Aerospace & DefenseFree Interactive Tool

DFARS 252.204-7012 Compliance Self-Assessment

This free DFARS 252.204-7012 self-assessment helps defense contractors and subcontractors measure compliance with the cybersecurity clause already embedded in most DoD contracts and flowdowns. Ten questions cover the clause's full scope - identifying Covered Defense Information, implementing NIST SP 800-171, maintaining an accurate SPRS score, 72-hour incident reporting through DIBNet, forensic preservation, FedRAMP Moderate cloud equivalency, and subcontractor flowdown. Unlike CMMC, which is phasing in, DFARS 7012 is a current contractual obligation: if the clause is in your contracts and you are not compliant, you are already exposed. Find out where you stand in five minutes.

0 of 10 answered0%

1. Have you identified which contracts include DFARS 252.204-7012 and what Covered Defense Information (CDI) you receive or generate under them?

2. Have you implemented the 110 security controls of NIST SP 800-171 on covered contractor information systems?

3. Is your NIST 800-171 self-assessment score current in SPRS, and does it honestly reflect your environment?

DFARS 252.204-7019/7020 require a current SPRS score before award. DOJ has pursued False Claims Act cases over inflated scores.

4. Do you have a documented System Security Plan (SSP) and Plans of Action (POA&M) for unimplemented controls?

5. Could you report a cyber incident to DoD via DIBNet within 72 hours of discovery, as the clause requires?

Reporting requires a DoD-approved Medium Assurance Certificate, which takes time to obtain - you cannot get one mid-incident.

6. Are you prepared to preserve images and forensic data for at least 90 days after a reported incident and support DoD damage assessment?

7. If you use cloud services to store or process CDI, do they meet FedRAMP Moderate baseline or equivalency?

8. Do you flow down DFARS 252.204-7012 to subcontractors who receive CDI, and verify their compliance?

9. Would your team recognize and escalate a reportable cyber incident affecting CDI or your covered systems?

10. Is malicious software discovered during a CDI incident handled per the clause (submitted to DoD Cyber Crime Center, not just deleted)?

How the assessment maps to the clause

Each question tracks a distinct obligation within 252.204-7012 and its companion clauses 7019 and 7020, scored 0-3 from absent to implemented-and-exercised. The weighting reflects enforcement reality: adequate security (NIST 800-171 implementation and an honest SPRS score) and incident reporting readiness carry the most practical risk, because those are the obligations tested by primes at award time and by DoD when a breach occurs. Questions on forensic preservation, malware submission, and cloud equivalency catch the lesser-known sub-requirements that even well-run programs miss. Your percentage score maps to three bands calibrated to the difference between paperwork compliance and operational compliance - the gap where most contractors actually sit.

Benchmarks and enforcement context

Calibrate your result against what is known about the defense supply base and how the government is enforcing the clause:

  • DoD's own reviews have found that a large majority of contractors with self-attested high SPRS scores could not substantiate them under assessment
  • The average DIB self-assessment score before remediation is negative on the -203 to 110 SPRS scale
  • DOJ's Civil Cyber-Fraud Initiative has settled multiple False Claims Act cases over misrepresented cybersecurity compliance, with penalties in the millions
  • A DoD Medium Assurance Certificate for DIBNet reporting typically takes days to weeks to obtain - it cannot be acquired reactively mid-incident

What to do with your score

A low score demands contract review before technical work: confirm which agreements carry the clause, because your obligations and your exposure flow from signed paper, not from generic best practice. Mid-range scores usually indicate a program that looks compliant in documents but has never been exercised - the fix is rehearsal, verification, and evidence, not more policy writing. Run a tabletop that walks from detection through DIBNet submission within 72 hours; pull equivalency documentation for every cloud vendor touching CDI; and check that your SPRS score would survive a DIBCAC assessment, because under CMMC those assessments become routine. High scorers should pivot their effort toward CMMC Level 2 certification, which formalizes the same 110 controls with third-party verification.

How Netray helps you operationalize DFARS 7012

CDI at a manufacturer concentrates in the ERP layer - part masters, routings, drawings on jobs, and customer-furnished data in SyteLine, LN, or Baan - which generic IT security programs consistently overlook. Netray brings ERP-native compliance engineering: we map CDI flows through your actual business processes, implement the 800-171 controls that touch ERP (access control, audit logging, FIPS encryption, media protection), build your SSP and POA&M around evidence rather than aspiration, and architect on-prem or GovCloud environments where equivalency is provable. Our on-prem AI practice means you can adopt modern AI tooling for quoting, planning, and quality without pushing CDI into non-compliant services.

Frequently Asked Questions

What is the difference between DFARS 7012 compliance and CMMC?

DFARS 252.204-7012 is a contract clause in force today: it requires you to implement NIST SP 800-171, report incidents within 72 hours, and meet cloud and flowdown obligations, all on a self-attestation basis backed by your SPRS score. CMMC adds third-party verification of essentially the same controls. Think of 7012 as the requirement and CMMC Level 2 as the audit. If you are genuinely 7012-compliant, CMMC preparation is largely evidence organization rather than new controls.

We are a small subcontractor and never signed a DoD contract directly. Does 7012 apply to us?

Very likely yes, through flowdown. Primes and higher-tier subs are required to flow the clause down to any subcontractor whose performance involves Covered Defense Information, and it appears in purchase order terms and supplier quality agreements that many small shops accept without reading. Check your POs and long-term agreements for references to DFARS 252.204-7012, 7019, or 7020. If you receive drawings or specs marked as export-controlled or CUI, assume the clause applies until proven otherwise.

What counts as a reportable cyber incident under the clause?

A reportable incident is one that affects Covered Defense Information, the covered contractor information system it lives on, or your ability to perform operationally critical support. That is broader than data theft - ransomware that locks your ERP, a compromised engineering workstation, or unauthorized access to a file server holding CDI all qualify. When in doubt, the clause's structure favors reporting: you have 72 hours from discovery, and under-reporting carries far more risk than over-reporting.

Take the self-assessment now and see exactly which DFARS 7012 obligations you can and cannot currently meet.