Skip to main content

DEFENSE & CMMC

What Is DFARS 252.204-7012 (Safeguarding Covered Defense Information)?

DEFINITION

DFARS 252.204-7012 is the Defense Federal Acquisition Regulation Supplement clause titled Safeguarding Covered Defense Information and Cyber Incident Reporting. It requires defense contractors to implement NIST SP 800-171 on systems that handle covered defense information, report cyber incidents to the Department of Defense within 72 hours of discovery, preserve related media, and flow the clause down to subcontractors.

DFARS 252.204-7012 is the contract clause that has anchored defense supply chain cybersecurity since before CMMC existed. It obligates contractors to provide adequate security for covered defense information, defined as implementing the security requirements of NIST SP 800-171 on any contractor system that processes, stores, or transmits that information. It also imposes operational duties: rapidly reporting cyber incidents to the DoD within 72 hours of discovery, preserving images of affected systems and relevant monitoring data for at least 90 days, submitting malicious software to the DoD Cyber Crime Center when discovered, and using cloud services that meet security requirements equivalent to the FedRAMP Moderate baseline when CUI goes to the cloud.

The clause appears in most DoD contracts other than those solely for commercially available off-the-shelf items, and it must be flowed down to subcontractors whose performance involves covered defense information. That flow-down is why small machine shops and niche engineering firms carry the same 110-requirement obligation as primes.

Practically, 7012 is a self-attestation regime: signing a contract containing the clause represents that NIST SP 800-171 is implemented. CMMC adds verification on top of that existing promise rather than creating new security requirements. As of mid-2026, NIST SP 800-171 Rev 2 remains the assessment baseline under a class deviation. See NIST 800-171 vs CMMC for how the clause relates to certification.

Running a program that has to satisfy this?

A Z Cyber advisor can walk your current posture against the requirement and show you what a running program looks like on Glance.

Meet Your Security Team →