CMMC Ready Now
Back to Knowledge Center
DFARS & Legal6 min read

DFARS 252.204-7012: Safeguarding CUI

The foundational DFARS clause requiring CUI protection, 72-hour cyber incident reporting, and cloud provider security standards. Has been in DoD contracts since 2016.

DFARS 252.204-7012 is the clause that established the modern CUI protection regime in defense contracting. First published in 2016, it requires contractors to implement NIST SP 800-171 security requirements and report cyber incidents to DoD within 72 hours.

What 7012 requires

  • Implement NIST SP 800-171 security requirements on any information system that processes, stores, or transmits covered defense information
  • Report cyber incidents to DoD through the DIBNet Portal within 72 hours of discovery
  • Preserve and protect images of compromised systems for 90 days, available to DoD upon request
  • Submit a damage assessment report detailing what was compromised and the potential impact
  • Use cloud services that meet the security requirements equivalent to FedRAMP Moderate or the DoD Cloud Computing SRG at Impact Level 2 or higher for CUI
  • Flow down 7012 requirements to all subcontractors who handle covered defense information

The cloud requirement matters

Using a consumer cloud service (personal Gmail, standard Dropbox, consumer OneDrive) to store or transmit CUI is a violation of DFARS 7012. You need a FedRAMP Moderate-authorized service — such as Microsoft 365 GCC High, Google Workspace Government, or an equivalent.

7012 and CMMC: the relationship

DFARS 7012 is not going away. It covers the operational obligations (reporting, cloud, media) while CMMC covers the certification of your security program against the 110 NIST SP 800-171 controls. Think of 7012 as the ongoing operational compliance requirement and CMMC as the periodic certification that your implementation is adequate.

Ready to start your CMMC journey?

Book a free 30-minute call with Rick to get a straight answer on where you stand and what to do next.