DFARS 252.204-7012 - Safeguarding Covered Defense Information
What is DFARS 252.204-7012 - Safeguarding Covered Defense Information?
DFARS clause 252.204-7012 (48 CFR 252.204-7012, clause edition MAY 2024). Requires DoD contractors to provide adequate security on covered contractor information systems by implementing NIST SP 800-171, to rapidly report cyber incidents (within 72 hours of discovery) to DoD via dibnet.dod.mil using a DoD-approved medium assurance certificate, to submit isolated malicious software to the DoD Cyber Crime Center (DC3), to preserve affected media and monitoring data for at least 90 days, to support forensic analysis and damage assessment, and to flow the clause down to in-scope subcontracts. It comprises 12 controls organised across 7 domains, and applies in the United States (DoD).
How DFARS 252.204-7012 - Safeguarding Covered Defense Information maps to other frameworks
All 12 controls, each one mapped to the equivalent requirement in other standards, with the evidence that carries across and the mappings that were judged and rejected shown alongside. No account needed to look.
See the control mappings →The 7 domains DFARS 252.204-7012 - Safeguarding Covered Defense Information groups its controls into
Where DFARS 252.204-7012 - Safeguarding Covered Defense Information overlaps with the standards you already hold
What DFARS 252.204-7012 - Safeguarding Covered Defense Information means in your sector
What DFARS 252.204-7012 - Safeguarding Covered Defense Information means for your job
Questions people ask about DFARS 252.204-7012 - Safeguarding Covered Defense Information
What is DFARS 252.204-7012 - Safeguarding Covered Defense Information?
How many controls does DFARS 252.204-7012 - Safeguarding Covered Defense Information have?
Where does DFARS 252.204-7012 - Safeguarding Covered Defense Information apply?
What frameworks does DFARS 252.204-7012 - Safeguarding Covered Defense Information map to?
How do I get started with DFARS 252.204-7012 - Safeguarding Covered Defense Information compliance?
Query DFARS 252.204-7012 - Safeguarding Covered Defense Information programmatically
DFARS 252.204-7012 - Safeguarding Covered Defense Information, its 12 controls and every mapping into other standards are available over a REST endpoint and an MCP server, so an agent can read them directly. The free tier is 10 calls a day and needs no signup.
DFARS 252.204-7012 - Safeguarding Covered Defense Information API reference and MCP config →What DFARS 252.204-7012 - Safeguarding Covered Defense Information requires, control by control
Each page carries the requirement text for one DFARS 252.204-7012 - Safeguarding Covered Defense Information control and what an assessor expects to see as evidence.
- DFARS-7012-B Adequate security - implement NIST SP 800-171
- DFARS-7012-C Cyber incident reporting (72-hour rapid report)
- DFARS-7012-D Malicious software submission to DC3
- DFARS-7012-E Media preservation and protection (90 days)
- DFARS-7012-F Access to additional information or equipment for forensic analysis
- DFARS-7012-G Cyber incident damage assessment activities
How ready are you for DFARS 252.204-7012 - Safeguarding Covered Defense Information?
Answer 25 questions and get a professional readiness report with gap analysis, maturity scores, and prioritised action items. Results in 5 minutes.