Atom Cybersecurity — two practices, one standard
Reference • DFARS 252.204-7012 • DIBNet

72 hours to report.

DFARS 252.204-7012 has two halves. The first: safeguard Covered Defense Information by implementing NIST SP 800-171. The second: report a cyber incident within 72 hours of discovery to the DoD through DIBNet. The clock starts when you discover the incident, not when you finish investigating. This page explains what the clause requires, what counts as reportable, and how a 24/7 SOC keeps you inside the window.

What the clause requires

Safeguard the data. Report the incident.

DFARS 252.204-7012 obligates contractors to provide “adequate security” for Covered Defense Information (CDI) on their systems — which the clause defines as implementing NIST SP 800-171. That is the same 110-requirement standard CMMC Level 2 measures against. Safeguarding is the standing obligation.

The reporting obligation is the sharp edge. When a cyber incident affects a covered system or the CDI on it, you must rapidly report it — within 72 hours of discovery — to the DoD via DIBNet. Submitting through DIBNet requires a DoD-approved medium assurance certificate, which takes time to obtain. That certificate must be in hand before an incident, not requested during one.

  • Adequate security — implement NIST SP 800-171 to protect CDI.
  • Rapid reporting — within 72 hours of discovery, via DIBNet.
  • Medium assurance certificate — required to file; obtain it in advance.
  • Discovery starts the clock — not the completion of your investigation.
The full set

Reporting is not the only obligation.

The 72-hour report triggers a chain of duties. Miss the supporting obligations and the report itself is not enough.

01

Malware submission

If malicious software is discovered and isolated in connection with a reported incident, it must be submitted to the DoD Cyber Crime Center (DC3) in the manner the department directs.

02

Preserve and image ~90 days

You must preserve and protect images of affected systems and relevant monitoring data for at least 90 days from the report, so the government can request them for its own analysis.

03

Flow-down to subcontractors

The clause flows down to subcontractors whose work involves CDI. Subs must meet the same safeguarding and reporting duties, and must report incidents to the prime and to DoD.

04

Cloud service requirements

When a cloud service is used to store, process, or transmit CDI on the contractor’s behalf, the provider must meet DoD requirements (FedRAMP Moderate equivalence or higher) and support the 7012 obligations.

The trigger

What counts as a reportable cyber incident?

A reportable cyber incident is one that actually or potentially adversely affects a covered contractor information system or the Covered Defense Information residing on it — or that affects the contractor’s ability to perform requirements designated as operationally critical support. It is a low bar by design: “potentially” and “compromise” are broad terms.

Because the standard is exposure rather than confirmed loss, the safe reading is to treat plausible compromise of a covered system as reportable and start the 72-hour clock at discovery — then let the investigation refine the detail in follow-up reporting. Waiting for certainty is how contractors miss the window.

  • Adverse effect on a covered system or the CDI on it — actual or potential.
  • Compromise of covered defense information, including exfiltration.
  • Operationally critical support — impact to designated critical performance.
  • When in doubt, report — the clock runs from discovery, not confirmation.
How this relates to CMMC

7012 is the obligation. CMMC is the verification.

DFARS 252.204-7012 has required NIST SP 800-171 and 72-hour reporting for years — it did not wait for CMMC. What CMMC 2.0 adds, through DFARS 252.204-7021, is verification: at Level 2 a C3PAO confirms the 800-171 controls are actually in place, rather than accepting a self-attestation.

Incident Response is one of the 14 control families of NIST SP 800-171, so your ability to detect, respond to, and report an incident is part of what a Level 2 assessment examines. The 72-hour rule and CMMC are not separate programs — they are the standing duty and the check that it is met.

How CMMC verifies 800-171 →

  • 7012 — safeguard CDI via 800-171; report within 72 hours.
  • 7021 — the CMMC clause that verifies 800-171 is implemented.
  • Incident Response family — the 800-171 controls behind reporting readiness.
  • One posture — meeting 7012 well is meeting a core part of Level 2.
How Atom supports the clock

You can’t report what you didn’t detect.

The reporting obligation is yours. Atom’s 24/7 SOC exists to make discovery fast and the 72-hour window comfortable rather than frantic — we support detection and the reporting timeline; we do not file on your behalf as the responsible party.

01

24/7 detection

Continuous monitoring and correlation across your covered systems so a compromise is discovered in hours, not weeks — because the 72-hour clock starts at discovery.

02

Triage & scoping

When something fires, we determine fast whether a covered system or CDI is affected — the judgment that decides whether the report clock has started.

03

Preservation & evidence

We help preserve and image affected systems and retain monitoring data so the ~90-day preservation duty is met and follow-up reporting is backed by real artifacts.

04

Runbook & timeline support

We build the incident-response runbook, confirm your medium assurance certificate is ready, and stand beside your team so the DIBNet submission lands inside 72 hours.

05

Flow-down coordination

Where subcontractors touch CDI, we help align their reporting so an incident does not stall at a weak link in your supply chain.

06

Post-incident hardening

After the report, we close the gap that allowed the incident and update the SSP and evidence — so the same finding does not resurface at your next assessment.

See our managed detection & response →

Before the clock starts

Be ready to report before you have to.

Request a readiness assessment. We’ll check your detection coverage, your medium assurance certificate, and your incident runbook — so a 72-hour report is a process you follow, not a crisis you improvise.

Request a Readiness Assessment