Capital Cyber News
Reporting for United States defense contractors and small business KEV catalog 2026.08.14

Practical Defense

Incident Response and the DFARS 72 Hour Clock

The Department of Defense introduced DFARS 252.204-7012 and its 72 hour reporting rule for Controlled Unclassified Information, placing new security obligations on contractors. Many organizations first encounter this “72 hour clock” after an incident, scrambling to understand the steps required. This article covers the specifics of the rule, its impact on incident response, and what actions you can take to prevent mistakes.

What is DFARS 72 hour reporting and who does it apply to?

DFARS 252.204-7012 requires that contractors and their subcontractors report certain cyber incidents to DoD within 72 hours of discovery. This applies to you if you process, store, or transmit CUI for DoD contracts, and includes both prime contractors and subcontractors. The report must be submitted through the DoD DIBNet portal, which is the official channel for Defense Industrial Base companies.

The 72 hour window starts when you determine that a cyber incident affecting covered defense information or your information systems has occurred. This is not limited to massive breaches. Any unauthorized access or activity that could impact CUI triggers the reporting requirement.

What exactly must be reported through DIBNet?

DFARS 252.204-7012 defines a “cyber incident” as actions taken through computer networks that result in an actual or potentially adverse effect on an information system and/or the information residing therein. When you discover such an incident, you must submit a report through DIBNet within 72 hours. The initial report must include as much detail as possible, such as:

  • Information about the affected systems and CUI
  • A summary of the incident, including how and when it was discovered
  • Any actions taken to contain and remediate the issue

You may not have all the answers within 72 hours, but you need to file a preliminary report and update it as you learn more. DFARS 252.204-7012 also requires you to preserve and protect images of affected systems and all relevant monitoring and packet capture data for at least 90 days from the submission of the report, in case DoD requests further information.

What does NIST SP 800-171 require for incident response?

DFARS 252.204-7012 mandates that Level 2 contractors implement all 110 controls in NIST SP 800-171 Rev 2. Incident response is one of the 14 control families, with three required practices:

  • IR.L2-3.6.1: Establish an operational incident-handling capability for incidents that includes preparation, detection, analysis, containment, recovery, and user response activities.
  • IR.L2-3.6.2: Track, document, and report incidents to appropriate officials and/or authorities both internal and external to the organization.
  • IR.L2-3.6.3: Test the organizational incident response capability.

These requirements mean you must have documented policies and procedures for handling incidents, keep records of incidents and responses, and perform regular exercises to make sure your team knows what to do.

How does the DFARS 72 hour reporting rule affect my incident response plan?

Many companies only learn about the DFARS 72 hour reporting requirement when they are already responding to an incident. By then, the clock is ticking and the risk of missing required steps is high.

To avoid this, your incident response plan must include:

  • Clear procedures for identifying when a cyber incident has occurred
  • Defined roles and responsibilities for reporting through DIBNet within 72 hours
  • Steps for collecting and preserving evidence as required by DFARS 252.204-7012
  • Documentation templates to speed up reporting under pressure

Remember, a policy or procedure is not enough. You must be able to produce timestamped evidence that your team can follow the plan and that you are meeting the reporting requirement. According to the CMMC Scoping and Assessment Guide L2 v2.13, assessors will look for real-world proof that your incident response process works, more than documentation.

What happens if I miss the DFARS 72 hour reporting window?

Failure to report a qualifying cyber incident within 72 hours is a violation of DFARS 252.204-7012 and can have serious consequences. The Department of Defense has enforced compliance through self-assessments and government-led assessments, particularly since the CMMC third party certification requirement was suspended in July 2026. Your annual self-assessment and the senior official’s affirmation are now the primary evidence of compliance.

False claims about your cybersecurity posture can lead to liability under the False Claims Act. Past cases have involved companies that falsely certified compliance or failed to follow required incident response procedures, resulting in settlements that named more than the company but also private equity owners and affiliates.

How do I prepare for DFARS 72 hour reporting on Monday morning?

You do not want to be learning about DFARS 72 hour reporting for the first time during a crisis. Here is what you can do now:

  • Review your incident response plan to ensure it specifically addresses DFARS 252.204-7012 reporting and DIBNet submission
  • Train your staff on how to recognize a reportable incident and who is responsible for submitting the report
  • Practice incident response exercises that simulate real reporting scenarios
  • Update your documentation to include evidence collection requirements and reporting templates

If you have not completed your System Security Plan (SSP) or Plan of Actions and Milestones (POA&M), you are not alone, but these documents are essential for demonstrating compliance and responding effectively to incidents.

What if I have not completed my CMMC Level 2 assessment?

As of July 2026, the requirement for a third party CMMC Level 2 certification is suspended. However, DFARS 252.204-7012, NIST SP 800-171 Rev 2, Level 2 self-assessments, SPRS posting, and annual senior official affirmation are all still required and actively enforced. With no third party assessor between you and the government, your senior official’s signature carries significant weight and increases your exposure under the False Claims Act if your self-assessment is not accurate.

Common questions

What is the DIBNet portal and why does it matter for DFARS 72 hour reporting? DIBNet is the Defense Industrial Base Cybersecurity portal where you must submit cyber incident reports as required by DFARS 252.204-7012. It is the official channel for reporting to DoD.

Does the DFARS 72 hour reporting rule apply to subcontractors? Yes, it applies to both prime contractors and subcontractors who process, store, or transmit CUI under DoD contracts.

What if I do not have all the incident details within 72 hours? You must submit a preliminary report with the information you have, then update it as you learn more. The key is to meet the 72 hour deadline for initial reporting.

Prepare Your Incident Response Plan Now

If you are a defense contractor handling CUI, make sure your incident response plan is tuned for DFARS 252.204-7012 and DIBNet reporting. If you need help assessing your readiness, the Cyber Grants Alliance offers an in kind CMMC Gap Assessment Grant delivered as services, covering all 110 NIST 800-171 controls for qualifying defense contractors. You can learn more about this opportunity at https://cybergrantsalliance.org/cmmc-gap-assessment-grant/.

Being prepared before an incident occurs is the best way to meet DFARS 72 hour reporting requirements, and protect your business and contracts.

More on Defense

Defense · 5 min MFA: What Actually Satisfies IA.L2-3.5.3

Understand what counts as multifactor authentication CMMC compliance, why SMS is weak, and how to meet requirements for privileged and non-privileged accounts.