The Defense Federal Acquisition Regulation Supplement (DFARS) clause titled “Safeguarding Covered Defense Information and Cyber Incident Reporting.” It requires defense contractors and subcontractors to implement adequate security measures to protect Controlled Unclassified Information (CUI) in non-federal systems and to report cyber incidents to the Department of Defense (DoD).
Under this clause, contractors must comply with the 110 security requirements defined in NIST SP 800-171, provide rapid notification of cyber incidents through the DoD’s reporting portal within 72 hours, and preserve evidence of the incident for potential government investigation. Additionally, DFARS 252.204-7012 requires contractors to flow down these obligations to subcontractors who handle CUI.
This clause is a cornerstone of DoD cybersecurity policy, serving as the legal and contractual foundation for the CMMC program, which builds on these requirements by adding third-party verification.