---
title: "What Is DFARS 252.204-7012? CMMC Definition"
description: "DFARS 7012 is the long-standing clause requiring contractors to safeguard covered defense information per NIST 800-171 and report cyber incidents within 72 hours."
url: https://policycortex.com/cmmc/glossary/dfars-7012
sealed: 2026-07-02
amended: 2026-07-13
register: cmmc/glossary/dfars-7012
records: 3
digest: sha3:1a577e2f8ac9f60275133f32918e41a953be3ef40468fc66cfe27d116900d9dd
---

# What is DFARS 252.204-7012?

Register / Glossary

DFARS 7012 is the long-standing clause requiring contractors to safeguard covered defense information per NIST 800-171 and report cyber incidents within 72 hours.

Sealed 2026-07-02 · Amended 2026-07-13

DFARS 252.204-7012 has been in DoD contracts since 2017. It requires implementing NIST SP 800-171, reporting cyber incidents to DoD within 72 hours, and flowing the requirement down to subcontractors handling covered defense information.

It also requires that cloud services storing CUI meet FedRAMP Moderate (or equivalency) — the clause that pulls a contractor's MSP or cloud provider into scope.

CMMC's contractual clause, DFARS 252.204-7021, works alongside 7012 and 7019/7020. The Phase II rollout of certification requirements is suspended while the Department reviews the program; the underlying 7012 safeguarding duty remains active.

## Related records

Guides and articles describe the work. The evidence that work produces is described in three proof pages and one architecture page.

- **proof.state**: [Proof of State](https://policycortex.com/proof/state). What the environment was, as of a date someone else picks: point-in-time records, content hashed and chained.
- **proof.change**: [Proof of Change](https://policycortex.com/proof/change). Who or what altered the environment, under what authority, with before and after state hashes.
- **proof.agency**: [Proof of Agency](https://policycortex.com/proof/agency). What a machine was permitted to do before it acted, what it did, and what would have stopped it.
- **architecture**: [Architecture](https://policycortex.com/architecture). How the chain is built and where it lives: inside your tenant, with no egress of evidence.

### Related terms and reading

| Entry |
|---|
| [NIST SP 800-171](https://policycortex.com/cmmc/glossary/nist-800-171): NIST SP 800-171 is the federal standard of 110 security controls for protecting CUI in non-federal systems: the technical basis of CMMC Level 2. |
| [CUI: Controlled Unclassified Information](https://policycortex.com/cmmc/glossary/cui): CUI is government-created or -owned information that requires safeguarding under law, regulation, or government-wide policy, but is not classified. |
| [SPRS: Supplier Performance Risk System](https://policycortex.com/cmmc/glossary/sprs): SPRS is the DoD system where contractors post their NIST 800-171 self-assessment score and, under CMMC, their certification status and affirmations. |
| [ESP vs CSP: When Your MSP Triggers FedRAMP](https://policycortex.com/blog/esp-vs-csp-cmmc-msp-fedramp-scoping) |

Know the term. Then see the record behind it. [Request Access](https://app.policycortex.com/auth?mode=request-access) · [Book a call](https://policycortex.com/book)

Dates of record

- **Sealed**: 2026-07-02
- **Last amended**: 2026-07-13
- **Record**: https://policycortex.com/cmmc/glossary/dfars-7012

## Register colophon

| Seq | Label | SHA3-256 | Prev |
|---|---|---|---|
| REC 0000 | HEAD | 54ee5edb19fb | db7ca30609e1 |
| REC 0001 | DEFINITION | 9a3fea3a8e16 | 54ee5edb19fb |
| REC 0002 | RELATED RECORDS | 1a577e2f8ac9 | 9a3fea3a8e16 |

Head sha3:1a577e2f8ac9f60275133f32918e41a953be3ef40468fc66cfe27d116900d9dd. Each digest is SHA3-256 over the previous digest, the register key, the record label, and the record copy; a second party can recompute it from this document.
