DFARS 252.204-7012: Cyber Incident Reporting
DFARS 252.204-7012: Cyber Incident Reporting
In March 2024, a defense subcontractor discovered lateral movement in their network during a routine log review. The adversary had been present for eleven days. The 72-hour reporting clock to DC3 started ticking from that Thursday morning log review --- not from the initial compromise eleven days earlier, not from Monday when the SOC analyst flagged the anomaly but triaged it as a false positive. By Sunday evening, they needed a complete incident report submitted to DIBNet with affected contract numbers, compromised CUI categories, and forensic images preserved.
They were not ready. Their DIBNet registration had lapsed. Their evidence preservation infrastructure could not produce forensic images on demand. Their contract management system could not map affected systems to specific contract numbers. The 72-hour window closed with an incomplete report and a subsequent DoD inquiry.
This scenario plays out across the defense industrial base regularly. DFARS 252.204-7012 is one of the most consequential cybersecurity clauses in federal contracting --- and the organizations that fail it almost never fail because they could not detect the incident. They fail because the reporting apparatus was never exercised until the clock was already running.
What DFARS 7012 Actually Requires
DFARS 252.204-7012, "Safeguarding Covered Defense Information and Cyber Incident Reporting," imposes two primary obligations on every contractor handling CUI under a DoD contract:
- Implement adequate security per NIST SP 800-171 --- the 110 security requirements that protect CUI in non-federal systems.
- Report cyber incidents affecting covered defense information or covered contractor information systems to the DoD Cyber Crime Center (DC3) within 72 hours of discovery.
The clause appears in virtually every DoD contract involving CUI. It flows down to subcontractors. It is not optional, not negotiable, and not satisfied by a written policy that has never been tested.
What Triggers the 72-Hour Clock
A "cyber incident" under 7012 means actions taken through computer networks that result in a compromise or an actual or potentially adverse effect on an information system or the information residing therein. The trigger categories:
- Confirmed data exfiltration --- CUI accessed or removed by unauthorized parties
- Potential data exposure --- CUI may have been exposed even without confirmed exfiltration
- System compromise --- malware installation, unauthorized access, or other compromise of systems processing CUI
- Denial of service --- actions affecting availability of systems handling covered defense information
The threshold is deliberately low: "actual or potentially adverse effect." This is the contrarian point most contractors get wrong: the reporting threshold is not "confirmed breach." It is "possible adverse effect." Organizations routinely under-report because they wait for forensic confirmation before starting the clock. That is backwards --- the clock starts at discovery of the potential compromise, and the investigation continues in parallel with reporting.
Under-reporting is a contractual violation. Over-reporting is not. When in doubt, report.
The 72-Hour Timeline in Practice
The clock starts at discovery --- the moment your organization determines that an event may constitute a cyber incident affecting covered defense information. Not when the incident occurred. Not when forensics confirm the scope. At discovery.
Seventy-two hours is not three business days. It is 72 consecutive hours including weekends and holidays. If you discover an incident at 4 PM Friday, your report is due by 4 PM Monday. If your IR team does not work weekends, you have already lost 48 hours before anyone opens a laptop.
What the Report Must Contain
The incident report submitted to DC3 via DIBNet (https://dibnet.dod.mil) must include:
- Company name, point of contact, and affected contract numbers
- Date the incident was discovered
- Date the incident occurred (if known)
- Type of cyber incident (exfiltration, denial of service, unauthorized access, etc.)
- Description of the incident including attack vector where known
- Affected networks, systems, and programs
- Type of information compromised (technical data, export-controlled, CUI categories)
- Protective and containment actions taken or planned
- Indicators of compromise (IOCs) --- IPs, hashes, domains, TTPs
The report does not need to be forensically complete at the 72-hour mark. It needs to be submitted. You can and should supplement it as investigation continues.
Evidence Preservation --- The 90-Day Obligation
The clause requires contractors to preserve and protect images of all known affected systems and all relevant monitoring/packet capture data for at least 90 days after the incident report. This evidence must be provided to DoD upon request.
This means your organization must be able to --- right now, without procurement lead time:
- Create forensic images of affected systems without altering evidence
- Preserve network logs and full packet captures from the incident window
- Store evidence securely with documented chain of custody
- Produce evidence to DoD investigators on demand
If your SIEM retention is 30 days and you discover an incident on day 31, you have already lost the evidence the clause requires you to preserve. Retention policies must account for 7012 obligations.
Flow-Down --- Your Subcontractors Are Your Problem
DFARS 7012 must be flowed down to every subcontractor handling covered defense information. The flow-down obligations:
- Subcontractor reports to DC3 within 72 hours (their own independent obligation)
- Subcontractor notifies the prime contractor (or next higher-tier sub) as soon as practicable
- Prime may have additional reporting obligations to the contracting officer based on the subcontractor's incident
This creates a chain of accountability. If your Tier 2 subcontractor experiences a CUI breach and you do not learn about it for three weeks because you never verified their reporting capability, the contracting officer's questions will come to you.
Practical implications:
- Your subcontract language must include 7012 flow-down verbatim
- You must verify subcontractor capability (not just contractual acknowledgment)
- You should define notification timelines in your subcontract terms (7012 says "as soon as practicable" --- your contract should define what that means)
- You need visibility into which subcontractors handle CUI on which contracts
Preparing Before the Clock Starts
The organizations that handle 7012 reporting successfully are the ones that built the apparatus before they needed it. Preparation has three phases:
Standing Readiness
Register with DIBNet now. Registration can take days. If you start the process after discovering an incident, you have already consumed a third of your reporting window on account creation. Verify your registration is current quarterly.
Map contracts to systems. When you report, you must identify affected contract numbers. This means maintaining a current mapping between information systems and the contracts they support. If "which contracts does this server support?" requires a week of research, you will not make the 72-hour window.
Establish forensic imaging capability. Either in-house tools and trained personnel or a retainer with a digital forensics firm that guarantees response time. The moment of discovery is not the moment to evaluate forensics vendors.
Configure adequate log retention. Your log management retention must exceed 90 days for systems processing CUI. Ideally 180+ days, since you need coverage before the incident window plus 90 days after reporting.
Pre-draft report templates. The nine required fields are known. Pre-populate everything you can (company info, POC, contract mappings). The report template should be a living document, updated when contracts change or systems are modified.
Detection and Rapid Review
When a potential incident surfaces, the first determination is whether covered defense information is involved. This rapid review must happen fast enough to leave time for reporting:
- Does the affected system process, store, or transmit CUI?
- Which CUI categories are potentially affected?
- Which contracts are supported by this system?
- What is the potential scope --- single system, segment, or lateral movement?
If the rapid review determines CUI is not involved, 7012 may not apply (though other reporting obligations might). If CUI is involved or potentially involved, the clock is running.
During the Incident
The 72-hour timeline imposes a parallel workflow that traditional incident response does not assume:
- Hour 0: Discovery. Document the time. Start the clock.
- Hours 0-12: Rapid review. Determine if CUI is involved. Identify affected systems and contracts. Begin containment.
- Hours 12-48: Evidence preservation. Forensic imaging. Log capture. Continue investigation while preserving evidence integrity.
- Hours 48-72: Report drafting and submission. Compile findings into the required DC3 format. Submit via DIBNet. Notify prime contractor if you are a sub.
- Hours 72+: Continue investigation. Submit supplemental reports as findings develop. Maintain evidence for 90-day preservation window.
Penalties for Getting It Wrong
Failure to comply with DFARS 7012 carries consequences that compound:
- Contract termination for material breach of contractual obligations
- False Claims Act liability if the organization certified compliance it did not have (treble damages)
- Suspension or debarment from future government contracts
- Loss of CUI access --- prohibited from receiving covered defense information on current and future contracts
- CMMC implications --- a 7012 failure creates evidence of inadequate IR controls that will surface in assessment
The False Claims Act dimension is particularly significant. DOJ has made clear through the Civil Cyber-Fraud Initiative that contractors who falsely represent their cybersecurity compliance --- including incident reporting capabilities --- face FCA enforcement. The qui tam provisions mean your own employees can initiate FCA actions.
DFARS 7012 and CMMC --- Complementary, Not Redundant
DFARS 7012 and CMMC are distinct but interlocking. DFARS 7012 is the contractual obligation: protect CUI and report incidents. CMMC is the verification mechanism: prove you can actually do what 7012 requires.
Both reference NIST 800-171 as the technical standard. The Incident Response (IR) family in 800-171 directly maps to 7012 reporting capability --- IR.L2-3.6.1 (establish operational incident-handling capability) and IR.L2-3.6.2 (track, document, and report incidents) are the controls a C3PAO will evaluate against your actual capability, not your written policy.
With CMMC implementation, demonstrating that you have reported incidents correctly under 7012 becomes positive evidence. Demonstrating that you failed to report --- or could not report because the apparatus did not exist --- becomes a finding that can block certification.
Key Takeaways
- The 72-hour clock starts at discovery of a potential compromise, not at forensic confirmation
- 72 hours is consecutive --- weekends and holidays count
- Under-reporting is a contractual violation; over-reporting is not
- Evidence must be preserved for 90+ days and produced to DoD on demand
- Flow-down to subcontractors creates accountability chains you must verify, not just document
- DIBNet registration, forensic imaging capability, and contract-to-system mapping must exist before an incident
Frequently Asked Questions
Does the 72-hour clock start when we confirm a breach or when we suspect one?
At suspicion --- specifically, when you determine that an event "may constitute" a cyber incident affecting covered defense information. You do not need forensic confirmation. The standard is "actual or potentially adverse effect." Waiting for confirmation before starting the clock is the single most common compliance failure under 7012.
What if we cannot complete the investigation within 72 hours?
Submit what you have. The initial report does not need to be forensically complete. 7012 requires submission within 72 hours, with supplemental reporting as investigation develops. An incomplete-but-timely report is compliant. A complete-but-late report is a violation.
Do we need to report incidents that affect systems adjacent to CUI systems but not the CUI itself?
If there is any possibility that CUI was affected --- even indirectly through lateral movement, shared credentials, or network adjacency --- report. The "potentially adverse effect" threshold is deliberately conservative. If the compromised system shares a network segment with CUI systems, the potential exists and reporting is prudent.
How does 7012 interact with state breach notification laws?
They are independent obligations with different triggers, timelines, and recipients. A single incident can trigger 7012 (72 hours to DC3), state breach notification (24-72 hours depending on jurisdiction for PII), and potentially HIPAA breach notification (60 days to HHS for PHI). Maintain a notification timeline matrix that maps incident types to all applicable reporting obligations simultaneously.
What counts as "discovery" if our SIEM alerts but nobody reviews for days?
This is contested territory, but the conservative read: discovery occurs when the organization has information sufficient to determine a potential incident, whether or not a human has reviewed it. If your SIEM fires an alert on Tuesday and nobody triages it until Friday, a regulator may argue discovery occurred Tuesday. Invest in MTTD reduction and triage SLAs, not in plausible deniability about when you "really" knew.
How Advisedly Helps
Advisedly provides the infrastructure that makes 72-hour reporting achievable under pressure --- incident workflow automation that tracks the reporting clock from discovery, pre-mapped contract-to-system relationships, integrated evidence preservation with chain-of-custody documentation, automated CUI scope determination across your environment, and continuous monitoring that reduces MTTD so you have more of the 72-hour window for investigation and response rather than burning it on detection. The platform maintains your reporting readiness posture as a measurable, auditable state --- not a policy aspiration. Contact begin@advisedly.ai
<!-- LI hook: 72 hours includes the weekend you discovered it -->