The Defense Federal Acquisition Regulation Supplement (DFARS) clause titled Safeguarding Covered Defense Information and Cyber Incident Reporting requires defense contractors and subcontractors to implement adequate security measures to protect Controlled Unclassified Information (CUI) in non-federal systems. It also mandates that federal contractors and subcontractors adhere to the DFARS 252.204-7012 72 hours cyber incident reporting requirement to notify the Department of Defense (DoD) of any cyber incidents.

Under this clause, contractors must comply with the 110 security requirements defined in NIST SP 800-171, provide rapid notification of cyber incidents through the DoD’s reporting portal within 72 hours, and preserve evidence of the incident for potential government investigation. Additionally, DFARS 252.204-7012 requires contractors to flow down these obligations to subcontractors who handle CUI. This DFARS CUI clause is crucial for ensuring that safeguarding covered defense information is maintained across all levels of federal contractors and subcontractors.

This clause is a cornerstone of DoD cybersecurity policy, serving as the legal and contractual foundation for the CMMC program, which builds on these requirements by adding third-party verification. For organizations seeking to meet these standards, DFARS compliance tools can be invaluable in navigating the complexities of the DFARS clause 252.204 and ensuring adherence to all cybersecurity mandates.

🍪 We Use Cookies

To enhance your experience and analyze site usage, we use cookies. By continuing to use our site, you agree to our use of cookies in accordance with our Privacy Policy.