Skip to main content

Plain-English clause guide · primary sources

"I just got DFARS 252.204-7012 in my contract." Now what?

DFARS clause 252.204-7012 puts three duties on you: safeguard covered defense information by implementing NIST SP 800-171, report cyber incidents within 72 hours at dibnet.dod.mil, and flow the clause down to subcontractors that handle the data. It is the contractual hook that makes CMMC Level 2 your near-term reality.

What the clause actually requires

DutyClauseIn plain English
Safeguard252.204-7012(b)Implement the NIST SP 800-171 security requirements on every contractor system that stores, processes, or transmits covered defense information (CDI). External cloud must meet FedRAMP Moderate (or equivalent) and the clause flows to the cloud provider.
Report incidents252.204-7012(c)Rapidly report any cyber incident affecting CDI or your ability to perform, within 72 hours of discovery, to DoD at dibnet.dod.mil. Reporting requires a DoD-approved medium-assurance certificate, and you must preserve affected media/images for at least 90 days.
Flow it down252.204-7012(m)Include the clause, without alteration, in subcontracts where performance involves CDI or operationally critical support. Your obligation does not stop at your own walls, because primes are responsible for their supply chain.

Source: DFARS 252.204-7012 (Safeguarding Covered Defense Information and Cyber Incident Reporting). Covered defense information (CDI) is, in practice, the same controlled unclassified information (CUI) that triggers CMMC Level 2.

How 7012 connects to CMMC

7012 has required NIST SP 800-171 since 2017, so the obligation is not new. What is new is verification. CMMC is how DoD moves from "you attested you implemented 800-171" to "a third party confirmed it." CMMC Phase 2 — which makes C3PAO-assessed Level 2 the default for new contracts involving CUI — was scheduled for November 10, 2026, but as of July 13, 2026 DoD suspended Phase 2 pending a 60-day review. Your 800-171 obligation and SPRS self-assessment are unchanged, and a prime can still require a C3PAO certification as a condition of award.

So if your contract carries 7012, the honest planning assumption is Level 2: all 110 NIST SP 800-171 requirements, a current SPRS score, and increasingly a C3PAO certification as a condition of award. The companion clauses make the mechanics explicit: 252.240-7997 (formerly 7019/7020) requires and governs the SPRS self-assessment, and 7021 is the CMMC clause itself.

CMMC phase dates: 32 CFR 170.3(e); DFARS rule effective Nov 10, 2025. As of July 13, 2026, DoD suspended CMMC Phase 2 (the third-party-assessment requirement) pending a 60-day review; the NIST 800-171 self-assessment and SPRS requirement is unchanged. See the Phase 2 status and Level 1 vs Level 2.

Your first week with the clause

01

Confirm whether you actually handle CDI

Covered defense information is essentially CUI, such as controlled technical information and export-controlled data. If your deliverables truly contain none of it, your obligations are far lighter (and you should document that determination). When you can't tell, ask your contracting officer or prime what the data is rather than guessing.

02

Find your real SPRS score

The clause requires NIST SP 800-171; the companion clause (252.240-7997, which replaced 252.204-7019/7020 in February 2026) requires you to post a current self-assessment score to SPRS. Most contractors have never computed theirs honestly. Start there, because you cannot plan a gap you have not measured.

03

Check your 72-hour reporting readiness

Two things block a fast report: not having a DoD-approved medium-assurance certificate provisioned at dibnet.dod.mil before you need it, and not knowing who pulls the trigger. Set both up now, because 72 hours is not the moment to start the paperwork.

04

Flow the clause to your subs

Anywhere a subcontractor touches CDI, the clause must appear in their subcontract unaltered. Map which of your subs handle the data and confirm the flow-down is in their agreements.

Straight answers

Does DFARS 252.204-7012 in my contract mean I need CMMC now?

It means you are already obligated to implement NIST SP 800-171, which 7012 has required since 2017 — and that obligation, plus posting a current SPRS self-assessment score, is unchanged. CMMC is the verification layer on top: Phase 2 (C3PAO-assessed Level 2 as the default for new DoD contracts involving CUI) was scheduled for November 10, 2026, but DoD suspended it on July 13, 2026 pending a 60-day review. So 7012 is the substance and remains fully in force; third-party CMMC verification is how DoD is expected to check it once Phase 2 resumes, and a prime can require it before then. If you have 7012, plan for Level 2.

What is the 72-hour reporting rule?

Under 252.204-7012(c), if you discover a cyber incident that affects covered defense information or your ability to perform the contract, you must report it to DoD at dibnet.dod.mil within 72 hours of discovery. Reporting requires a DoD-approved medium-assurance certificate, and under the clause you preserve and protect affected media and system images for at least 90 days so DoD can request them.

Do I have to flow 252.204-7012 down to my subcontractors?

Yes. Under 252.204-7012(m), you include the clause without alteration in subcontracts whose performance involves covered defense information or operationally critical support. As a prime, you are responsible for ensuring subs that handle the data carry the same obligations. A subcontractor is not exempt for being downstream.

What if I do not actually handle CUI or covered defense information?

Then your obligations under the clause are substantially lighter, but make that determination deliberately and write it down, because the cost of being wrong is high. If you receive technical drawings, specifications, export-controlled data, or anything marked CUI/CDI, you are in scope. When it is unclear, ask the contracting officer or prime what the deliverable contains rather than assuming. This is compliance information, not legal advice.

How is 252.204-7012 different from 7019, 7020, and 7021?

7012 is the safeguarding-and-reporting clause: implement NIST SP 800-171 and report incidents. 7019 (current self-assessment posted to SPRS) and 7020 (DoD assessment rights and flow-down) were consolidated into 252.240-7997 for new awards by Class Deviation 2026-O0025, effective February 1, 2026 — contracts awarded earlier still carry the old pair. 7021 is the CMMC clause that requires the applicable CMMC level as a condition of award. They work together: 7012 is the substance, and the others are the verification and contracting mechanics.

This is compliance information, not legal advice. The clause text governs; for contract-interpretation or FCA questions, consult qualified counsel.

How far are you from the NIST 800-171 standard 7012 requires?

The free assessment walks the 110 NIST SP 800-171 requirements in plain English and computes your SPRS score with the exact DoD methodology, so 7012 becomes a checklist, not a cliff.

Start the free assessment