Regulatory Guide

DFARS 252.204-7012 Compliance Guide for Defense Contractors (2026)

Last updated: 2026-02-27

What DFARS 252.204-7012 Is The Four Clauses You Need to Know What NIST SP 800-171 Actually Requires The 72-Hour Cyber Incident Reporting Requirement DFARS 7012 and the SPRS Score

What DFARS 252.204-7012 Is

DFARS 252.204-7012, formally titled "Safeguarding Covered Defense Information and Cyber Incident Reporting," is a Defense Federal Acquisition Regulation Supplement clause that has been required in DoD contracts involving Controlled Unclassified Information since December 2017. It is not a guideline or a best practice. It is a contractual requirement, and the moment you sign a contract containing it, you are legally bound by its terms.

The clause does three things. It requires contractors to implement the security controls in NIST SP 800-171 on all systems that process, store, or transmit covered defense information. It requires contractors to report cyber incidents to the DoD within 72 hours of discovery. And it requires contractors to flow those same obligations down to any subcontractor that handles CUI under the same work.

The Core Obligation in Plain Terms
If DFARS 252.204-7012 is in your contract and your company systems touch CUI, you must implement all 110 NIST SP 800-171 security requirements, maintain a current SPRS score reflecting your actual compliance posture, and report any cyber incident affecting CUI to the DoD within 72 hours. These are not aspirational targets — they are contract terms you have already agreed to.

Many contractors discovered this clause in their contracts years after signing, having taken no meaningful compliance action. The DOJ's Civil Cyber-Fraud Initiative, launched in 2021, was built specifically to address that gap. More than $26 million in settlements against defense contractors followed. The enforcement record makes clear that "we did not know" is not a defense when the obligation was written into the contract.

The Four Clauses You Need to Know

DFARS 252.204-7012 does not operate alone. Three companion clauses govern different aspects of the same compliance framework. Together they define your full contractual cybersecurity obligation under current DoD acquisition rules.

DFARS 252.204-7012The foundational clause. Requires implementation of NIST SP 800-171 on all systems handling covered defense information, 72-hour cyber incident reporting to the DoD, and flow-down to subcontractors who touch CUI. In force since December 2017. If this clause is in your contract, you are already required to be NIST 800-171 compliant.
DFARS 252.204-7019Requires contractors to conduct a NIST SP 800-171 self-assessment using the DoD assessment methodology and submit the resulting score to the Supplier Performance Risk System (SPRS) before contract award. The score must be current — no more than three years old.
DFARS 252.204-7020Gives the DoD the right to review a contractor's NIST SP 800-171 implementation and verify that the SPRS score reflects the contractor's actual security posture. Enables the DoD to conduct or commission an independent assessment of any contractor's CUI systems.
DFARS 252.204-7021The CMMC clause, effective November 2025. Requires contractors to achieve and maintain a specific CMMC certification level as a condition of contract award. This clause is being phased into new solicitations on a rolling basis. When present, it means self-attestation is no longer sufficient — a C3PAO assessment is required.

The presence of 252.204-7012 in your current contracts means CMMC is coming to those contracts. The presence of 252.204-7021 means it is already required. Review every active DoD contract for these clause numbers if you have not done so.

What NIST SP 800-171 Actually Requires

DFARS 252.204-7012 incorporates NIST SP 800-171 by reference, which means the 110 security requirements in that document are effectively contract terms. They span 14 security domains covering every major aspect of how an organization protects information on its systems.

The requirements are not vague principles. Each one specifies a concrete security capability your organization must implement and be able to demonstrate. A C3PAO assessor — or a DoD reviewer under DFARS 7020 — will evaluate your implementation against the CMMC Assessment Guide's examine, interview, and test criteria for each of the 110 requirements.

Access Control (22)Who can access systems handling CUI, under what conditions, with what privileges. Includes multi-factor authentication, least-privilege enforcement, and remote access controls.
System & Comms Protection (16)Network boundary controls, encryption of CUI in transit, and architectural separation of CUI systems from general-purpose networks.
Identification & Authentication (11)Managing user identities, enforcing strong authenticators, and ensuring only authorized individuals access CUI systems.
Audit & Accountability (9)Logging user and system activity, protecting audit records, and reviewing logs for anomalous behavior.
Configuration Management (9)Secure baseline configurations, change control processes, and restriction of unauthorized software on CUI systems.
Media Protection (9)Controlling access to physical and digital media containing CUI, sanitizing media before disposal or reuse.
System & Info Integrity (7)Anti-malware protections, security alert monitoring, and timely patching of identified vulnerabilities.
Maintenance (6)Controlled maintenance of CUI systems, equipment sanitization before off-site work, and vetting of maintenance personnel.
Physical Protection (6)Physical access controls to CUI systems and facilities, visitor management, and physical access monitoring.
Risk Assessment (5)Periodic risk assessments, vulnerability scanning, and remediation of identified weaknesses on a defined schedule.
Security Assessment (4)Periodic assessment of security controls and maintaining an active Plan of Action and Milestones for any deficiencies.
Incident Response (3)Documented incident response capability, regular testing, and reporting confirmed incidents to the DoD within 72 hours.
Awareness & Training (3)Ensuring all personnel with CUI access understand their security responsibilities and can recognize current threats.
Personnel Security (2)Screening individuals before granting CUI system access and revoking access promptly upon termination or role change.

The 72-Hour Cyber Incident Reporting Requirement

One of the most time-sensitive obligations under DFARS 252.204-7012 is the cyber incident reporting requirement. When a contractor discovers a cyber incident affecting systems that process, store, or transmit covered defense information, the DoD must be notified within 72 hours of discovery — not 72 hours after investigation is complete, not 72 hours after the incident is contained. Seventy-two hours from the point at which the organization becomes aware that an incident has occurred.

Reporting is done through the DIBNet portal at dibnet.dod.mil. The report must include the company name and point of contact, contract numbers affected, facility CAGE code, date incident was discovered, location of compromised systems, type of compromise, description of the technique or method used, a description of CUI categories involved, and a narrative of what happened.

What Triggers the 72-Hour Clock
A "cyber incident" under DFARS 7012 is broadly defined as actions taken through the use of computer networks that result in an actual or potentially adverse effect on an information system or the information residing therein. This includes unauthorized access, exfiltration of data, malware infection affecting CUI systems, and denial-of-service attacks on covered systems. When in doubt, report. Failure to report is itself a contract violation.

Contractors who experience a reportable incident are also required to preserve images of all known affected systems for at least 90 days to support any DoD damage assessment. The DoD may request access to those images. This means your incident response plan must include specific procedures for evidence preservation — not just incident containment and remediation.

Building the 72-hour reporting capability before an incident occurs is the requirement. An organization that discovers a breach and then scrambles to figure out what to report, who submits it, and how to access the DIBNet portal is already behind. The incident response plan documented in your SSP must identify specifically who is responsible for DFARS 7012 reporting and walk through the submission process in advance.

DFARS 7012 and the SPRS Score

DFARS 252.204-7019 requires contractors to self-assess their NIST SP 800-171 implementation using the DoD Assessment Methodology and submit the resulting score to the Supplier Performance Risk System before contract award. The score is calculated by starting at 110 — representing full implementation — and subtracting the weighted point value of each requirement that is not yet implemented. The minimum possible score is -203.

The SPRS score is not a private internal document. It is visible to DoD contracting officers and prime contractors who use it to evaluate supply chain risk. A low score does not automatically disqualify you from contract award, but an inaccurate score — particularly one that is materially higher than your actual implementation level — is the direct basis for False Claims Act exposure.

The Enforcement Pattern
In the MORSECORP case, a third-party gap assessment revealed an actual SPRS score of -142. The company continued reporting a higher score for nearly a year before updating it. That delay — knowing the true score and not reporting it — cost $4.6 million. In the Penn State case, deficiencies were disclosed in 2020 but inadequately remediated through 2023. In both cases, the legal problem was not the gap itself. It was continuing to certify compliance while knowing the gaps existed.

The practical rule: if you conduct any form of gap assessment and learn that your actual NIST 800-171 implementation score is materially different from what you have submitted to SPRS, update the score promptly. An accurate low score with an active POA&M is legally defensible. A knowingly inflated score is not.

The Flow-Down Obligation

DFARS 252.204-7012 does not stop at the prime contractor. The clause contains an explicit flow-down requirement: prime contractors must include the substance of DFARS 7012 in all subcontracts — at any tier — where the subcontractor will process, store, or transmit covered defense information or operate systems that provide security protection for those systems.

This has significant practical implications for both primes and subcontractors. As a prime, you are responsible for ensuring your subcontractors are compliant with NIST SP 800-171 on the CUI they handle under your contract. If a subcontractor suffers a breach of CUI they received from you, the prime may bear responsibility for inadequate flow-down and oversight.

As a subcontractor, even if your direct contract with a prime does not explicitly reference CMMC or DFARS 7012, your obligation may exist by virtue of the prime's contract with the DoD. If you handle CUI — technical data packages, drawings, specifications, controlled program information — received from a prime, that data is almost certainly covered under the prime's DFARS 7012 clause and your obligation flows through whether or not the paperwork makes it explicit.

The safe assumption for any subcontractor in the defense supply chain: if you touch CUI, DFARS 7012 applies to you. Verify with your prime and review your subcontract for the relevant clauses. Do not wait for a formal flow-down notice that may never arrive.

DFARS 7012 vs. CMMC: How They Relate

DFARS 252.204-7012 and CMMC are not competing requirements — they are sequential layers of the same framework. Understanding how they relate prevents confusion about whether compliance with one satisfies the other.

DFARS 252.204-7012 has been in force since 2017 and requires NIST SP 800-171 implementation through self-attestation. Contractors were required to implement the 110 controls, assess themselves, and report their score. No third-party verification was required. This self-assessment regime produced the gap that CMMC was built to close — contractors reporting high scores while third-party assessments revealed scores in negative territory.

CMMC Level 2 uses the same 110 NIST SP 800-171 requirements without adding new technical controls. What it adds is mandatory third-party verification by a C3PAO. When DFARS 252.204-7021 is present in a contract, a C3PAO assessment is required in addition to — not instead of — the underlying DFARS 7012 compliance.

DFARS 7012 without 7021Requires NIST SP 800-171 implementation and an accurate SPRS score. No third-party assessment required. Self-attestation is the compliance mechanism. FCA exposure exists if the score does not reflect actual implementation.
DFARS 7012 with 7021Requires NIST SP 800-171 implementation plus a valid CMMC Level 2 certification from a C3PAO as a condition of contract award. Self-attestation is not sufficient. Phase 2 begins November 2026 for most CUI contracts.
DFARS 7019 and 7020Always accompany 7012 in current contracts. Govern the SPRS score submission process and the DoD's right to independently verify the score. Active even when 7021 is not yet present.

The bottom line: if DFARS 252.204-7012 is in your contract today, you are already required to have implemented NIST SP 800-171 and to have an accurate SPRS score on file. CMMC adds the verification layer. Organizations that treat DFARS 7012 compliance seriously — with genuine control implementation, accurate scoring, and maintained documentation — are the same organizations best positioned for a successful C3PAO assessment.

What Non-Compliance Costs

The consequence framework for DFARS 252.204-7012 non-compliance has three components, each operating on a different timeline.

Contract termination and ineligibility is the most direct consequence. Failure to implement required cybersecurity controls is a material breach of contract terms. Contracting officers can terminate a contract for default and debar the contractor from future awards. As CMMC phase-in accelerates, contractors without valid certifications will be ineligible to bid on covered contracts — representing a complete loss of that revenue stream.

False Claims Act liability is the more financially severe consequence. The DOJ's Civil Cyber-Fraud Initiative applies FCA theory to cybersecurity non-compliance: when a contractor certifies compliance as part of a contract claim or invoice while knowing it is not compliant, each submission is a false claim. Penalties include treble damages and per-claim fines that currently exceed $28,000. With dozens or hundreds of invoices submitted over a multi-year contract, exposure compounds rapidly.

Incident-triggered liability is the emerging third category. If a CUI breach occurs on systems where required NIST 800-171 controls were not implemented, the failure to implement those controls becomes directly relevant to the resulting investigation and any subsequent civil action. The controls exist specifically to prevent the kind of exfiltration that nation-state adversaries have repeatedly executed against the defense industrial base.

The Enforcement Record to Date
Five False Claims Act settlements totaling more than $26 million since 2022: Aerojet Rocketdyne ($9M), Raytheon/RTX/Nightwing ($8.4M), MORSECORP ($4.6M), Pennsylvania State University ($1.25M), and Georgia Tech ($875K). In four of five cases the action originated from a whistleblower who was a senior technical employee at the organization. The Civil Cyber-Fraud Initiative has continued through two administrations and shows no sign of slowing. Read the full enforcement case analysis.

How to Get Compliant: The Practical Path

If you have identified DFARS 252.204-7012 in your contracts and have not taken formal compliance action, the path forward is sequential. Each step builds on the last and produces artifacts that are both compliance deliverables and legal protection.

Step 1: Identify your CUI scopeDetermine exactly which systems in your environment process, store, or transmit CUI. Review contracts for DFARS clause presence, examine what data your customers send you, and identify every system that touches it — including cloud services, email, file shares, and remote access infrastructure.
Step 2: Conduct a gap assessmentAssess your current implementation against all 110 NIST SP 800-171 requirements using the DoD Assessment Methodology. Document each requirement as implemented, partially implemented, or not implemented. This produces your true SPRS score and identifies the work ahead.
Step 3: Update your SPRS scoreSubmit your actual score to SPRS at piee.eb.mil. If your current score in SPRS does not reflect your actual posture, update it immediately. The FCA risk of a knowingly inflated score far exceeds any competitive disadvantage of an honest low score with an active POA&M.
Step 4: Build your SSPDocument how each of the 110 requirements is implemented in your specific environment. The System Security Plan is the primary artifact a C3PAO assessor will examine. It must describe your actual systems, tools, configurations, and personnel — not a generic template that does not reflect your environment.
Step 5: Build and work your POA&MFor every requirement not yet fully implemented, create a POA&M item with a named owner, specific gap description, interim mitigation in place, and a credible completion date within 180 days. Then actually remediate the items on the timeline you committed to.
Step 6: Prepare for C3PAO assessmentOnce your controls are implemented, evidence is collected, and documentation is complete, engage an authorized C3PAO for formal assessment. Book early — assessment slots are filling with 3 to 6 month lead times ahead of the November 2026 Phase 2 deadline.

Frequently Asked Questions

What is DFARS 252.204-7012?

DFARS 252.204-7012 is the DoD contract clause that requires defense contractors to implement all 110 NIST SP 800-171 security requirements on systems handling Controlled Unclassified Information, report cyber incidents to the DoD within 72 hours, and flow the same requirements down to subcontractors who touch CUI. It has been in force since December 2017.

How do I know if DFARS 7012 applies to my contract?

Search your contract documents for the text "252.204-7012" or "Safeguarding Covered Defense Information." If the clause is present and your systems handle any CUI under that contract, you are bound by its requirements. If you are a subcontractor, review your subcontract and ask your prime whether their DoD contract contains DFARS 7012.

What is the difference between DFARS 7012 and CMMC?

DFARS 252.204-7012 requires NIST SP 800-171 implementation through self-attestation — you assess yourself and report your score to SPRS. CMMC Level 2 uses the same 110 requirements but adds mandatory third-party C3PAO verification. When DFARS 252.204-7021 (the CMMC clause) is present in your contract, a C3PAO assessment is required on top of the underlying 7012 compliance.

What happens if I discover a cyber incident?

You must report to the DoD within 72 hours of discovery through the DIBNet portal at dibnet.dod.mil. The report must include your CAGE code, affected contract numbers, date of discovery, compromised system descriptions, and a narrative of what occurred. You must also preserve images of affected systems for at least 90 days. Your incident response plan should document this process in advance — not for the first time during an actual incident.

Can I just submit a low SPRS score and get compliant later?

An accurate low score with an active POA&M is legally defensible and much safer than an inflated score. The FCA enforcement cases have been built on contractors who knew their actual posture did not match their reported score and continued certifying anyway. Submit your true score, build a credible POA&M, and work the remediation. Contracting officers and primes understand that compliance takes time — what they cannot overlook is misrepresentation.

Do I need to flow DFARS 7012 down to my subcontractors?

Yes. If a subcontractor will process, store, or transmit CUI under your contract, you must include the substance of DFARS 7012 in your subcontract with them. This means they must also implement NIST SP 800-171 and report any cyber incidents affecting CUI they receive from you. As a prime, you share responsibility for ensuring your supply chain is compliant with the CUI they handle on your behalf.

What is the SPRS score and how do I submit it?

The SPRS score is your self-assessed NIST SP 800-171 implementation score, ranging from -203 (nothing implemented) to 110 (fully implemented). It is calculated using the DoD Assessment Methodology — start at 110 and subtract the weighted point value of each unimplemented requirement. Submit through the Procurement Integrated Enterprise Environment (PIEE) at piee.eb.mil. The score must be current, no more than three years old, and accurately reflect your actual implementation posture.

What cloud services can I use for CUI under DFARS 7012?

Cloud services that process, store, or transmit CUI must meet FedRAMP Moderate baseline requirements at minimum. Standard commercial Microsoft 365, Google Workspace, and similar offerings do not meet this bar. You must use government cloud variants such as Microsoft 365 GCC or equivalent FedRAMP Moderate-authorized services. Using non-compliant cloud services for CUI was a specific element of the MORSECORP False Claims Act settlement.

Miss nothing.

1TEN gives your team the structure to govern CMMC compliance without building a compliance department around it.

Request a Demo