FAR and DFARS › DFARS Part 252: Solicitation Provisions and Contract Clauses › Subpart 252.2

DFARS 252.204-7008 Compliance with safeguarding covered defense information controls.

The codified text (eCFR, as of 2026-10-02). Under the Revolutionary FAR Overhaul ↗, agencies follow class deviations with new text for many parts while the formal rules go through the Federal Register: check the solicitation and your contract's clauses, which rule.

In plain English

This provision requires contractors to implement security requirements for covered defense information on their information systems that support the contract. It also allows offerors to request variations from specific NIST SP 800-171 requirements by providing a written explanation to the contracting officer for DoD CIO consideration.

Applies to: Offerors and contractors handling covered defense information on covered contractor information systems

What it requires

  • Implement the security requirements required by contract clause 252.204-7012 for all covered defense information on all covered contractor information systems that support the performance of this contract.
  • By submission of offer, represent that it will implement the security requirements specified by NIST SP 800-171 that are in effect at the time the solicitation is issued or as authorized by the contracting officer, not later than December 31, 2017.
  • If proposing to vary from any NIST SP 800-171 security requirements, submit to the Contracting Officer a written explanation of why a requirement is not applicable or how an alternative equally effective security measure is used.

Key terms: covered defense information · covered contractor information system · NIST SP 800-171 · security requirements · variance

Written by AI from this section's text. A guide, not legal advice: the text below rules.

The text

As prescribed in 204.7304(a), use the following provision:

Compliance With Safeguarding Covered Defense Information Controls (OCT 2016)

(a) Definitions. As used in this provision—

Controlled technical information, covered contractor information system, covered defense information, cyber incident, information system, and technical information are defined in clause 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting.

(b) The security requirements required by contract clause 252.204-7012, shall be implemented for all covered defense information on all covered contractor information systems that support the performance of this contract.

(c) For covered contractor information systems that are not part of an information technology service or system operated on behalf of the Government (see 252.204-7012(b)(2))—

(1) By submission of this offer, the Offeror represents that it will implement the security requirements specified by National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171, “Protecting Controlled Unclassified Information in Nonfederal Information Systems and Organizations” (see http://dx.doi.org/10.6028/NIST.SP.800-171)that are in effect at the time the solicitation is issued or as authorized by the contracting officer, not later than December 31, 2017.

(2)(i) If the Offeror proposes to vary from any of the security requirements specified by NIST SP 800-171 that are in effect at the time the solicitation is issued or as authorized by the Contracting Officer, the Offeror shall submit to the Contracting Officer, for consideration by the DoD Chief Information Officer (CIO), a written explanation of—

(A) Why a particular security requirement is not applicable; or

(B) How an alternative but equally effective, security measure is used to compensate for the inability to satisfy a particular requirement and achieve equivalent protection.

(ii) An authorized representative of the DoD CIO will adjudicate offeror requests to vary from NIST SP 800-171 requirements in writing prior to contract award. Any accepted variance from NIST SP 800-171 shall be incorporated into the resulting contract.

(End of provision)

Sections it refers to

  • 204.7304 Solicitation provisions and contract clauses.
  • 252.204-7012 Safeguarding Covered Defense Information and Cyber Incident Reporting.

Sections that refer to it

  • 204.7304 Solicitation provisions and contract clauses.
  • 212.301 Solicitation provisions and contract clauses for the acquisition of commercial products and commercial services.
  • 212.371 Inapplicability of certain provisions and clauses to contracts for the acquisition of commercially available off-the-shelf items.

← 252.204-7007 Alternate A, Annual Representations and Certifications. · 252.204-7009 Limitations on the Use or Disclosure of Third-Party Contractor Reported Cyber Incident Information. →

Rule changes for DFARS Part 252

Source: eCFR, 48 CFR chapters 1 and 2 (GPO GovInfo bulk data) ↗. Plain words for the terms: glossary.

DFARS 252.204-7008 Compliance with safeguarding covered defense information controls · SpendQuery