What DFARS 7012 Incident Reporting Requires

DFARS 252.204-7012 is a contract clause that appears in most Department of Defense agreements involving controlled unclassified information. It establishes mandatory incident reporting obligations that apply the moment a contractor suspects covered defense information has been compromised.

The clause requires contractors to report cyber incidents affecting covered defense information to the Department of Defense within 72 hours of discovery. Covered defense information includes technical data, proprietary information and other controlled unclassified information provided by or generated for the DoD under contract.

A reportable incident occurs when there is reasonable belief that covered defense information has been accessed by unauthorized persons, or when a system processing such information exhibits characteristics consistent with compromise. The standard is not certainty but reasonable suspicion.

Why This Creates Executive Accountability

The reporting obligation is contractual, not technical. It binds the organization whether or not anyone has been formally tasked with deciding what to report. When an incident occurs, someone must make a judgment about whether it meets the reporting threshold, prepare the required notification, and submit it to the DoD Cyber Crime Center within the required timeframe.

Failure to report creates contract performance risk and potential False Claims Act exposure if the contractor continues to invoice while in breach of a material contract term. The consequences fall on the organization's leadership, not on technical staff who may lack the context to make reporting decisions.

Many defense contractors discover their reporting obligation only after an incident has already occurred. IT teams may recognize that something is wrong but lack clarity on whether it rises to the DFARS threshold, who should make that determination, and how to file the report. The 72-hour clock begins at discovery, not at the moment leadership learns of the problem.

What Must Be Reported and to Whom

Reports must be submitted to the DoD Cyber Crime Center through the designated online portal. The report must include a description of the compromised covered defense information, the systems affected, and the contractor's assessment of the incident's scope.

The contractor must also preserve and protect images of affected systems and forensic data for at least 90 days from submission of the report, unless directed otherwise by the DoD. This preservation requirement often requires advance planning, as routine backup processes may not produce forensically sound images.

The clause also requires contractors to report the incident to the FBI and to the DoD contracting officer. This creates parallel reporting channels that must be coordinated. Each recipient may have different follow-up requirements and timelines.

The 72-Hour Timeline and When It Begins

The 72-hour reporting window begins when the contractor discovers the incident, defined as when a responsible person becomes aware of facts that would lead a reasonable person to suspect covered defense information has been compromised.

This definition creates tension. Technical staff may observe anomalies days or weeks before they connect those observations to covered defense information. Security tools may generate alerts that sit in queues. The question of when discovery occurred becomes a matter of documented judgment, not system logs.

Organizations that lack clear incident classification procedures face particular risk. Without a defined process for escalating potential incidents and a designated decision-maker with authority to declare an incident reportable, the discovery date becomes ambiguous. Ambiguity works against the contractor in any after-action review.

How This Relates to Incident Readiness

DFARS 7012 reporting obligations cannot be satisfied through improvisation during an incident. The decisions required—what information is covered, whether the threshold is met, who has authority to file the report, how to preserve forensic data—must be made before an incident occurs.

This is the domain of incident readiness and response planning. A defensible incident response plan establishes who makes reporting decisions, what criteria they apply, what information must be gathered before filing, and how the 72-hour timeline will be tracked. It also documents the organization's interpretation of key terms like covered defense information and discovery.

These plans must be written for the people who will execute them under pressure, often outside normal business hours. They must account for the contractor's technical environment, the location and classification of covered defense information, and the communication paths between technical teams and executive leadership.

Who Owns Incident Reporting Inside the Organization

The reporting obligation is a business decision disguised as a technical problem. IT teams can identify technical indicators of compromise, but they cannot determine whether covered defense information was at risk or whether the incident meets the contractual reporting threshold. Those judgments require contract knowledge, risk assessment capability, and executive authority.

In organizations with mature security governance, this decision falls to the CISO or an equivalent role that sits between technical operations and executive leadership. That role translates technical findings into business context and makes binding decisions about regulatory and contractual reporting.

Many defense contractors lack this role. Technical leadership reports to the CTO or CIO, whose primary concern is operational stability. Legal counsel understands the contract but lacks the technical context to assess incidents in real time. Program managers are accountable for contract performance but have no visibility into security events until they escalate into reportable incidents.

This gap creates the risk that incidents will be misclassified, reported late, or not reported at all. [vCISO leadership](/vciso/) provides the designated decision-maker who owns the interpretation of DFARS requirements, the classification of incidents, and the execution of reporting obligations.

What Leadership Should Do Now

First, confirm that someone in the organization has been explicitly assigned responsibility for DFARS 7012 compliance and incident reporting. That person must have authority to make binding decisions, access to technical findings, and direct communication with executive leadership and legal counsel.

Second, verify that the organization's incident response plan addresses DFARS reporting specifically. The plan should define covered defense information in the context of the contractor's actual systems, establish decision criteria for reportable incidents, document the reporting process, and identify who is authorized to file reports with the DoD.

Third, confirm that the technical team knows how to preserve forensic evidence in a manner that satisfies the 90-day retention requirement. This often requires tools and processes that differ from standard backup procedures.

Fourth, test the reporting process. A tabletop exercise that simulates a potential incident will reveal gaps in communication, unclear decision authority, and missing documentation before those gaps create contract performance problems.

If your organization lacks the internal security leadership to own these decisions, Heights Consulting Group provides fractional vCISO services structured around regulatory compliance and incident readiness. A confidential consultation will clarify what adequate ownership looks like for your contracts and risk profile.

Sources

  1. Cybersecurity Framework | NIST , www.nist.gov
  2. Privacy and Security | Federal Trade Commission , www.ftc.gov
  3. Privacy Framework | NIST , www.nist.gov

Related service: Incident Readiness and Response Planning

A response plan that names decision makers, defines escalation and notification paths, and has been tested with the executives who would have to use it.

Read about Incident Readiness and Response Planning