ITAR Registration Code:
M49438 / Cage Code: 94U86

What defense contractors and subcontractors need to know about Covered Defense Information, NIST SP 800-171, cyber incident reporting, cloud services, System Security Plans, subcontractor flow-down, SPRS, and related DFARS clauses.

Quick Answer

DFARS 252.204-7012 is a Department of War contract clause that requires applicable contractors and subcontractors to safeguard Covered Defense Information, implement applicable NIST SP 800-171 security requirements, report cyber incidents, meet applicable cloud-security requirements, and flow the clause down to applicable subcontractors.

The 2024 CMMC materials identify DFARS 252.204-7012 as an existing cybersecurity requirement for protecting applicable CUI on contractor and subcontractor information systems. They identify NIST SP 800-171 as the minimum safeguarding baseline and separately identify cyber incident reporting as an obligation under the clause.

Key takeaway: DFARS 252.204-7012 is not simply a paperwork requirement. It establishes continuing cybersecurity obligations for applicable defense contractors and subcontractors handling Covered Defense Information on contractor information systems.

What Is DFARS 252.204-7012?

DFARS 252.204-7012 is titled Safeguarding Covered Defense Information and Cyber Incident Reporting.

The clause is part of the cybersecurity framework applied to certain defense contracts and subcontracts. It addresses the protection of Covered Defense Information when that information resides on or moves through applicable contractor information systems.

The 2024 CMMC materials identify DFARS 252.204-7012 as one of the cybersecurity requirements that predates CMMC and connect it with implementation of NIST SP 800-171 for applicable CUI.

That distinction matters because DFARS 252.204-7012 and CMMC are related, but they are not interchangeable.

DFARS 252.204-7012 establishes contractual cybersecurity obligations.

CMMC provides an assessment framework used to verify implementation of applicable cybersecurity requirements.

What Information Does DFARS 252.204-7012 Protect?

DFARS 252.204-7012 applies to Covered Defense Information handled on applicable contractor information systems.

The uploaded materials distinguish between several categories of federal information.

Federal Contract Information

Federal Contract Information, or FCI, is information that is not intended for public release and is provided by or generated for the Government under a contract to develop or deliver a product or service.

The CMMC Level 1 materials tie FCI to the basic safeguarding requirements in FAR 52.204-21.

Controlled Unclassified Information

Controlled Unclassified Information, or CUI, is information that requires safeguarding or dissemination controls under applicable law, regulation, or government-wide policy.

The uploaded CMMC materials identify NIST SP 800-171 as the minimum safeguarding requirement for CUI in applicable nonfederal systems.

Covered Defense Information

DFARS 252.204-7012 specifically addresses Covered Defense Information.

For contractors, understanding what information is received, created, processed, stored, or transmitted is critical because that determines which systems and security requirements may apply.

What Does DFARS 252.204-7012 Require?

The clause can be understood through several core obligations.

1. Safeguard Covered Defense Information

Contractors must provide adequate security for Covered Defense Information residing on or transiting through applicable contractor information systems.

The 2024 CMMC materials identify NIST SP 800-171 as the minimum safeguarding requirement for applicable CUI.

That means security requirements must be implemented in the actual systems that process, store, transmit, or protect covered information.

2. Implement NIST SP 800-171 Security Requirements

NIST SP 800-171 provides security requirements for protecting CUI in nonfederal systems and organizations.

The uploaded NIST material states that the requirements apply to components of nonfederal systems that process, store, or transmit CUI, as well as components that provide protection for those systems.

A simple way to understand the relationship is:

3. Maintain Appropriate Security Documentation

The NIST SP 800-171 framework requires organizations to document how applicable security requirements are implemented or planned to be implemented.

One of the central documents used for this purpose is the System Security Plan, or SSP.

The SSP describes the system and how applicable security requirements are implemented or planned to be implemented. The Level 2 scoping guidance also requires treatment of important asset categories to be documented in the SSP.

4. Report Cyber Incidents

DFARS 252.204-7012 establishes cyber incident reporting obligations for applicable contractor systems and addresses incidents affecting the contractor’s ability to perform requirements designated as operationally critical. Reports are submitted through the DoD’s DIBNet portal.

The 2024 CMMC overview identifies cyber incident reporting as an existing obligation under the clause.

Incident reporting should therefore be treated as a separate contractual responsibility rather than something that disappears after an assessment.

5. Address Cloud-Security Requirements

When a Cloud Service Provider processes, stores, or transmits CUI, additional cloud-security requirements apply.

The contractor remains responsible for its own environment, system configuration, security documentation, assessment scope, and customer-assigned responsibilities.

6. Flow Applicable Requirements to Subcontractors

DFARS cybersecurity obligations can extend beyond the prime contractor.

The uploaded CMMC materials expressly identify subcontractor flow-down requirements.

If Covered Defense Information is shared with a subcontractor, the prime contractor must understand which requirements need to be met.

For subcontractors, this means cybersecurity obligations can originate through a prime contract even when the subcontractor does not contract directly with the Department of War.

Need CMMC & DOW Compliance Documentation?

Stop searching across multiple sources for the guidance you need. Access CMMC resources, DOW compliance documentation, DFARS information, SSP guidance, POA&M resources, and assessment materials in one place.

Download the CMMC & DOW Compliance Documentation PDF to help support your cybersecurity and compliance program.

Does CMMC Replace DFARS 252.204-7012?

No. CMMC does not replace the underlying safeguarding and reporting obligations associated with DFARS 252.204-7012. CMMC is an assessment framework used to verify implementation of applicable cybersecurity requirements.

The 2024 CMMC overview describes CMMC as a consistent assessment methodology for determining whether a prospective contractor has implemented cybersecurity protections needed to safeguard government information.

It identifies DFARS 252.204-7012, 252.204-7019, and 252.204-7020 as existing cybersecurity requirements.

The CMMC Assessment Process likewise describes CMMC as an assessment and certification process rather than a replacement for underlying contractual requirements.

The relationship can be summarized simply:

DFARS 252.204-7012 vs. 7019, 7020, and 7021

Defense contractors often encounter several related DFARS clauses, and the numbers can be confusing.

ClauseWhat It Does
DFARS 252.204-7012Safeguarding Covered Defense Information and cyber incident reporting
DFARS 252.204-7019Requires current NIST SP 800-171 assessment information
DFARS 252.204-7020Addresses government assessment access and related subcontractor obligations
DFARS 252.204-7021Establishes CMMC-related contractual requirements

The 2024 CMMC overview distinguishes these responsibilities. It states that 7019 requires implementation of 7012 and current Basic NIST SP 800-171 assessment information in SPRS; 7020 addresses government access for higher-level assessments and applicable subcontractor assessment requirements; and 7021 addresses CMMC Status, assessment, affirmation, and flow-down requirements.

DFARS 252.204-7012

This is the core safeguarding and cyber incident reporting clause.

It addresses protection of applicable information and implementation of NIST SP 800-171 requirements.

DFARS 252.204-7019

The uploaded materials state that 7019 requires implementation of 7012 and requires at least a current Basic NIST SP 800-171 assessment to be posted in the Supplier Performance Risk System, or SPRS.

DFARS 252.204-7020

The uploaded materials describe 7020 as addressing government access when necessary to conduct or renew higher-level assessments.

It also addresses applicable subcontractor assessment responsibilities.

DFARS 252.204-7021

The uploaded CMMC overview identifies 7021 as the CMMC clause.

It addresses CMMC Status requirements, assessments, annual affirmations, and subcontractor flow-down requirements.

NIST SP 800-171 Rev. 2 vs. Rev. 3

NIST SP 800-171 Revision 3 is the current NIST publication, but contractors still need to distinguish the current NIST publication from the version incorporated into applicable contractual and assessment requirements.

NIST withdrew SP 800-171 Revision 2 on May 14, 2024, and superseded it with Revision 3.

However, the 2024 CMMC materials state that CMMC assessment requirements remain aligned to Revision 2.

They also state that contractors may implement Revision 3 but must still comply with Revision 2 requirements not covered in Revision 3 to satisfy the CMMC assessment requirements described in those materials.

The practical lesson is important:

The newest NIST publication does not automatically change the requirements incorporated into an existing contract or assessment framework.

Contractors should distinguish between:

Does DFARS 252.204-7012 Require a System Security Plan?

Yes. For systems subject to the applicable NIST SP 800-171 requirements, the organization must maintain a System Security Plan describing the system and how applicable security requirements are implemented or planned to be implemented.

NIST SP 800-171 Revision 2 requires organizations to describe in an SSP how specified security requirements are met or how the organization plans to meet them.

Separately, the CMMC Level 2 Scoping Guide requires the treatment of CUI Assets, Security Protection Assets, and Contractor Risk Managed Assets to be documented in the SSP.

The SSP should accurately describe the environment in which CUI is protected and how applicable security requirements are implemented.

What Should a System Security Plan Describe?

An SSP should accurately reflect the applicable information system and the implementation of relevant security requirements.

Based on the uploaded materials, this includes documenting how applicable requirements are satisfied or planned to be satisfied and describing treatment of relevant assets.

Depending on the environment, the SSP may address:

The Level 2 Scoping Guide also requires organizations to maintain an asset inventory and provide a network diagram of the assessment scope.

Together, the SSP, asset inventory, and network diagram describe the security environment and assessment boundary.

What Are the Cloud Requirements Under DFARS 252.204-7012?

When a Cloud Service Provider processes, stores, or transmits CUI, the applicable cloud service must satisfy the applicable FedRAMP requirements associated with DFARS 252.204-7012. Using a qualifying cloud provider does not make the contractor compliant by itself.

The organization remains responsible for its own environment and assigns security responsibilities.

This can include:

The Level 2 Scoping Guide makes clear that assets processing, storing, or transmitting CUI remain part of the assessment scope and that security-protection assets can also be in scope.

Cloud compliance should therefore be viewed as a shared responsibility issue, not as a transfer of all cybersecurity responsibility to the provider.

What Is a Customer Responsibility Matrix?

A Customer Responsibility Matrix, or CRM, divides security responsibilities between a cloud provider and its customer.

The purpose of the CRM is to identify which responsibilities the provider handles, and which remain with the contractor.

Customer-assigned responsibilities still need to be documented and implemented by the contractor.

That means a contractor should not treat a compliant cloud provider as proof that the contractor itself has satisfied every applicable requirement.

Does DFARS 252.204-7012 Apply to Subcontractors?

Yes, applicable requirements can flow down to subcontractors when the subcontract involves Covered Defense Information or otherwise meets the applicable flow-down conditions.

The 2024 CMMC materials expressly identify subcontractor flow-down requirements.

This makes subcontractor management an important part of DFARS compliance.

Before sharing protected information, a prime contractor should understand:

Subcontractors should likewise review their agreements carefully rather than assuming cybersecurity requirements apply only to prime contractors.

How Does SPRS Relate to DFARS 252.204-7012?

SPRS is closely connected to the NIST SP 800-171 assessment requirements implemented through related DFARS clauses.

The uploaded CMMC overview states that DFARS 252.204-7019 requires at least a current Basic NIST SP 800-171 assessment to be posted in SPRS.

It also states that DFARS 252.204-7020 supports government access for higher-level assessments and requires applicable subcontractors to conduct and submit assessments.

The simplest way to understand the relationship is:

Having assessment information in SPRS should not be confused with the underlying obligation to implement the applicable security requirements.

What Is a NIST SP 800-171 Assessment?

A NIST SP 800-171 assessment evaluates an organization’s implementation of applicable NIST SP 800-171 security requirements.

The uploaded materials describe a Basic Assessment as part of the existing cybersecurity assessment framework and connect DFARS 252.204-7019 with maintaining current assessment information in SPRS.

A Basic Assessment produces an assessment score reflecting implementation of applicable NIST SP 800-171 requirements, using the NIST SP 800-171 DoD Assessment Methodology.

DFARS 252.204-7019 requires current assessment information to be available in SPRS under the conditions described in the applicable requirements.

CMMC provides a separate assessment mechanism for verifying implementation of applicable cybersecurity requirements.

Can Contractors Use Alternative Security Measures?

The supplied materials recognize approved alternative security measures.

However, that does not mean a contractor can independently decide to substitute one security measure for another.

Where an alternative security measure has been formally approved through the applicable government process, that approval should be reflected in the organization’s security documentation.

The key distinction is between:

Common DFARS 252.204-7012 Mistakes

Several mistakes can create unnecessary compliance risk.

Assuming CMMC Replaces DFARS 252.204-7012

It does not. CMMC assesses implementation of applicable cybersecurity requirements. It does not eliminate the underlying contractual obligations.

Treating NIST SP 800-171 as Optional Guidance

Where applicable DFARS requirements incorporate NIST SP 800-171, the security requirements become part of the contractor’s contractual cybersecurity obligations.

Maintaining an Incomplete SSP

The SSP should accurately describe the system and how applicable requirements are implemented or planned to be implemented. An SSP that does not reflect the actual environment can create problems during an assessment.

Assuming the Cloud Provider Handles Everything

Cloud services operate under a shared-responsibility model. Contractors remain responsible for responsibilities assigned to the customer side of that model.

Ignoring Subcontractor Flow-Down

Protected information can move through multiple tiers of the defense supply chain. Applicable requirements must be addressed when information is shared with subcontractors.

Assuming Revision 3 Automatically Replaces Revision 2

NIST may publish a newer revision, but that does not automatically change the revision incorporated into an existing contract or assessment framework.

Confusing an SPRS Assessment with Full Compliance

A current assessment record in SPRS does not by itself demonstrate that every underlying security requirement has been fully implemented.

Practical DFARS 252.204-7012 Checklist

When reviewing an applicable contract or subcontract, determine whether:

Frequently Asked Questions

What Is DFARS 252.204-7012?

DFARS 252.204-7012 is the safeguarding and cyber incident reporting clause for applicable defense contracts involving Covered Defense Information. It connects applicable contractor information systems with NIST SP 800-171 safeguarding requirements and establishes cyber incident reporting obligations.

Who Must Comply with DFARS 252.204-7012?

Applicable prime contractors and subcontractors may be subject to the clause depending on the information involved and the contractual requirements flowing down to them. Organizations should review the actual solicitation, contract, or subcontract to determine which requirements apply.

Does DFARS 252.204-7012 Require NIST SP 800-171?

Yes. The supplied government materials identify NIST SP 800-171 as the minimum safeguarding baseline associated with DFARS 252.204-7012 for applicable systems handling CUI.

Does DFARS 252.204-7012 Require a System Security Plan?

Yes, for systems subject to the applicable NIST SP 800-171 requirements. The SSP describes the system and how applicable security requirements are implemented or planned to be implemented.

Does DFARS 252.204-7012 Apply to Subcontractors?

It can. The CMMC materials supplied expressly identify subcontractor flow-down requirements within the defense supply chain.

What Are the Cloud Requirements Under DFARS 252.204-7012?

Cloud providers handling CUI must satisfy the applicable cloud-security requirements associated with DFARS 252.204-7012, while the contractor remains responsible for its own systems, configuration, documentation, and assigned responsibilities.

Is DFARS 252.204-7012 the Same as CMMC?

No. DFARS 252.204-7012 establishes safeguarding and incident-reporting obligations. CMMC provides an assessment mechanism used to verify implementation of applicable cybersecurity requirements.

What Is the Difference Between 7012, 7019, 7020, and 7021?

7012 addresses safeguarding and incident reporting; 7019 addresses current NIST SP 800-171 assessment information; 7020 addresses government assessment access and related subcontractor obligations; and 7021 establishes CMMC-related contractual requirements.

Does NIST SP 800-171 Rev. 3 Replace Rev. 2 for CMMC?

Not automatically. NIST withdrew Rev. 2 and replaced it with Rev. 3 in May 2024, but the supplied CMMC materials continued to align CMMC assessment requirements with Revision 2.

Does Having an SPRS Assessment Mean You Are Fully Compliant?

Not necessarily. SPRS records assessment information, but contractors still need to implement the applicable underlying security requirements and maintain accurate supporting documentation.

Authoritative Sources Used

This article relies on the supplied government and NIST materials:

The Bottom Line

DFARS 252.204-7012 is a foundational cybersecurity clause for applicable defense contractors and subcontractors handling Covered Defense Information on contractor information systems.

For organizations subject to the clause, central responsibilities include protecting Covered Defense Information, implementing applicable NIST SP 800-171 security requirements, maintaining appropriate security documentation, understanding cyber incident reporting obligations, addressing cloud-service responsibilities, and flowing applicable requirements to subcontractors.

CMMC, SPRS, DFARS 252.204-7019, 252.204-7020, and 252.204-7021 all interact with those obligations, but they serve different purposes and should not be treated as interchangeable.

Schedule a free consultation with the Brea Networks team to review your current environment, identify compliance risks, and understand what steps are required to move forward. A short conversation can help you avoid costly mistakes and focus on what matters for contract eligibility and security.

About Brea Networks

Brea Networks is a cybersecurity and compliance-focused IT partner dedicated to supporting Defense Industrial Base (DIB) contractors. We help organizations understand and implement the security requirements outlined in FAR 52.204-21, DFARS 252.204-7012, and the CMMC framework from Level 1 self-assessments to Level 2 and Level 3 readiness. Our team works alongside contractors to strengthen system security, define assessment scope, prepare documentation such as System Security Plans (SSPs) and POA&Ms, and build sustainable cybersecurity programs that protect FCI and CUI. Whether you are preparing for a self-assessment or simply improving your security posture. Brea Networks provides practical guidance and technical expertise to help you move forward with confidence.

Brea Networks, LLC
471 W Lambert Rd Ste 105
Brea, CA 92821

https://www.cmmccompliance.us
https://www.breanetworks.com

Telephone: 714-592-0063

Redirecting to Download Full Offline Documents

Redirecting to Download GCC High Buyer`s Guide

Redirecting to ITAR Compliance Checklist

Redirecting to CMMC Level 2 Audit Checklist

Redirecting to CMMC Level 1 Audit Checklist

Redirecting to Discovery Call