What Is DFARS 7012? Compliance Guide for Contractors
For SaaS vendors pursuing Department of War (DoW) revenue, compliance with the clause in the Defense Federal Acquisition Regulation Supplement (DFARS) 252.204-7012 can determine whether their products are eligible to handle covered data. Nearly every DoW solicitation and contract includes the clause, and it flows down to all covered subcontractors and cloud services that touch it.
When selling into a prime contractor's program, a commercial email host or document platform can become a "covered contractor information system" with contractual security and incident-reporting duties attached. The same applies to an analytics product.
NOTE: The Department of Defense now operates as the Department of War under Executive Order 14347 (September 2025); this article uses DoW for the department and retains "DoD" only in official names, regulatory citations, and issuances that have not been reissued (for example, DFARS itself, "covered defense information," and DoD Class Deviation 2024-O0013).
Key Takeaways
- DFARS 7012 is contractual. DoW inserts it into every solicitation and contract except buys solely for commercial off-the-shelf (COTS) items, and primes flow it down unaltered to subcontractors handling covered defense information.
- Four obligations define compliance. SaaS vendors must implement National Institute of Standards and Technology (NIST) SP 800-171 Rev2 (the operative revision under DFARS 7012, even though NIST later published Rev3), use a Federal Risk and Authorization Management Program (FedRAMP) Moderate or equivalent cloud provider, report cyber incidents within 72 hours of discovery, and preserve forensic images for 90 days.
- Certification adds verification, but is currently paused. Cybersecurity Maturity Model Certification (CMMC) Level 2 assesses the same 110 NIST SP 800-171 Rev2 requirements; DoW suspended Phase 2 third-party certification on July 13, 2026, and placed Phases 3 and 4 in abeyance pending a 60-day CMMC Reform Task Force review, while Phase 1 self-assessment and all DFARS 7012 duties remain in force.
- Misrepresentation triggers liability. Department of Justice (DoJ) False Claims Act has targeted false self-assessment scores and unvetted SaaS vendors.
DFARS 252.204-7012 Is the DoW's Baseline Cybersecurity Contract Clause
The clause bears the full title "Safeguarding Covered Defense Information and Cyber Incident Reporting," and is codified in DFARS Part 252 at title 48 of the Code of Federal Regulations (CFR), § 252.204-7012.
The DoW enforces the clause contractually. DFARS 204.7304(c) directs contracting officers to include the clause in all solicitations and contracts, including commercial-item buys under the Federal Acquisition Regulation (FAR) Part 12, "except for solicitations and contracts solely for the acquisition of COTS items." COTS means commercial off-the-shelf; FAR is the Federal Acquisition Regulation.
The clause took its current form in 2016. It requires "adequate security" for unclassified sensitive DoW data sitting on contractor networks and gives DoW visibility into cyber incidents on those networks.
Covered Defense Information Reaches Well Beyond Classified Data
Covered defense information (CDI) is unclassified controlled technical information, or other information described in the Controlled Unclassified Information (CUI) Registry, that requires safeguarding or dissemination controls. It counts as CDI whether the DoW marked it and handed it over under the contract or the contractor collected, developed, received, transmitted, used, or stored it in performance of the contract. That second prong covers data the contractor generates as well as data the department supplies.
CUI is the government-wide framework; CDI is the DoW contractual subset. Contractors most often encounter:
- controlled technical information
- covered export-controlled information
- operations security information
- anything else the contract flags as requiring safeguarding
Each category falls within the clause when the contract requires safeguarding or dissemination controls.
A "covered contractor information system" is any unclassified system owned or operated by or for a contractor that processes, stores, or transmits CDI. The definition turns on function, not deliverable status. A SaaS product that stores CDI is in scope even when the software isn't what the contract buys.
The Clause Imposes Four Concrete Obligations on Every Covered Contractor
The clause imposes four principal duties.
1. Implement NIST SP 800-171 Rev2 on Every Covered Contractor Information System
The contractor implements NIST SP 800-171 Rev2 on every system that touches CDI: 110 security requirements across 14 control families. Rev2 remains the operative standard for DFARS 7012 even though NIST published Rev3 in May 2024 and later withdrew the Rev2 publication; DFARS 252.204-7012 was never amended to point to Rev3, and DoD Class Deviation 2024-O0013 (May 2, 2024) expressly holds contractors to Rev2. Anywhere this article refers to a NIST SP 800-171 requirement in a DFARS 7012 context, Rev2 applies.
In practice, that means standing up a System Security Plan (SSP) describing the system as it actually runs, plus a Plan of Action and Milestones (POA\&M) covering open Rev2 requirements. DFARS 252.204-7019 and 7020 later added self-assessment scoring and reporting to the Supplier Performance Risk System (SPRS).
2. Use a Cloud Service Provider That Meets FedRAMP Moderate or Equivalent
Any external cloud service provider (CSP) that stores, processes, or transmits CDI must meet security requirements equivalent to FedRAMP Moderate and follow the same incident-reporting and forensics duties.
The DoW policy defines FedRAMP Moderate equivalency, and the CMMC Program final rule, 32 CFR part 170, published October 15, 2024, requires FedRAMP Moderate or DoW-defined FedRAMP Moderate equivalency. A CSP already authorized at FedRAMP Moderate or High meets the clause's FedRAMP Moderate baseline requirement.
3. Report Cyber Incidents to the DoW Within 72 Hours of Discovery
Under DFARS 252.204-7012, a cyber incident is any action taken through computer networks that results in an actual or potentially adverse effect on an information system or the information residing therein, and "rapidly report" means within 72 hours of discovery, not occurrence.
Vendors must file reports through the DoW's cyber incident reporting portal. The report requires the contractor's Commercial and Government Entity (CAGE) code and affected contract numbers.
4. Preserve Forensic Evidence and Submit Malware to the DoW Cyber Crime Center (DC3)
The contractor must preserve images of affected systems plus relevant monitoring data "for at least 90 days from the submission of the cyber incident report" so the department can request the media or decline interest. Packet capture data must be preserved for the same period. Isolated malicious software goes directly to DC3 through its Electronic Malware Submission portal, never by email, and never to the contracting officer.
Those four duties attach to whoever holds the CDI, which is rarely just the prime.
DFARS 252.204-7012 Applies to Every Contractor and Subcontractor Handling CDI
Across the Defense Industrial Base (DIB), the clause has no dollar threshold, no small-business exemption, and no sector carve-out. The sole exclusion is for acquisitions solely of COTS items. Commercial item contracts under FAR Part 12 are expressly included, and a mixed buy of commercial services alongside COTS products doesn't qualify for the exclusion.
The clause travels down the supply chain. Primes must include it "without alteration, except to identify the parties" in every subcontract where performance involves CDI or operationally critical support, and the prime decides whether the information it passes down keeps its identity as CDI. Subcontractors must tell the next higher tier when they seek a variance from a NIST SP 800-171 Rev2 requirement and must share the DoW-assigned incident report number when they report an incident.
The entities covered are therefore:
- DoW prime contractors that receive or generate CDI under a contract.
- Subcontractors at any tier that receive CDI or provide operationally critical support, whether or not they ever negotiated with the department.
- Small businesses, which get no relief from the cybersecurity requirements.
- Universities and research institutions, unless the contracting officer determines in writing that the fundamental research involved requires no safeguarding of CDI.
- SaaS vendors whose products store, process, or transmit CDI for a prime.
A prime that can't get a subcontractor to accept the clause can't share CDI with that subcontractor at all. Contractual flow-down establishes responsibility, but it doesn't by itself demonstrate that the required safeguards are operating.
DFARS 7012 Is the Foundation CMMC and NIST 800-171 Build on
DFARS 7012 incorporates NIST SP 800-171 Rev2 by reference. The clause never restates the 110 requirements; it points to the NIST publication as the implementation standard. Because the clause gives the department no way to verify implementation before award, later clauses closed that gap.
DFARS 252.204-7019 and 7020, added in 2020, made the contractor post a self-assessment score to SPRS before award and gave the DoW the right to assess that score itself.
DFARS 252.204-7021 is the contractual vehicle for CMMC. CMMC Level 2 assesses the same 110 NIST SP 800-171 Rev2 requirements DFARS 7012 already mandates; when a contract requires third-party assessment, validation is performed by a Certified Third-Party Assessment Organization (C3PAO), and the resulting CMMC certificate remains valid for three years. A contractor can be fully DFARS 7012 compliant and still hold no CMMC certificate until an assessor validates the work.
The CMMC rollout is currently paused. Phase 1, covering Level 1 and Level 2 self-assessments, remains in force. On July 13, 2026, the DoW suspended Phase 2 (the mandatory C3PAO certification milestone previously scheduled for November 10, 2026), and placed Phases 3 and 4 in abeyance pending a 60-day CMMC Reform Task Force review; no new Phase 2 date has been announced, and 32 CFR Part 170 is unamended. The pause is a policy suspension, not a rule change: DFARS 252.204-7012 and Phase 1 self-assessment obligations continue to apply in full.
As verification increases, unsupported compliance representations carry corresponding liability risk.
Non-Compliance Exposes Contractors to Federal Liability
Non-compliance can create False Claims Act (FCA) exposure. The DOJ's Civil Cyber-Fraud Initiative targets contractors that knowingly misrepresent their cybersecurity practices or fail to report incidents they are contractually bound to report.
A contractor that can't back up its representations faces FCA liability for false SPRS scores, a prime's failure to flow the clause down to a subcontractor that touches CDI, or knowingly unreported incidents. Aerojet Rocketdyne paid $9 million in 2022. MORSECORP Inc. paid $4.6 million in 2025 after reporting an SPRS score of 104 when its actual score was -142 and using a SaaS email provider without flowing down security requirements.
The Phase 2 suspension and the abeyance of Phases 3 and 4 changed none of this. The DoW's July 13, 2026 announcement confirms that all defense contractors and subcontractors remain contractually obligated to safeguard covered defense information under DFARS 252.204-7012, and DoJ continues to treat every SPRS score and every unreported incident as an actionable representation.
Of the four DFARS 7012 duties, the cloud-provider requirement is the only one a SaaS vendor can resolve through procurement rather than months of internal control engineering. Deploying inside a pre-authorized FedRAMP boundary lets an application inherit most required NIST controls from an already assessed and authorized environment, collapsing the equivalency question into a hosting decision and shrinking the surface area for false representation.
Knox Systems Is the Pre-Authorized Boundary for CDI-Bearing SaaS
Knox Systems operates a FedRAMP-as-a-Service pre-authorized managed cloud platform, where applications are designed to inherit 60% to 80% of required NIST SP 800-53 Rev5 controls. That inheritance turns the cloud-provider obligation under DFARS 252.204-7012 into a deployment step rather than a multi-year authorization project.
Knox currently supports FedRAMP Moderate and FedRAMP High, and it supports Defense Information Systems Agency (DISA) Impact Level 4 (IL-4). IL-5 authorization is in process, with an estimated completion date of December 2026.
Scoping CDI hosting before signing a CDI-bearing contract avoids eligibility delays at award. To assess CDI hosting inside the Knox FedRAMP boundary, book a meeting with Knox.
FAQs about DFARS 252.204-7012
What Does DFARS Compliance Mean for a Defense Contractor?
Day to day, the contractor must keep an External Certification Authority (ECA) medium assurance certificate on hand. Maintaining that certificate is part of the contractor's operational readiness.
How Should a SaaS Vendor Scope CDI?
Start by identifying every system that stores, processes, or transmits CDI, including external cloud services. That boundary determines where NIST SP 800-171 Rev2 and the clause's cloud-provider duties apply.
How Do DFARS 7019, 7020, and 7021 Build on DFARS 7012?
Under 7021, a senior "affirming official" must file an annual affirmation in SPRS of continuous compliance with the required CMMC level. That affirmation is an ongoing obligation, not a one-time filing, and it remains in place during the current Phase 2 suspension for contracts that reference a CMMC level.
What Must a Subcontractor Provide to the Next Higher Tier?
A subcontractor seeking a variance from a NIST SP 800-171 Rev2 requirement must notify the next higher tier. After reporting a cyber incident, it must also share the DoW-assigned incident report number.
What Happens if a Contractor Misses the 72-Hour Reporting Window?
The clause sets no separate penalty for late reporting. The contractual reporting duty still applies.