The Defense Federal Acquisition Regulation Supplement (DFARS) clause titled “Safeguarding Covered Defense Information and Cyber Incident Reporting.” This requirement applies to all Department of Defense (DoD) contractors and subcontractors that process, store, or transmit Controlled Unclassified Information (CUI).
Under this clause, contractors must:
-
Implement the 110 security requirements defined in NIST SP 800-171.
-
Report cyber incidents affecting CUI within 72 hours through the DoD’s reporting portal.
-
Preserve and protect evidence of cyber incidents for potential government review.
-
Flow down the same requirements to any subcontractors handling CUI.
DFARS 252.204-7012 is considered the cornerstone of defense cybersecurity compliance. While it establishes the mandatory safeguards, the CMMC program builds on these requirements by introducing independent third-party verification to ensure contractors are not only documenting compliance but also effectively implementing it.