FAR and DFARS › DFARS Part 204: Administrative and Information Matters › Subpart 204.73
DFARS 204.7302 Policy.
The codified text (eCFR, as of 2026-10-02). Under the Revolutionary FAR Overhaul ↗, agencies follow class deviations with new text for many parts while the formal rules go through the Federal Register: check the solicitation and your contract's clauses, which rule.
In plain English
This section requires contractors and subcontractors to provide adequate security on covered contractor information systems and to rapidly report cyber incidents to the Department of Defense. It also establishes requirements for NIST SP 800-171 DoD Assessments and protects contractor attributional/proprietary information shared during incident reporting.
Applies to: Contractors and subcontractors with covered contractor information systems
What it requires
- Provide adequate security on all covered contractor information systems.
- Have at least a Basic NIST SP 800-171 DoD Assessment that is current at time of award, if required to implement NIST SP 800-171.
- Rapidly report cyber incidents directly to DoD at http://dibnet.dod.mil.
- Subcontractors must provide the incident report number automatically assigned by DoD to the prime contractor, and lower-tier subcontractors must report the number to their higher-tier subcontractor until the prime contractor is reached.
Key terms: covered contractor information systems · NIST SP 800-171 · Basic NIST SP 800-171 DoD Assessment · cyber incident · contractor attributional/proprietary information
Written by AI from this section's text. A guide, not legal advice: the text below rules.
The text
(a)(1) Contractors and subcontractors are required to provide adequate security on all covered contractor information systems.
(2) Contractors required to implement NIST SP 800-171, in accordance with the clause at 252.204-7012, Safeguarding Covered Defense Information and Cyber incident Reporting, are required at time of award to have at least a Basic NIST SP 800-171 DoD Assessment that is current (i.e., not more than 3 years old unless a lesser time is specified in the solicitation) (see 252.204-7019).
(3) The NIST SP 800-171 DoD Assessment Methodology is located at https://www.acq.osd.mil/asda/dpc/cp/cyber/safeguarding.html#nistSP800171.
(4) High NIST SP 800-171 DoD Assessments will be conducted by Government personnel using NIST SP 800-171A, “Assessing Security Requirements for Controlled Unclassified Information.”
(5) The NIST SP 800-171 DoD Assessment will not duplicate efforts from any other DoD assessment or the Cybersecurity Maturity Model Certification (CMMC) (see subpart 204.75), except for rare circumstances when a re-assessment may be necessary, such as, but not limited to, when cybersecurity risks, threats, or awareness have changed, requiring a re-assessment to ensure current compliance.
(b) Contractors and subcontractors are required to rapidly report cyber incidents directly to DoD at http://dibnet.dod.mil. Subcontractors provide the incident report number automatically assigned by DoD to the prime contractor. Lower-tier subcontractors likewise report the incident report number automatically assigned by DoD to their higher-tier subcontractor, until the prime contractor is reached.
(1) If a cyber incident occurs, contractors and subcontractors submit to DoD—
(i) A cyber incident report;
(ii) Malicious software, if detected and isolated; and
(iii) Media (or access to covered contractor information systems and equipment) upon request.
(2) Contracting officers shall refer to PGI 204.7303-4(c) for instructions on contractor submissions of media and malicious software.
(c) Information shared by the contractor may include contractor attributional/proprietary information that is not customarily shared outside of the company, and that the unauthorized use or disclosure of such information could cause substantial competitive harm to the contractor that reported the information. The Government shall protect against the unauthorized use or release of information that includes contractor attributional/proprietary information.
(d) A cyber incident that is reported by a contractor or subcontractor shall not, by itself, be interpreted as evidence that the contractor or subcontractor has failed to provide adequate security on their covered contractor information systems, or has otherwise failed to meet the requirements of the clause at 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting. When a cyber incident is reported, the contracting officer shall consult with the DoD component Chief Information Officer/cyber security office prior to assessing contractor compliance (see PGI 204.7303-3(a)(3)). The contracting officer shall consider such cyber incidents in the context of an overall assessment of a contractor's compliance with the requirements of the clause at 252.204-7012.
(e) Support services contractors directly supporting Government activities related to safeguarding covered defense information and cyber incident reporting (e.g., forensic analysis, damage assessment,, or other services that require access to data from another contractor) are subject to restrictions on use and disclosure of reported information.
Sections it refers to
- 252.204-7012 Safeguarding Covered Defense Information and Cyber Incident Reporting.
- 252.204-7019 Notice of NIST SP 800-171 DoD Assessment Requirements.
← 204.7301 Definitions. · 204.7303 Procedures. →
Rule changes for DFARS Part 204
- Defense Federal Acquisition Regulation Supplement: Assessing Contractor Implementation of Cybersecurity Requirements (DFARS Case 2019-D041) ↗ · final rule 2025-09-10 · effective 2025-11-10
- Defense Federal Acquisition Regulation Supplement: Inapplicability of Additional Defense-Unique Laws and Certain Non-Statutory DFARS Clauses to Commercial Item Contracts (DFARS Case 2018-D074) ↗ · final rule 2024-11-15 · effective 2024-11-25
- Defense Federal Acquisition Regulation Supplement; Technical Amendments ↗ · final rule 2024-09-26 · effective 2024-10-01
- Defense Federal Acquisition Regulation Supplement: Data Universal Numbering System to Unique Entity Identifier Transition (DFARS Case 2022-D023) ↗ · final rule 2024-09-26 · effective 2024-10-01
- Defense Federal Acquisition Regulation Supplement: Modification of Notification of Intent To Transport Supplies by Sea (DFARS Case 2020-D026) ↗ · final rule 2024-09-26 · effective 2024-10-01
- Defense Federal Acquisition Regulation Supplement: Assessing Contractor Implementation of Cybersecurity Requirements (DFARS Case 2019-D041) ↗ · proposed 2024-08-15 · comments due 2024-10-15
- Defense Federal Acquisition Regulation Supplement; Technical Amendments ↗ · final rule 2024-07-29 · effective 2024-07-29
- Defense Federal Acquisition Regulation Supplement: Modification of Notification of Intent To Transport Supplies by Sea (DFARS Case 2020-D026) ↗ · proposed 2024-03-26 · comments due 2024-05-28
Source: eCFR, 48 CFR chapters 1 and 2 (GPO GovInfo bulk data) ↗. Plain words for the terms: glossary.