Intepro Systems

DFARS 252.204-7012 for Test-Equipment Suppliers: The 72-Hour Report and the Media You Must Not Wipe

Defence procurement · 6 min read · 5 cited facts

If you supply test equipment into a US defence programme, the contract clause most likely to catch you unprepared is not electrical. DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting, is prescribed for all DoD solicitations and contracts — including commercial-product buys under FAR part 12 — except those solely for the acquisition of commercially available off-the-shelf items. It arrives as boilerplate, and most of its obligations only become visible on the worst day of your year. Source: DFARS 204.7304 and clause 252.204-7012 (MAY 2024) — acquisition.gov. Retrieved 2026-08-24.

The clause turns on one defined term. 'Covered defense information' — the clause keeps the American spelling — is unclassified controlled technical information, or other information listed in the Controlled Unclassified Information Registry, that is either marked or otherwise identified in the contract and provided to you by or on behalf of DoD, or collected, developed, received, transmitted, used or stored by you in support of performance. The clause's own examples of technical information read like a test-equipment delivery: engineering drawings and associated lists, specifications, standards, process sheets, manuals, technical reports, data sets, and computer software executable code and source code. The drawings a prime sends you for a fixture, and the test programs you develop against them, can both qualify. Whether they do on your contract is a question about your contract — the operative words are 'marked or otherwise identified', so when nothing is marked, ask the contracting officer in writing rather than deciding for yourself.

The security obligation you carry before anything goes wrong

For covered contractor information systems not operated on behalf of the Government, paragraph (b)(2) of the clause requires implementation of NIST SP 800-171 — with a deadline that passed on 31 December 2017, so this is a present obligation, not a roadmap. If you use an external cloud service to store, process or transmit covered defense information, paragraph (b)(2)(ii)(D) requires the provider to meet security requirements equivalent to the FedRAMP Moderate baseline and to comply with the clause's own reporting and preservation paragraphs. Source: DFARS 252.204-7012(b) — acquisition.gov. Retrieved 2026-08-24.

The clause reaches you even when the Government did not sign your contract. Paragraph (m) requires the prime — or the next higher tier — to include it in subcontracts for operationally critical support, or where subcontract performance will involve covered defense information, including subcontracts for commercial products, and to include it without alteration except to identify the parties. There is no negotiating the text at your tier. The question a supplier can usefully raise is whether performance actually involves covered defense information — a determination the clause assigns to the prime, in consultation with the contracting officer where necessary.

Seventy-two hours, and what starts the clock

'Rapidly report' is a defined term: within 72 hours of discovery of any cyber incident. The report goes to DoD at dibnet.dod.mil — not to your prime's security office — although paragraph (m)(2)(ii) separately requires a subcontractor to pass the DoD-assigned incident report number up to the prime or next higher tier as soon as practicable. Note what the definition keys on: discovery, not confirmation. The clause also requires a review for evidence of compromise — identifying affected computers, servers, specific data and user accounts — but the 72-hour window is not paused while that review completes.

The duty people breach while doing the right thing

Paragraph (e) is the one we have watched nearly go wrong on a live compromise. When a contractor discovers a cyber incident, it must preserve and protect images of all known affected information systems and all relevant monitoring and packet-capture data for at least 90 days from submission of the cyber incident report, so DoD can request the media or decline interest. The natural instinct after a compromise — and the first offer most hosting providers make — is to wipe the machine and rebuild. Rebuilding on the affected system destroys exactly what paragraph (e) obliges you to keep. Image first, preserve the image, rebuild on fresh media. The two actions are compatible; the order is not negotiable. Source: DFARS 252.204-7012(e) — acquisition.gov. Retrieved 2026-08-24.

Two smaller duties travel with it. Isolated malicious software goes to the DoD Cyber Crime Center in accordance with DC3's instructions — paragraph (d) says expressly not to send it to the contracting officer. And on request, paragraph (f) obliges you to give DoD access to additional information or equipment necessary for forensic analysis — a second reason the wiped-and-rebuilt server is a compliance failure rather than a housekeeping success.

252.204-7012 is also no longer the whole cyber story. The same DFARS subpart prescribes 252.204-7019 and -7020, the NIST SP 800-171 DoD Assessment provision and clause, and a separate subpart prescribes 252.204-7021, Contractor Compliance With the Cybersecurity Maturity Model Certification Level Requirements, whose current edition is dated November 2025 and keys to CMMC levels defined in 32 CFR part 170. Which of these your contract carries, and at what level, is a fact about your contract rather than about the regulation — read your own clause list before assuming. Source: DFARS 204.7304; DFARS 252.204-7021 (NOV 2025) — acquisition.gov. Retrieved 2026-08-24.

None of this is legal advice, and the clause text — free on acquisition.gov — outranks every summary of it, including this one. What we can say from the equipment side is narrower: know whether your contract carries the clause, know where covered defense information sits on your systems before an incident rather than during one, and hold the medium assurance certificate before you need it.

Supplying a rack into a defence programme?

Send the requirement and the flow-downs that arrived with it. We will tell you what we can deliver against it — and if the technical data package raises a safeguarding question, we would rather have that conversation at RFQ than after award.

Talk to an engineer

Related

More on defence procurement