DFARS 252.204-7012 is the clause that started all of this. Long before CMMC existed, and all through the 2026 suspension of CMMC Phase 2, this one paragraph in your contract has required you to protect Department of Defense information on your systems and to report it when something goes wrong. If you handle Controlled Unclassified Information (CUI) for a DoD prime, 7012 applies to you today, whether or not a CMMC level ever appears in your solicitation.
This post explains what the clause actually says, in the order a small contractor runs into it: who it covers, what "adequate security" means, the 72-hour reporting rule, the cloud rule, and how it flows down through primes to subs. It is explanatory content, not legal advice. When your contract and this post disagree, your contract wins.
What DFARS 252.204-7012 is
The full name is Safeguarding Covered Defense Information and Cyber Incident Reporting. It is a Defense Federal Acquisition Regulation Supplement (DFARS) clause, which means the contracting officer inserts it into DoD contracts and it becomes a term you agreed to when you signed. It has been in its current form since the end of 2017. The current text is on acquisition.gov.
Three other clauses are easy to confuse with it, and the difference matters:
| Clause | What it does | Status in 2026 |
|---|---|---|
| 252.204-7012 | Requires you to implement NIST SP 800-171 and report cyber incidents | Unchanged. In nearly every non-commercial DoD contract. |
| 252.204-7019 / 7020 | Added the scored self-assessment posted in SPRS and DoD's right to assess you | How and when they are used in solicitations has shifted several times this year. See our SPRS obligations post. |
| 252.204-7021 | Carries the CMMC level requirement (Level 1, Level 2, Level 3) | Only self-assessed levels may be required while Phase 2 is suspended. |
Put simply: 7012 is the requirement to protect the information. SPRS and CMMC are two different ways DoD checks whether you did. The checks were paused and rewritten in 2026. The requirement was not.
Who it applies to
The clause applies to any contractor whose unclassified information system handles covered defense information (CDI). The clause defines CDI as unclassified controlled technical information, or other information listed in the CUI Registry, that is either marked and provided to you by DoD, or that you create, collect or receive while performing the contract. In practice, "CDI" and "CUI" mean the same thing for a defense contractor.
Two exceptions. The clause is not used in contracts solely for commercially available off-the-shelf (COTS) items. And if your contract involves only Federal Contract Information (FCI) and no CUI, the safeguarding requirement you face is the lighter FAR 52.204-21 set, which is what CMMC Level 1 covers. Not sure which one you have? Start with Do you actually handle CUI?
One point people miss: the clause covers the system, not just the file. If a CUI drawing lands in your company email, the email system is a covered contractor information system. If it gets copied to a laptop, the laptop is in scope. This is why scoping matters so much.
Requirement 1: adequate security means NIST SP 800-171
Paragraph (b) of the clause requires "adequate security" on every covered system, and it defines the minimum: the security requirements in NIST Special Publication 800-171, all 110 of them. The clause points to the version "in effect at the time the solicitation is issued," and DoD issued a class deviation in May 2024 that holds the requirement at Revision 2. Revision 3 exists, but it is not what your contract requires yet. Here is the Rev 2 versus Rev 3 breakdown.
Two details in the same paragraph are worth knowing:
- Variances go through the DoD CIO. If you believe a requirement does not apply to you, or you have an alternative but equally effective measure, the clause says you must ask the DoD Chief Information Officer in writing, through your contracting officer. You do not get to decide it yourself, and neither does your prime.
- The System Security Plan and POA&M are how you show it. Requirement 3.12.4 of 800-171 asks for an SSP that describes how each requirement is met, and 3.12.2 asks for a plan of action for anything not yet done. When a prime or DoD asks whether you comply with 7012, these two documents are the answer.
Requirement 2: the cloud rule
Paragraph (b)(2)(ii)(D) is the part that catches small shops. If you use an outside cloud service to store, process or transmit CDI (email, file sharing, a CAD vault, a backup service), the clause requires that the cloud provider meet security requirements "equivalent to" the FedRAMP Moderate baseline, and that it can support the incident reporting, preservation and access obligations described below.
DoD published a memo in December 2023 spelling out what "equivalent" means: the provider must have a Moderate-baseline body of evidence assessed by a FedRAMP-recognized third party, and you are responsible for confirming it. This is the real reason the GCC High versus commercial Microsoft 365 question comes up, and why a random consumer file-sharing plan is a problem the moment a CUI drawing is uploaded to it. The rule does not say "use a government cloud." It says the cloud holding CUI must be able to prove a specific level of security and support DoD's incident process.
Requirement 3: report cyber incidents within 72 hours
Paragraph (c) is the one most owners have never read. When you discover a cyber incident that affects a covered system, the CDI on it, or your ability to provide operationally critical support, you must:
- Review your systems for evidence of compromise and identify which computers, servers, accounts and data were affected.
- Rapidly report to DoD at dibnet.dod.mil. The clause defines "rapidly" as within 72 hours of discovery. Reporting requires a DoD-approved medium assurance certificate, which takes days to obtain, so get it before you need it.
- Send any malicious software you find to the DoD Cyber Crime Center (DC3), not to the contracting officer.
- Preserve images of all known affected systems and all relevant monitoring and packet capture data for at least 90 days from the date you submit the report, in case DoD asks for them.
- Give DoD access to additional information or equipment if requested for a damage assessment.
The clause's definition of a cyber incident is broad: actions taken through computer networks that result in a compromise, or an actual or potentially adverse effect, on a system or the information on it. A ransomware event on a machine that touches CUI counts. So does a phishing account takeover of a mailbox that holds a prime's drawings. "We are not sure anything was taken" is exactly the situation the 72-hour clock was written for. You report what you know and update it later.
Note what the clause does not say. It does not say a report proves you failed 800-171. Paragraph (c)(2) actually says DoD will not interpret a report by itself as evidence that you failed to provide adequate security. What does get contractors in trouble is not reporting.
Requirement 4: flow it down
Paragraph (m) requires the prime to include the full clause, unchanged, in every subcontract where the work involves CDI or operationally critical support. Subcontractors must then flow it down to their own subs. Two extra duties come with it: a sub must tell the next tier up when it asks DoD CIO for a variance, and when a sub reports a cyber incident to DoD, it must pass the DoD-assigned incident report number up to the prime as soon as practicable.
This is why a two-person engineering firm three tiers below a prime can find 7012 in its purchase order. The prime did not add it to be difficult. The prime is required to. More on what subs actually owe.
What 7012 does not require
- It does not require a certification. No third party signs anything under 7012. Certification is CMMC's job, under a different clause.
- It does not require a particular product, cloud, or consultant. It requires outcomes, described in 800-171.
- It does not require perfection on day one. Requirements you have not met belong on a POA&M with dates. What it does not tolerate is silence: no SSP, no POA&M, no report.
Why this matters in 2026. When people ask whether CMMC is cancelled, the honest answer is that the third-party assessment schedule is suspended and self-assessed levels remain. But the question they should ask is whether 7012 is still in their contract. It is. Every prime that checks your SPRS score, every questionnaire asking for your SSP, is a prime trying to confirm you meet a clause you already signed.
What to do this week
- Find the clause. Search your active contracts and purchase orders for "252.204-7012". If it is there, everything above applies.
- Decide where CUI lives. Email, file server, laptops, a cloud drive, a CAD system. Write the list down. That list is your scope.
- Check the cloud rule. For every cloud service on that list, confirm in writing that it meets the FedRAMP Moderate baseline or equivalent. If a service cannot say, CUI should not be in it.
- Get the medium assurance certificate now. You cannot file a DIBNet report without one, and 72 hours is not enough time to obtain it during an incident.
- Run the 110-requirement self-assessment. The output is your SSP, your POA&M and your SPRS score, which is the paperwork 7012 expects you to have. CMMC Map, CMMC compliance software built for small contractors, does this for free and explains each requirement in plain English.
- Write down who reports. One page: who decides it is an incident, who files at DIBNet, who preserves the images, who tells the prime. Tape it inside the server closet.
See where you stand on the 110 requirements 7012 points to
CMMC Map walks you through NIST SP 800-171 in plain English and shows your SPRS score as you go. The assessment is free, no credit card, and the gap list tells you what 7012 would ask you to fix first.
Start free in CMMC Map