
Key takeaways
- DFARS 252.204-7012 puts four obligations into your contract, covering safeguarding, incident reporting, cloud services, and subcontractor flowdown, and you implement all four yourself, since no auditor issues a DFARS certificate.
- The July 2026 suspension of third-party CMMC assessment left the clause untouched. All four still bind you, along with the annual affirmation a senior official signs in SPRS (Supplier Performance Risk System).
- A DoD (Department of Defense) class deviation holds the clause at NIST SP 800-171 Revision 2, which NIST retired in May 2024.
- The 72-hour report goes through DIBNet (Defense Industrial Base Cybersecurity portal), which will not accept it without a medium assurance certificate.
- Any cloud provider touching covered defense information has to clear the FedRAMP Moderate baseline in full, and you are the one who holds the evidence proving it.
A prime sent through a subcontract with DFARS 252.204-7012 in it, which binds you from the day of award, applies to every system that touches covered defense information, and follows that information out into your cloud providers and your own subcontractors.
What does DFARS 252.204-7012 require?
The clause text sets out four obligations, each with a different trigger.
What counts as covered defense information?
Covered Defense Information (CDI) is unclassified information that DoD gives you, or that you generate performing the contract, where law or policy requires safeguarding. The clause anchors that to the CUI Registry, which puts CDI and Controlled Unclassified Information on much the same ground. Your contract or the data itself should be marked to tell you which you hold.
Federal Contract Information (FCI) sits below it: contract information not intended for public release, triggering FAR 52.204-21 and its 15 basic safeguarding requirements against the 110 in NIST SP 800-171. A supplier holding only FCI does not owe DFARS 7012.
Does the CMMC pause change what you owe under DFARS 7012?
Nothing in the clause changed when the Department suspended Phase 2 of the CMMC program on July 13, 2026, and opened a 60-day review. Phase 2 would have made third-party C3PAO (CMMC Third-Party Assessment Organization) certification a condition of award from November 10, 2026, and the suspension arrived as a memorandum, not a regulation, reaching that assessment requirement alone.
Phase 1 continues underneath it. You still self-assess against NIST SP 800-171 and post the score to SPRS, and a senior official still affirms it every year.
The weight now sits on your own attestation. An SPRS affirmation is a representation to the government, and misrepresenting it carries False Claims Act exposure under the Department of Justice Civil Cyber-Fraud Initiative. The same exposure runs one level down, where CMMC Level 1 self-assessments carry their own annual affirmation.
How to implement DFARS 252.204-7012
The work runs in a fixed order, and each step ends on a condition you can check before moving to the next.
Why the clause still points to a withdrawn version of NIST SP 800-171
The clause used to require whichever version of NIST SP 800-171 was in effect when the solicitation was issued. On May 2, 2024, Class Deviation 2024-O0013 replaced that with Revision 2 by name.
Twelve days later, NIST published Revision 3, reorganizing the standard into 17 families and cutting 110 requirements to 97, and withdrew Revision 2 the same day. The deviation has never been rescinded. Your contract still names a document NIST no longer publishes.
Revision 3 remains a migration to plan for, and DoD published its parameter values for it in April 2025.
What the 72-hour cyber incident report involves
The hardest part of this obligation has nothing to do with security. The clock starts at discovery, not at confirmation. Four things belong in the runbook before that matters:
- The medium assurance certificate, applied for and issued
- DIBNet registration, tested with someone who can log in
- Malware handling, with a defined route for isolated samples to reach DC3
- Evidence preservation, with the scope of the 90-day hold already decided
None of these can be arranged after an incident starts.
What DFARS 7012 requires of your cloud providers
Paragraph (b)(2)(ii)(D) is where that requirement lives, and a December 2023 DoD CIO memorandum sets the bar for what equivalent means. A provider qualifies by holding FedRAMP Moderate or High authorization, or by producing an assessment from a FedRAMP-recognized 3PAO (third-party assessment organization) showing full compliance with the Moderate baseline, backed by a System Security Plan, Security Assessment Plan, Security Assessment Report, and POA&M. Every POA&M must be closed before the service carries your data, and the assessment repeats annually.

Your own program can carry open POA&Ms and an SPRS score below 110 while you remediate. Your provider's evidence has to be complete on day one. The memo also leaves that body of evidence in your hands to collect and hold, and names you as the reporting party if the cloud service itself is compromised. That makes cloud selection a third-party risk decision.
How the clause flows down to subcontractors
The clause reaches you through flowdown and travels the same route to your own suppliers: every subcontract involving covered defense information or operationally critical support carries it. Subcontracts for commercial products and services are covered, with a carve-out for COTS (commercially available off-the-shelf) suppliers.
Reporting duty sits with different parties depending on the vendor. A breached subcontractor reports to DoD directly and hands you the incident report number. When the breach is at your cloud provider, the 72-hour filing is yours.
Primes can also require CMMC Level 2 through their own contractual requirements, regardless of the Department's timeline. If you are selling into government through a prime, the flowdown schedule in your subcontract governs you.
Put DFARS 7012 on autopilot with Koop
Your environment moves even when the clause does not, and last year's SPRS score still has to be true after twelve months of infrastructure changes, new subcontracts, and a shifting cloud stack.
- Housekeeper AI Agent keeps evidence current between assessments, cutting 95% of the manual work.
- Automated SSP, POA&M, and SPRS scoring with GovCloud integrations, putting the artifacts in place before DIBCAC (Defense Industrial Base Cybersecurity Assessment Center) or a prime asks for them.
- Compliance, vendor risk, and insurance on one platform, with 3.6x better value and 60%savings on DFARS readiness compared with fragmented tooling.
Frequently asked questions
- What is the difference between DFARS 7012 and CMMC?
DFARS 7012 is the contract clause requiring you to implement NIST SP 800-171 and report incidents. CMMC is the program built to verify you did exactly that.
- Does DFARS 252.204-7012 apply to subcontractors?
Yes, wherever a subcontract involves covered defense information or operationally critical support. The prime includes the clause without alteration, including in subcontracts for commercial products and services, with a carve-out for those solely supplying commercially available off-the-shelf items.
- Which NIST SP 800-171 revision applies under DFARS 7012?
Revision 2, even though NIST no longer publishes it. DoD Class Deviation 2024-O0013 named that revision in May 2024, and it has not been rescinded. A program built to Revision 3's 97 requirements does not satisfy the clause as written.



