Skip to content
CMMC Guidance
← Knowledge Base

The clause that started all of this.

If this clause is in your contract, you have already agreed to safeguard covered defense information and to report cyber incidents rapidly. Most suppliers discover the second half only when they need it.

The clause does two distinct things, and they tend to get collapsed into one. The first is a safeguarding obligation: implement the security requirements for covered defense information on covered contractor information systems. The second is a reporting obligation, and it operates on a clock.

The 72-hour clock

A cyber incident that affects covered defense information, or the ability to perform operationally critical support, must be reported rapidly — within 72 hours of discovery. That window is short enough that it cannot be met by improvising. It has to be a rehearsed procedure, with the medium assurance certificate needed to submit already obtained and the people who will make the call already identified.

The obligation also does not end at the report. There are expectations around preserving images and relevant monitoring data, and around supporting any subsequent damage assessment. A response plan that gets the report filed but has already overwritten the evidence has met the deadline and failed the requirement.

It flows down

The clause is required to be included in subcontracts for operationally critical support or where subcontract performance will involve covered defense information. In practice that is how most suppliers acquire the obligation: not from a direct DoD contract but from a prime, several tiers up, passing it along. If you send covered defense information to a supplier, the obligation travels with it, and your compliance position now includes theirs.

Cloud services

Where covered defense information is handled by an external cloud service provider on your behalf, the clause carries specific security and reporting expectations for that arrangement. The relevant question is not whether a provider markets itself as compliant, but what your contract with them actually obliges them to do and to tell you, and how quickly.

The clause text is short and worth reading in full rather than in summary. It is linked below, along with the related assessment clauses.

Primary sources

Reference material, not legal advice. Where a specific number, deadline or level determination affects a decision, work from the source document and your own contract language.

Need this answered for your environment?

These pages are general. The readiness call is where it gets specific to your boundary, your contracts and your actual score.

  • Your CUI boundary sketched on the call
  • The requirements costing you the most points, named
  • A written summary afterward, yours to keep
Book the readiness call

NDA signed before anything technical. No cost, no obligation.