Hacked and On the Clock: Surviving DFARS 252.204-7012
This article was researched and written by Ask Pub K, drawing on Pub K's curated library of authoritative GovCon documents. It has been lightly edited by Pub K's editors for accuracy and clarity.

A three-day clock, a federal reporting portal, and a mountain of paperwork — all triggered the moment your network admin spots something suspicious. That’s the reality facing every defense contractor under DFARS 252.204-7012, the clause that turns a bad day on your network into a federal compliance event. If your company touches covered defense information, this clause is already in your contract — whether your incident response plan is ready for it is another question.
What the Clause Actually Requires
DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting, obligates contractors to provide “adequate security” on all covered contractor information systems and to rapidly report any cyber incident affecting covered defense information or the contractor’s ability to perform operationally critical support.[1] “Rapidly report” has a hard number attached to it: within 72 hours of discovery.[2] The clause is incorporated into DoD solicitations and contracts governmentwide, including commercial-item acquisitions, and must flow down to subcontractors at every tier that handle covered defense information.[3]
Reporting runs through the DoD’s DIBNet portal, and a contractor must hold a DoD-approved medium assurance certificate to submit a report there.[4] The report itself calls for a detailed narrative — company and contract identifiers, facility and incident-location CAGE codes, the type and technique of compromise, and the impact on covered defense information or critical support.[5] Contractors must also isolate and submit any malicious software discovered, and preserve affected media and systems for at least 90 days so DoD can request access if needed.[6]
Where It Gets Complicated: “Discovery”
The clause does not define precisely when the 72-hour clock starts — it runs from “discovery,” a term that invites real disputes between contractors and the government over whether routine anomaly investigation counts, or only a confirmed compromise does. Contractors that wait too long to decide an incident is reportable risk being second-guessed after the fact, which is why a defined, rehearsed incident-response process — with a documented trigger for what counts as a “confirmed incident” — matters as much as the technical safeguards themselves.
A Moving Target Right Now
This clause is also in motion. DoD is folding its information-security and supply-chain clauses — including 252.204-7012 and its companions — into a newly created DFARS Part 240, under DARS Class Deviation 2026-O0025, now on its third revision, effective since February 1, 2026.[7] Some related clauses are already being renumbered under that effort (for example, the NIST SP 800-171 assessment clause has moved from 252.204-7020 toward a 252.240-series number), even as 252.204-7012 itself continues to be cited at its legacy number in current contracts.[8] Separately, DoD has used standalone deviations — such as Deviation 2024-O0013 — to substitute alternative clause text tied to evolving NIST SP 800-171 and CMMC assessment requirements ahead of formal rulemaking.[9] A contractor relying on the FAR/DFARS text alone, without checking the current deviation, can easily end up complying with yesterday’s clause.
As Pub K has noted, the incident-reporting half of this regime deserves the same attention as the safeguarding half — the 72-hour window leaves no time to improvise a response plan after the fact.[10]
The Takeaway
DFARS 252.204-7012 is not static text — it is a living regulatory framework currently being restructured in real time through DoD class deviations. Questions like which clause number currently governs your contract, whether a given deviation applies to your buying agency, or whether your incident qualifies as “discovered” under the clause are exactly the kind of live, fact-specific, currency-sensitive questions that deserve more than a quick Google search. That is where Ask Pub K comes in: built to check not just what the FAR and DFARS say, but what they say today, agency deviation by agency deviation.
This article is for informational purposes and does not constitute legal advice; consult counsel regarding your specific contractual obligations.
Footnotes
1. DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting, Acquisition.gov ↩
2. DFARS Subpart 204.73, Safeguarding Covered Defense Information and Cyber Incident Reporting, Acquisition.gov ↩
3. Bass, Berry & Sims, DoD Contractors Beware: New Network Penetration Reporting and Cloud Services Requirements Are Here ↩
4. Sheppard Mullin, Achieving Cyber Fitness, Part 5 ↩
5. Sheppard Mullin, Achieving Cyber Fitness, Part 5 ↩
6. Chess Consulting, The Continuing Evolution of Federal Cybersecurity Requirements, Part 3 ↩
7. DARS Class Deviation 2026-O0025, Revision 3, DFARS Part 240 (acq.osd.mil) ↩
8. MAD Security, DFARS Clause Renumbering Under the CMMC Deviation: What Contractors Need to Know ↩
9. Wiley Law, Not So Fast, NIST: DoD Issues Class Deviation to Retake Control Over What Cybersecurity Requirements Apply to Its Contracts ↩
10. Pub K, Incident Reporting Key to New Cybersecurity Rule ↩




