DFARS 252.204-7012 is the clause that requires defense contractors to safeguard covered defense information and report cyber incidents within 72 hours. It's the obligation underneath CMMC - and unlike CMMC's third-party certification, it was explicitly left in full force by the July 2026 suspension.
Book a 15-minute review →What it requires: implement NIST SP 800-171 as 'adequate security' for covered defense information (which includes CUI), report cyber incidents to DIBNet within 72 hours, meet FedRAMP Moderate (or equivalent) for clouds that touch that information, and flow the clause down to subcontractors. These are contractual obligations, live in your existing contracts right now.
Who it applies to: any DoD contractor or subcontractor whose systems process, store, or transmit covered defense information. The flow-down requirement means it reaches deep into the supply chain - a small machine shop three tiers down can be bound by it through its purchase orders.
Why it matters after the suspension: the July 2026 memos made clear that suspending CMMC Phase 2 did not touch 252.204-7012. The 72-hour reporting requirement, the NIST 800-171 baseline, and the flow-down all remain operative. Contractors who assumed the suspension relaxed everything are mistaken - and exposed.
MDRwatchdog monitors the systems where covered defense information lives, maps your posture to the NIST 800-171 baseline the clause requires, and produces the incident timelines and evidence you'd need to demonstrate compliance. Readiness and evidence, not legal advice - confirm your specific clause obligations with counsel.
Yes, fully. The July 2026 DoW memos explicitly kept 252.204-7012 in force, including NIST 800-171 implementation, the 72-hour incident-reporting requirement, and subcontractor flow-down.
If you experience a cyber incident affecting covered defense information or your ability to perform, you must report it to DIBNet within 72 hours of discovery. This requirement is unchanged by the CMMC suspension.
Yes. Prime contractors must flow the clause down to subcontractors whose work involves covered defense information, and that flow-down remains active.
MDRwatchdog provides security monitoring and compliance evidence to support readiness. It is not a certification and not legal advice. Certification and formal audits are performed by the appropriate authorized bodies (a C3PAO for CMMC, a licensed CPA firm for SOC 2, an accredited body for ISO 27001).