Skip to content

Evidence request lists

DFARS 252.204-7012 - Safeguarding Covered Defense Information

Evidence request list. 12 controls, 12 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

DFARS 7012: Adequate Security

DFARS-7012-b
Adequate security - implement NIST SP 800-171

The Contractor shall provide adequate security on all covered contractor information systems; for systems that are not part of an IT service or system operated on behalf of the Government, this means implementing the security requirements in NIST SP 800-171 in effect at the time the solicitation is issued (or as authorised by the Contracting Officer).

Artefacts an auditor will ask for
  • A System Security Plan (SSP) describing how each NIST SP 800-171 requirement is met
  • An SPRS self-assessment score
  • Implementation evidence for the 110 NIST SP 800-171 security requirements
Where this commonly fails
  • Missing or stale SSP
  • No SPRS score submitted
  • Claiming full implementation without supporting artefacts
DFARS-7012-b-cloud
Cloud and external service provider security

Cloud computing services provided as part of an IT service operated on behalf of the Government are subject to clause 252.239-7010; where the Contractor uses an external cloud service provider to store, process or transmit covered defense information, the Contractor shall require the provider to meet security requirements equivalent to the FedRAMP Moderate baseline and to comply with paragraphs (c) through (g) of this clause.

Artefacts an auditor will ask for
  • Evidence the external cloud service provider meets a FedRAMP Moderate-equivalent baseline
  • Contractual flowdown of paragraphs (c)-(g) to the cloud provider
Where this commonly fails
  • Using a cloud provider with no FedRAMP Moderate equivalency
  • No flowdown of incident-reporting obligations to the provider
DFARS-7012-b-var
Variance requests and alternative measures

The Contractor may submit requests to vary from NIST SP 800-171 in writing to the Contracting Officer for consideration by the DoD CIO, and may propose to use alternative but equally effective security measures; the Contracting Officer documents adjudication of any such requests.

Artefacts an auditor will ask for
  • Written variance/deviation requests and the DoD CIO adjudication
  • Documentation of any alternative-but-equally-effective measures accepted
Where this commonly fails
  • Deviating from 800-171 without an approved variance
  • Undocumented compensating controls

DFARS 7012: Cyber Incident Reporting

DFARS-7012-c
Cyber incident reporting (72-hour rapid report)

When the Contractor discovers a cyber incident affecting a covered contractor information system, the covered defense information residing therein, or its ability to perform operationally critical support, it shall conduct a review for evidence of compromise and rapidly report the incident (within 72 hours of discovery) to DoD at https://dibnet.dod.mil, including the required report content, and shall have or acquire a DoD-approved medium assurance certificate to make the report.

Artefacts an auditor will ask for
  • Incident review records evidencing the compromise assessment
  • The cyber incident report submitted via dibnet.dod.mil within 72 hours
  • A DoD-approved medium assurance certificate
Where this commonly fails
  • Reporting later than 72 hours after discovery
  • No medium assurance certificate in place
  • Incomplete incident report content

DFARS 7012: Definitions and Scope

DFARS-7012-a
Definitions

The clause defines the key terms governing its obligations, including adequate security, compromise, contractor attributional/proprietary information, covered contractor information system, covered defense information (CUI), cyber incident, malicious software, media, operationally critical support, rapidly report (within 72 hours of discovery), and technical information.

Artefacts an auditor will ask for
  • Mapping of contract data flows to identify covered defense information (CUI) and covered contractor information systems
  • Determination of whether the contract designates operationally critical support
Where this commonly fails
  • Failing to identify which systems hold covered defense information
  • Treating only classified data as in-scope

DFARS 7012: Forensics and Damage Assessment

DFARS-7012-f
Access to additional information or equipment for forensic analysis

Upon request, the Contractor shall provide DoD with access to additional information or equipment necessary to conduct a forensic analysis of a reported cyber incident.

Artefacts an auditor will ask for
  • A process to provide DoD access to systems/data/equipment for forensic analysis
  • Records of access provided on request
Where this commonly fails
  • Refusing or delaying forensic access requests
  • No procedure to support DoD forensic analysis
DFARS-7012-g
Cyber incident damage assessment activities

If DoD elects to conduct a damage assessment, the Contracting Officer will request that the Contractor provide all of the damage assessment information gathered in accordance with the media preservation paragraph.

Artefacts an auditor will ask for
  • Damage assessment information packaged from preserved media on request
  • Support to the DoD damage assessment process
Where this commonly fails
  • Unable to produce damage assessment information from preserved media

DFARS 7012: Information Protection and Use

DFARS-7012-hk
DoD safeguarding and use of contractor attributional/proprietary information

Information shared by the Contractor under this clause that qualifies as contractor attributional/proprietary information is safeguarded and used by DoD subject to restrictions on use and release (whether or not created by or for DoD), and all activities under the clause are conducted in accordance with applicable law and regulation.

Artefacts an auditor will ask for
  • Markings on attributional/proprietary information provided to DoD
  • Awareness of the use/release protections that apply to reported information
Where this commonly fails
  • Not marking proprietary information when reporting
  • Assuming reported data carries no protection

DFARS 7012: Malicious Software and Media Preservation

DFARS-7012-d
Malicious software submission to DC3

When the Contractor or a subcontractor discovers and isolates malicious software in connection with a reported cyber incident, it shall submit the malicious software to the DoD Cyber Crime Center (DC3) in accordance with DC3 or Contracting Officer instructions, and shall not send malicious software to the Contracting Officer.

Artefacts an auditor will ask for
  • Records of malicious software isolated and submitted to DC3
  • DC3 submission instructions followed
Where this commonly fails
  • Sending malware to the Contracting Officer
  • Not submitting isolated malware to DC3
DFARS-7012-e
Media preservation and protection (90 days)

The Contractor shall preserve and protect images of all known affected information systems identified in the incident review and all relevant monitoring/packet-capture data for at least 90 days from submission of the cyber incident report, to allow DoD to request the media or decline interest.

Artefacts an auditor will ask for
  • Forensic images of affected systems retained at least 90 days
  • Retained monitoring/packet-capture data with chain of custody
Where this commonly fails
  • Wiping or re-imaging affected systems before 90 days
  • No packet-capture/monitoring data retained

DFARS 7012: Other Requirements and Subcontract Flowdown

DFARS-7012-l
Other safeguarding or reporting requirements

The safeguarding and cyber incident reporting required by this clause are in addition to, and do not abrogate, any other safeguarding or reporting requirements imposed by law or by other provisions of the contract.

Artefacts an auditor will ask for
  • Register of other applicable safeguarding/reporting obligations in the contract
  • Evidence those obligations are met alongside 7012
Where this commonly fails
  • Treating 7012 as the only applicable cyber requirement
DFARS-7012-m
Subcontract flowdown

The Contractor shall include this clause, without alteration except to identify the parties, in subcontracts (including for commercial products or services) for operationally critical support or whose performance will involve covered defense information, determine whether information retains its identity as covered defense information, and require subcontractors to report cyber incidents to the prime (or next higher-tier subcontractor) and to DoD via dibnet.

Artefacts an auditor will ask for
  • Subcontracts containing clause 252.204-7012 unaltered
  • Determination of which subcontracts involve covered defense information
  • Subcontractor incident-reporting obligations to the prime and DoD
Where this commonly fails
  • Omitting the clause from in-scope subcontracts
  • No mechanism for subcontractor incident reporting to the prime
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.