DFARS 252.204-7012 — Safeguarding Covered Defense Information
Defense Federal Acquisition Regulation Supplement (DFARS) clause 252.204-7012 requires Department of Defense (DoD) contractors and subcontractors to safeguard Covered Defense Information (CDI) and report cyber incidents. Contractors must implement security requirements in accordance with NIST SP 800-171 and comply with additional requirements related to cyber incident reporting and evidence preservation. This clause is being transitioned under the Cybersecurity Maturity Model Certification (CMMC) framework.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (25)
Adequate Security Requirements
| Code | Title |
|---|---|
| 7012(c)(1) | NIST SP 800-171 Implementation |
| 7012(c)(2) | System Security Plan |
| 7012(c)(3) | Plan of Action and Milestones |
| 7012(c)(4) | Alternative Security Measures |
| 7012(c)(5) | Cloud Computing Security |
Cloud
| Code | Title |
|---|---|
| DFARS-7012-b3 | Cloud Service Provider FedRAMP Moderate |
Compliance Overlap
| Code | Title |
|---|---|
| DFARS-7012-i | Other Requirements Not Limited |
Confidentiality
| Code | Title |
|---|---|
| DFARS-7012-e | Protection of Reported Information |
Cooperation
| Code | Title |
|---|---|
| DFARS-7012-h | Forensic Analysis Cooperation |
Cyber Incident Reporting
| Code | Title |
|---|---|
| 7012(d)(1) | Rapid Incident Reporting |
| 7012(d)(2) | Incident Report Content |
| 7012(d)(3) | Malicious Software Submission |
| 7012(d)(4) | Media Preservation |
Damage Assessment
| Code | Title |
|---|---|
| DFARS-7012-c5 | Cyber Incident Damage Assessment Activities |
Definitions and Scope
Sections 5-10: Key definitions and covered entities
| Code | Title |
|---|---|
| 7012(a) | Definitions |
| 7012(b)(1) | Covered Defence Information Identification |
| 7012(b)(2) | Scope of Protected Systems |
| 7012(b)(3) | COTS Exclusion |
| BIPA-SEC5-1 | Biometric Identifier Definition |
| BIPA-SEC5-2 | Biometric Information Definition |
| BIPA-SEC5-3 | Private Entity Definition |
| CTDPA-1 | Definitions |
| CTDPA-2 | Applicability Thresholds |
| MSA-5 | Definition of Modern Slavery |
| MSA-Commonwealth | Commonwealth Entities |
| MSA-Threshold | Revenue Threshold |
| NAIC-668-1 | Title and Purpose |
| NAIC-668-3 | Definitions |
| NAIC-668-9 | Exemptions |
DoD Cooperation
| Code | Title |
|---|---|
| DFARS-7012-c4 | Access to Additional Information |
Documentation
| Code | Title |
|---|---|
| DFARS-7012-POAM | Plan of Action and Milestones Currency |
| DFARS-7012-SSP | System Security Plan Currency |
Flow-Down and Subcontractor Requirements
| Code | Title |
|---|---|
| 7012(f)(1) | Subcontract Flow-Down |
| 7012(f)(2) | Subcontractor Incident Reporting |
| 7012(f)(3) | Subcontractor Security Compliance |
| 7012(g) | Compliance Verification |
Flowdown
| Code | Title |
|---|---|
| DFARS-7012-f | Contractor Use of Subcontractors |
Forensic Preservation
| Code | Title |
|---|---|
| DFARS-7012-c3 | Media Preservation |
Incident Analysis
| Code | Title |
|---|---|
| DFARS-7012-c1ii | Incident Review Scope |
Incident Reporting
| Code | Title |
|---|---|
| DFARS-7012-c1 | Cyber Incident Reporting Timeline |
Incident Reporting
Cyber incident reporting and preservation
| Code | Title |
|---|---|
| DFARS-7012-c1 | Cyber Incident Reporting Timeline |
Investigation Support
| Code | Title |
|---|---|
| 7012(e)(1) | Damage Assessment Support |
| 7012(e)(2) | Access to Equipment and Information |
| 7012(e)(3) | Contractor Attribution Protection |
| 7012(e)(4) | 90-Day Data Retention |
Malware Handling
| Code | Title |
|---|---|
| DFARS-7012-c2 | Malicious Software Submission |
NIST 800-171
| Code | Title |
|---|---|
| DFARS-7012-b2 | NIST SP 800-171 Implementation |
Reporting Mechanism
| Code | Title |
|---|---|
| DFARS-7012-d | Use of DoD-Approved Medium Assurance Certificate |
Scope
| Code | Title |
|---|---|
| DFARS-7012-a | Definitions and Scope |
Security Baseline
| Code | Title |
|---|---|
| DFARS-7012-b1 | Adequate Security Requirement |
| DFARS-7012-b2ii | Alternative but Equally Effective Measures |
Security Requirements
QKD module and network security
Self-Assessment
| Code | Title |
|---|---|
| DFARS-7012-SPRS | SPRS Self-Assessment Score Submission |
Subcontractor Reporting
| Code | Title |
|---|---|
| DFARS-7012-g | Subcontractor Cyber Incident Reporting |
Your Compliance Coverage
If you comply with DFARS 252.204-7012 — Safeguarding Covered Defense Information, you already cover:
Singapore Government Instruction Manual on ICT&SS Management (IM8)
23%
12 controls mapped
Compare →ASEAN Data Management Framework
21%
11 controls mapped
Compare →NIST SP 800-124 Rev 2 — Mobile Device Security
21%
11 controls mapped
Compare →+ 656 more: FAA Cybersecurity Framework for Aviation (21%), Modern Slavery Act 2018 (Australia) (19%)
See all 659 mapped frameworks ↓Maps to 659 other frameworks
Frequently Asked Questions
What is DFARS 252.204-7012 — Safeguarding Covered Defense Information?
DFARS 252.204-7012 — Safeguarding Covered Defense Information is a compliance framework from United States (DoD) with 25 domains and 52 controls. Defense Federal Acquisition Regulation Supplement (DFARS) clause 252.204-7012 requires Department of Defense (DoD) contractors and subcontractors to safeguard Covered Defense Information (CDI) and report cyber incidents. Contractors must implement security requirements in accordance with NIST SP 800-171 and comply with additional requirements related to cyber incident reporting and evidence preservation. This clause is being transitioned under the Cybersecurity Maturity Model Certification (CMMC) framework. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does DFARS 252.204-7012 — Safeguarding Covered Defense Information have?
DFARS 252.204-7012 — Safeguarding Covered Defense Information has 52 controls organised across 25 domains. The largest domains are Definitions and Scope (15 controls), Adequate Security Requirements (5 controls), Cyber Incident Reporting (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does DFARS 252.204-7012 — Safeguarding Covered Defense Information map to?
DFARS 252.204-7012 — Safeguarding Covered Defense Information maps to 659 other compliance frameworks. The top mapping partners are Singapore Government Instruction Manual on ICT&SS Management (IM8) (23% coverage), ASEAN Data Management Framework (21% coverage), NIST SP 800-124 Rev 2 — Mobile Device Security (21% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with DFARS 252.204-7012 — Safeguarding Covered Defense Information compliance?
Start your DFARS 252.204-7012 — Safeguarding Covered Defense Information compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about DFARS 252.204-7012 — Safeguarding Covered Defense Information requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 52 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 718 frameworks.
Get Started Free →Free forever — no credit card required