Back to Knowledge HubCybersecurity & DFARS

DoD Cyber Incident Reporting: The 72-Hour Rule Federal Subcontractors Should Know

A 72-hour reporting clock is not the time to discover who owns the incident-response process, what systems are covered, or how the prime expects to be notified.

For subcontractors subject to DFARS 252.204-7012, cyber incident response is partly a contract-administration process. The company may need to investigate affected systems, report rapidly to DoD, preserve technical evidence, and communicate the assigned incident report number upstream.

Those obligations are much easier to satisfy when responsibility, access, credentials, escalation paths, and evidence-preservation procedures are established before an incident occurs.

The reporting window is 72 hours

DFARS 252.204-7012 defines rapidly report as within 72 hours of discovery. The clause requires review for evidence of compromise and reporting of qualifying cyber incidents to DoD.

Official source: DFARS 252.204-7012 — Cyber Incident Reporting.

Reporting is only one part of the response

  • Identify compromised computers, servers, data, and user accounts as required by the clause.
  • Preserve affected system images and relevant monitoring or packet-capture data for at least 90 days after the report.
  • Follow DoD instructions for malicious software rather than sending malicious code to the contracting officer.
  • Provide the DoD-assigned incident report number to the next higher-tier contractor as soon as practicable when required.
  • Preserve contract, data-flow, and system records that help determine which covered information was involved.

Prime notification may be faster than the DFARS clock

Some prime-drafted subcontracts require notice to the prime within hours of discovery, even though the federal reporting deadline is 72 hours. That may be operationally reasonable, but the subcontractor should identify the exact trigger, recipient, format, and whether preliminary notice can be updated as facts develop.

Prepare the contract side of incident response

Incident-response planning should include a contract matrix showing which active subcontracts contain DFARS 252.204-7012, what information each project handles, which systems are in scope, which primes must be notified, and who is authorized to communicate externally. That prevents a technical incident from becoming a contract-notice failure.

Explore the full topic

CMMC & DoD Cybersecurity Hub