FAR and DFARS › DFARS Part 252: Solicitation Provisions and Contract Clauses › Subpart 252.2
DFARS 252.204-7008 Compliance with safeguarding covered defense information controls.
The codified text (eCFR, as of 2026-10-02). Under the Revolutionary FAR Overhaul ↗, agencies follow class deviations with new text for many parts while the formal rules go through the Federal Register: check the solicitation and your contract's clauses, which rule.
In plain English
This provision requires contractors to implement security requirements for covered defense information on their information systems that support the contract. It also allows offerors to request variations from specific NIST SP 800-171 requirements by providing a written explanation to the contracting officer for DoD CIO consideration.
Applies to: Offerors and contractors handling covered defense information on covered contractor information systems
What it requires
- Implement the security requirements required by contract clause 252.204-7012 for all covered defense information on all covered contractor information systems that support the performance of this contract.
- By submission of offer, represent that it will implement the security requirements specified by NIST SP 800-171 that are in effect at the time the solicitation is issued or as authorized by the contracting officer, not later than December 31, 2017.
- If proposing to vary from any NIST SP 800-171 security requirements, submit to the Contracting Officer a written explanation of why a requirement is not applicable or how an alternative equally effective security measure is used.
Key terms: covered defense information · covered contractor information system · NIST SP 800-171 · security requirements · variance
Written by AI from this section's text. A guide, not legal advice: the text below rules.
The text
As prescribed in 204.7304(a), use the following provision:
Compliance With Safeguarding Covered Defense Information Controls (OCT 2016)
(a) Definitions. As used in this provision—
Controlled technical information, covered contractor information system, covered defense information, cyber incident, information system, and technical information are defined in clause 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting.
(b) The security requirements required by contract clause 252.204-7012, shall be implemented for all covered defense information on all covered contractor information systems that support the performance of this contract.
(c) For covered contractor information systems that are not part of an information technology service or system operated on behalf of the Government (see 252.204-7012(b)(2))—
(1) By submission of this offer, the Offeror represents that it will implement the security requirements specified by National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171, “Protecting Controlled Unclassified Information in Nonfederal Information Systems and Organizations” (see http://dx.doi.org/10.6028/NIST.SP.800-171)that are in effect at the time the solicitation is issued or as authorized by the contracting officer, not later than December 31, 2017.
(2)(i) If the Offeror proposes to vary from any of the security requirements specified by NIST SP 800-171 that are in effect at the time the solicitation is issued or as authorized by the Contracting Officer, the Offeror shall submit to the Contracting Officer, for consideration by the DoD Chief Information Officer (CIO), a written explanation of—
(A) Why a particular security requirement is not applicable; or
(B) How an alternative but equally effective, security measure is used to compensate for the inability to satisfy a particular requirement and achieve equivalent protection.
(ii) An authorized representative of the DoD CIO will adjudicate offeror requests to vary from NIST SP 800-171 requirements in writing prior to contract award. Any accepted variance from NIST SP 800-171 shall be incorporated into the resulting contract.
(End of provision)
Sections it refers to
- 204.7304 Solicitation provisions and contract clauses.
- 252.204-7012 Safeguarding Covered Defense Information and Cyber Incident Reporting.
Sections that refer to it
- 204.7304 Solicitation provisions and contract clauses.
- 212.301 Solicitation provisions and contract clauses for the acquisition of commercial products and commercial services.
- 212.371 Inapplicability of certain provisions and clauses to contracts for the acquisition of commercially available off-the-shelf items.
← 252.204-7007 Alternate A, Annual Representations and Certifications. · 252.204-7009 Limitations on the Use or Disclosure of Third-Party Contractor Reported Cyber Incident Information. →
Rule changes for DFARS Part 252
- Defense Federal Acquisition Regulation Supplement: Modifications to Printed Circuit Board Acquisition Restrictions (DFARS Case 2022-D011) ↗ · proposed 2026-07-02 · comments due 2026-08-31
- Defense Federal Acquisition Regulation Supplement: Certification Requirement for Military Recruitment Advertising (DFARS Case 2024-D022) ↗ · proposed 2026-06-25 · comments due 2026-08-24
- Defense Federal Acquisition Regulation Supplement: Small Purchase Exception for the Acquisition of U.S. Flags (DFARS Case 2024-D013) ↗ · proposed 2026-06-25 · comments due 2026-08-24
- Defense Federal Acquisition Regulation Supplement: Mitigating Risks Related to Foreign Ownership, Control, or Influence (DFARS Case 2021-D011) ↗ · proposed 2026-05-07 · comments due 2026-07-06
- Defense Federal Acquisition Regulation Supplement: Assessing Contractor Implementation of Cybersecurity Requirements (DFARS Case 2019-D041) ↗ · final rule 2025-09-10 · effective 2025-11-10
- Defense Federal Acquisition Regulation Supplement: Limitation on Certain Institutes of Higher Education (DFARS Case 2024-D023); Correction ↗ · final rule 2025-08-28 · effective 2025-08-28
- Defense Federal Acquisition Regulation Supplement: Disclosure of DoD Funding in Technical Publications (DFARS Case 2024-D003) ↗ · proposed 2025-08-25 · comments due 2025-10-24
- Defense Federal Acquisition Regulation Supplement: Limitation on Certain Institutes of Higher Education (DFARS Case 2024-D023) ↗ · final rule 2025-08-25 · effective 2025-08-25
Source: eCFR, 48 CFR chapters 1 and 2 (GPO GovInfo bulk data) ↗. Plain words for the terms: glossary.