Subcontractor CMMC Tracker
Findings · finding 5 of 12

Subcontractor handles CUI but cannot report cyber incidents: DFARS 252.204-7012(c)

DFARS 252.204-7012 flows down where subcontract performance involves covered defense information (7012(m)(1)); reporting a cyber incident within 72 hours needs a Department of War (DoD) medium assurance certificate (7012(c)(3)).

What the register reads

a question

A question for the subcontracts lead: can the subcontractor report a cyber incident to DoD within 72 hours, and does it hold the medium assurance certificate?

The rule sentences behind it

3 cited
DFARS 252.204-7012(c)(3)codified text, eCFR current to 24 Sep 2026; 252.204-7012 (MAY 2024) is kept in Class Deviation 2026-O0025, effective 1 Feb 2026

In order to report cyber incidents in accordance with this clause, the Contractor or subcontractor shall have or acquire a DoD-approved medium assurance certificate to report cyber incidents.

Threshold read: a medium assurance certificate to report cyber incidents. Source
DFARS 252.204-7012(a), "rapidly report"codified text, eCFR current to 24 Sep 2026

Rapidly report means within 72 hours of discovery of any cyber incident.

Threshold read: 72 hours from discovery. Source
DFARS 252.204-7012(m)(1)codified text, eCFR current to 24 Sep 2026

Include this clause, including this paragraph (m), in subcontracts, or similar contractual instruments, for operationally critical support, or for which subcontract performance will involve covered defense information, including subcontracts for commercial products or commercial services, without alteration, except to identify the parties.

Threshold read: flows down where subcontract performance involves covered defense information. Source

The clauses behind it

DFARS 252.204-7012 (c)Cyber incident reporting (72-hour rapid report)

When the Contractor discovers a cyber incident affecting a covered contractor information system, the covered defense information residing therein, or its ability to perform operationally critical support, it shall conduct a review for evidence of compromise and rapidly report the incident (within 72 hours of discovery) to DoD at https://dibnet.dod.mil, including the required report content, and shall have or acquire a DoD-approved medium assurance certificate to make the report.

What an assessor asks to see: Incident review records evidencing the compromise assessment; The cyber incident report submitted via dibnet.dod.mil within 72 hours; A DoD-approved medium assurance certificate
Where subcontractors usually fall short: Reporting later than 72 hours after discovery; No medium assurance certificate in place; Incomplete incident report content
Source: DFARS 252.204-7012
DFARS 252.204-7012 (m)Subcontract flowdown

The Contractor shall include this clause, without alteration except to identify the parties, in subcontracts (including for commercial products or services) for operationally critical support or whose performance will involve covered defense information, determine whether information retains its identity as covered defense information, and require subcontractors to report cyber incidents to the prime (or next higher-tier subcontractor) and to DoD via dibnet.

What an assessor asks to see: Subcontracts containing clause 252.204-7012 unaltered; Determination of which subcontracts involve covered defense information; Subcontractor incident-reporting obligations to the prime and DoD
Where subcontractors usually fall short: Omitting the clause from in-scope subcontracts; No mechanism for subcontractor incident reporting to the prime
Source: DFARS 252.204-7012
CMMC L2 IR.L2-3.6.2Incident Reporting 5 points in the score

Track, document and report incidents to the designated internal officials and to external authorities where required.

What an assessor asks to see: Incident register with tracking and documentation per incident; Defined internal officials and external reporting obligations; Evidence of reports made within required timeframes
Where subcontractors usually fall short: External reporting obligations unidentified; Incidents handled informally and never documented; Reporting timeframes undefined so notifications are late
Source: CMMC 2.0 Level 2 (NIST SP 800-171 Rev 2)

A line that raises it

invented

Arcwright Composites | 8AC19 | 108 | 2024-12-02 | Level 2 (Self) | 2026-06-02 | yes | no | applying

See it in the specimen