Page: Cybersecurity Series
Revision date: September 17, 2026
Author: Penny Marbel, JPI Worldwide
A qualifying cyber incident creates a contractual reporting deadline that does not depend on completing the investigation. Under DFARS 252.204-7012, a contractor must rapidly report certain cyber incidents to the Department of Defense within 72 hours of discovery.
The same clause requires preservation of affected-system images and relevant monitoring or packet-capture data. The contractor may also be required to provide malicious software, additional information, equipment, or access to support forensic analysis and a DoD damage assessment.
Quotable definition: The 72-hour rule is a reporting deadline that begins when a covered cyber incident is discovered. It is not a deadline that begins after the investigation is complete.
This obligation is relevant to primes, direct government contractors, subcontractors, and lower-tier subcontractors handling covered defense information or performing designated operationally critical support.
1. Determine whether the incident is reportable
A contractor should first determine whether the incident affects one of the categories identified in the contract and DFARS 252.204-7012.
A reportable event may involve:
- A covered contractor information system.
- Covered defense information residing on that system.
- A compromise or potential compromise of covered defense information.
- A cyber event affecting designated operationally critical support.
- Systems, accounts, servers, or data that may have been accessed as a result of the incident.
The clause defines a cyber incident broadly. It includes actions taken through computer networks that result in a compromise or an actual or potentially adverse effect on an information system or the information residing in that system.
The initial determination should not be delayed while personnel attempt to establish every fact. The contractor should preserve the available evidence, document the basis for the determination, and escalate the matter to the designated incident response and contracts personnel.
2. Start the internal clock at discovery
The contractual clock begins at discovery. Internal procedures should therefore use a shorter escalation window.
JPI recommends that contractors establish the following internal sequence:
- Immediate triage: Record the date, time, reporting source, affected business function, and initial indicators.
- Early escalation: Notify the incident response lead, information security leadership, contracts representative, legal counsel, and executive decision-maker under the approved response plan.
- Contract review: Identify affected contracts, clauses, covered information, prime or higher-tier reporting requirements, and government points of contact.
- Evidence control: Protect logs, system images, volatile data where practicable, ticket history, communications, and analyst notes.
- DoD reporting: Submit the report within 72 hours of discovery through the applicable DoD reporting process.
- Prime notification: Provide the automatically assigned incident report number to the prime contractor or next higher-tier subcontractor as soon as practicable.
These internal milestones are recommended operating controls. They do not replace the contractual 72-hour requirement.

3. Report to DoD and provide available facts
DFARS 252.204-7012 requires the contractor or subcontractor to report qualifying cyber incidents directly to DoD through DIBNet, using the required reporting credentials and portal instructions.
The report should include the information required by the reporting system. Contractors should expect to provide, as applicable:
- Contractor identification and CAGE or other required identifiers.
- Affected contract, task order, or program information.
- The date and time the incident was discovered.
- A description of the suspected event.
- Affected systems, computers, servers, accounts, or services.
- The type of information potentially accessed, altered, lost, or exfiltrated.
- Known or suspected malicious software.
- Containment, mitigation, and recovery actions.
- Government, prime-contractor, and internal points of contact.
A contractor should report the facts reasonably available within the 72-hour period. It should not wait for a perfect forensic narrative. Supplemental information may be provided as directed by DoD or the contracting officer.
If malicious software is discovered and isolated in connection with a reported cyber incident, it must be submitted to the DoD Cyber Crime Center in accordance with applicable instructions. It should not be sent directly to the contracting officer.
4. Preserve media for at least 90 days
After discovering a cyber incident, the contractor must preserve and protect images of all known affected information systems identified during the review. The contractor must also preserve relevant monitoring and packet-capture data for at least 90 days from submission of the cyber incident report.
This requirement does not, by itself, require a contractor to create packet captures where none exist. It does require preservation of relevant data that the contractor maintains or collects.
Evidence retention should be governed by a written hold process. The record should identify:
- The systems and devices placed under preservation.
- The individuals responsible for collection and custody.
- The collection date and time.
- The tool or method used.
- Hashes or other integrity records, where applicable.
- Storage location and access restrictions.
- Transfers to investigators, counsel, the prime, or the Government.
- Any reason an item could not be collected or preserved.

The contractor should not dispose of relevant media at the end of an ordinary retention period if a government request, investigation, litigation hold, or contract instruction requires continued preservation.
5. Support forensic analysis and damage assessment
DoD may request additional information or equipment necessary to conduct a forensic analysis. If DoD elects to conduct a damage assessment, the contracting officer may request the damage assessment information gathered under the clause.
A contractor should be prepared to coordinate controlled access to:
- System images.
- Log and monitoring data.
- Network records.
- Relevant hardware or removable media.
- Incident response reports.
- Account and access records.
- System security plan material relevant to the incident.
- Evidence custody and preservation documentation.
The contractor should route the request through authorized personnel. It should also document what was provided, when it was provided, to whom it was provided, and under what authority.
Contractor attributional and proprietary information may be included in incident reporting. The contractor should identify and mark such information where appropriate, while recognizing that DFARS provides specific rules governing government use and disclosure.
6. Understand subcontractor flowdown
DFARS 252.204-7012 must be flowed down to subcontracts involving covered defense information or operationally critical support, including applicable subcontracts for commercial products and commercial services.
The prime contractor should verify that:
- The clause is included where required.
- Covered defense information is identified and remains protected.
- Subcontractors understand the direct DoD reporting obligation.
- Subcontractors know how to notify the prime or next higher-tier subcontractor.
- Incident report numbers are passed upward promptly.
- Contract-specific notification procedures are documented.
- Lower-tier subcontractors are included in the escalation model.
A subcontractor generally reports the qualifying incident directly to DoD and then provides the automatically assigned report number to the prime or next higher-tier subcontractor. The prime should not treat subcontractor reporting as a substitute for its own contract administration and coordination responsibilities.
7. Do not treat CMMC timing as a reporting exemption
The suspension of the CMMC Phase 2 third-party assessment transition does not suspend DFARS 252.204-7012 reporting obligations. It also does not eliminate applicable NIST SP 800-171 Rev. 2 requirements incorporated into a contract.
Under Class Deviation 2026-O0025, Revision 3, effective September 3, 2026, the universal CMMC mandate is moved to November 10, 2028 under the current acquisition framework. That change affects the timing and manner in which CMMC requirements are inserted into certain contracts. It does not create a safe harbor for failing to report a qualifying incident, preserve evidence, or maintain required cybersecurity controls.
Contractors should review the actual contract clauses, modifications, task orders, and applicable flowdown language. A CMMC transition change should not be interpreted as a waiver of separate DFARS, NIST, or contract-specific duties.

8. Treat SPRS scores as material representations
A self-assessment score in the Supplier Performance Risk System is not merely an internal technical metric. It represents the contractor’s stated cybersecurity posture for a defined system and assessment scope.
A government assessment may contradict that representation. A Defense Industrial Base Cybersecurity Assessment Center assessment can examine documentation, interview personnel, review system security plans, and test whether controls operate as represented. The resulting score may take precedence over a self-reported score under applicable DoD assessment procedures.
Recent public enforcement actions demonstrate the financial and contractual consequences.
- On September 1, 2026, Honeywell Aerospace agreed to pay $2,042,518 to resolve False Claims Act allegations that it failed to comply with NIST SP 800-171 cybersecurity requirements on a DoD contract. The Department of Justice described the claims as allegations and stated that there had been no determination of liability.
- On June 18, 2026, LOGZONE Inc. agreed to pay $507,144 to resolve False Claims Act allegations involving cybersecurity requirements in Navy contracts. A government assessment produced a score of -170, despite a self-reported perfect score of 110 in SPRS. The Department of Justice reported that the assessment was conducted by DCMA with DIBCAC assistance.
These settlements are public enforcement examples, not findings that every cybersecurity deficiency creates False Claims Act liability. They demonstrate, however, that inaccurate representations about implemented controls may create exposure when connected to government payment claims or other material contract representations.
Practical rule: Do not enter a score in SPRS unless the score is supported by the defined system boundary, current evidence, documented methodology, and an accountable review process.
9. Apply a defensible contractor response model
A practical response program should connect cybersecurity operations with contracts, accounting, legal, and program management. Incident reporting is not solely an information technology task.
The responsible team should maintain:
- A current inventory of covered systems and data.
- A contract-to-system and contract-to-subcontractor map.
- An incident response plan with a 72-hour decision point.
- A DoD reporting account and approved reporting credentials.
- A media-preservation and evidence-custody procedure.
- A current list of internal and government points of contact.
- A documented SPRS assessment basis.
- A process for validating claims and representations before submission.
- Periodic exercises involving technical, contracts, legal, and executive personnel.
JPI Worldwide provides cybersecurity and secure infrastructure services for government agencies, prime contractors, and subcontractors. JPI can support network security architecture, access control, monitoring, system hardening, secure remote access, incident-response coordination, technical staffing, and field infrastructure.
To discuss how JPI can help reduce operational friction for a prime, subcontractor, agency, or department, use the JPI contact page or contact connect@jpiworldwide.com. Do not submit classified information, CUI, export-controlled technical data, credentials, or incident evidence through a public contact form.
Questions and Answers
What is the DFARS 252.204-7012 reporting deadline?
A qualifying cyber incident must be rapidly reported to DoD within 72 hours of discovery.
What must a contractor preserve after a cyber incident?
The contractor must preserve and protect images of known affected information systems and relevant monitoring or packet-capture data for at least 90 days from submission of the report.
Does a subcontractor report directly to DoD?
Yes. When the clause applies, a subcontractor reports directly to DoD and provides the assigned incident report number to the prime contractor or next higher-tier subcontractor as soon as practicable.
Does the CMMC Phase 2 suspension eliminate DFARS 7012 duties?
No. The CMMC timing change does not suspend DFARS 252.204-7012 reporting, evidence-preservation, forensic-support, or applicable NIST SP 800-171 obligations.
Can a DIBCAC or government assessment contradict an SPRS score?
Yes. A government assessment may identify deficiencies that produce a materially different score. The contractor should be able to support its SPRS representation with current, scope-specific evidence.

