DFARS 252.204-7012 Explained: What Defense Contractors Must Actually Do
DFARS 252.204-7012 is the contract clause that turns cybersecurity into a legal requirement for defense contractors, not a nice-to-have. It applies to any Department of Defense contract or subcontract that may involve covered defense information. There’s no minimum contract size or company headcount that exempts you.
That scope catches more businesses than most owners expect. Primes are covered, obviously. So are subcontractors two or three tiers down, and often the IT vendors who support them.
The clause itself is short. Actually meeting it is not. It requires NIST SP 800-171 security controls, specific standards for any cloud provider you use, and a 72-hour incident reporting deadline that catches businesses off guard almost every time. This guide walks through what the clause actually demands, what “covered defense information” means in plain terms, and why that 72-hour clock trips up so many contractors.
What DFARS 252.204-7012 Requires
The clause’s full name is “Safeguarding Covered Defense Information and Cyber Incident Reporting.” Its official text lays out six core obligations for any covered contract:
- Implement NIST SP 800-171. You must put the full set of NIST SP 800-171 security requirements in place on any system that touches covered defense information.
- Use a FedRAMP Moderate-equivalent cloud provider. If an external cloud service stores, processes, or transmits covered defense information, that provider’s security must be equivalent to the FedRAMP Moderate baseline.
- Report cyber incidents within 72 hours. Any cyber incident affecting covered defense information gets reported to DoD at dibnet.dod.mil within 72 hours of discovery.
- Submit malicious software to DC3. If you find malware tied to the incident, you submit it to the DoD Cyber Crime Center.
- Preserve system images and monitoring data for 90 days. Affected system images and related monitoring or packet-capture data get preserved for at least 90 days from the report date.
- Flow the clause down to subcontractors, unaltered. If you’re a prime, you’re required to pass this same clause down to your subcontractors word for word.

The clause is mandatory in nearly every DoD contract and subcontract that may touch covered defense information. There’s no opt-out for smaller vendors. If your contract carries the clause, all six requirements apply to you the same way they apply to a prime.
What Counts as “Covered Defense Information”
Covered defense information is DoD’s term for a specific category of Controlled Unclassified Information, or CUI. CUI itself is a government-wide category, not something DoD invented on its own. The National Archives defines it as sensitive government information that isn’t classified but still needs safeguarding.

In plain terms: it’s not a state secret, but it’s also not public. Common examples include controlled technical data, export-controlled information, and certain program-related records tied to a federal contract.
CUI comes in two control levels, and the difference matters for how strict your handling has to be:
One more distinction worth knowing: NIST doesn’t decide what counts as CUI. That’s the National Archives’ job, through its CUI Registry. NIST’s role starts after that: NIST SP 800-171 is the standard that tells you how to protect CUI’s confidentiality once it’s sitting on your systems. That’s the standard DFARS 252.204-7012 points to in requirement one above.
The 72-Hour Clock
This is the requirement that trips up the most businesses, and it’s not close.
Contractors must report a cyber incident to DoD within 72 hours of discovery, not 72 hours from when the incident started.
That distinction is the whole trap. “Discovery” means the moment you become aware of the incident, not the moment it actually happened. A breach that sat undetected for three weeks doesn’t give you three weeks of grace once you find it. The clock starts the day you know.
Most businesses that miss this deadline don’t miss it on purpose. They miss it because nobody was watching closely enough to catch the incident fast, or because nobody on staff knew the 72-hour requirement existed at all. By the time IT flags something unusual and someone connects it to a DoD contract, hours or days have already gone by.
What actually has to get reported isn’t complicated once you know it’s coming. DoD wants a description of the incident, the compromised information involved, and the impact on your ability to perform the contract. The hard part is never the paperwork. It’s having monitoring in place that surfaces an incident fast enough to leave room to report it within the window, and having a process ready so nobody is scrambling to figure out where dibnet.dod.mil even is on day one of an actual incident.
Consequences of Falling Short
NIST itself doesn’t fine anyone for missing DFARS 252.204-7012. That’s not where the real risk sits.
The risk sits with the Department of Justice, which uses the Civil Cyber-Fraud Initiative and the False Claims Act to go after contractors who falsely certify cybersecurity compliance. Two 2025 settlements show exactly how that plays out.
| Date | Company | Penalty | Reason |
|---|---|---|---|
| May 1, 2025 | Raytheon Company and Nightwing Intelligence Solutions | $8.4 million | Falsely certified cybersecurity-requirement compliance on DoD contracts and subcontracts |
| July 31, 2025 | Aero Turbine, Inc. and Gallant Capital Partners | $1.75 million | Knowingly failed to meet cybersecurity requirements in an Air Force contract, disclosed voluntarily |
Beyond the fines, non-compliance blocks you structurally, not just financially. A federal system that can’t meet its baseline doesn’t get an Authorization to Operate. A cloud vendor without FedRAMP authorization can’t sell to federal agencies. A contractor that falsely certifies compliance risks treble damages, contract termination, and debarment from future federal work.
How This Connects to CMMC and Your SPRS Score
DFARS 252.204-7012 requires NIST SP 800-171. CMMC is how DoD checks that you actually did it.
It’s an assessment layer that verifies your controls are real, not just claimed on paper. CMMC Level 2 maps directly to the full NIST SP 800-171 control set. Some contracts only require self-assessment. Others, involving more sensitive CUI, require a third-party C3PAO assessment. That distinction became contractual on November 10, 2025, when DoD’s CMMC rule took effect.
Your SPRS score is where that self-assessment becomes visible to DoD. Since November 10, 2025, a current score in SPRS is required before contract award on covered solicitations.
For the fuller picture, see NIST 800-53 vs CMMC, explained and what an SPRS score is.
What an MSP Actually Operates vs. What Stays Yours
DFARS 252.204-7012 compliance isn’t something you hand off entirely. Some of it can’t be delegated.
The technical controls behind NIST SP 800-171 are exactly the kind of work a managed IT and cybersecurity provider is built to run day to day. Signing the contract and certifying compliance to DoD are not.
| Approach | NIST 800-171 Technical Controls | 72-Hour Incident Reporting | SSP / POA&M Documentation | What Stays Yours |
|---|---|---|---|---|
| Handle it in-house | You build and maintain every control yourself | You monitor and file the report yourself | You write and update it yourself | Everything |
| Generic IT provider, no compliance focus | Partial, varies by vendor | Not typically monitored for DoD’s 72-hour window | Rarely offered | Verifying coverage gaps yourself |
| LeadingIT managed IT and cybersecurity | Sets up and manages controls across the relevant technical families | Runs the monitoring that catches an incident fast enough to hit the window, then helps you file it | Helps assemble your SSP and POA&M | The contract itself, and the officer-level decision to certify |
LeadingIT is a Chicagoland managed IT and cybersecurity provider based in Woodstock and Manteno, Illinois. For a defense contractor, the day-to-day work centers on:
- Access Control — unique logins, least privilege, multifactor authentication
- Audit and Accountability — centralized logging and log review
- Configuration Management — hardened, documented system baselines
- Incident Response — a tested plan built to meet the 72-hour reporting clock
- System and Communications Protection — network segmentation, encryption in transit and at rest
- System and Information Integrity — patch management, endpoint detection, vulnerability scanning
LeadingIT also helps assemble the System Security Plan and Plan of Action and Milestones a client needs to self-assess NIST SP 800-171 and generate an SPRS score. What stays yours is the contract itself, and the decision to certify compliance to DoD.
See Where You Stand
Get a plain-English read on where your organization stands against the control families that matter most, and the gaps to fix first. No sign-up needed to see your result.
Take the free 2-minute NIST 800-53 Risk-Check
Related Guides
- What Is NIST SP 800-53? The Plain-English Guide
- NIST 800-53 Compliance Checklist: The Practical Starting Point
- NIST 800-53 vs. CMMC: What’s the Difference?
- What Is an SPRS Score? The DoD Contractor’s Guide to Self-Assessment Scoring
Frequently Asked Questions
Any DoD contractor or subcontractor whose contract may involve covered defense information, regardless of company size. Primes are covered, and so are subcontractors several tiers down. There’s no minimum contract value or headcount that exempts a business.
It’s DoD’s term for a category of Controlled Unclassified Information, sensitive government information that isn’t classified but still needs safeguarding. Examples include controlled technical data and export-controlled information. The National Archives, not NIST, defines what qualifies as CUI.
Within 72 hours of discovery, not 72 hours from when the incident actually happened. The clock starts the moment you become aware of it. Reports go to DoD at dibnet.dod.mil.
NIST doesn’t issue fines, but falsely certifying compliance can trigger False Claims Act liability through the Department of Justice. Two 2025 settlements, Raytheon and Nightwing at $8.4 million and Aero Turbine and Gallant Capital at $1.75 million, show that risk is real. Consequences can also include contract termination and suspension or debarment from future federal work.
Yes. Prime contractors are required to flow the clause down to subcontractors unaltered. If a subcontract may involve covered defense information, the same six requirements apply, regardless of tier.
DFARS 252.204-7012 is the contract clause requiring NIST SP 800-171 implementation. CMMC is the certification program that verifies that implementation actually happened, through self-assessment or third-party assessment depending on the contract. They work together rather than replacing each other.
Since November 10, 2025, a current score in SPRS is required before award on covered DoD solicitations.</p> </details>
Ready to Close the Gaps?
Meeting DFARS 252.204-7012 on your own, on top of running a business, is a lot to carry. LeadingIT’s NIST 800-53 / federal compliance IT services build and manage these controls for you, so you can focus on the contract instead of the audit trail.
Want our cybersecurity insights first? Add LeadingIT as a preferred source on Google and see more of our guidance in your results.
