Defense Contractors and Cyber Incident Reporting: Prepare Now

Contractors that handle covered defense information may have strict reporting duties after a cyber incident. Here is how to prepare the people and paperwork.

3 min readBy Ironfield Cyber Team

Most cyber incident plans focus on getting systems back. Contractors that handle covered defense information have an additional job: telling the government, and sometimes a prime contractor, quickly and accurately. The time to learn what that involves is before an incident, not during one.

This post is a general orientation, not legal advice. Your contract clauses control, so read them and involve your attorney.

What the clause generally requires

Many defense contracts include the DFARS clause 252.204-7012, which addresses safeguarding covered defense information and cyber incident reporting. In general terms, it expects contractors to provide adequate security on systems that process covered defense information, to report cyber incidents that affect those systems or the information on them within 72 hours of discovery, and to preserve certain images and data for a period so investigators can review them. Reports are made through a designated Department of Defense reporting portal, and the contractor typically needs a medium assurance certificate to use it.

Check the exact language in your contract and any flow-down clauses. Subcontractors often must also notify the prime contractor.

Why preparation matters

Seventy-two hours sounds generous until you consider what happens in the first day of an incident. Systems are down, people are guessing and nobody is sure what was touched. Without preparation, the reporting duty can be forgotten, delayed or mishandled.

Build the pieces ahead of time

Know what counts as covered

Maintain a clear map of where covered defense information and controlled unclassified information live. If you cannot say which systems hold it, you cannot say whether an incident affected it. Scope documentation from your NIST SP 800-171 work is the right starting point.

Assign roles

Name specific people for these jobs.

  1. Incident lead: coordinates the response and decisions.
  2. Reporting owner: responsible for the government and prime contractor notifications.
  3. Technical lead: directs containment and evidence preservation.
  4. Legal contact: advises on obligations and communications.
  5. Executive sponsor: authorizes spending and external statements.

Name backups for each. Incidents do not wait for vacations.

Prepare access to the reporting channel

Do not wait until an incident to find out how reporting works. Confirm who in your company holds or can obtain the required certificate, how long that takes and where the instructions live. Keep a plain-language reference of the information the report asks for.

Plan evidence preservation

Preserving images of affected systems and relevant logs for the period the clause specifies requires some foresight. Decide where evidence will be stored, who can access it and how it is protected. Avoid wiping or rebuilding systems before images are captured unless safety demands it, and document any exceptions.

Write the contact list

Keep a printed or offline list of contacts: your prime contractor's security contact, contracting officer information where relevant, legal counsel, insurance carrier, your IT provider and forensic resources. If email is down, you will still need these.

Practice once

Run a short tabletop exercise with a realistic scenario, such as suspicious sign-ins on an account that handles CUI.

  • When does the 72-hour clock start in your reading of the clause?
  • Who decides whether the event is reportable?
  • What information do you have, and what is missing?
  • How do you notify the prime contractor?
  • Where is evidence being saved?

Capture the gaps and fix them.

Common mistakes

  • Treating the report as an IT task rather than a business and legal one.
  • Waiting for complete certainty before reporting. Reports can generally be supplemented as facts emerge, so ask counsel how to handle partial information.
  • Deleting logs or rebuilding machines too soon.
  • Not telling the cyber insurer promptly, which can affect coverage.
  • Forgetting that subcontractors and IT providers may hold relevant evidence.

Link to CMMC

CMMC 2.0 builds on the same NIST SP 800-171 requirements for Level 2, including incident response. A tested incident response and reporting process helps with both contract compliance and assessment readiness.

Next steps

Start by reading the clauses in your active contracts and writing the reporting steps on a single page. Ironfield Cyber helps defense subcontractors prepare incident response and reporting procedures and run tabletop exercises. If you would like help building yours, we can start with a short review of your current plan.