The Defense Federal Acquisition Regulation Supplement (DFARS) is the Department of Defense's companion to the Federal Acquisition Regulation (FAR). It specifies DoD-specific contracting rules, including the cybersecurity obligations that bind every defense contractor who handles Covered Defense Information (CDI), the category that includes Controlled Unclassified Information.
What is DFARS clause 252.204-7012?
The operative cybersecurity clause is DFARS 252.204-7012, "Safeguarding Covered Defense Information and Cyber Incident Reporting." It has three core requirements:
-
Implement NIST SP 800-171. Contractor systems that process, store, or transmit CDI must implement the 110 security controls in NIST SP 800-171. This is the direct link to the CMMC Level 2 control set.
-
72-hour cyber incident reporting. The contractor must report cyber incidents to DoD via DIBNet within 72 hours of discovery. The definition is broad: compromise of CDI, adverse effects on a covered system, or actions that could affect the contractor's ability to perform. Reports route to the DoD Cyber Crime Center (DC3).
-
Cloud service flowdown. If the contractor uses a cloud service to store or process CDI, the provider must meet FedRAMP Moderate baseline equivalency, and the contractor must flow these obligations down to subcontractors through the contract.
What are the other DFARS cybersecurity clauses?
Three additional clauses round out the framework:
- DFARS 252.204-7019 requires a current NIST 800-171 self-assessment score posted in the Supplier Performance Risk System (SPRS) before award.
- DFARS 252.204-7020 formalizes the self-assessment methodology and DoD's right to conduct its own assessments.
- DFARS 252.204-7021 activates CMMC in a contract. A contract containing 7021 requires the relevant CMMC level at the specified phase.
How does DFARS relate to CMMC?
DFARS 252.204-7012 has required NIST SP 800-171 implementation since 2017, on a self-attestation basis. CMMC adds third-party verification of the same controls. The timeline:
- 2017: DFARS 7012 takes effect; contractors self-attest.
- 2020: DFARS 7019 and 7020 add SPRS scoring and DoD assessment rights.
- 2024: The CMMC Program Rule (32 CFR 170) is finalized.
- 2026-11-10: CMMC Phase 2 begins; contracts with DFARS 7021 require a C3PAO-issued Level 2 certification.
The DFARS clauses are the contract mechanism; CMMC is the assessment mechanism. A contractor cannot satisfy DFARS 7012 without implementing the same 110 controls that CMMC Level 2 verifies.
What does 252.204-7012 mean for OT assets?
Many defense manufacturers process CUI on OT assets: G-code carrying technical drawings, firmware with export-controlled parameters, test data from sensitive programs. DFARS 7012 covers those assets with the same 110 controls. Where an asset cannot satisfy a control natively, the CMMC Enduring Exception mechanism and compensating controls apply.
The 72-hour reporting requirement covers OT incidents too. A ransomware-induced production stop that affects the contractor's ability to perform triggers the same obligation as a data breach on IT systems. This is where Access Gate helps: it enforces identity-based access and session-level audit on CUI paths, including the OT segments that traditional IT controls miss.

