Skip to main content
Greypike's CMMC Knowledge Base

Welcome to the CMMC Knowledgebase. Search for CMMC, resources, tools, sources, sites, and platforms using the search box below.
We add more to the database weekly, check back often.

If you cannot find an answer then contact us or click the chat button on the lower right..

< All Topics
Print

What DFARS 252.204-7012 Requires, in Plain English

DFARS 252.204-7012 is the clause that turns a defense contract into a cybersecurity obligation. It has been in contracts since 2016, it survived the CMMC Phase 2 suspension untouched, and it is the single clause most likely to be why someone sent you here. For how it fits alongside the other four, start with DFARS and FAR Cybersecurity Clauses: What Each One Actually Requires.

The clause is often called “the NIST 800-171 clause,” which undersells it. Implementing 800-171 is one of four separate obligations, and the other three are where contractors get caught.

Obligation 1: adequate security

The clause requires “adequate security” on any covered contractor information system — meaning any system that processes, stores, or transmits covered defense information. For most contractors, adequate security means implementing all 110 requirements of NIST SP 800-171.

Two things people misread.

You do not have to be finished to be compliant. The clause contemplates gaps. Where a requirement isn’t implemented, document it in a System Security Plan and track remediation in a Plan of Action and Milestones. What is not acceptable is a POA&M with no dates, no owner, and no movement between years — that reads as a decision not to comply rather than a plan to.

110 requirements is not 110 tasks. The DoD Assessment Methodology breaks those into 320 assessment objectives. A requirement counts as implemented only when every objective under it is met. Contractors who self-score at the requirement level rather than the objective level consistently overstate their position — and that gap is exactly what a DIBCAC assessment surfaces.

Obligation 2: report incidents within 72 hours

This is the requirement most contractors are least ready for, and it has the tightest clock.

When you discover a cyber incident affecting a covered contractor information system or the covered defense information on it, you report to DoD through DIBNet within 72 hours of discovery. Not 72 hours from confirming scope. Not 72 hours from deciding it’s material. Discovery.

The operational trap: submitting a report requires a DoD-approved medium assurance certificate, which you must obtain in advance. Acquiring one takes time and paperwork. If your first attempt happens during an active incident, you will miss the window — and a late report becomes a documented compliance failure attached to an event you were already having a bad day about.

If you take one thing from this article: check today whether anyone at your company holds a current medium assurance certificate. If nobody does, that’s a fifteen-minute discovery that prevents a very expensive one later. An incident is also one of the clearest trigger events in the whole compliance calendar — the readiness has to exist before it happens.

Obligation 3: preserve media and submit malicious software

Preserve and protect images of all known affected systems, plus relevant monitoring and packet capture data, for at least 90 days from the incident report, so DoD can request them.

Submit malicious software to the DoD Cyber Crime Center if you discover and isolate any in connection with a reported incident. Note the routing — DC3, not your contracting officer.

Ninety days of forensic images is a real storage and process requirement. It is also a question you will be asked in an assessment, and “we’d figure it out” is not an answer.

Obligation 4: cloud services

If an external cloud service provider stores, processes, or transmits covered defense information on your behalf, that provider must meet the FedRAMP Moderate baseline or equivalent, and must comply with the incident reporting, media preservation, and malicious software terms.

This is where the government-cloud question actually originates. DoD does not mandate GCC High by name — it’s that commercial Microsoft 365 does not meet FedRAMP Moderate equivalency for CUI in the way GCC High and Google Assured Workloads do. If your CUI lives in commercial email, this obligation is why that’s a problem.

It’s also where contractors over-buy. The requirement attaches to systems handling covered defense information. Scope properly, put CUI in one enclave, and the rest of the business does not need to move. Choosing that provider is its own decision — see vendor and partner selection.

Flowdown

You must include the substance of this clause in subcontracts where the subcontractor’s performance involves covered defense information. Read that condition carefully — the clause flows down based on data, not on whether someone is a subcontractor.

You’re also expected to determine, in consultation with your contracting officer, whether the information a supplier will handle is actually covered defense information. Flowdown: which clauses you must pass to your subcontractors has a decision tree for running that determination without papering every vendor you have.

What the CMMC suspension changed about DFARS 252.204-7012

Nothing.

The July 13, 2026 suspension paused CMMC Phase 2 — the mandatory third-party certification assessments scheduled to begin November 10, 2026. DoD stated explicitly that contractors remain contractually obligated to safeguard covered defense information under this clause.

Everything above still applies: 800-171 implementation, 72-hour reporting, media preservation, cloud requirements, flowdown. The government also retains assessment authority — see DFARS 252.204-7019 vs 7020 vs 7021 for what each of those clauses still triggers.

The risk that grew rather than shrank is False Claims Act exposure. When a contractor certifies compliance as a condition of award or payment and that certification is false, that is a False Claims Act theory, and the Civil Cyber-Fraud Initiative exists to pursue exactly it. A suspended assessment program does not make an overstated SPRS score safer — it removes the deadline that would have surfaced it.

If it’s already in a contract you signed

Common, and fixable, but the sequence matters — establish your own position before you call your contracting officer. See a clause in a contract you already signed.

And if your working assumption is that this doesn’t apply because of what you make or how small you are, test that honestly against who is exempt from CMMC and DFARS cybersecurity clauses. Most of the common arguments don’t hold, and the ones that do are narrower than people expect.

The five questions to answer this week

  1. Does 7012 appear in our contracts, and which ones?
  2. Do we know which systems touch covered defense information, and can we draw that boundary on one page?
  3. Does anyone here hold a current medium assurance certificate for DIBNet reporting?
  4. Is our SPRS score calculated at the objective level, or did we score at the requirement level?
  5. Which suppliers touch this data, and what did we actually flow down?

Most contractors answer one or two confidently. The gap between what you can answer and what you can’t is a fair description of your exposure.

Common questions about DFARS 252.204-7012

What does DFARS 252.204-7012 require?

Four things: implement NIST SP 800-171 as adequate security on systems handling covered defense information; report cyber incidents to DoD through DIBNet within 72 hours of discovery; preserve affected system images for 90 days and submit any isolated malicious software to DC3; and ensure cloud providers handling that data meet FedRAMP Moderate or equivalent. The clause also flows down to subcontractors whose work involves the covered information.

How long do I have to report a cyber incident under DFARS 252.204-7012?

72 hours from discovery. Reporting requires a DoD-approved medium assurance certificate obtained in advance — obtaining one during an active incident will not meet the deadline.

Does DFARS 252.204-7012 require GCC High?

Not by name. The clause requires that any cloud service provider handling covered defense information meet the FedRAMP Moderate baseline or equivalent. Commercial Microsoft 365 does not meet that equivalency for CUI; GCC High and Google Assured Workloads do. If your CUI is scoped into a single enclave, the rest of your environment does not need to move.

Is DFARS 252.204-7012 still in effect after the CMMC suspension?

Yes, entirely. The July 2026 suspension paused CMMC Phase 2 third-party certification assessments. DoD stated explicitly that contractors remain contractually obligated to safeguard covered defense information under 252.204-7012. Every obligation in the clause continues.

Can I be compliant with DFARS 252.204-7012 if I have not implemented all 110 controls?

Yes. The clause contemplates gaps. Unimplemented requirements belong in a System Security Plan with remediation tracked in a Plan of Action and Milestones. What does not hold up is a POA&M with no dates, no owner, and no progress between years.


Next step: If question four gave you pause, the SPRS Score Reality Check is a second look at the score you’re already relying on. Free, no email required.

Last reviewed: August 2026. Verify current requirements against official sources before acting.

Table of Contents