Under DFARS 252.204-7012, contractors working with the Department of Defense are required to report cyber incidents within 72 hours of discovery. But understanding the process—and the options—can be overwhelming.
We’ve created a simple infographic to help you quickly understand:
✅ The preferred method for secure reporting using a DoD-Approved Certificate
⚠️ Alternative options like One-Time Tokens and DoD SAFE
⏱️ Key timing requirements for reporting, support, and evidence retention
Use this visual guide to stay compliant, respond confidently, and protect your contracts.
📌 Bookmark this page or download the infographic as a quick reference for your compliance team.

FAQ’s
1. What requirement does DFARS 252.204-7012 place on DoD contractors regarding cyber incident reporting?
Under DFARS 252.204-7012, Department of Defense contractors must report cyber incidents involving covered defense information within 72 hours of discovery.
2. What reporting methods are highlighted in the guide?
The guide explains the preferred method of secure reporting using a DoD-approved certificate and mentions alternatives such as one-time tokens and DoD SAFE.
3. What key information does the infographic help contractors understand?
The infographic helps contractors quickly understand reporting methods, timeline requirements for reporting and evidence retention, and how to stay compliant.