DFARS Cyber Safeguarding · 1 of 3

Covered defense information and adequate security

← All Insights

In short

  • Covered defense information includes controlled technical information.
  • Variances from NIST SP 800-171 are adjudicated by the Defense CIO.
  • External cloud providers must meet FedRAMP Moderate equivalence.
Published10 October 2026
Last reviewed10 October 2026
Sources current as of10 October 2026

1. What the cyber subpart covers

Defense Federal Acquisition Regulation Supplement (DFARS) subpart 204.73 applies to contracts and subcontracts that require safeguarding of covered defense information. The safeguarding covers information in covered contractor information systems, through specified network security requirements (DFARS 204.7300(a)). It also requires reporting of cyber incidents. The subpart does not abrogate other requirements for physical, personnel, information, technical or administrative security of unclassified information, nor does it affect the National Industrial Security Program (DFARS 204.7300(b)).

Contractors and subcontractors are required to provide adequate security on all covered contractor information systems (DFARS 204.7302(a)(1)). Adequate security means protective measures commensurate with the consequences and probability of loss, misuse, unauthorized access to, or modification of information (DFARS 204.7301).

2. Covered defense information

Covered defense information is unclassified controlled technical information or other information described in the Controlled Unclassified Information (CUI) Registry that requires safeguarding or dissemination controls under law, regulation and Governmentwide policy (DFARS 204.7301). It must also meet one of two conditions. It is marked or otherwise identified in the contract, task order or delivery order and provided to the contractor by or for the Defense Department in support of performance. Or it is collected, developed, received, transmitted, used or stored by or for the contractor in support of performance.

Controlled technical information is technical information with military or space application that is subject to controls on access, use, reproduction, release, disclosure or dissemination (DFARS 204.7301). It would meet the criteria for distribution statements B through F under Department of Defense Instruction 5230.24 if disseminated. It does not include information lawfully publicly available without restrictions. Technical information means technical data or computer software, such as engineering drawings, specifications, manuals, technical reports, data sets and source code.

An information system is a discrete set of information resources organized for the collection, processing, maintenance, use, sharing, dissemination or disposition of information (DFARS 204.7301). Media means physical devices or writing surfaces, such as magnetic tapes, optical disks, memory chips and printouts, on which covered defense information is recorded, stored or printed within a covered system. A covered contractor information system is an unclassified information system owned, or operated by or for, a contractor that processes, stores or transmits covered defense information (DFARS 204.7301).

3. Systems operated for the Government

The clause at DFARS 252.204-7012 sets the minimum protections, which depend on the kind of system (DFARS 252.204-7012(b)). For covered systems that are part of an information technology service or system operated on behalf of the Government, cloud computing services are subject to the clause at 252.239-7010 (DFARS 252.204-7012(b)(1)). Any other such service or system is subject to the security requirements specified elsewhere in the contract.

4. Contractor systems and the NIST standard

Other covered systems are generally subject to National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171. The version is the one in effect when the solicitation is issued, or as the contracting officer authorizes (DFARS 252.204-7012(b)(2)(i)). The clause required implementation as soon as practical, but not later than December 31, 2017. For contracts awarded before October 1, 2017, the contractor had to notify the Defense Department Chief Information Officer (CIO) within 30 days of award of any NIST SP 800-171 requirements not yet implemented (DFARS 252.204-7012(b)(2)(ii)(A)).

Requests to vary from NIST SP 800-171 go in writing to the contracting officer, for consideration by the CIO (DFARS 252.204-7012(b)(2)(ii)(B)). The contractor need not implement a requirement that an authorized representative of the CIO adjudicates as nonapplicable. The same holds where the representative finds an alternative but equally effective measure that may be used in its place. A copy of an earlier CIO approval goes to the contracting officer when the contractor asks for its recognition under the contract (DFARS 252.204-7012(b)(2)(ii)(C)).

5. External cloud providers and added measures

A contractor may use an external cloud service provider to store, process or transmit covered defense information. It must then require and ensure that the provider meets security requirements equivalent to the Federal Risk and Authorization Management Program (FedRAMP) Moderate baseline (DFARS 252.204-7012(b)(2)(ii)(D)). The provider must also comply with the clause’s requirements for incident reporting, malicious software, media preservation, forensic access and damage assessment.

The contractor must apply other security measures when it reasonably determines they may be required for adequate security in a dynamic environment or to accommodate special circumstances, such as medical devices (DFARS 252.204-7012(b)(3)). The same applies to individual, isolated or temporary deficiencies based on an assessed risk or vulnerability. These measures may be addressed in a system security plan. The contractor must also conduct its activities under the clause in line with the laws and regulations on interception, monitoring, access, use and disclosure of electronic communications and data (DFARS 252.204-7012(k)). The clause does not abrogate the contractor’s other safeguarding or incident reporting duties under other contract clauses or under statute or regulation (DFARS 252.204-7012(l)).

6. Where the clause applies

Contracting officers use the clause at 252.204-7012 in all solicitations and contracts, including those for commercial products and commercial services under Federal Acquisition Regulation (FAR) part 12 (DFARS 204.7304(c)). The exception is solicitations and contracts solely for commercially available off-the-shelf (COTS) items. The provision at 252.204-7008, on compliance with safeguarding controls, goes in all solicitations except those solely for COTS items (DFARS 204.7304(a)).

The contractor must include the clause, without alteration except to identify the parties, in subcontracts for operationally critical support or where performance will involve covered defense information (DFARS 252.204-7012(m)(1)). It must determine whether information required for subcontract performance keeps its identity as covered defense information, consulting the contracting officer if necessary. The contractor must require subcontractors to notify the prime contractor, or next higher-tier subcontractor, when they ask the contracting officer to vary from a NIST SP 800-171 requirement (DFARS 252.204-7012(m)(2)(i)). Incident reporting under the clause is covered in reporting a cyber incident under DFARS.

Key terms

Covered defense informationControlled technical or other CUI provided for, or developed in, contract performance.
Covered contractor information systemAn unclassified contractor system that holds covered defense information.
Adequate securityProtection matched to the consequences and probability of loss or misuse.
VarianceA CIO-adjudicated finding that a NIST SP 800-171 requirement does not apply or has an equal alternative.
FedRAMP Moderate equivalenceThe standard an external cloud provider must meet.

Every statement above links to the document behind it. The full source list for this piece is on the sources page.

This page describes public United States government programs for general information. It is not legal, regulatory or procurement advice, and it does not address the facts of any particular case.

How Sentfore supports this

Contractors abroad often hold covered defense information. Sentfore works at the delivery end of defense programs in difficult environments, providing secure movement, protective security, facilities and life support. Requirements can be sent through the contact page.