> ## Content Index
> Fetch the complete content index at: https://www.cmmcoperator.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# Incident Reporting Under DFARS 252.204-7012: The 72-Hour Clock
- URL: https://www.cmmcoperator.com/incident-reporting-under-dfars-252-204-7012-the-72-hour-clock/
- Published: 2026-08-15T14:18:33.000Z
- Updated: 2026-08-15T14:18:33.000Z
- Author: HydratedSec
- Tags: CMMC, DFARS, Incident Response, CUI, CMMC Level 2

If a cyber incident touches CUI on your systems, the clock starts immediately. DFARS 252.204-7012 gives defense contractors 72 hours to report to the Department of Defense, and the requirement applies whether or not you are CMMC certified yet. Most contractors do not discover the gaps in their incident process until they are in the middle of one. The fix is to build the muscle memory before you need it.

## What the Clause Requires

DFARS 252.204-7012 requires that you implement NIST SP 800-171, report cyber incidents that affect covered defense information within 72 hours, preserve and protect affected systems and images for at least 90 days, and flow the same requirements down to subcontractors. The reporting is done through the DoD reporting portal, which requires a medium assurance certificate. That certificate can take time to obtain, which is why it should be in hand long before an incident, not requested during one.

## What Counts as a Reportable Incident

The threshold is broader than a confirmed breach. Watch for these triggers:

- Any compromise that affects covered defense information on a covered system.
- Compromise of the contractor system that processes, stores, or transmits that information.
- Events affecting your ability to perform requirements designated as operationally critical support.
- When in doubt, the safer posture is to report rather than to sit on a judgment call past the deadline.

## Build the Process Before You Need It

Seventy-two hours sounds generous until an incident lands on a Friday afternoon. The contractors who report cleanly are the ones who decided in advance who declares an incident, who holds the medium assurance certificate and portal access, what information the report needs, and how to preserve images without tipping off an adversary or destroying evidence. Write this into your incident response plan, assign the roles by name, and run at least one tabletop exercise so the team has walked the path once before doing it for real.

Reporting is not an admission of fault. It is a contractual obligation, and meeting it on time protects you far more than a delayed or missed report ever could.

## Incident Readiness Checklist

- Obtain a medium assurance certificate and confirm portal access now, not later.
- Name the person authorized to declare an incident and submit the report.
- Document the 72-hour workflow and the data the report requires.
- Define how to preserve affected systems and images for 90 days.
- Flow the reporting requirement down to subcontractors in your agreements.
- Run a tabletop exercise to test the process end to end.

CMMC Operator provides compliance readiness resources for informational and planning purposes only. This article is not legal advice, an assessment determination, or a substitute for a qualified C3PAO or GRC advisor. Validate your reporting obligations against the current text of DFARS 252.204-7012 and your specific contracts.