204-7012)
Second, report fast. "Rapidly" means within 72 hours of discovery. (DFARS 252.204-7012) You report to the Defense Department through its official portal. (DFARS 252.204-7012)
Third, set up reporting access before you need it. You need a DoD-approved medium assurance certificate to file a report. (DFARS 252.204-7012) A certificate you cannot find at 2 a.m. is the same as no certificate.
Fourth, protect the evidence. Keep images of affected systems and packet capture data for at least 90 days after your report. (DFARS 252.204-7012)
Fifth, handle malicious software correctly. Send it to the DoD Cyber Crime Center, not to your contracting officer. (DFARS 252.204-7012)
What is the flow-down rule?
Put this clause in every subcontract that will involve covered defense information. (DFARS 252.204-7012) Include it unchanged, except to name the parties. (DFARS 252.204-7012)
It also flows to subcontracts for operationally critical support. (DFARS 252.204-7012) That is a defined term, so check your contract to see if it applies.
You must decide whether the subcontractor's information still counts as covered defense information. (DFARS 252.204-7012) If you are unsure, ask your contracting officer. (DFARS 252.204-7012)
Subcontractors have two extra duties. They must notify the prime before asking to skip an 800-171 requirement. (DFARS 252.204-7012) They must give the prime the DoD incident report number as soon as practical. (DFARS 252.204-7012)
What about cloud services?
If you use an outside cloud provider for covered defense information, that provider has extra rules. It must meet security requirements equal to the FedRAMP Moderate baseline. (DFARS 252.204-7012)
FedRAMP stands for the Federal Risk and Authorization Management Program. It is the government's cloud security program.
The provider must also follow the same incident reporting and evidence rules as you. (DFARS 252.204-7012) Check this before you sign the cloud contract, not after.
What is one thing to do this week?
Open your contract and check for this clause. If it is there, list every system that touches the covered data. That list is step one for everything else.
Then confirm your incident reporting access works. Practice beats panic.
PolicyCortex reads live Azure configuration and maps it to NIST 800-171 controls, so your proof stays current.
Sources
- DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting (May 2024)
- DFARS 204.7304, Solicitation provision and contract clauses
Next step
Have the clause in your contract? Start gathering your NIST 800-171 proof now.
See how PolicyCortex collects compliance evidence automatically