Malware submission
If malicious software is discovered and isolated in connection with a reported incident, it must be submitted to the DoD Cyber Crime Center (DC3) in the manner the department directs.
DFARS 252.204-7012 has two halves. The first: safeguard Covered Defense Information by implementing NIST SP 800-171. The second: report a cyber incident within 72 hours of discovery to the DoD through DIBNet. The clock starts when you discover the incident, not when you finish investigating. This page explains what the clause requires, what counts as reportable, and how a 24/7 SOC keeps you inside the window.
DFARS 252.204-7012 obligates contractors to provide “adequate security” for Covered Defense Information (CDI) on their systems — which the clause defines as implementing NIST SP 800-171. That is the same 110-requirement standard CMMC Level 2 measures against. Safeguarding is the standing obligation.
The reporting obligation is the sharp edge. When a cyber incident affects a covered system or the CDI on it, you must rapidly report it — within 72 hours of discovery — to the DoD via DIBNet. Submitting through DIBNet requires a DoD-approved medium assurance certificate, which takes time to obtain. That certificate must be in hand before an incident, not requested during one.
The 72-hour report triggers a chain of duties. Miss the supporting obligations and the report itself is not enough.
If malicious software is discovered and isolated in connection with a reported incident, it must be submitted to the DoD Cyber Crime Center (DC3) in the manner the department directs.
You must preserve and protect images of affected systems and relevant monitoring data for at least 90 days from the report, so the government can request them for its own analysis.
The clause flows down to subcontractors whose work involves CDI. Subs must meet the same safeguarding and reporting duties, and must report incidents to the prime and to DoD.
When a cloud service is used to store, process, or transmit CDI on the contractor’s behalf, the provider must meet DoD requirements (FedRAMP Moderate equivalence or higher) and support the 7012 obligations.
A reportable cyber incident is one that actually or potentially adversely affects a covered contractor information system or the Covered Defense Information residing on it — or that affects the contractor’s ability to perform requirements designated as operationally critical support. It is a low bar by design: “potentially” and “compromise” are broad terms.
Because the standard is exposure rather than confirmed loss, the safe reading is to treat plausible compromise of a covered system as reportable and start the 72-hour clock at discovery — then let the investigation refine the detail in follow-up reporting. Waiting for certainty is how contractors miss the window.
DFARS 252.204-7012 has required NIST SP 800-171 and 72-hour reporting for years — it did not wait for CMMC. What CMMC 2.0 adds, through DFARS 252.204-7021, is verification: at Level 2 a C3PAO confirms the 800-171 controls are actually in place, rather than accepting a self-attestation.
Incident Response is one of the 14 control families of NIST SP 800-171, so your ability to detect, respond to, and report an incident is part of what a Level 2 assessment examines. The 72-hour rule and CMMC are not separate programs — they are the standing duty and the check that it is met.
The reporting obligation is yours. Atom’s 24/7 SOC exists to make discovery fast and the 72-hour window comfortable rather than frantic — we support detection and the reporting timeline; we do not file on your behalf as the responsible party.
Continuous monitoring and correlation across your covered systems so a compromise is discovered in hours, not weeks — because the 72-hour clock starts at discovery.
When something fires, we determine fast whether a covered system or CDI is affected — the judgment that decides whether the report clock has started.
We help preserve and image affected systems and retain monitoring data so the ~90-day preservation duty is met and follow-up reporting is backed by real artifacts.
We build the incident-response runbook, confirm your medium assurance certificate is ready, and stand beside your team so the DIBNet submission lands inside 72 hours.
Where subcontractors touch CDI, we help align their reporting so an incident does not stall at a weak link in your supply chain.
After the report, we close the gap that allowed the incident and update the SSP and evidence — so the same finding does not resurface at your next assessment.
Request a readiness assessment. We’ll check your detection coverage, your medium assurance certificate, and your incident runbook — so a 72-hour report is a process you follow, not a crisis you improvise.
Request a Readiness Assessment →