DFARS 252.204-7012 obligates defense contractors to “rapidly report” a cyber incident to the DoD within 72 hours of discovery, through the DIBNet portal at dibnet.dod.mil (which requires a DoD-approved ECA medium-assurance certificate). But the 72-hour report is only the headline. The same clause requires you to preserve affected system images and monitoring data for at least 90 days, submit any malicious software you isolate to the DoD Cyber Crime Center (DC3), support a DoD damage assessment, and flow all of this down to subcontractors. Prepare before you need it — 72 hours is not enough time to figure out the process from scratch.
The 72-hour clock
DFARS 252.204-7012 — “Safeguarding Covered Defense Information and Cyber Incident Reporting” — is included in nearly every Department of Defense contract that involves Covered Defense Information (CDI), which includes Controlled Unclassified Information (CUI). Two obligations sit at its core: implement NIST SP 800-171, and rapidly report cyber incidents.
“Rapidly report” has a precise meaning: within 72 hours of discovery of a cyber incident. The clock starts when you *discover* the incident — not when you finish investigating it, and not when you confirm exactly what was taken.
You do not get to wait until the investigation is complete. If in doubt, report inside 72 hours with what you know; you can supplement the report as you learn more. A late report is a compliance failure on its own.
What counts as a “cyber incident”
The clause defines a cyber incident as actions that result in a compromise or an actual or potentially adverse effect on a covered contractor information system or the CDI residing on it. That is a deliberately broad definition — it is not limited to confirmed data theft.
In practice, if an event affects a system that stores, processes, or transmits CUI — ransomware, a confirmed intrusion, or credible evidence of unauthorized access — treat the 72-hour clock as running and involve the people who can make the reporting call.
How to report
- Report through DIBNet at https://dibnet.dod.mil — the DoD’s reporting portal for the Defense Industrial Base.
- Get your certificate first. Submitting a report requires a DoD-approved medium-assurance certificate (an ECA certificate). Acquiring one takes time — so obtain it *before* an incident, not during one. See https://public.cyber.mil/eca/.
- Include the required fields. The report captures the incident details, affected systems, CUI involved, and technical indicators specified on DIBNet.
The single most common way contractors blow the 72-hour deadline is discovering — mid-incident — that no one has an ECA medium-assurance certificate, and that getting one takes days. Provision it now, and make sure more than one person can access it.
Beyond the report: what else the clause requires
Filing the report does not discharge your obligations. DFARS 7012 also requires you to:
- Preserve and protect images of all known affected information systems and relevant monitoring/packet-capture data for at least 90 days from the submission of the report, so DoD can request them if it chooses.
- Submit malicious software to the DoD Cyber Crime Center (DC3) if you discover and isolate it in connection with the incident — do not send it with the incident report; DC3 has a separate process.
- Support a damage assessment — provide DoD access to additional information or equipment if it conducts one.
- Flow the clause down to subcontractors whose work involves CDI. Subcontractors report incidents to DoD *and* provide the incident report number to the prime.
The cloud-service requirement
If you use an external cloud service provider to store, process, or transmit CDI, the clause requires that provider to meet security requirements equivalent to the FedRAMP Moderate baseline and to comply with the reporting, media-preservation, and malicious-software paragraphs.
That is the clause floor. For CUI Specified, ITAR/export-controlled technical data, and higher DoD impact levels, the practical bar rises to FedRAMP High / DoD Impact Level 4–5 — which is why environments like Microsoft 365 GCC High and Azure Government are the standard answer for those workloads.
How to prepare (before the clock ever starts)
- Write an incident-response plan that names who declares an incident, who files the DIBNet report, and who preserves evidence.
- Provision the ECA certificate now and confirm at least two people can use it.
- Pre-stage evidence preservation — know how you will image affected systems and retain logs for 90+ days without tipping off or destroying evidence.
- Add the flow-down to your subcontract templates so it is automatic.
- Run a tabletop exercise. Walk the 72-hour timeline end to end at least once a year, so the real event feels familiar. (This is the DoW “Brilliant at the Basics” OT-04 and workforce-readiness idea applied to IT incident response.)
Key takeaways
- 72 hours from discovery — the clock starts when you find the incident, not when you finish investigating.
- Report via DIBNet (dibnet.dod.mil), which requires a DoD-approved ECA medium-assurance certificate you should obtain in advance.
- Preserve affected media and logs for at least 90 days, and submit isolated malicious software to DC3 separately.
- Flow the clause down to subcontractors; they report to DoD and give you the incident number.
- External clouds handling CDI must meet at least FedRAMP Moderate-equivalent security — higher for ITAR/CUI Specified.
- Prepare in advance. 72 hours is not enough time to build the process from scratch; write the plan and provision the certificate now.
Sources
- eCFR — 48 CFR 252.204-7012 (full clause text) ↗
- Acquisition.gov — DFARS 252.204-7012 ↗
- DIBNet — DoD cyber incident reporting portal ↗
- DoD — External Certification Authority (ECA) certificates ↗
Cloud consoles and federal guidance change; confirm control text and clause language against the official publication that applies to your contract. This article is independent education and does not by itself establish compliance or confer CMMC certification.