DFARS
Definition
DFARS
DFARS is the defence supplement to the US federal acquisition rules, adding requirements that apply to defence contracts specifically. Its cyber clause drives the flow-down, obliging contractors to impose the same safeguarding duties on the suppliers beneath them.
Flow-down is what makes this a supply chain issue rather than a prime contractor one.
A single clause in a prime contract propagates downward through every tier that touches covered information — companies with no direct relationship to the defence department end up operating to its requirements.
Most of them find out when a customer sends a contract amendment, which is a poor moment to discover what the obligations cost.
Key takeaways
- DFARS supplements the federal acquisition regulation for defence contracts.
- Clause 252.204-7012 covers safeguarding covered defence information and cyber incident reporting.
- Cyber incidents must be reported within 72 hours of discovery.
- Assessments must be current, meaning not more than three years old.
How it works
The relevant material sits in the subpart on safeguarding covered defence information and cyber incident reporting. Several clauses operate together rather than one doing all the work.
Clause 252.204-7012 is the core safeguarding and reporting obligation. Around it sit 252.204-7008 on compliance, 252.204-7009 on the use of third-party incident information, and 252.204-7019 and 252.204-7020 on assessment requirements.
Reporting speed is defined rather than left to judgement — to report rapidly means within 72 hours of discovery of any cyber incident, which is a demanding window for an organisation that has just discovered a problem.
Assessment currency is the second hard number. Assessments must be not more than three years old, unless a shorter period is specified in the solicitation.
The flow-down mechanism is specific about reporting routes. Subcontractors provide the incident report number assigned by the department to the prime contractor, and lower tiers pass their number to the tier above until the prime is reached.
The underlying security requirements come from elsewhere. They are the controlled unclassified information requirements for non-federal systems, which the clauses incorporate rather than restate.
| Clause | What it does |
|---|---|
| 252.204-7008 | Compliance with safeguarding controls |
| 252.204-7009 | Limits on using third-party incident information |
| 252.204-7012 | Core safeguarding and 72-hour incident reporting |
| 252.204-7019 | Notice of assessment requirements in solicitations |
| 252.204-7020 | Assessment requirements in contracts and task orders |
Read 252.204-7009 carefully if you are a subcontractor — it restricts what a prime may do with incident information you reported, which is a protection rather than a burden.
Examples
Defence clauses reach organisations that never negotiated with the government, and the reporting chain is where the practical difficulty concentrates. Each case below involves a control that somebody assumed the other party owned.
A commercial software supplier receives flow-down clauses through a prime. Its obligations are real and it has no relationship with the department imposing them.
A subcontractor detects an incident and must report through the chain. Report numbers travel upward tier by tier, which takes coordination nobody rehearsed.
A contractor’s assessment is three and a half years old at bid time. Currency is a stated requirement, so compliance outsourcing support cannot retroactively fix the date.
A prime asks a supplier to accept clauses it cannot meet. That is a vendor management outsourcing conversation better held before award than after.
Related terms
Defence acquisition layers clauses, programmes and underlying standards, and suppliers frequently mistake one for another. Each entry here is kept narrow, and the narrowness is the genuinely useful part.
- Government outsourcing: public sector contracting, the wider context these clauses sit in.
- Cybersecurity outsourcing: buying security capability to meet the safeguarding duties.
- Compliance outsourcing: delegating regulatory work, which cannot alter a flow-down clause.
- Contract lifecycle outsourcing: managing contracts as a service, where flow-down tracking belongs.
- Vendor management outsourcing: running supplier assurance across the tiers.
- Information security analyst: the role implementing the safeguards the clauses require.
- Regulated outsourcing: sector rules layering above general acquisition regulation.
FAQ
What does DFARS stand for?
The Defense Federal Acquisition Regulation Supplement, which adds defence-specific requirements on top of the general federal acquisition regulation.
What is clause 252.204-7012?
The core clause covering safeguarding of covered defence information and cyber incident reporting, including the rapid reporting obligation.
What is the incident reporting deadline?
Rapid reporting is defined as within 72 hours of discovery of any cyber incident. The clock runs from discovery, not from confirmation.
How current must an assessment be?
Not more than three years old, unless the solicitation specifies a shorter period. Stale assessments affect eligibility.
Do these clauses flow down to subcontractors?
Yes. Obligations pass down the tiers, and incident report numbers pass back up until they reach the prime contractor.
How does DFARS relate to CMMC?
CMMC verifies that the practices these clauses require have actually been implemented, rather than imposing separate security requirements.
Begin at Outsource Accelerator and count the clauses that flow down before you price the work.







Independent




