DFARS Part 204 — Administrative Matters (and where DoD cyber lives)
What this Part does
On paper, DFARS Part 204 is the DoD analog to FAR Part 4 — administrative matters, records, CAGE codes, contract execution. In practice, it’s the home of the modern DoD cybersecurity regime. Sections 204.73, 204.74, 204.75, and their cousins prescribe the cyber clauses that define how defense contractors must protect Controlled Unclassified Information (CUI), report cyber incidents, and — under the phased CMMC rollout — achieve third-party certification before award.
The key subparts:
- 204.4 — Safeguarding classified information within industry (points to NISPOM, 32 CFR 117).
- 204.7 — Foreign acquisition of U.S. defense contractors (FOCI gate).
- 204.73 — Safeguarding covered defense information and cyber incident reporting — prescribes DFARS 252.204-7012.
- 204.75 — Compliance with safeguarding controls — prescribes the NIST SP 800-171 self-assessment clauses DFARS 252.204-7019 and DFARS 252.204-7020.
- 204.76 — Cybersecurity Maturity Model Certification (CMMC) — prescribes DFARS 252.204-7021.
- 204.77 — Prohibition on certain semiconductor products and services (implementing section 5949 of the FY23 NDAA).
When you’d look here
- A DoD RFP cites DFARS 252.204-7012 and you need to assess the client’s readiness.
- A client had a cyber incident and is on the 72-hour clock for DC3/DCISE reporting under DFARS 252.204-7012(c)(1)(ii).
- The solicitation includes DFARS 252.204-7021 (CMMC) at a specific level and you need to advise on the certification runway.
- A flow-down clause in a subcontract references 252.204-7012 and the sub is asking whether they really have to comply.
- Your client is a CSP (cloud service provider) and needs to understand the FedRAMP-Moderate-or-equivalent requirement in DFARS 252.239-7010.
Case study: the 72-hour clock
Quantum Avionics (hypothetical), a $90M-revenue avionics integrator, suffered a ransomware-style intrusion into its engineering network on a Thursday afternoon. The Director of IT Security noticed anomalous encryption activity at 2:47 PM. By 4:00 PM, the incident response team had isolated three servers and identified that the attackers had exfiltrated roughly 1.8 GB of data before deploying the encryption payload.
The engineering network held Covered Defense Information (CDI) on several active DoD programs, including unclassified controlled technical information on a torpedo seeker program under a contract with DFARS 252.204-7012 incorporated.
The clock starts at discovery — not at confirmation of CDI impact, not at completion of the forensic review, not at any “reasonable” later time. DFARS 252.204-7012(c)(1)(ii) requires reporting “within 72 hours of discovery of any cyber incident” via the DoD DC3 system (dibnet.dod.mil). “Discovery” is defined broadly as the earliest moment the contractor knew or reasonably should have known.
Quantum’s counsel on call that evening advised filing the DIBnet report that night — Thursday — even though the forensic review was only hours old. The report flagged the incident, identified the contracts that MIGHT be affected, and explicitly noted the forensic review was in flight and subsequent reports would follow.
Over the next 60 days, Quantum filed supplemental reports under DFARS 252.204-7012(c)(4) as the forensic picture clarified. The final forensic report determined that CDI had been accessed but there was no evidence of exfiltration of CDI specifically (the exfiltrated data appeared to be engineering drawings for a non-defense commercial product also on the network, evidently the attacker’s actual target).
The contracting officer reviewed Quantum’s response record. Quantum had implemented NIST SP 800-171 controls (confirmed via the SPRS posting under DFARS 252.204-7020) and had filed timely reports. The CO did not issue a show-cause notice. Quantum preserved the contract.
Teaching points:
- 72 hours from discovery, not from confirmation. Err on the side of reporting early. The clause allows supplemental reports as the picture clarifies (DFARS 252.204-7012(c)(4)). A late filing is actionable; an early-filed preliminary report is not.
- “Discovery” is broadly construed. It’s the moment the contractor knew or reasonably should have known. Counsel should document the discovery timestamp carefully.
- SPRS posting and NIST SP 800-171 compliance are the backstop. A contractor that hasn’t posted a current self-assessment score under DFARS 252.204-7019 is on ineligibility ground for any DoD contract with 7012 applicability, incident or no incident.
- Flow down. 252.204-7012 must be flowed down to subcontractors who will handle CDI. A prime’s own compliance doesn’t excuse sub noncompliance.
Case study: FOCI disclosure and mitigation
Solstice Systems (hypothetical), a cleared defense contractor, received a minority investment from a foreign sovereign wealth fund — 18% equity, one board seat. Under DFARS 204.470-2 and the NISPOM regime (32 CFR 117), the investment triggered a FOCI notification obligation via Solstice’s Facility Security Officer to the DCSA.
The investment was large enough to trigger a FOCI review but not automatically disqualifying. The analysis: the foreign shareholder gained no majority control, but the single board seat created potential for adverse foreign influence over classified program decisions. DCSA required a FOCI mitigation agreement before Solstice could continue classified work.
Options ranked from least to most restrictive:
- Board Resolution — lightest. Acknowledges FOCI and commits corporate governance safeguards. Typically for < 5% foreign ownership.
- Security Control Agreement (SCA) — mid-tier. The foreign shareholder stays on the board but is walled off from sensitive information via internal procedures.
- Special Security Agreement (SSA) — the structure DCSA required here. A separate FOCI Committee of the board, with inside directors only, holds exclusive authority over classified program decisions. Foreign director attends only non-FOCI matters.
- Proxy Agreement / Voting Trust — most restrictive. Foreign shareholder’s voting rights transfer to U.S. proxy holders.
- Non-Mitigation — DCSA denies continued clearance; Solstice would have to divest or lose its FCL (Facility Security Clearance) and associated contracts.
Solstice negotiated an SSA with DCSA over 6 months. The deal-making arc: foreign investor accepted the governance structure in exchange for continued financial returns; Solstice retained its FCL and all classified programs; the foreign director accepted exclusion from FOCI-related matters.
Teaching points:
- FOCI is not a “no foreign ownership” rule. It’s a “foreign influence must be mitigated” rule. The regime expects foreign investment in cleared contractors but requires structural safeguards proportional to the influence.
- DFARS only gates the disclosure; the substantive FOCI regime lives in NISPOM (32 CFR Part 117) administered by DCSA. When working a FOCI issue, read both.
- CFIUS is separate. A foreign investment of the size here would also trigger CFIUS review under 50 USC 4565 / 31 CFR 800. CFIUS and FOCI are parallel regimes with overlapping but distinct concerns (national security vs. classified-info protection).
Key sections
- DFARS 204.404-70 — Standard contract clause provisions.
- DFARS 204.470 (Subpart) — Safeguarding classified information, FOCI disclosure.
- DFARS 204.73 (Subpart) — Safeguarding CDI and Cyber Incident Reporting — prescribes 252.204-7012.
- DFARS 204.74 (Subpart) — Disclosure of Information to Litigation Support Contractors.
- DFARS 204.75 (Subpart) — Compliance with safeguarding covered defense information controls — prescribes 252.204-7019 and 252.204-7020.
- DFARS 204.76 (Subpart) — CMMC — prescribes 252.204-7021.
- DFARS 204.77 (Subpart) — Prohibition on certain semiconductor products and services.
Key clauses
- DFARS 252.204-7008 — Compliance with Safeguarding Covered Defense Information Controls.
- DFARS 252.204-7012 — Safeguarding Covered Defense Information and Cyber Incident Reporting. The marquee cyber clause.
- DFARS 252.204-7019 — NIST SP 800-171 DoD Assessment Requirements (pre-award notification).
- DFARS 252.204-7020 — NIST SP 800-171 DoD Assessment Requirements (SPRS posting).
- DFARS 252.204-7021 — CMMC certification requirement (phased rollout).
- DFARS 252.204-7024 — Notice on the use of the Supplier Performance Risk System.
Related
- FAR Part 4 — Civilian FAR administrative Part (much thinner on cyber; FAR’s baseline is FAR 52.204-21 for Federal Contract Information — a lighter standard than DFARS 7012 for CDI).
- DFARS Part 239 — IT / cloud; cross-references DFARS 252.239-7010 (FedRAMP Moderate for cloud services handling DoD data).
- NISPOM (32 CFR 117) — classified information handling.
- CFIUS (31 CFR 800, 802) — foreign investment review.
- Statutory authority:
- 10 USC 2224 — DoD information assurance authority (historical).
- 50 USC 4565 — CFIUS (for FOCI-adjacent review).
- Related landmark EOs: EO 14028 (cyber), EO 13587 (classified info sharing).