DFARS 252.204-7012 - Safeguarding Covered Defense Information
Evidence request list. 12 controls, 12 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
DFARS 7012: Adequate Security
The Contractor shall provide adequate security on all covered contractor information systems; for systems that are not part of an IT service or system operated on behalf of the Government, this means implementing the security requirements in NIST SP 800-171 in effect at the time the solicitation is issued (or as authorised by the Contracting Officer).
- A System Security Plan (SSP) describing how each NIST SP 800-171 requirement is met
- An SPRS self-assessment score
- Implementation evidence for the 110 NIST SP 800-171 security requirements
- Missing or stale SSP
- No SPRS score submitted
- Claiming full implementation without supporting artefacts
Cloud computing services provided as part of an IT service operated on behalf of the Government are subject to clause 252.239-7010; where the Contractor uses an external cloud service provider to store, process or transmit covered defense information, the Contractor shall require the provider to meet security requirements equivalent to the FedRAMP Moderate baseline and to comply with paragraphs (c) through (g) of this clause.
- Evidence the external cloud service provider meets a FedRAMP Moderate-equivalent baseline
- Contractual flowdown of paragraphs (c)-(g) to the cloud provider
- Using a cloud provider with no FedRAMP Moderate equivalency
- No flowdown of incident-reporting obligations to the provider
The Contractor may submit requests to vary from NIST SP 800-171 in writing to the Contracting Officer for consideration by the DoD CIO, and may propose to use alternative but equally effective security measures; the Contracting Officer documents adjudication of any such requests.
- Written variance/deviation requests and the DoD CIO adjudication
- Documentation of any alternative-but-equally-effective measures accepted
- Deviating from 800-171 without an approved variance
- Undocumented compensating controls
DFARS 7012: Cyber Incident Reporting
When the Contractor discovers a cyber incident affecting a covered contractor information system, the covered defense information residing therein, or its ability to perform operationally critical support, it shall conduct a review for evidence of compromise and rapidly report the incident (within 72 hours of discovery) to DoD at https://dibnet.dod.mil, including the required report content, and shall have or acquire a DoD-approved medium assurance certificate to make the report.
- Incident review records evidencing the compromise assessment
- The cyber incident report submitted via dibnet.dod.mil within 72 hours
- A DoD-approved medium assurance certificate
- Reporting later than 72 hours after discovery
- No medium assurance certificate in place
- Incomplete incident report content
DFARS 7012: Definitions and Scope
The clause defines the key terms governing its obligations, including adequate security, compromise, contractor attributional/proprietary information, covered contractor information system, covered defense information (CUI), cyber incident, malicious software, media, operationally critical support, rapidly report (within 72 hours of discovery), and technical information.
- Mapping of contract data flows to identify covered defense information (CUI) and covered contractor information systems
- Determination of whether the contract designates operationally critical support
- Failing to identify which systems hold covered defense information
- Treating only classified data as in-scope
DFARS 7012: Forensics and Damage Assessment
Upon request, the Contractor shall provide DoD with access to additional information or equipment necessary to conduct a forensic analysis of a reported cyber incident.
- A process to provide DoD access to systems/data/equipment for forensic analysis
- Records of access provided on request
- Refusing or delaying forensic access requests
- No procedure to support DoD forensic analysis
If DoD elects to conduct a damage assessment, the Contracting Officer will request that the Contractor provide all of the damage assessment information gathered in accordance with the media preservation paragraph.
- Damage assessment information packaged from preserved media on request
- Support to the DoD damage assessment process
- Unable to produce damage assessment information from preserved media
DFARS 7012: Information Protection and Use
Information shared by the Contractor under this clause that qualifies as contractor attributional/proprietary information is safeguarded and used by DoD subject to restrictions on use and release (whether or not created by or for DoD), and all activities under the clause are conducted in accordance with applicable law and regulation.
- Markings on attributional/proprietary information provided to DoD
- Awareness of the use/release protections that apply to reported information
- Not marking proprietary information when reporting
- Assuming reported data carries no protection
DFARS 7012: Malicious Software and Media Preservation
When the Contractor or a subcontractor discovers and isolates malicious software in connection with a reported cyber incident, it shall submit the malicious software to the DoD Cyber Crime Center (DC3) in accordance with DC3 or Contracting Officer instructions, and shall not send malicious software to the Contracting Officer.
- Records of malicious software isolated and submitted to DC3
- DC3 submission instructions followed
- Sending malware to the Contracting Officer
- Not submitting isolated malware to DC3
The Contractor shall preserve and protect images of all known affected information systems identified in the incident review and all relevant monitoring/packet-capture data for at least 90 days from submission of the cyber incident report, to allow DoD to request the media or decline interest.
- Forensic images of affected systems retained at least 90 days
- Retained monitoring/packet-capture data with chain of custody
- Wiping or re-imaging affected systems before 90 days
- No packet-capture/monitoring data retained
DFARS 7012: Other Requirements and Subcontract Flowdown
The safeguarding and cyber incident reporting required by this clause are in addition to, and do not abrogate, any other safeguarding or reporting requirements imposed by law or by other provisions of the contract.
- Register of other applicable safeguarding/reporting obligations in the contract
- Evidence those obligations are met alongside 7012
- Treating 7012 as the only applicable cyber requirement
The Contractor shall include this clause, without alteration except to identify the parties, in subcontracts (including for commercial products or services) for operationally critical support or whose performance will involve covered defense information, determine whether information retains its identity as covered defense information, and require subcontractors to report cyber incidents to the prime (or next higher-tier subcontractor) and to DoD via dibnet.
- Subcontracts containing clause 252.204-7012 unaltered
- Determination of which subcontracts involve covered defense information
- Subcontractor incident-reporting obligations to the prime and DoD
- Omitting the clause from in-scope subcontracts
- No mechanism for subcontractor incident reporting to the prime
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.