Under DFARS 252.204-7012, a defense contractor must provide adequate security for covered defense information on its information systems and report cyber incidents to DoD within 72 hours of discovery. The June 2026 edition, issued under Class Deviation 2026-O0025, sets NIST SP 800-171 Revision 2 as the minimum. The contractor must also submit isolated malicious software to the DoD Cyber Crime Center (DC3), preserve affected-system images for at least 90 days after reporting, and flow the clause down to subcontracts involving covered defense information. Contracting officers insert it in DoD solicitations and contracts, commercial ones included, except those solely for commercially available off-the-shelf (COTS) items, and no size or dollar threshold applies. DFARS 7012 predates CMMC, and CMMC does not replace it: as of September 2026, with CMMC Phase 2 suspended and designations limited to Level 1 (Self) or Level 2 (Self), 7012 remains in effect.
If a defense contract involves covered defense information, DFARS 252.204-7012 sets the baseline cybersecurity and incident-reporting terms for the contractor’s systems. Its clause number dates to November 2013, and even then it required cyber incident reports within 72 hours of discovery. An August 2015 interim rule brought the current title, the covered defense information scope and the NIST SP 800-171 requirement. A December 2015 interim rule set December 31, 2017 as the deadline to implement NIST SP 800-171. The final rule followed in October 2016.
This guide reads the clause paragraph by paragraph and shows which contracts must include it. It also walks through a 72-hour incident report on the current reporting route and dates what changed in 2026. It’s part of the contract obligations hub, which covers owning a requirement after award.
As of September 2026: On July 13, 2026, the Department of War (DoW) suspended the move to CMMC Phase 2. During the review, contracts may designate only CMMC Level 1 (Self) or Level 2 (Self). Both July memos state that the DFARS 252.204-7012 requirements remain in effect. For what to check in a specific solicitation, see what to check during the CMMC pause.
What DFARS 252.204-7012 Requires
DFARS 252.204-7012 is formally titled “Safeguarding Covered Defense Information and Cyber Incident Reporting.” It places two core obligations on a contractor whose systems handle covered defense information. First comes adequate security, with NIST SP 800-171 as the minimum. Second is rapid reporting of cyber incidents. In the clause, that means reporting “within 72 hours of discovery.” Other paragraphs cover malicious software, media preservation, forensic access, damage assessment and subcontract flowdown. The table after the two obligations summarizes every paragraph.
Obligation 1: Implement NIST SP 800-171 Revision 2
Paragraph (b) requires the contractor to “provide adequate security on all covered contractor information systems.” That means implementing, “at a minimum,” the protections that follow.
- Systems operated on behalf of the Government, (b)(1). Cloud computing services follow clause 252.239-7010, and other IT operated for the Government follows the contract’s own security terms.
- Contractor systems, (b)(2). These must meet NIST SP 800-171, which the clause required “as soon as practical, but not later than December 31, 2017.” The June 2026 deviation text names Revision 2 of the standard.
- Other measures, (b)(3). The contractor applies additional security measures when it “reasonably determines” they may be needed to provide adequate security “in a dynamic environment.” The clause adds that these measures “may be addressed in a system security plan.”
A contractor that wants to vary from a NIST SP 800-171 requirement sends a written request to the Contracting Officer. Consideration falls to the DoD CIO. If an authorized representative of the DoD CIO has adjudicated a requirement as nonapplicable, the contractor doesn’t have to implement it. The same applies where that representative has adjudicated an “alternative, but equally effective, security measure” to take its place. When a prior adjudication exists, a copy “shall be provided” to the Contracting Officer. Before award, the 252.204-7008 provision has the DoD CIO adjudicate variance requests in writing.
External cloud services carry their own condition in (b)(2)(ii)(D). The cloud service provider must meet security requirements equivalent to the FedRAMP Moderate baseline. It must also comply with paragraphs (c) through (g) in the table below. What counts as “equivalent”? A DoD CIO memo dated December 21, 2023 sets the test: 100 percent compliance with the latest FedRAMP Moderate baseline, assessed by a FedRAMP-recognized Third Party Assessment Organization (3PAO). That memo does not apply to cloud service offerings that are already FedRAMP Moderate Authorized. For how this affects a Microsoft 365 decision, see GCC High versus commercial Microsoft 365.
Obligation 2: Report Cyber Incidents Within 72 Hours
Paragraph (c) applies when a contractor discovers a cyber incident that affects a covered contractor information system or the covered defense information on it. It also applies when an incident affects the contractor’s ability to perform requirements “designated as operationally critical support and identified in the contract.” Either way, the contractor must review for evidence of compromise of covered defense information and rapidly report the incident to DoD. In the clause, “rapidly report” means “within 72 hours of discovery of any cyber incident.”
A cyber incident, in the clause’s definition, includes an “actual or potentially adverse effect” on a system or its information. So the clock starts at discovery. Confirmation and the full picture can follow in a later report.
Each report must include, “at a minimum, the required elements” published at the DoD reporting site. DC3’s Incident Collection Format (ICF) lists them:
- Company and contract identifiers: company name, Unique Entity Identifier (UEI), facility CAGE code, facility clearance level, contract number (PIID), contract numbers affected and contract clearance level.
- Points of contact for the company, the U.S. Government program manager and the contracting officer.
- Discovery and location: date discovered, locations of compromise, the incident location’s CAGE code, and the DoW programs, platforms or systems involved.
- Method and outcome: type of compromise, technique or method used, and outcome (successful compromise, failed attempt or unknown).
- Impact and narrative: the impact to covered defense information, the effect on the ability to provide operationally critical support, an incident narrative and any additional information.
Two related duties run alongside the report. Isolated malicious software goes to DC3, and paragraph (d) says “Do not send the malicious software to the Contracting Officer.” Preservation comes under paragraph (e). Contractors must preserve images of all known affected systems, along with relevant monitoring and packet capture data. The hold lasts “at least 90 days from the submission of the cyber incident report.” The reporting section below walks through each step on the current route.
Both obligations reach the supply chain through paragraph (m). Contractors must include the clause in subcontracts for operationally critical support and in subcontracts whose performance will involve covered defense information. Flowdown is “without alteration, except to identify the parties.” A prime determines whether information it passes down keeps its identity as covered defense information. If necessary, it consults the Contracting Officer. Subcontractors report incidents directly to DoD and give the incident report number to the prime or next higher-tier subcontractor. CMMC for subcontractors covers the subcontractor side.
DFARS 252.204-7012 Paragraph by Paragraph, (a) to (m)
Both the codified May 2024 text and the June 2026 deviation text use the same paragraphs, (a) through (m). This table summarizes each one.
| Paragraph | What it says | What the contractor does | What to keep on file |
|---|---|---|---|
| (a) Definitions | Defines 14 terms, including adequate security, covered defense information, covered contractor information system, controlled technical information, cyber incident, operationally critical support and “rapidly report” (within 72 hours of discovery) | Reads the contract’s markings and its own systems against these definitions | A list of the information and systems in scope |
| (b)(1) Government-operated IT | Cloud services operated for the Government follow 252.239-7010. Other IT operated for the Government follows the contract’s own security terms | Identifies any system it operates on the Government’s behalf | The contract terms that govern those systems |
| (b)(2) Contractor systems | NIST SP 800-171 at a minimum (Revision 2 in the June 2026 text). Variances go in writing to the Contracting Officer for the DoD CIO. External cloud must meet FedRAMP Moderate or equivalent | Implements the requirements, requests variances in writing and vets cloud providers | Assessment results, variance decisions and cloud provider evidence |
| (b)(3) Other measures | Additional measures where the contractor “reasonably determines” they may be needed | Adds measures for specific risks | The system security plan, where these measures may be addressed |
| (c) Cyber incident reporting | Review for evidence of compromise and report within 72 hours of discovery with the required elements, using a DoD-approved medium assurance certificate | Files the ICF with DC3 | The ICF, the incident report number and any follow-on ICF |
| (d) Malicious software | Isolated malware goes to DC3 and never to the Contracting Officer | Submits it by DC3’s instructions | A record of what was submitted and when |
| (e) Media preservation | Images of known affected systems and relevant monitoring and packet capture data, kept at least 90 days from report submission | Preserves before cleanup | The preserved images and captures |
| (f) Forensic access | On DoD request, access to additional information or equipment needed for forensic analysis | Responds to the request | The request and the response |
| (g) Damage assessment | If DoD elects a damage assessment, the Contracting Officer requests the information gathered under (e) | Provides it on request | The request and what was provided |
| (h) to (j) Contractor information | The Government protects attributional or proprietary information the contractor provides, and the contractor identifies and marks it “to the maximum extent practicable” (h). The clause also authorizes release outside DoD for listed purposes, such as cyber incident mitigation, counterintelligence or law enforcement investigations and national security (i). Information created by or for DoD, including the incident report, may also be used and released for any other lawful Government purpose, subject to legal restrictions (j) | Marks attributional and proprietary information before submitting it | Marked copies of what was provided |
| (k) Lawful monitoring | Activities under the clause must follow applicable laws and regulations on the “interception, monitoring, access, use, and disclosure of electronic communications and data” | Checks that monitoring, capture and forensic support meet those laws | The legal review or policy that covers monitoring and data handling |
| (l) Other duties | The clause “in no way abrogates” other safeguarding or incident-reporting responsibilities | Meets other reporting duties as well | A list of other reporting obligations that apply |
| (m) Subcontracts | Flowdown without alteration for operationally critical support or covered defense information, commercial subcontracts included. Subcontractors notify the prime or next higher-tier subcontractor of variance requests and pass up the incident report number | Includes the clause and decides whether shared information keeps its CDI identity | Subcontract clause lists and report numbers received |
What Covered Defense Information Means
Covered defense information (CDI) is the information DFARS 252.204-7012 protects. The clause defines it as “unclassified controlled technical information or other information, as described in the Controlled Unclassified Information (CUI) Registry,” that requires safeguarding or dissemination controls and is either:
- marked or otherwise identified in the contract, task order or delivery order and provided to the contractor by or on behalf of DoD in support of performance, or
- collected, developed, received, transmitted, used or stored by or on behalf of the contractor in support of performance.
CDI is therefore a contract-linked subset of CUI.
Controlled technical information is “technical information with military or space application” that is subject to controls on access, use, release or dissemination. It covers information that “would meet the criteria, if disseminated, for distribution statements B through F.” In the National Archives (NARA) CUI Registry, Controlled Technical Information sits under the Defense grouping. For how controlled drawings and specifications reach a contractor, see receiving controlled technical data.
Four more definitions set the clause’s reach.
| Term | Definition in the clause | What it decides |
|---|---|---|
| Covered contractor information system | ”an unclassified information system that is owned, or operated by or for, a contractor and that processes, stores, or transmits covered defense information” | Which systems must meet paragraph (b) |
| Adequate security | ”protective measures that are commensurate with the consequences and probability of loss, misuse, or unauthorized access to, or modification of information” | The standard of protection, with NIST SP 800-171 as its floor |
| Cyber incident | ”actions taken through the use of computer networks that result in a compromise or an actual or potentially adverse effect on an information system and/or the information residing therein” | What starts the 72-hour clock |
| Operationally critical support | Supplies or services the Government designates as critical for airlift, sealift, intermodal transportation or logistical support essential to mobilizing, deploying or sustaining the Armed Forces in a contingency operation | When incidents that affect contract performance must be reported |
Adequate security is a proportional standard. Under the clause, NIST SP 800-171 is the minimum for contractor systems. Paragraph (b)(3) adds other measures when the contractor reasonably determines they’re needed. Federal CUI rules point the same way. 32 CFR 2002.14(h)(2) says agencies “must use NIST SP 800-171” for CUI on non-Federal systems. Deviated DFARS 240.370-3(a)(1) requires adequate security “in accordance with 32 CFR 2002 and the clause at 252.204-7012.”
Markings are the starting point for scope. Under PGI 240.370-4, the requiring activity notifies the contracting officer when a contract will involve covered defense information or operationally critical support. From there, the solicitation and contract should require the contractor to mark covered defense information when appropriate. Information the contractor develops or receives in performance can also be CDI without a marking in the contract. So scope still depends on where the information goes. Scoping which systems handle CUI covers how to draw that boundary.
Is DFARS 252.204-7012 in Every DoD Contract?
The clause is prescribed for all of them, with one exception. Contracting officers insert DFARS 252.204-7012 in DoD solicitations and contracts, including those for commercial products and commercial services under FAR Part 12. That exception is a solicitation or contract solely for the acquisition of commercially available off-the-shelf (COTS) items. No size or dollar threshold appears in the prescription. CMMC is narrower on that point: 32 CFR 170.3(c) covers contracts “valued at greater than the micro-purchase threshold.”
In 2026, the prescription moved. Its codified text still sits in DFARS 204.7304, but the deviations in use as of September 2026 place it elsewhere.
| Item | Codified DFARS | Class deviations in use as of September 2026 |
|---|---|---|
| Prescription | 204.7304(c) | 240.370-5(c), Class Deviation 2026-O0025 Revision 3 |
| Scope | All solicitations and contracts, FAR Part 12 buys included, except those solely for COTS items | The same scope and the same COTS-only exception |
| Assessment clauses beside it | 252.204-7019 and 252.204-7020, with 252.204-7021 prescribed separately at 204.7504(a) | 252.240-7997, with 252.204-7021 prescribed separately at 240.371-5(a) |
Class Deviation 2026-O0043, effective February 17, 2026, reserves the codified subpart 204.73. Wherever the deviations are used, that displaces the 204.7304 prescription. On the same COTS-only terms, the 252.204-7008 provision is prescribed in solicitations. In it, the offeror represents that it will implement NIST SP 800-171.
Whether the clause is in a contract and whether its duties apply to a system are separate questions. A contract can include the clause before any covered defense information reaches the contractor. Safeguarding under paragraph (b) attaches to covered contractor information systems. Paragraph (c)‘s reporting duty attaches to incidents that affect those systems or their covered defense information. It also attaches to incidents that affect operationally critical support identified in the contract. Each contract that includes the clause calls for a check of which systems, if any, handle covered defense information.
What DFARS 252.204-7012 Means for a Small Defense Contractor
In plain English, the clause’s duties reach your company when a DoD contract or subcontract that includes it gives you controlled technical information or other covered defense information. They also apply when your work on the contract collects, develops, receives or stores that information. Your company must then protect the computers and cloud services that hold that information to at least NIST SP 800-171. It must also report cyber incidents affecting those systems to DoD within 72 hours of discovery and keep incident evidence for DoD. Subcontracts that involve the information must include the clause. There’s no small-business exemption, because the prescription sets no size or dollar threshold.
Three checks decide whether those duties reach a given system.
| Check | Where to look | If the answer is yes |
|---|---|---|
| 1. Is DFARS 252.204-7012 in the contract or subcontract? | The clause list, including the date after the clause title | The clause’s terms apply to the contract |
| 2. Does the work involve covered defense information? | Markings and identified information in the contract, drawings with distribution statements B through F, and information your team develops for the contract | That information is protected as CDI |
| 3. Does that information touch your systems or cloud services? | Email, file shares, laptops and the cloud services where files land | Those systems must meet NIST SP 800-171, and incidents affecting them are reportable within 72 hours |
When all three answers are yes, start with four actions.
- List where covered defense information lives, naming each system and cloud service that processes, stores or transmits it.
- Compare those systems with NIST SP 800-171 Revision 2. Record which of the 110 requirements are met, which need work and who owns each gap. Send any variance request in writing to the Contracting Officer.
- Set up incident reporting before an incident. Obtain a DoD-approved medium assurance certificate from an approved External Certification Authority (ECA) vendor (DC3 names IdenTrust and WidePoint), and decide who files the report.
- Check cloud providers and subcontracts. For each cloud service that holds covered defense information, confirm FedRAMP Moderate authorization or equivalency. Also confirm the clause appears in each subcontract that involves it.
No-cost help exists. A July 13, 2026 memo from the DoW CIO says existing DoW services “will continue to serve as no-cost resources.” It names DC3 services, NSA Cybersecurity Collaboration Center services and the Office of Small Business Programs’ Project Spectrum.
Keep on file what the last column of the paragraph table above lists, plus the clause list for each contract, with each clause’s date and any deviation number, and the certificate details, incident contacts and reporting steps.
How to Report a Cyber Incident Within 72 Hours
A contractor reports a DFARS 7012 cyber incident to the DoD Cyber Crime Center (DC3). DC3’s DCISE serves as the “single focal point and data repository” for the Defense Industrial Base (DIB) cyber incident reports the clause requires. The clause text still names dibnet.dod.mil. As of September 2026, that address redirects to DC3’s DCISE page. DC3 directs mandatory reports to its Incident Collection Format (ICF) portal at icf.dcise.cert.org “within 72 hours of discovery.” That portal requires a DoD-approved medium assurance certificate. A contractor without one can email DC3.DCISE@us.af.mil or call 410-981-0104 for reporting assistance.
Before an Incident: Certificate, Contacts and Preservation
- Certificate. Obtain the medium assurance certificate that paragraph (c)(3) requires from an approved ECA vendor, and decide who holds it.
- Contacts. The DCISE hotline, (410) 981-0104, operates 24/7. The toll-free number is 1-877-838-2174.
- Keep the identifiers the ICF asks for in one place: UEI, CAGE codes, contract numbers and the contracting officer’s contact details.
- Preservation plan. Decide how the team will capture images of affected systems and relevant monitoring and packet capture data, and where it will keep them for at least 90 days after the report.
Access needs its own check. 32 CFR 236.4(e), in the DIB cybersecurity program rule, says a contractor needs a PIEE account to access dibnet.dod.mil. DC3’s reporting page mentions only the medium assurance certificate. Confirm current access requirements with DC3 before an incident.
The First 72 Hours, Step by Step
Here’s a worked example. At 16:00 on a Friday, an administrator notices that an unfamiliar account has signed in to the file server that holds a customer’s controlled drawings. Discovery is 16:00 Friday, so the report is due by 16:00 Monday.
- Friday 16:00, hour 0: record the discovery time. The 72 hours run from discovery of the incident.
- From Friday 16:00: review for compromise. Paragraph (c)(1)(i) requires a review for evidence of compromise of covered defense information. The review starts at once and can continue after the report. The 72-hour deadline applies to the report.
- Preserve before cleanup. Capture images of the known affected systems and keep the relevant monitoring and packet capture data. The 90 days are counted from the report’s submission.
- By Monday 16:00: file the ICF. Sign in to the ICF portal with the certificate and report “as much of the following information as can be obtained within 72 hours.” Facts learned later go in a follow-on ICF.
- With or after the ICF, submit isolated malware to DC3. Upload malicious files through DC3’s EMS, or email DC3.DCISE@us.af.mil with the ICF number in the subject line to request a one-time upload link. DC3’s instruction is “DO NOT use email to submit malicious files.” Paragraph (d) adds that malware never goes to the Contracting Officer.
- Record the incident report number, which DoD assigns automatically. A subcontractor gives it to the prime or next higher-tier subcontractor “as soon as practicable.”
A mandatory report belongs to the affected company. If a vendor or customer says it suffered an attack, the mandatory ICF is theirs to file. DC3 answers that question directly: “No. DFARS 252.204-7012 requires the impacted company to submit a report on the specific cyber incident.”
After the Report: Follow-On ICF, Media Requests and 90 Days
| When | What happens | Source |
|---|---|---|
| As new facts emerge | The contractor files a follow-on ICF | DC3 |
| After DC3 receives the report | DC3 sends an unclassified encrypted email with the report to the contracting officers identified on the ICF | PGI 240.370-4(e) |
| For at least 90 days after submission | The contractor keeps images and packet capture data so DoD can request the media or decline interest. The contracting officer sends a written request for media, or notifies the contractor when media are not required. DC3 confirms receipt of media in writing | Clause (e); PGI 240.370-4(k), (l) and (n) |
| On DoD request | The contractor provides access to additional information or equipment needed for forensic analysis | Clause (f) |
| If DoD elects a damage assessment | The contracting officer requests the damage assessment information gathered under (e) | Clause (g) |
| Throughout | Other safeguarding and incident-reporting obligations still apply | Clause (l) |
Filing a report doesn’t, by itself, show a security failure. Deviated DFARS 240.370-3(d) says a reported incident “must not, by itself, be interpreted as evidence that the contractor or subcontractor has failed to provide adequate security.”
Which NIST SP 800-171 Revision Applies
DFARS 252.204-7012 requires NIST SP 800-171 Revision 2 in any contract that carries the June 2026 deviation text or the 2024-O0013 deviation text. Class Deviation 2024-O0013 required contractors subject to 7012 to comply with NIST SP 800-171 Revision 2 “instead of the version of NIST SP 800-171 in effect at the time the solicitation is issued or as authorized by the contracting officer.” The codified May 2024 clause names no revision and points to the version “in effect at the time the solicitation is issued or as authorized by the Contracting Officer.” Separately, the July 13, 2026 USW(A&S) implementing memo states that during the suspension the Department “will enforce baseline compliance with NIST SP 800-171 Rev 2.”
| Clause text | Where it appears | NIST SP 800-171 revision |
|---|---|---|
| 252.204-7012 (MAY 2024), codified | acquisition.gov and eCFR, and contracts awarded under the codified prescription | None named. The clause points to the version “in effect at the time the solicitation is issued or as authorized by the Contracting Officer” |
| 252.204-7012 (MAY 2024) (DEVIATION 2024-O0013, REVISION 1) | Solicitations that used Class Deviation 2024-O0013 (issued May 2, 2024; Revision 1 on May 22, 2024). The deviation no longer appears on DoD’s current deviation list | Revision 2, by name |
| 252.204-7012 (MAY 2024) under the original Class Deviation 2026-O0025 | Solicitations under the deviation from February 1, 2026 until Revision 1 | None named. The text matches the codified clause |
| 252.204-7012 (JUN 2026) (DEVIATION 2026-O0025) | Solicitations under Deviation 2026-O0025 from Revision 1 (signed June 29, 2026) onward. Revision 1 printed the clause date as “[DATE]”, and Revision 3 prints JUN 2026 | Revision 2, by name |
Older contracts may carry earlier codified editions not listed in the table. The date after the clause title, and any deviation number beside it, identifies the text that applies.
NIST SP 800-171 Revision 2 contains 110 security requirements in 14 families. NIST withdrew it on May 14, 2024, when it published Revision 3, but the deviated 7012 clause and CMMC Level 2 still name Revision 2. RIN 0790-AM01, the rule that would move CMMC to Revision 3, was targeted for July 2026. As of September 24, 2026, it hadn’t been published. NIST SP 800-171 Rev 2 vs Rev 3 covers the differences between the two revisions.
How DFARS 7012 Connects to CMMC
DFARS 7012 sets the security requirement, and CMMC provides a way to verify it. 32 CFR 170.5(e) states that the CMMC Program “does not alter any separately applicable requirements” to protect covered defense information under 48 CFR 252.204-7012. That section adds that it “provides a means of verifying implementation” of FAR 52.204-21, NIST SP 800-171 R2 and NIST SP 800-172. CMMC Level 2 uses the same 110 security requirements as NIST SP 800-171 Rev 2. There is no separate Level 2 control set: 32 CFR 170.14(c)(3) says the Level 2 requirements “are identical to the requirements in NIST SP 800-171 R2.”
Posting NIST SP 800-171 assessment scores in SPRS became a requirement later. That came with the 252.204-7019 notice and the 252.204-7020 clause, in an interim rule effective November 30, 2020.
As of September 2026:
- Phase 2 is suspended. On July 13, 2026, the DoW suspended the move to CMMC Phase 2, which had been due November 10, 2026, and held all pending and future CMMC implementation milestones in abeyance. Phase 1 self-assessment requirements, in effect since November 10, 2025, remain in place.
- Only self-assessed levels may be designated. The USW(A&S) implementing memo states that “the allowed designations are CMMC Level 1 (Self) or CMMC Level 2 (Self).” Level 2 (C3PAO) and Level 3 (DIBCAC) may not be designated, and no waivers are granted. The DoW CIO describes the program as “paused in Phase 1.” The Cyber AB stated on July 15, 2026 that all CMMC program elements, including C3PAO Level 2 certification assessments, “remain operational and available.”
- 252.204-7021 is still prescribed. Its row in the table below gives the terms. When it is present, the contractor needs the specified CMMC status at the time of award. Under the July 13 memos, new designations can be only Level 1 (Self) or Level 2 (Self). An active solicitation that still shows Level 2 (C3PAO) or Level 3 (DIBCAC) is to be amended as soon as practicable, and an existing contract modified before its next option period or at its next scheduled administrative modification.
- Under 32 CFR 170.15 and 170.16, a Level 1 self-assessment is repeated annually and a Level 2 self-assessment every three years. Results go to SPRS.
The review’s outcome is still open. A CMMC Reform Task Force’s 60-day review ended around September 11, 2026. As of September 24, 2026, no report or decision had been published. If DoW restores C3PAO designations under the current rule, 7021 and 32 CFR 170 would carry them. Should 32 CFR 170 or the DFARS be amended, the amended text will set the requirement and its schedule. A continued self-assessment-only period keeps the current designations. Neither July memo changes DFARS 7012. Both state that it remains in effect.
The CMMC pause guide covers how the suspension reaches a specific solicitation or contract.
7012, 7019, 7020, 7021 and 252.240-7997 in One Table
DFARS 7012 is the safeguarding clause in a family of DoD cybersecurity clauses. As of September 2026, Class Deviation 2026-O0025 has replaced 7019 and 7020 with 252.240-7997 for Government assessments in solicitations issued under the deviation. Existing contracts may still carry 7019 and 7020. CMMC (Self) status now carries the self-assessment obligation where a contract designates it.
| Clause | What it does | Status as of September 2026 |
|---|---|---|
| 252.204-7012 | Safeguarding covered defense information and cyber incident reporting | Prescribed at 240.370-5(c). The June 2026 deviation text names NIST SP 800-171 Revision 2 |
| 252.204-7019 | Notice of NIST SP 800-171 DoD Assessment Requirements, added in 2020: before award, the offeror needs a current assessment (Basic, Medium or High) posted in SPRS | Not prescribed under Class Deviation 2026-O0025. Still listed in codified 204.7304, and may remain in existing contracts |
| 252.204-7020 | NIST SP 800-171 DoD Assessment Requirements, added in 2020 | Replaced by 252.240-7997 in solicitations under the deviation. May remain in existing contracts |
| 252.240-7997 (FEB 2026) | Medium and High NIST SP 800-171 DoD Assessments conducted by Government personnel, contractor access for them, SPRS posting of summary scores with a 14-business-day rebuttal window, and flowdown to subcontracts other than COTS. It applies to systems that must comply with NIST SP 800-171 under 7012, and DCMA results take precedence over other assessments | Prescribed at 240.370-5(d). It contains no Basic self-assessment requirement and no pre-award SPRS posting requirement |
| 252.204-7021 | CMMC status requirements | Prescribed at 240.371-5(a). Until November 9, 2028, used only when the program office or requiring activity sets a CMMC level. Under the July 2026 memos, new designations may be only Level 1 (Self) or Level 2 (Self) |
An existing contract generally keeps the clauses it was awarded with until a modification changes them. So check your own contract. To read each clause’s edition and insertion in a solicitation package, use the DFARS 252.204 clause family reading map.
What Changed in 2026
The FAR overhaul reached DFARS 7012 through class deviations, and one of them changed the clause text. On June 29, 2026, Revision 1 of Class Deviation 2026-O0025 named Revision 2 in the deviated clause, as Class Deviation 2024-O0013 had done since May 2, 2024. This table dates each 2026 change that touches the clause, as of September 24, 2026.
| Date | Change | Effect on DFARS 7012 |
|---|---|---|
| February 1, 2026 | Class Deviation 2026-O0025, signed December 18, 2025, takes effect | 252.240-7997 (FEB 2026) replaces 7019 and 7020 in solicitations under the deviation. The deviated 7012 carries the codified May 2024 text, which names no NIST SP 800-171 revision |
| February 17, 2026 | Class Deviation 2026-O0043, signed February 3, 2026, replaces DFARS Part 204 and reserves subpart 204.73 | The codified 7012 prescription at 204.7304, which also lists 7019 and 7020, is displaced wherever the deviations are used |
| June 29, 2026 | Class Deviation 2026-O0025 Revision 1 is signed | The deviated 7012 names NIST SP 800-171 Revision 2 |
| July 13, 2026 | DoW CIO and USW(A&S) memos suspend the move to CMMC Phase 2 | Only Level 1 (Self) and Level 2 (Self) may be designated. Both memos state that 7012 remains in effect |
| July 16, 2026 | Class Deviation 2026-O0025 Revision 2 is issued | Per the Revision 3 cover memo, it directs contracting officers to work with requiring activities to remove or revise CMMC requirements under the July 13 CIO memo |
| September 3, 2026 | Class Deviation 2026-O0025 Revision 3 is signed | The deviated clause, prescribed at 240.370-5(c), is dated (JUN 2026) (DEVIATION 2026-O0025). 7008, 7012, 252.240-7997 and 7021 remain prescribed |
| About September 11, 2026 | The CMMC Reform Task Force’s 60-day review ends | No report or decision published as of September 24, 2026 |
Deep Fathom compared the codified May 2024 clause with the June 2026 deviation text, word by word, for paragraphs (a) through (m). Apart from the Revision 2 reference, the only substantive difference is a technical-information cross-reference, which moves from 252.227-7013 to 252.227-7989. Both read the same on the 72-hour window, the 90-day preservation period and the flowdown terms.
One change came earlier. Web archive captures show dibnet.dod.mil redirecting to DC3’s DCISE page from June 22, 2025 onward. As of September 2026, it still does. Yet the clause, the deviation and 32 CFR 236.4 still print the DIBNet address.
As of September 24, 2026, acquisition.gov still displays the codified May 2024 clause, marked “DFARS Change 5/7/2026,” and the codified 204.7304 that lists 7019 and 7020. Deviated texts appear only in the DARS class deviation attachments. Check acquisition.gov and you’ll see the pre-deviation text.
What Contractors Get Wrong About DFARS 7012
Thinking the clause applies only when CUI is marked in the contract. Covered defense information, by definition, includes information the contractor collects, develops, receives, transmits, uses or stores in support of performance. That information can be in your environment even when the contract carries no marking guide.
Finishing the investigation before reporting. The report is due within 72 hours of discovery. Whether the review is finished doesn’t change that. DC3 asks for “as much of the following information as can be obtained within 72 hours” and takes later facts in a follow-on ICF.
Old reporting habits cause three more. The clause still prints dibnet.dod.mil, but as of September 24, 2026, that address redirects to DC3, and reports go through the ICF portal. The 90-day preservation clock doesn’t start at the incident. It starts at the report’s submission. And don’t email malware. Use EMS or the one-time upload link in the steps above.
Reading the COTS exception as a commercial exception. The prescription covers commercial products and commercial services bought under FAR Part 12. Its exception covers only solicitations and contracts solely for COTS items.
Clause text does change. The June 2026 deviation text names NIST SP 800-171 Revision 2, and as of September 2026 acquisition.gov still shows the May 2024 text. Check the date after the clause title in each contract.
Assuming flowdown happens on its own. The prime must include the clause in subcontracts that involve covered defense information or operationally critical support. It must also decide whether the information it shares keeps its identity as covered defense information. A subcontractor that receives covered defense information under a subcontract without the clause should raise it with the prime.
Assuming DFARS 7012 compliance means CMMC readiness. Both use the same 110 security requirements. CMMC adds a defined assessment, results submitted in SPRS and a status that a solicitation can require at award. In Deep Fathom’s view, the harder part of moving a 7012 program toward a CMMC assessment is usually the evidence record. That record shows, requirement by requirement, how each control is implemented and where its evidence is kept.
What to Do About It
- Confirm the clause and its edition in every contract and subcontract, and record the date after the clause title and any deviation number.
- Assess against NIST SP 800-171 Revision 2 and know your current state against all 110 requirements. SPRS still matters where a contract designates Level 1 (Self) or Level 2 (Self), and in older contracts that carry 7019 or 7020.
Then work through the four actions in the small-contractor section, extend the map of covered defense information to subcontractors, and rehearse the 72-hour steps above.
Deep Fathom organizes each DFARS 7012 requirement, its owner and its evidence in one record. That way, gaps and stale evidence show up before an incident report or an assessment. The contractor files incident reports with DC3 and signs its own representations and affirmations. The DoD CIO adjudicates variance requests. Government assessors conduct Medium and High assessments.
Next Step
Send us the clause list from your contract or solicitation and a short description of where covered defense information lives in your systems and cloud services. Our team will review them and reply within one business day. Our reply covers which DFARS 7012 paragraphs apply, which clause edition you’re working under and what to address first. Send them to our team, or create a free workspace to track the work yourself.
References · 6 official sources
| Source | What it covers | Type |
|---|---|---|
| DFARS 252.204-7012 (Safeguarding Covered Defense Information and Cyber Incident Reporting) | The codified May 2024 clause: definitions, adequate security, 72-hour reporting, malicious software, 90-day preservation, forensic access, damage assessment and flowdown | Regulation |
| Class Deviation 2026-O0025, Revision 3 (DFARS Part 240) | The June 2026 deviated clause naming NIST SP 800-171 Revision 2, the prescription at 240.370-5(c), 252.240-7997, the 7021 prescription and the PGI steps after a report | Regulation |
| DC3 DCISE: DIB cyber incident reporting | The ICF portal, the medium assurance certificate, ICF fields, follow-on reports, malware submission and DCISE contacts | Guidance |
| 32 CFR Part 170 (CMMC Program Rule) | CMMC’s relationship to 7012, Level 2’s identity with NIST SP 800-171 R2, the micro-purchase threshold and SPRS self-assessment timing | Regulation |
| DoW CIO memo on the CMMC Phase II suspension and review (July 13, 2026) | The Phase 2 suspension, 7012 remaining in effect and the no-cost DoW resources | Guidance |
| NIST SP 800-171 Rev 2 | The 110 security requirements and the revision’s withdrawn status | Standard |