DFARS 252.204‑7012 ("Safeguarding Covered Defense Information and Cyber Incident Reporting") requires defense contractors handling Covered Defense Information to implement adequate security per NIST SP 800-171 Rev 2 (110 controls), report cyber incidents to DoD within 72 hours via dibnet.dod.mil, preserve affected media for 90 days, and submit malicious software to the DoD Cyber Crime Center.
The clause has been in defense contracts since 2013, but enforcement posture has changed. Where contracting officers once accepted self-attestation, the False Claims Act now sits behind every signed System Security Plan. The cost of a misstatement is no longer administrative; it is litigated.
This analysis walks the clause section-by-section, identifies the three places contractors most often fail, and offers a remediation pattern that has held up under DCMA review on engagements across the Defense Industrial Base.
What the clause requires.
The operative paragraph is (b)(2)(ii)(A): contractors shall implement, at a minimum, the security requirements in NIST SP 800-171 Revision 2. "Adequate security" is the contract's term of art; not a checklist, but a continuous obligation that the contract makes a contract term.
- 110 controls across 14 control families, mapped to the contract by reference.
- 72-hour reporting on discovery of any cyber incident affecting Covered Defense Information.
- 90-day forensic media preservation, with chain of custody.
- Annual System Security Plan and Plan of Action & Milestones, signed by a senior official.
The three places contractors fail.
Across the engagements The Audit Defense has reviewed since 2022, the same three failures recur. None are exotic; all are documentation discipline.
First: the 72-hour clock starts on discovery, not on confirmation.
Contractors interpret "discovery" as "the moment we are sure" and lose the first 36 hours to triage. The clause is unambiguous; the clock begins when an analyst reasonably believes Covered Defense Information may be affected. The audit fix. Establish a clock-management protocol owned by a named incident commander; pre-stage the dibnet submission template; rehearse the cross-functional handoff once per quarter.
Second: the System Security Plan is treated as a deliverable, not a register.
An SSP authored once and shelved is, on a False Claims Act review, a misrepresentation. The plan must reflect the operating environment as it is, not as it was at procurement. The audit fix. Operate the SSP as a living register; tie every Plan of Action & Milestones entry to a control, an owner, and a target date; review quarterly; sign annually.
Third: subcontractor flow-down is asserted, not verified.
Prime contractors flow 7012 to subcontractors by reference and assume the obligation transfers cleanly. It does not. The prime remains accountable for the subcontractor's Covered Defense Information posture under (m). The audit fix. Require subcontractor SSP excerpts as part of award; verify control coverage on the subcontractor's environment, not on the prime's.
The contract makes adequate security a contract term. The False Claims Act makes its assertion a litigated one. — DCMA review observation, 2025
What this means for CMMC alignment.
DFARS 7012 and CMMC 2.0 share the same control floor; NIST SP 800-171 Rev 2; but treat assessment differently. 7012 is self-attestation; CMMC adds third-party assessment for Level 2 contracts and government-led for Level 3. A 7012-clean program is the prerequisite for a CMMC Level 2 certification; the inverse is not true.
Contractors preparing for CMMC Level 2 should, in order: (1) close the 800-171 control gaps already implied by 7012; (2) document continuous monitoring of the controls, not point-in-time compliance; (3) engage a Certified Third-Party Assessment Organization six months before contract award.
Most contractors fail not on the controls themselves but on the documentation that proves the controls operate continuously.
The 72-hour reporting clock is the single audit risk most often overlooked. It begins on discovery, not on confirmation; a named incident commander, a pre-staged submission template, and a quarterly rehearsal are the practical fix. Treat the System Security Plan as a register, not a deliverable, and the rest of the clause aligns to its own logic.
Subscribe to The Authority Brief to receive next week's analysis: a walkthrough of the DCMA's 2026 audit posture and what it means for primes operating under multi-year IDIQ awards.
Adequate security is the contract; not a posture you achieve, but a posture you sustain.
— Josef Kamara · CPA, CISSP, CISA · The Audit Defense · 28 April 2026