DFARS 252.204-7012 — Safeguarding Covered Defense Information
Defense Federal Acquisition Regulation Supplement (DFARS) clause 252.204-7012 requires Department of Defense (DoD) contractors and subcontractors to provide adequate security for Covered Defense Information (CDI) and report cyber incidents. Contractors must implement NIST SP 800-171 security requirements, report cyber incidents within 72 hours to the DoD Cyber Crime Center (DC3), and preserve images for 90 days. Foundational requirement flowing down through the defense industrial base (DIB).
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (7)
Adequate Security Requirements
| Code | Title |
|---|---|
| 7012(c)(1) | NIST SP 800-171 Implementation |
| 7012(c)(2) | System Security Plan |
| 7012(c)(3) | Plan of Action and Milestones |
| 7012(c)(4) | Alternative Security Measures |
| 7012(c)(5) | Cloud Computing Security |
Cyber Incident Reporting
| Code | Title |
|---|---|
| 7012(d)(1) | Rapid Incident Reporting |
| 7012(d)(2) | Incident Report Content |
| 7012(d)(3) | Malicious Software Submission |
| 7012(d)(4) | Media Preservation |
Definitions and Scope
Sections 5-10: Key definitions and covered entities
| Code | Title |
|---|---|
| 7012(a) | Definitions |
| 7012(b)(1) | Covered Defence Information Identification |
| 7012(b)(2) | Scope of Protected Systems |
| 7012(b)(3) | COTS Exclusion |
| BIPA-SEC5-1 | Biometric Identifier Definition |
| BIPA-SEC5-2 | Biometric Information Definition |
| BIPA-SEC5-3 | Private Entity Definition |
| CTDPA-1 | Definitions |
| CTDPA-2 | Applicability Thresholds |
| MSA-5 | Definition of Modern Slavery |
| MSA-Commonwealth | Commonwealth Entities |
| MSA-Threshold | Revenue Threshold |
| NAIC-668-1 | Title and Purpose |
| NAIC-668-3 | Definitions |
| NAIC-668-9 | Exemptions |
Flow-Down and Subcontractor Requirements
| Code | Title |
|---|---|
| 7012(f)(1) | Subcontract Flow-Down |
| 7012(f)(2) | Subcontractor Incident Reporting |
| 7012(f)(3) | Subcontractor Security Compliance |
| 7012(g) | Compliance Verification |
Incident Reporting
Cyber incident reporting and preservation
Investigation Support
| Code | Title |
|---|---|
| 7012(e)(1) | Damage Assessment Support |
| 7012(e)(2) | Access to Equipment and Information |
| 7012(e)(3) | Contractor Attribution Protection |
| 7012(e)(4) | 90-Day Data Retention |
Security Requirements
QKD module and network security
Maps to 636 other frameworks
Frequently Asked Questions
What is DFARS 252.204-7012 — Safeguarding Covered Defense Information?
DFARS 252.204-7012 — Safeguarding Covered Defense Information is a compliance framework from United States (DoD) with 7 domains and 32 controls. Defense Federal Acquisition Regulation Supplement (DFARS) clause 252.204-7012 requires Department of Defense (DoD) contractors and subcontractors to provide adequate security for Covered Defense Information (CDI) and report cyber incidents. Contractors must implement NIST SP 800-171 security requirements, report cyber incidents within 72 hours to the DoD Cyber Crime Center (DC3), and preserve images for 90 days. Foundational requirement flowing down through the defense industrial base (DIB). It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does DFARS 252.204-7012 — Safeguarding Covered Defense Information have?
DFARS 252.204-7012 — Safeguarding Covered Defense Information has 32 controls organised across 7 domains. The largest domains are Definitions and Scope (15 controls), Adequate Security Requirements (5 controls), Cyber Incident Reporting (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does DFARS 252.204-7012 — Safeguarding Covered Defense Information map to?
DFARS 252.204-7012 — Safeguarding Covered Defense Information maps to 636 other compliance frameworks. The top mapping partners are Singapore Government Instruction Manual on ICT&SS Management (IM8) (38% coverage), ASEAN Data Management Framework (34% coverage), NIST SP 800-124 Rev 2 — Mobile Device Security (34% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with DFARS 252.204-7012 — Safeguarding Covered Defense Information compliance?
Start your DFARS 252.204-7012 — Safeguarding Covered Defense Information compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about DFARS 252.204-7012 — Safeguarding Covered Defense Information requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 32 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 692 frameworks.
Get Started Free →Free forever — no credit card required