FAR and DFARS › DFARS Part 252: Solicitation Provisions and Contract Clauses › Subpart 252.2

DFARS 252.204-7009 Limitations on the Use or Disclosure of Third-Party Contractor Reported Cyber Incident Information.

The codified text (eCFR, as of 2026-10-02). Under the Revolutionary FAR Overhaul ↗, agencies follow class deviations with new text for many parts while the formal rules go through the Federal Register: check the solicitation and your contract's clauses, which rule.

In plain English

This clause restricts how a contractor may use or disclose information it receives or creates about a third party's reported cyber incident under DFARS 252.204-7012. The contractor may only use that information to advise or assist the Government on cyber incident reporting and safeguarding activities, must protect it from unauthorized release, and must flow the clause down to certain subcontracts. Breaching these obligations can lead to Government penalties and civil action by the third-party contractor that reported the incident.

Applies to: Contractors and subcontractors that receive or create third-party cyber incident information in performance of a contract referencing DFARS 252.204-7009

What it requires

  • Access and use the information only to furnish advice or technical assistance directly to the Government in support of its activities related to DFARS 252.204-7012.
  • Protect the information against unauthorized release or disclosure.
  • Ensure employees are subject to use and non-disclosure obligations consistent with this clause before they access or use the information.
  • Include this clause, including paragraph (c), in subcontracts or similar instruments for services that include support for the Government's activities related to safeguarding covered defense information and cyber incident reporting, including subcontracts for commercial products and commercial servi

Key terms: Compromise · Controlled technical information · Covered defense information · Cyber incident · Information system

Written by AI from this section's text. A guide, not legal advice: the text below rules.

The text

As prescribed in 204.7304(b), use the following clause:

Limitations on the Use or Disclosure of Third-Party Contractor Reported Cyber Incident Information (JAN 2023)

(a) Definitions. As used in this clause—

Compromise means disclosure of information to unauthorized persons, or a violation of the security policy of a system, in which unauthorized intentional or unintentional disclosure, modification, destruction, or loss of an object, or the copying of information to unauthorized media may have occurred.

Controlled technical information means technical information with military or space application that is subject to controls on the access, use, reproduction, modification, performance, display, release, disclosure, or dissemination. Controlled technical information would meet the criteria, if disseminated, for distribution statements B through F using the criteria set forth in DoD Instruction 5230.24, Distribution Statements on Technical Documents. The term does not include information that is lawfully publicly available without restrictions.

Covered defense information means unclassified controlled technical information or other information (as described in the Controlled Unclassified Information (CUI) Registry at http://www.archives.gov/cui/registry/category-list.html) that requires safeguarding or dissemination controls pursuant to and consistent with law, regulations, and Governmentwide policies, and is—

(1) Marked or otherwise identified in the contract, task order, or delivery order and provided to the contractor by or on behalf of DoD in support of the performance of the contract; or

(2) Collected, developed, received, transmitted, used, or stored by or on behalf of the contractor in support of the performance of the contract.

Cyber incident means actions taken through the use of computer networks that result in a compromise or an actual or potentially adverse effect on an information system and/or the information residing therein.

Information system means a discrete set of information resources organized for the collection, processing, maintenance, use, sharing, dissemination, or disposition of information.

Media means physical devices or writing surfaces including, but is not limited to, magnetic tapes, optical disks, magnetic disks, large-scale integration memory chips, and printouts onto which covered defense information is recorded, stored, or printed within a covered contractor information system.

Technical information means technical data or computer software, as those terms are defined in the clause at DFARS 252.227-7013, Rights in Technical Data—Other Than Commercial Products and Commercial Services, regardless of whether or not the clause is incorporated in this solicitation or contract. Examples of technical information include research and engineering data, engineering drawings, and associated lists, specifications, standards, process sheets, manuals, technical reports, technical orders, catalog-item identifications, data sets, studies and analyses and related information, and computer software executable code and source code.

(b) Restrictions. The Contractor agrees that the following conditions apply to any information it receives or creates in the performance of this contract that is information obtained from a third-party's reporting of a cyber incident pursuant to DFARS clause 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting (or derived from such information obtained under that clause):

(1) The Contractor shall access and use the information only for the purpose of furnishing advice or technical assistance directly to the Government in support of the Government's activities related to clause 252.204-7012, and shall not be used for any other purpose.

(2) The Contractor shall protect the information against unauthorized release or disclosure.

(3) The Contractor shall ensure that its employees are subject to use and non-disclosure obligations consistent with this clause prior to the employees being provided access to or use of the information.

(4) The third-party contractor that reported the cyber incident is a third-party beneficiary of the non-disclosure agreement between the Government and Contractor, as required by paragraph (b)(3) of this clause.

(5) A breach of these obligations or restrictions may subject the Contractor to—

(i) Criminal, civil, administrative, and contractual actions in law and equity for penalties, damages, and other appropriate remedies by the United States; and

(ii) Civil actions for damages and other appropriate remedies by the third party that reported the cyber incident, as a third party beneficiary of this clause.

(c) Subcontracts. The Contractor shall include this clause, including this paragraph (c), in subcontracts, or similar contractual instruments, for services that include support for the Government's activities related to safeguarding covered defense information and cyber incident reporting, including subcontracts for commercial products and commercial services, without alteration, except to identify the parties.

(End of clause)

Sections it refers to

  • 204.7304 Solicitation provisions and contract clauses.
  • 252.227-7013 Rights in Technical Data—Other Than Commercial Products and Commercial Services.
  • 252.204-7012 Safeguarding Covered Defense Information and Cyber Incident Reporting.

Sections that refer to it

  • 204.7304 Solicitation provisions and contract clauses.
  • 212.301 Solicitation provisions and contract clauses for the acquisition of commercial products and commercial services.
  • 252.204-7012 Safeguarding Covered Defense Information and Cyber Incident Reporting.

← 252.204-7008 Compliance with safeguarding covered defense information controls. · 252.204-7010 Requirement for Contractor To Notify DoD if the Contractor's Activities are Subject to Reporting Under the U.S.-International Atomic Energy Agency Additional Protocol. →

Rule changes for DFARS Part 252

Source: eCFR, 48 CFR chapters 1 and 2 (GPO GovInfo bulk data) ↗. Plain words for the terms: glossary.

DFARS 252.204-7009 Limitations on the Use or Disclosure of Third-Party Contractor Reported Cyber Incident Information · SpendQuery