What does DFARS 252.204-7012 require?

Short answer

DFARS 252.204-7012 requires defense contractors that handle covered defense information to implement NIST SP 800-171 Rev 2, use only cloud providers meeting FedRAMP Moderate-equivalent requirements, report cyber incidents to DoD within 72 hours, preserve affected system images for at least 90 days and flow the clause down to subcontractors. It remains fully in effect during the CMMC Phase 2 suspension.

Who it applies to

The clause covers any unclassified contractor information system that processes, stores or transmits covered defense information, meaning CUI marked or identified in your contract or developed by your company in support of it. Contractors were required to implement it no later than December 31, 2017.

Under the Revolutionary FAR Overhaul, DFARS Class Deviation 2026-O0025 republished the clause (dated June 2026) inside the new DFARS Part 240. The deviation text now names NIST SP 800-171 Revision 2 directly.

The security requirement

Your covered systems must meet the NIST SP 800-171 Rev 2 requirements. If you believe a requirement does not apply or have an equally effective alternative, you submit a written variance request to the contracting officer for the DoD CIO to adjudicate. The clause also expects additional measures where your risk calls for them, which may be addressed in your system security plan.

If an external cloud provider stores, processes or transmits covered defense information, you must ensure it meets security requirements equivalent to the FedRAMP Moderate baseline and complies with the clause's incident reporting, malware, media preservation, forensic access and damage assessment paragraphs.

When an incident happens

  • Review affected systems for evidence that covered defense information was compromised.
  • Rapidly report to DoD at dibnet.dod.mil, which the clause defines as within 72 hours of discovery.
  • Hold a DoD-approved medium assurance certificate, which is required to file the report.
  • Submit isolated malicious software to the DoD Cyber Crime Center (DC3), not to the contracting officer.
  • Preserve images of affected systems and relevant monitoring or packet capture data for at least 90 days from your report.
  • Give DoD access to information or equipment needed for forensic analysis or damage assessment on request.

Subcontractors and how 7012 fits with CMMC

You must include the clause, without alteration, in subcontracts that involve covered defense information or operationally critical support, and your subcontractors must report incidents and pass their report numbers to you.

7012 is the obligation; CMMC is how DoD verifies it. The July 13, 2026 memo suspending CMMC Phase 2 states that DoD will enforce baseline NIST SP 800-171 Rev 2 compliance through Level 1 and Level 2 self-assessments and select government-led assessments, and that 7012 remains in effect. Government-led Medium and High assessments now sit in DFARS 252.240-7997.

Common follow-up questions

Does DFARS 7012 require CMMC certification?

No. 7012 sets the security and incident-reporting obligations. CMMC, through DFARS 252.204-7021, verifies them. While Phase 2 is suspended, new solicitations may require only Level 1 (Self) or Level 2 (Self), but 7012 obligations apply whenever the clause is in your contract.

What counts as a reportable cyber incident?

The clause defines a cyber incident as actions through computer networks that result in a compromise, or an actual or potentially adverse effect, on an information system or its information. Report affecting covered systems within 72 hours of discovery, based on what you know at that point.

When should I get a medium assurance certificate?

Before you need it. The clause requires a DoD-approved medium assurance certificate to file an incident report, and obtaining one takes time. With a 72-hour reporting window, waiting until after an incident puts the deadline at risk.

Need help with this?

LAN Service Group's ISSO-led compliance practice implements NIST SP 800-171 controls, incident response plans and FedRAMP Moderate-equivalent cloud environments such as Microsoft 365 GCC High for defense contractors subject to DFARS 252.204-7012.

Talk to LAN Service Group (888) 281-7243

Sources