People search for CMMC incident reporting 72 hours and expect to find a CMMC rule. There is not one. The 72-hour clock comes from a contract clause, DFARS 252.204-7012, and it has been running since before CMMC existed. When you discover a cyber incident on a system that handles covered defense information, you have 72 hours from discovery to report it to the Department of Defense at dibnet.dod.mil. You need a DoD-approved medium assurance certificate to file, you must keep images of the affected systems for at least 90 days, and any malicious software you isolate goes to the DoD Cyber Crime Center (DC3).

CMMC's part is different. CMMC Level 2 checks whether you have the internal capability to notice, handle and report an incident at all, through NIST SP 800-171 requirements 3.6.1 to 3.6.3. This post covers only the reporting paragraphs and those three requirements. For the safeguarding side, the cloud rule and flowdown, read our DFARS 252.204-7012 explainer.

The short version. The definitions in DFARS 252.204-7012 say "rapidly report" means within 72 hours of discovery of any cyber incident. The clock starts when you discover it, not when you finish investigating it. You report what you know and follow up with what you learn.

CMMC incident reporting 72 hours: where the clock actually comes from

Paragraph (c)(1) of the clause is triggered when you discover a cyber incident that affects a covered contractor information system, the covered defense information on it, or your ability to perform operationally critical support named in the contract. Two duties follow at once: review for evidence of compromise (which computers, servers, data and accounts, and what else on the network was reached), and rapidly report to DoD at dibnet.dod.mil. The definitions fix rapidly at 72 hours from discovery. Not from confirmation, and not from the end of the review.

A report is not an admission. The DFARS policy text at 204.7302(d) says a cyber incident reported by a contractor shall not, by itself, be interpreted as evidence that the contractor failed to provide adequate security or otherwise failed to meet the clause, and the contracting officer must consult the DoD component's CIO office before assessing compliance. Silence is what gets read badly, not the report.

CMMC's role is narrower. Under 32 CFR 170.14(c)(3) the Level 2 requirements are identical to NIST SP 800-171 Revision 2, and requirement 3.6.2 asks you to report incidents to designated authorities external to the organization. DoD through DIBNet is that authority. CMMC adds no second clock; it checks whether you could meet the one you have.

What counts as a cyber incident

The clause defines a cyber incident as actions taken through the use of computer networks that result in a compromise or an actual or potentially adverse effect on an information system and/or the information residing therein. Compromise covers disclosure to unauthorized persons, or a violation of a system's security policy in which unauthorized disclosure, modification, destruction, loss, or copying to unauthorized media may have occurred.

Read "potentially" and "may have occurred" twice. The clause does not require proof that CUI left the building, only that harm to a covered system or its data is possible.

What happenedAgainst the definitionWhy
Ransomware encrypts a workstation that holds customer drawingsMeets itNetwork action, adverse effect on a covered system, copying may have occurred
A phishing login takes over a mailbox that holds a prime's RFQ packagesMeets itUnauthorized access to a system storing CDI; disclosure may have occurred
An attacker reaches the office network and you cannot yet tell whether the CUI share was touchedMeets itA potentially adverse effect is enough; the clock is already running
A phishing email arrives, nobody clicks, the filter catches itNot by itselfNo compromise, no adverse effect. DC3 takes voluntary reports of phishing if you want to share them

Reporting costs you a form. Not reporting a qualifying incident is a contract failure that 204.7302(d) does not protect. If you are unsure whether a machine is in scope, report and document your reasoning.

What goes in the DIBNet report, and the certificate you need to file it

The clause says the report must include, at a minimum, the required elements at dibnet.dod.mil. That address lands on the DC3 DCISE page, the single focal point for the reporting 7012 requires, and the report is filed through the Incident Collection Format (ICF) portal linked there. The page asks for as much of the following as can be obtained within 72 hours, with a follow-on ICF for anything learned later:

The first three bullets never change, and they matter: under DFARS PGI 204.7303-3, DC3 sends your report by encrypted email to the contracting officers you named on the ICF. Keep the static fields on one page with the incident response plan, so the 72 hours go to the narrative.

Then the gate. Paragraph (c)(3) requires a DoD-approved medium assurance certificate and points to the External Certification Authority (ECA) program. DC3's page names the approved vendors, IdenTrust and WidePoint. It is bought from a vendor, not issued by DoD on the day of the incident. DC3 publishes a hotline (410-981-0104) and an address ([email protected]) for contractors who must report without one. Do not plan to be that contractor.

The certificate is the step small shops skip. Everything else in the clause can be done under pressure. Buying, installing and testing a certificate cannot. Get it now.

Preserve for 90 days, and send malware to DC3, not your contracting officer

Paragraph (e) is the one that catches people three months later. From the day you submit the report, you must preserve and protect images of all known affected systems and all relevant monitoring and packet capture data for at least 90 days, so DoD can request the media or decline interest. In a small shop that means: do not wipe and reimage the infected laptop to get it back into service. Image it first, store the image where the attacker cannot reach it, and keep the firewall, endpoint and mail logs from that window before retention rolls them off. Paragraphs (f) and (g) sit behind this one: on request you give DoD access to information or equipment for forensic analysis, and if DoD runs a damage assessment, the contracting officer asks for what you gathered. A media request comes in writing with submission instructions, and DC3 confirms receipt in writing (PGI 204.7303-4).

Malicious software takes a separate path under paragraph (d): submit it to DC3 following DC3's instructions, never to the contracting officer, who the PGI says should never receive it directly. DC3's page describes an Electronic Malware Submission portal for certificate holders and a one-time upload link you can request by email with your ICF number in the subject line. It says twice not to email the files.

Subcontractors report to DoD, then tell the prime

A subcontractor does not report through the prime. Under paragraph (m)(2)(ii) and DFARS 204.7302(b), subcontractors report directly to DoD and then give the incident report number DoD assigns to the prime, or the next higher tier, as soon as practicable. The prime gets the number, not necessarily the narrative. A flowdown letter may add notification terms on top, so read it. More in what subcontractors actually owe.

The capability side: 3.6.1 to 3.6.3

This is the part CMMC scores. The Incident Response family in NIST SP 800-171 Revision 2 has three requirements, and under 32 CFR 170.24 two of them carry five points, the highest value in the scoring table.

RequirementPointsWhat 800-171A checksSmallest thing that satisfies it
3.6.1 Establish an operational incident-handling capability5Seven objectives: a capability exists and includes preparation, detection, analysis, containment, recovery and user responseA short written plan naming who decides, files, preserves and calls the prime; users told how to report; alerts or logs
3.6.2 Track, document and report incidents5Six objectives: incidents tracked and documented, external authorities and internal officials identified, both notifiedAn incident log, with DoD and the prime named as the authorities and the owner as the internal official
3.6.3 Test the incident response capability1One objective: the capability is testedA dated tabletop walk-through with notes on what broke

The objectives come from the June 2018 edition of NIST SP 800-171A, which CMMC still scores against, and every one must be satisfied with evidence in final form for the requirement to count, the all-or-nothing rule from our post on assessment objectives. Objective 3.6.2[c] asks whether the authorities you report to are identified. A plan that says report to DoD at DIBNet within 72 hours, then give the prime the report number, satisfies it in one sentence. A plan that says notify management does not. Ten points ride on 3.6.1 and 3.6.2, and the free SPRS calculator shows what they do to a score.

What to do this week

  1. Name two people. One who decides an event is a cyber incident under the clause definition, one who files, plus a backup.
  2. Buy the certificate. From IdenTrust or WidePoint, installed on the filer's machine and tested against the portal.
  3. Fill in the static half of the ICF now. UEI, CAGE code, facility clearance, every active contract number carrying 7012, contracting officer and program manager contacts. One page.
  4. Decide how you would image a machine, where the image goes, and who confirms your firewall, endpoint and mail logs will still exist 90 days later.
  5. Start the incident log and run a 30-minute tabletop. Ransomware on the CAM workstation at 4 PM on a Friday. Walk the plan, write down what broke, sign and date it. That is 3.6.2[a], 3.6.2[b] and 3.6.3 with dates on them.
  6. Tell your prime what they will get. The incident report number, not the forensic narrative, and know who at the prime receives it.

CMMC Map, CMMC compliance software for small defense contractors, walks the three incident response requirements objective by objective with the rest of the 110. The assessment and the live SPRS score are free forever. The generated policies, system security plan, plan of action and readiness report are the one paid plan at $149 a month.

This is explanatory content about a contract clause, not legal advice. Your contract and your prime's flowdown terms govern.

See whether 3.6.1 to 3.6.3 are covered before you need them

The CMMC Map assessment walks all 110 NIST SP 800-171 requirements, including the incident response family, and shows your live SPRS score. Free, no credit card.

Start free in CMMC Map
Free to assess · Documents $149/mo · No credit card