DFARS 252.204-7012 Explained: What "Running 7012" Actually Means

"Running 7012" is contractor shorthand for complying with DFARS 252.204-7012, the clause that requires you to protect covered defense information on your own systems. In practice it comes down to three duties: implement NIST SP 800-171, report cyber incidents to the government within 72 hours, and pass both requirements down to your subcontractors.

Where the phrase comes from

Nobody at the Pentagon says "running 7012." It is industry shorthand, and it usually reaches a small firm the same way: a prime emails to ask whether you are running 7012 before they send you drawings, specs, or technical data. What they are really asking is whether your environment can lawfully receive covered defense information.

The clause behind the phrase is DFARS 252.204-7012, "Safeguarding Covered Defense Information and Cyber Incident Reporting." It has been in defense contracts since 2015 and applies to nearly every DoD solicitation and contract. The one meaningful carve-out under DFARS 204.7304 is for solicitations exclusively for commercially available off-the-shelf items. Everything else is in scope.

Two definitions decide whether it touches you:

  • Covered defense information (CDI) is unclassified controlled technical information or other information in the CUI Registry that requires safeguarding, and that is either provided to you for the contract or generated by you in performing it.

  • A covered contractor information system is any system you own or operate that processes, stores, or transmits that information.

If CDI never lands on your systems, the clause imposes no safeguarding burden. The moment it does, all of it applies at once.

What running 7012 requires

The clause reads as a list of obligations, and it helps to see them as six distinct duties rather than one vague mandate.

1. Provide adequate security. For systems that are not operated on behalf of the government, that means implementing NIST SP 800-171, currently Revision 2. That is the 110 controls across 14 families, and it is the substantive heart of the clause.

2. Report cyber incidents rapidly. "Rapidly" is defined: within 72 hours of discovering the incident, filed through the DIBNet portal at dibnet.dod.mil.

3. Preserve the evidence. Keep images of affected systems and relevant monitoring data for at least 90 days from the date of the report, so the government can request them.

4. Submit isolated malware. If you find and isolate malicious software connected to a reported incident, it goes to the DoD Cyber Crime Center.

5. Support follow-on activity. The government may request additional information, access to equipment, or your participation in a damage assessment.

6. Flow it down. The clause goes into your subcontracts, unaltered, whenever a subcontractor will handle CDI. Their incident reports go to the government directly, with a copy to you.

The three clocks nobody plans for

Most compliance failures under this clause are not architectural. They are scheduling failures.

72 hours is the incident report deadline, and the clock starts at discovery, not at containment or root cause. You will still be figuring out what happened when the deadline hits. That is expected: the initial report is not a forensic conclusion.

90 days is the minimum media preservation window after a report. Firms that image a compromised machine, remediate, and reuse the hardware have destroyed evidence they were obliged to keep.

30 days is the quiet one. Under paragraph (b)(2)(ii)(A), a contractor is required to notify the DoD CIO by email of any NIST SP 800-171 requirement not implemented at the time of award. Most small firms have never sent that notification and do not know the obligation exists.

There is also a variance path that goes unused. Under paragraph (b)(2)(ii)(B) you may submit a written request to the contracting officer, for the DoD CIO's consideration, to vary from a specific requirement. If the CIO adjudicates a control as non-applicable or accepts an equally effective alternative, you do not have to implement it as written. That is a legitimate route for a control that genuinely does not fit your environment, and almost nobody uses it.

The certificate that blocks your incident report

Here is the detail that turns a manageable incident into a compliance failure. To file a report through DIBNet, you need a DoD-approved medium assurance certificate, required by paragraph (c)(3) of the clause and issued through the External Certification Authority program.

Obtaining one takes time. It involves an approved vendor, identity verification, and issuance. If you start that process after an incident, the 72-hour window will close before you can log in to report.

Get the certificate before you need it. It is the cheapest insurance in the entire clause, and it is the single most common reason a firm misses the deadline.

Cloud: the rule that disqualifies ordinary tools

If you use an external cloud service provider to store, process, or transmit CDI, that provider must meet security requirements equivalent to the FedRAMP Moderate baseline, and the arrangement carries its own reporting and access obligations.

This is where a lot of small firms are quietly out of step. Ordinary commercial file sharing, ordinary consumer email, ordinary project tools: most were never built to that baseline. The gap usually goes unnoticed until an assessment, or until a prime asks where the data actually sits.

What 7012 is not

Three misconceptions cost firms real money.

It is not a certification. There is no 7012 certificate and no 7012 assessor. You accept the obligation by signing a contract that contains the clause, and you attest to your own compliance. It sits alongside the other four DFARS cyber clauses, which handle assessment, scoring, and certification. That self-attested posture is exactly what CMMC was built to verify.

CMMC does not replace it. Even with CMMC Phase 2 suspended, 7012 continues in full force, including the 72-hour duty. It was never a stepping stone toward CMMC. It is the underlying obligation that CMMC checks.

Compliance is not invisible. Your NIST 800-171 implementation shows up as a score in SPRS that contracting officers and primes can see, and that self-attestation carries False Claims Act exposure. Contractors have paid seven-figure settlements for scores they could not support.

If you are the subcontractor

Being asked whether you run 7012 usually means a prime is deciding whether to send you data. Four moves make that conversation go well:

  1. Confirm in writing what data you will receive. If nothing meets the CDI definition, the safeguarding obligation does not attach to your systems.

  2. Scope tightly. Keep CDI inside a defined enclave rather than letting it spread across your whole network. This is the single largest lever on cost.

  3. Get your SPRS score current. Primes are required to verify subcontractor scores, and an old score stalls the award.

  4. Obtain the medium assurance certificate now. See above. It takes longer than you think.

A note on where this is heading: the defense side runs on Rev 2 today, but the civilian side of the government is moving separately. A proposed FAR rule would extend CUI safeguarding to civilian contractors at Rev 3, which means firms working both sides may face two versions of the same standard. Worth watching, not worth acting on yet.

Key Takeaways

  • "Running 7012" means complying with DFARS 252.204-7012: implement NIST SP 800-171, report incidents within 72 hours, and flow both down to subcontractors handling CDI.

  • The clause applies to nearly all DoD contracts. The main exception is solicitations solely for commercially available off-the-shelf items.

  • Three clocks matter: 72 hours to report through DIBNet, 90 days of media preservation, and a 30-day notice to the DoD CIO of any control not implemented at award.

  • You cannot file a DIBNet report without a DoD-approved medium assurance certificate. Get it before an incident, not during one.

  • It is self-attested, not certified. CMMC verifies it rather than replacing it, and your SPRS score is the visible evidence.

FAQ

What does "running 7012" mean? It is industry shorthand for complying with DFARS 252.204-7012. A prime asking whether you run 7012 wants to know whether your systems can lawfully receive covered defense information, which means you have implemented NIST SP 800-171, can report a cyber incident within 72 hours, and will flow the same terms to any subcontractor who touches the data.

Does DFARS 252.204-7012 apply to my contract? Almost certainly, if it is a DoD contract and you handle covered defense information. The clause is prescribed for use in all DoD solicitations and contracts, with the main exception being solicitations exclusively for commercially available off-the-shelf items. If no CDI reaches your systems, the safeguarding obligations do not attach.

How fast do I have to report a cyber incident under 7012? Within 72 hours of discovery, submitted through the DIBNet portal. You also preserve affected system images and relevant monitoring data for at least 90 days and submit any isolated malicious software to the DoD Cyber Crime Center.

Do I need anything special to file a DIBNet report? Yes. The clause requires a DoD-approved medium assurance certificate, obtained through the External Certification Authority program. Acquiring one takes time, so get it before an incident rather than during one.

Is DFARS 7012 the same as CMMC? No. 7012 is the underlying obligation and it is self-attested. CMMC is the framework built to verify it. Even with CMMC Phase 2 currently suspended, 7012 applies in full, including the 72-hour reporting duty.

Does 7012 flow down to subcontractors? Yes. The clause must be included, without alteration, in subcontracts where the subcontractor will handle covered defense information. Subcontractors report incidents to the government directly and provide the incident report number to the prime.

Most contractors meet 7012 the hard way: a prime asks, and suddenly a clause that has been in the contract all along becomes urgent. The clauses that gate small-business work keep shifting, and the ones that do not shift are the ones people forget they signed. Federal Cyber Brief tracks what is being bought, who can bid, and what is changing across federal IT and cyber contracting, and sends the parts that matter to your inbox each week. Primary sources only. No noise.

SOURCES

DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting (acquisition.gov / eCFR, 48 CFR 252.204-7012). Definitions of covered defense information, covered contractor information system, and rapidly report; the adequate security requirement at paragraph (b); the 30-day DoD CIO notification and variance process at (b)(2)(ii)(A)–(C); the external cloud service provider requirement at (b)(2)(ii)(D); 72-hour incident reporting via DIBNet at (c)(1); the medium assurance certificate requirement at (c)(3); malicious software submission at (d); 90-day media preservation at (e); damage assessment support at (g); and subcontractor flow-down at (m).

DFARS 204.7304, Solicitation provision and contract clauses (acquisition.gov). Prescription of the clause for DoD solicitations and contracts, including the exception for solicitations solely for commercially available off-the-shelf items.

DFARS 252.239-7010, Cloud Computing Services (acquisition.gov). Cloud service requirements referenced by 252.204-7012 for CDI handled by an external cloud service provider.

DoD Defense Industrial Base Cybersecurity Program, DIBNetdibnet.dod.mil. Required elements of the cyber incident report and the reporting portal.

DoD External Certification Authority (ECA) programpublic.cyber.mil/eca. Source of the DoD-approved medium assurance certificate required to submit a cyber incident report.

NIST SP 800-171 Revision 2 (csrc.nist.gov). The 110 security requirements across 14 control families that constitute adequate security under the clause, and the version currently required for DoD contracts.

Keep Reading