DFARS
Defense Federal Acquisition Regulation Supplement
Contractual cybersecurity mandates for DoD suppliers, centered on DFARS clause 252.204-7012 and NIST SP 800-171.
Who It Applies To
Any contractor or subcontractor performing on a DoD contract that includes the DFARS 252.204-7012 clause, particularly those that create, receive, or transmit Controlled Unclassified Information (CUI) in the course of contract performance.
How We Help
Implement and document the 110 NIST SP 800-171 security controls
Stand up a 72-hour DoD cyber incident reporting procedure
Maintain System Security Plans (SSPs) and POA&Ms as contractual evidence
Correctly flow down security requirements to your subcontractors
Build a control baseline that carries directly into CMMC Level 2 readiness
Ready to close your compliance gaps?
Get a free security assessment, no obligation.