DFARS 252.204-7012 is the Department of Defense contract clause that requires any contractor or subcontractor handling covered defense information to protect that information using the security controls in NIST Special Publication 800-171, report cyber incidents to DoD within 72 hours, and pass the same obligations down to lower-tier subcontractors. The clause appears in nearly every DoD contract that touches sensitive but unclassified defense data, and non-compliance can cost you payments, contract options, and, increasingly, False Claims Act settlements.
When the Clause Applies to You
The trigger is covered defense information (CDI): unclassified information that requires protection under the contract. CDI comes in two forms. The first is controlled technical information, such as engineering drawings, test data, or specifications marked with a distribution statement. The second is any other category listed in the National Archives’ Controlled Unclassified Information Registry that requires safeguarding or dissemination limits.1Defense.gov. Safeguarding Covered Defense Information – The Basics
CDI includes information the government hands you and information you create, collect, or store while performing the work. Research data, logistics plans, program schedules, and technical specifications can all qualify. The practical test is whether the information is marked or identified as requiring protection in the contract, or whether the nature of the work means the information you develop inherently needs safeguarding.1Defense.gov. Safeguarding Covered Defense Information – The Basics
Markings often lag reality. Program offices sometimes share sensitive data without proper CUI markings, and contractors generate technical information without realizing it qualifies. If you’re producing engineering specs, test results, or software tied to a defense system, treat the output as CDI until your contracting officer says otherwise.
Security Controls: NIST SP 800-171
The core requirement of DFARS 252.204-7012 is to implement the security controls in NIST SP 800-171 on every system that processes, stores, or transmits CDI.2Acquisition.GOV. 252.204-7012 Safeguarding Covered Defense Information and Cyber Incident Reporting Revision 2 contains 110 security requirements grouped into 14 families covering access control, incident response, configuration management, system integrity, and other core cybersecurity disciplines.3DoD CIO. Cybersecurity Maturity Model Certification (CMMC) Model Overview Version 2.0
NIST published Revision 3 of SP 800-171 in May 2024.4National Institute of Standards and Technology. NIST SP 800-171 Rev 3 DoD has not updated DFARS 252.204-7012 to require Rev 3, and as of 2026 contractors are still assessed against Rev 2. Moving to Rev 3 before DoD mandates it won’t improve your compliance posture and can complicate assessments.
The System Security Plan
Implementing controls isn’t enough on its own. NIST SP 800-171 requires a system security plan (SSP) that documents your system boundaries, the operating environment, how each requirement is implemented, and how your systems connect to others. An assessor should be able to follow it and verify what you’ve done.5Department of Defense. Guidance for Selected Elements of DFARS Clause 252.204-7012
Plans of Action and Milestones
Few contractors implement every requirement on day one. The clause allows a Plan of Action and Milestones (POA&M) documenting any control not yet in place, what you’re doing to close the gap, and when it will be fixed.5Department of Defense. Guidance for Selected Elements of DFARS Clause 252.204-7012 A POA&M is not a free pass. Anything sitting on it counts as “not implemented” for scoring, and letting items linger can be treated as a material breach.
Cloud Providers Handling Your CDI
If you use a cloud service to process, store, or transmit CDI, the provider must meet security requirements equivalent to the FedRAMP Moderate baseline. A full FedRAMP Moderate Authorization satisfies the requirement outright. For providers without formal authorization, DoD allows a “FedRAMP equivalency” path, but the bar is high: 100% compliance with the current baseline, confirmed by a FedRAMP-recognized third-party assessor, all high and critical findings closed before the assessment ends, and a full documentation package including the SSP, security assessment report, incident response plan, and continuous monitoring records.6DoD CIO. FedRAMP Authorization and Equivalency The government cannot accept residual risk on an equivalency determination, so partial compliance won’t work.
The 72-Hour Cyber Incident Report
When you discover a cyber incident affecting a system that handles CDI or your ability to perform operationally critical work, you must report it to DoD within 72 hours. Discovery starts the clock, not the completion of your investigation. Reports go through the DIBNet portal at dibnet.dod.mil and must include the information elements the portal requires.7GovInfo. 48 CFR 252.204-7012
Reporting isn’t the end of the obligation. You must preserve forensic images and relevant data from affected systems for at least 90 days after the report so DoD can conduct its own damage assessment if it chooses. If DoD asks for equipment access or additional information, you have to cooperate. Any malicious software discovered during the incident must be isolated and submitted to the DoD Cyber Crime Center.
Get Your DIBNet Certificate Now
To submit a report through DIBNet, you need a DoD-approved medium assurance certificate, obtained through the DoD External Certification Authority program from vendors such as IdenTrust or WidePoint.8Department of Defense. Safeguarding Covered Defense Information and Cyber Incident Reporting – Class Deviation These take time to issue. If you wait for an incident to start the process, the 72-hour window will close before you can log in.
Flowing the Clause Down to Subcontractors
If a subcontractor will handle CDI or provide operationally critical support, you must include the full text of DFARS 252.204-7012 in that subcontract, without alteration other than identifying the parties. The flow-down exists to prevent weak links in the supply chain.1Defense.gov. Safeguarding Covered Defense Information – The Basics
As the prime, you decide whether information shared with a subcontractor keeps its CDI status. You can consult your contracting officer if the answer isn’t clear, but the call is yours. If a subcontractor won’t comply, CDI cannot reside on their systems. Don’t share it, and find a compliant alternative.1Defense.gov. Safeguarding Covered Defense Information – The Basics
Verifying subcontractor compliance falls to you. SPRS doesn’t give primes direct access to subcontractor scores, so you’ll have to ask them for their assessment results.9Supplier Performance Risk System (SPRS). Frequently Asked Questions Many experienced primes build verification into their subcontract terms and require evidence before sharing any CDI.
SPRS Scores and DoD Assessments
Two companion clauses turn compliance into something measurable. Under DFARS 252.204-7019, contractors must post a current NIST SP 800-171 assessment score in the Supplier Performance Risk System (SPRS) to be eligible for award. The score cannot be more than three years old. If you don’t have one posted, you can conduct a basic self-assessment and submit it, but it must be in SPRS before the award decision.10eCFR. 48 CFR 252.204-7019
DFARS 252.204-7020 requires you to give the government access to facilities and systems when medium or high assessments are needed, with the resulting scores also posted to SPRS.11eCFR. 48 CFR 252.204-7020
A perfect score is 110, meaning every requirement is fully implemented. The DoD assessment methodology subtracts 5, 3, or 1 point for each unmet requirement based on severity, and scores can go negative. Anything on a POA&M is scored as “not implemented” regardless of progress. Multifactor authentication rolled out to 90% of users still costs you the full point deduction until the last 10% is done.12Department of Defense. NIST SP 800-171 DoD Assessment Methodology Version 1.2.1
What Non-Compliance Costs
Failing to implement or make progress on NIST SP 800-171 requirements can be treated as a material breach. DoD’s available remedies include withholding progress payments, declining to exercise remaining options, and terminating the contract in whole or in part. Willful non-compliance can trigger suspension or debarment proceedings that lock you out of all federal contracting.13National Institute of Standards and Technology. Regulated Cybersecurity – The Consequences of Non-Compliance
The bigger risk today is the False Claims Act. The Department of Justice launched its Civil Cyber-Fraud Initiative in October 2021 to pursue contractors who misrepresent their cybersecurity compliance. When you post an SPRS score or affirm compliance to win a contract, that’s a representation to the government; if it’s false, the FCA applies. In 2025, Raytheon paid $8.5 million to resolve allegations of a non-compliant system security plan sustained over six years, MORSE Corp settled for $4.6 million over control and FedRAMP failures, and Georgia Tech Research Corporation paid $875,000 after allegations that it posted a fabricated SPRS score of 98 that didn’t reflect any actual system handling CDI.14U.S. Department of Justice. Georgia Tech Research Corporation Agrees to Pay $875,000 to Resolve Civil Cyber-Fraud Litigation A wide gap between your posted score and your actual implementation is the pattern that draws DOJ attention.
How CMMC 2.0 Changes the Picture
DFARS 252.204-7012 remains in force, but DoD is layering verification on top of it through the Cybersecurity Maturity Model Certification program. The CMMC final rule (32 CFR Part 170) took effect December 16, 2024, and phased implementation began November 10, 2025.15Federal Register. Cybersecurity Maturity Model Certification (CMMC) Program The rollout runs over three years in four phases. Phase 1, from November 2025 through November 2026, focuses on CMMC Level 1 and Level 2 self-assessments, with Level 2 third-party assessments expected in a smaller share of solicitations during the first year.16Department of Defense Chief Information Officer. About CMMC
For contractors handling CDI, CMMC Level 2 is the relevant tier. It maps to the same 110 NIST SP 800-171 Rev 2 requirements DFARS 252.204-7012 already requires.17DoD CIO. CMMC Model Overview Version 2.0 What changes is accountability. Under the existing regime you self-assess and post a score. Under CMMC, certain contracts will require an independent assessment by an authorized third-party organization (C3PAO) every three years, with annual affirmations in between. Whether your contract requires a self-assessment or a C3PAO assessment depends on whether the CUI involved falls within the National Archives’ Defense Organizational Index Grouping. If you’re genuinely meeting Rev 2 today, Level 2 shouldn’t require major new investment; contractors who have been optimistic in their self-assessments will have the hardest transition.