sha3:1a577e2f8ac9f60275133f32918e41a953be3ef40468fc66cfe27d116900d9ddIntact54ee5edb19fb256959c73b76effc1c27d424a3b9fb9c877b27ad54b6f3ca68fdprev:db7ca30609e1RegisterGlossary
What is DFARS 252.204-7012?
DFARS 7012 is the long-standing clause requiring contractors to safeguard covered defense information per NIST 800-171 and report cyber incidents within 72 hours.
9a3fea3a8e16abb0920d9ca0d294ad2266f66053801553a289830b6bd8d7a283prev:54ee5edb19fbDFARS 252.204-7012 has been in DoD contracts since 2017. It requires implementing NIST SP 800-171, reporting cyber incidents to DoD within 72 hours, and flowing the requirement down to subcontractors handling covered defense information.
It also requires that cloud services storing CUI meet FedRAMP Moderate (or equivalency) — the clause that pulls a contractor's MSP or cloud provider into scope.
CMMC's contractual clause, DFARS 252.204-7021, works alongside 7012 and 7019/7020. The Phase II rollout of certification requirements is suspended while the Department reviews the program; the underlying 7012 safeguarding duty remains active.
1a577e2f8ac9f60275133f32918e41a953be3ef40468fc66cfe27d116900d9ddprev:9a3fea3a8e16Related records
Guides and articles describe the work. The evidence that work produces is described in three proof pages and one architecture page.
- proof.state
- Proof of State. What the environment was, as of a date someone else picks: point-in-time records, content hashed and chained.
- proof.change
- Proof of Change. Who or what altered the environment, under what authority, with before and after state hashes.
- proof.agency
- Proof of Agency. What a machine was permitted to do before it acted, what it did, and what would have stopped it.
- architecture
- Architecture. How the chain is built and where it lives: inside your tenant, with no egress of evidence.
Related terms and reading
Know the term. Then see the record behind it.
- Sealed
- Last amended