Adequate security
Implement NIST SP 800-171 on covered contractor information systems that process, store, or transmit Covered Defense Information. This is the part everyone knows about, and it is the largest body of work. The 110 requirements →
The clause is usually read as "implement NIST 800-171." It requires more than that: a reporting capability with a hard deadline, evidence preservation, obligations you inherit from your cloud providers, and flow-down to your own subcontractors. Cyberneza works through each obligation and tells you which ones you are currently unable to meet.
Personal reply within one business day.
Implement NIST SP 800-171 on covered contractor information systems that process, store, or transmit Covered Defense Information. This is the part everyone knows about, and it is the largest body of work. The 110 requirements →
Report a cyber incident affecting covered systems or Covered Defense Information to DoD via DIBNet within 72 hours of discovery. Reporting requires a medium assurance certificate — which takes time to obtain, so an organization that starts the process during an incident has already missed the window.
Preserve and protect images of affected systems and relevant monitoring data for at least 90 days from submission, so DoD can request them. This is a capability question, not a policy one: most environments cannot produce a forensic image on demand.
The clause flows down to subcontractors whose work involves Covered Defense Information. That makes your suppliers' posture part of your own compliance position, and their incidents reportable to you.
Where you use an external cloud service provider to store, process, or transmit Covered Defense Information, 7012 requires that provider to meet security requirements equivalent to FedRAMP Moderate, and requires you to ensure the incident reporting and media preservation obligations reach through to them.
In practice this is what pushes organizations toward GCC High or a purpose-built enclave — and it is worth deciding deliberately rather than discovering it mid-contract. GCC High & enclave planning →
Read the clauses in your actual contract, establish what each one obligates you to do, and close the gaps between that and what your organization can do today.
Work through the DFARS clauses in your contract and identify which obligations attach to you, and where CDI actually flows.
The safeguarding half of the clause, scoped to the covered systems rather than the whole company.
Build the capability to detect, decide, and report inside 72 hours — including obtaining the medium assurance certificate before you need it.
Establish how images and monitoring data are captured and retained so a DoD request can actually be answered.
Determine whether your providers meet the FedRAMP Moderate equivalency requirement, and what to do when they do not.
Get the clause into your subcontracts and establish how supplier incidents reach you in time to meet your own deadline.
Send us the clauses. We will tell you which obligations attach, where Covered Defense Information actually flows, and which requirements you cannot currently meet.