{"description":"Documents matching '\"252.204-7012\"' and affecting 48 CFR 252","count":15,"total_pages":1,"results":[{"title":"Defense Federal Acquisition Regulation Supplement: Assessing Contractor Implementation of Cybersecurity Requirements (DFARS Case 2019-D041)","type":"Rule","abstract":"DoD is issuing a final rule amending the Defense Federal Acquisition Regulation Supplement (DFARS) to incorporate contractual requirements related to the final Cybersecurity Maturity Model Certification program rule, titled Cybersecurity Maturity Model Certification Program. This final DFARS rule also partially implements a section of the National Defense Authorization Act for Fiscal Year 2020 that directed the Secretary of Defense to develop a consistent, comprehensive framework to enhance cybersecurity for the U.S. defense industrial base.","document_number":"2025-17359","html_url":"https://www.federalregister.gov/documents/2025/09/10/2025-17359/defense-federal-acquisition-regulation-supplement-assessing-contractor-implementation-of","pdf_url":"https://www.govinfo.gov/content/pkg/FR-2025-09-10/pdf/2025-17359.pdf","public_inspection_pdf_url":"https://public-inspection.federalregister.gov/2025-17359.pdf?1757421911","publication_date":"2025-09-10","agencies":[{"raw_name":"DEPARTMENT OF DEFENSE","name":"Defense Department","id":103,"url":"https://www.federalregister.gov/agencies/defense-department","json_url":"https://www.federalregister.gov/api/v1/agencies/103","parent_id":null,"slug":"defense-department"},{"raw_name":"Defense Acquisition Regulations System","name":"Defense Acquisition Regulations System","id":97,"url":"https://www.federalregister.gov/agencies/defense-acquisition-regulations-system","json_url":"https://www.federalregister.gov/api/v1/agencies/97","parent_id":103,"slug":"defense-acquisition-regulations-system"}],"excerpts":"information systems. Several respondents stated that the 72-hour reporting requirement at DFARS <span class=\"match\">252.204-7012</span> paragraph (c) provides sufficient notification of relevant information security incidents.\n \n \n Response: \n Based on public comments, the notification requirement in this rule to report to the contracting officer lapses in information security or changes in compliance with 32 CFR part 170 was removed. The reporting requirement at DFARS <span class=\"match\">252.204-7012</span> paragraph (c) to provide notification of information security incidents and the annual affirmation"},{"title":"Defense Federal Acquisition Regulation Supplement; Technical Amendments","type":"Rule","abstract":"DoD is amending the Defense Federal Acquisition Regulation Supplement (DFARS) to make needed editorial changes.","document_number":"2024-11516","html_url":"https://www.federalregister.gov/documents/2024/05/30/2024-11516/defense-federal-acquisition-regulation-supplement-technical-amendments","pdf_url":"https://www.govinfo.gov/content/pkg/FR-2024-05-30/pdf/2024-11516.pdf","public_inspection_pdf_url":"https://public-inspection.federalregister.gov/2024-11516.pdf?1716986713","publication_date":"2024-05-30","agencies":[{"raw_name":"DEPARTMENT OF DEFENSE","name":"Defense Department","id":103,"url":"https://www.federalregister.gov/agencies/defense-department","json_url":"https://www.federalregister.gov/api/v1/agencies/103","parent_id":null,"slug":"defense-department"},{"raw_name":"Defense Acquisition Regulations System","name":"Defense Acquisition Regulations System","id":97,"url":"https://www.federalregister.gov/agencies/defense-acquisition-regulations-system","json_url":"https://www.federalregister.gov/api/v1/agencies/97","parent_id":103,"slug":"defense-acquisition-regulations-system"}],"excerpts":"changes to update two outdated hyperlinks at DFARS <span class=\"match\">252.204-7012</span>. \n \n List of Subjects in 48 CFR Part 252 \n Government procurement. \n \n \n Jennifer D. Johnson, \n Editor/Publisher, Defense Acquisition Regulations System. \n \n Therefore, 48 CFR part 252 is amended as follows: \n \n 1. The authority citation for 48 CFR part 252 continues to read as follows: \n \n Authority: \n 41 U.S.C. 1303 and 48 CFR chapter 1. \n \n \n \n PART 252—SOLICITATION PROVISIONS AND CONTRACT CLAUSES \n \n \n 2. Amend section <span class=\"match\">252.204-7012</span>— \n a. By revising the clause date; \n \n b. In paragraph"},{"title":"Defense Federal Acquisition Regulation Supplement: Assessing Contractor Implementation of Cybersecurity Requirements (DFARS Case 2019-D041)","type":"Proposed Rule","abstract":"DoD is proposing to amend the Defense Federal Acquisition Regulation Supplement (DFARS) to incorporate contractual requirements related to the proposed Cybersecurity Maturity Model Certification 2.0 program rule, Cybersecurity Maturity Model Certification Program. This proposed DFARS rule also partially implements a section of the National Defense Authorization Act for Fiscal Year 2020 that directed the Secretary of Defense to develop a consistent, comprehensive framework to enhance cybersecurity for the U.S. defense industrial base.","document_number":"2024-18110","html_url":"https://www.federalregister.gov/documents/2024/08/15/2024-18110/defense-federal-acquisition-regulation-supplement-assessing-contractor-implementation-of","pdf_url":"https://www.govinfo.gov/content/pkg/FR-2024-08-15/pdf/2024-18110.pdf","public_inspection_pdf_url":"https://public-inspection.federalregister.gov/2024-18110.pdf?1723639522","publication_date":"2024-08-15","agencies":[{"raw_name":"DEPARTMENT OF DEFENSE","name":"Defense Department","id":103,"url":"https://www.federalregister.gov/agencies/defense-department","json_url":"https://www.federalregister.gov/api/v1/agencies/103","parent_id":null,"slug":"defense-department"},{"raw_name":"Defense Acquisition Regulations System","name":"Defense Acquisition Regulations System","id":97,"url":"https://www.federalregister.gov/agencies/defense-acquisition-regulations-system","json_url":"https://www.federalregister.gov/api/v1/agencies/97","parent_id":103,"slug":"defense-acquisition-regulations-system"}],"excerpts":"of commercial products and commercial services, except those solely for the acquisition of COTS items.\n \n 7. Duplication of DFARS Clause <span class=\"match\">252.204-7012</span> and DFARS Clause 252.204-7021 \n \n Comment: \n A respondent commented on whether DFARS clause <span class=\"match\">252.204-7012</span> and DFARS clause 252.204-7021 duplicate one another.\n \n \n Response: \n These clauses are not duplicative as they have distinct purposes. DFARS clause <span class=\"match\">252.204-7012</span>, Safeguarding Covered Defense Information and Cyber Incident Reporting, levies cybersecurity requirements on contractors, and DFARS clause"},{"title":"Defense Federal Acquisition Regulation Supplement: Definition of “Commercial Item” (DFARS Case 2018-D066)","type":"Rule","abstract":"DoD is issuing a final rule to amend the Defense Federal Acquisition Regulation Supplement (DFARS) to implement the revised definition of \"commercial item\" in accordance with two sections of the John S. McCain National Defense Authorization Act for Fiscal Year 2019.","document_number":"2023-01294","html_url":"https://www.federalregister.gov/documents/2023/01/31/2023-01294/defense-federal-acquisition-regulation-supplement-definition-of-commercial-item-dfars-case-2018-d066","pdf_url":"https://www.govinfo.gov/content/pkg/FR-2023-01-31/pdf/2023-01294.pdf","public_inspection_pdf_url":"https://public-inspection.federalregister.gov/2023-01294.pdf?1675086319","publication_date":"2023-01-31","agencies":[{"raw_name":"DEPARTMENT OF DEFENSE","name":"Defense Department","id":103,"url":"https://www.federalregister.gov/agencies/defense-department","json_url":"https://www.federalregister.gov/api/v1/agencies/103","parent_id":null,"slug":"defense-department"},{"raw_name":"Defense Acquisition Regulations System","name":"Defense Acquisition Regulations System","id":97,"url":"https://www.federalregister.gov/agencies/defense-acquisition-regulations-system","json_url":"https://www.federalregister.gov/api/v1/agencies/97","parent_id":103,"slug":"defense-acquisition-regulations-system"}],"excerpts":"section <span class=\"match\">252.204-7012</span>— \n a. By revising the section heading; \n b. In the introductory text by removing “204.7304c” and adding “204.7304(c)” in its place; \n c. By revising the clause date; \n d. In paragraph (a), in the definition of “Technical information”, by removing “Noncommercial Items” and adding “Other Than Commercial Products and Commercial Services” in its place; and \n e. In paragraph (m)(1) by removing “commercial items” and adding “commercial products or commercial services” in its place. \n The revisions read as follows: \n \n <span class=\"match\">252.204-7012</span> \n \n"},{"title":"Defense Federal Acquisition Regulation Supplement: Revision of Definition of “Commercial Item” (DFARS Case 2018-D066)","type":"Proposed Rule","abstract":"DoD is proposing to amend the Defense Federal Acquisition Regulation Supplement (DFARS) to implement the revised definition of \"commercial item\" in accordance with two sections of the John S. McCain National Defense Authorization Act for Fiscal Year 2019.","document_number":"2022-05536","html_url":"https://www.federalregister.gov/documents/2022/03/18/2022-05536/defense-federal-acquisition-regulation-supplement-revision-of-definition-of-commercial-item-dfars","pdf_url":"https://www.govinfo.gov/content/pkg/FR-2022-03-18/pdf/2022-05536.pdf","public_inspection_pdf_url":"https://public-inspection.federalregister.gov/2022-05536.pdf?1647521115","publication_date":"2022-03-18","agencies":[{"raw_name":"DEPARTMENT OF DEFENSE","name":"Defense Department","id":103,"url":"https://www.federalregister.gov/agencies/defense-department","json_url":"https://www.federalregister.gov/api/v1/agencies/103","parent_id":null,"slug":"defense-department"},{"raw_name":"Defense Acquisition Regulations System","name":"Defense Acquisition Regulations System","id":97,"url":"https://www.federalregister.gov/agencies/defense-acquisition-regulations-system","json_url":"https://www.federalregister.gov/api/v1/agencies/97","parent_id":103,"slug":"defense-acquisition-regulations-system"}],"excerpts":"section <span class=\"match\">252.204-7012</span> by— \n a. Revising the section heading; \n b. In the introductory text, removing “204.7304c” and adding “204.7304(c)” in its place; \n c. Revising the date of the clause; \n d. In paragraph (a), in the definition of “Technical information”, removing “Noncommercial Items” and adding “Other Than Commercial Products and Commercial Services” in its place; and \n e. In paragraph (m)(1), removing “commercial items” and adding “commercial products or commercial services” in its place. \n The revision reads as follows: \n \n <span class=\"match\">252.204-7012</span> \n \n "},{"title":"Defense Federal Acquisition Regulation Supplement: Assessing Contractor Implementation of Cybersecurity Requirements (DFARS Case 2019-D041)","type":"Rule","abstract":"DoD is issuing an interim rule to amend the Defense Federal Acquisition Regulation Supplement (DFARS) to implement a DoD Assessment Methodology and Cybersecurity Maturity Model Certification framework in order to assess contractor implementation of cybersecurity requirements and enhance the protection of unclassified information within the DoD supply chain.","document_number":"2020-21123","html_url":"https://www.federalregister.gov/documents/2020/09/29/2020-21123/defense-federal-acquisition-regulation-supplement-assessing-contractor-implementation-of","pdf_url":"https://www.govinfo.gov/content/pkg/FR-2020-09-29/pdf/2020-21123.pdf","public_inspection_pdf_url":"https://public-inspection.federalregister.gov/2020-21123.pdf?1601297122","publication_date":"2020-09-29","agencies":[{"raw_name":"DEPARTMENT OF DEFENSE","name":"Defense Department","id":103,"url":"https://www.federalregister.gov/agencies/defense-department","json_url":"https://www.federalregister.gov/api/v1/agencies/103","parent_id":null,"slug":"defense-department"},{"raw_name":"Defense Acquisition Regulations System","name":"Defense Acquisition Regulations System","id":97,"url":"https://www.federalregister.gov/agencies/defense-acquisition-regulations-system","json_url":"https://www.federalregister.gov/api/v1/agencies/97","parent_id":103,"slug":"defense-acquisition-regulations-system"}],"excerpts":"security requirements for CUI specified in NIST SP 800-171 per DFARS clause <span class=\"match\">252.204-7012</span>. Furthermore, the CMMC model includes an additional five processes and 61 practices across Levels 2-5 that demonstrate a progression of cybersecurity maturity.\n \n \n   \n \n Level \n Description \n \n \n 1 \n Consists of the 15 basic safeguarding requirements from FAR clause 52.204-21. \n \n \n 2 \n Consists of 65 security requirements from NIST SP 800-171 implemented via DFARS clause <span class=\"match\">252.204-7012</span>, 7 CMMC practices, and 2 CMMC processes. Intended as an optional intermediary"},{"title":"Defense Federal Acquisition Regulation Supplement: Technical Amendments","type":"Rule","abstract":"DoD is making needed technical amendments to update the Defense Federal Acquisition Regulation Supplement (DFARS).","document_number":"2019-27829","html_url":"https://www.federalregister.gov/documents/2019/12/31/2019-27829/defense-federal-acquisition-regulation-supplement-technical-amendments","pdf_url":"https://www.govinfo.gov/content/pkg/FR-2019-12-31/pdf/2019-27829.pdf","public_inspection_pdf_url":"https://public-inspection.federalregister.gov/2019-27829.pdf?1577713516","publication_date":"2019-12-31","agencies":[{"raw_name":"DEPARTMENT OF DEFENSE","name":"Defense Department","id":103,"url":"https://www.federalregister.gov/agencies/defense-department","json_url":"https://www.federalregister.gov/api/v1/agencies/103","parent_id":null,"slug":"defense-department"},{"raw_name":"Defense Acquisition Regulation System","name":"Defense Acquisition Regulations System","id":97,"url":"https://www.federalregister.gov/agencies/defense-acquisition-regulations-system","json_url":"https://www.federalregister.gov/api/v1/agencies/97","parent_id":103,"slug":"defense-acquisition-regulations-system"}],"excerpts":"when considering alternative approaches or making the determination that the contracting approach selected is in the best interest of the Government, as required by FAR 15.404-1(h)(2).\n \n \n \n \n PART 252—SOLICITATION PROVISIONS AND CONTRACT CLAUSES \n \n <span class=\"match\">252.204-7012</span> \n \n \n \n \n 4. Amend section <span class=\"match\">252.204-7012</span> by— \n a. Removing the clause date “(OCT 2016)” and adding “(DEC 2019)” in its place; and \n \n b. In paragraphs (c)(1)(ii) and (c)(2), removing “\n http://dibnet.dod.mil” \n and adding “\n https://dibnet.dod.mil” \n in both places; and\n \n \n c. In paragraph"},{"title":"Defense Federal Acquisition Regulation Supplement: Inapplicability of Certain Laws and Regulations to Commercial Items (DFARS Case 2017-D010)","type":"Proposed Rule","abstract":"DoD is proposing to amend the Defense Federal Acquisition Regulation Supplement (DFARS) to implement a section of the National Defense Authorization Act for Fiscal Year 2017 that addresses the inapplicability of certain laws and regulations to the acquisition of commercial items, including commercially available off-the-shelf items.","document_number":"2018-14043","html_url":"https://www.federalregister.gov/documents/2018/06/29/2018-14043/defense-federal-acquisition-regulation-supplement-inapplicability-of-certain-laws-and-regulations-to","pdf_url":"https://www.govinfo.gov/content/pkg/FR-2018-06-29/pdf/2018-14043.pdf","public_inspection_pdf_url":"https://public-inspection.federalregister.gov/2018-14043.pdf?1530189934","publication_date":"2018-06-29","agencies":[{"raw_name":"DEPARTMENT OF DEFENSE","name":"Defense Department","id":103,"url":"https://www.federalregister.gov/agencies/defense-department","json_url":"https://www.federalregister.gov/api/v1/agencies/103","parent_id":null,"slug":"defense-department"},{"raw_name":"Defense Acquisition Regulations System","name":"Defense Acquisition Regulations System","id":97,"url":"https://www.federalregister.gov/agencies/defense-acquisition-regulations-system","json_url":"https://www.federalregister.gov/api/v1/agencies/97","parent_id":103,"slug":"defense-acquisition-regulations-system"}],"excerpts":"51739 and 81 FR 72986); DFARS 252.204-7008, 252.204-7009, and <span class=\"match\">252.204-7012</span>). This rule proposes to clarify that the flowdown requirement in paragraph (m) of the clause at DFARS <span class=\"match\">252.204-7012</span> excludes flowdown to COTS items. Although the final rule under DFARS case 2013-D018 stated the exclusion of applicability to COTS items for all provisions and clauses under the case and the clause prescriptions were amended, the corresponding amendment to paragraph (m) of the clause at DFARS <span class=\"match\">252.204-7012</span> did not explicitly exclude flowdown to COTS items. This statute"},{"title":"Defense Federal Acquisition Regulation Supplement: Network Penetration Reporting and Contracting for Cloud Services (DFARS Case 2013-D018)","type":"Rule","abstract":"DoD is adopting as final, with changes, an interim rule amending the Defense Federal Acquisition Regulation Supplement (DFARS) to implement a section of the National Defense Authorization Act for Fiscal Year 2013 and a section of the National Defense Authorization Act for Fiscal Year 2015, both of which require contractor reporting on network penetrations, as well as DoD policy on the purchase of cloud computing services.","document_number":"2016-25315","html_url":"https://www.federalregister.gov/documents/2016/10/21/2016-25315/defense-federal-acquisition-regulation-supplement-network-penetration-reporting-and-contracting-for","pdf_url":"https://www.govinfo.gov/content/pkg/FR-2016-10-21/pdf/2016-25315.pdf","public_inspection_pdf_url":"https://public-inspection.federalregister.gov/2016-25315.pdf?1476967523","publication_date":"2016-10-21","agencies":[{"raw_name":"DEPARTMENT OF DEFENSE","name":"Defense Department","id":103,"url":"https://www.federalregister.gov/agencies/defense-department","json_url":"https://www.federalregister.gov/api/v1/agencies/103","parent_id":null,"slug":"defense-department"},{"raw_name":"Defense Acquisition Regulations System","name":"Defense Acquisition Regulations System","id":97,"url":"https://www.federalregister.gov/agencies/defense-acquisition-regulations-system","json_url":"https://www.federalregister.gov/api/v1/agencies/97","parent_id":103,"slug":"defense-acquisition-regulations-system"}],"excerpts":"responsible for ensuring that CSPs comply with DFARS clause <span class=\"match\">252.204-7012</span>, and requested that this be confirmed or clarified.\n \n \n Response: \n When a contractor uses an external CSP to store, process, or transmit any covered defense information for the contract, DFARS Clause <span class=\"match\">252.204-7012</span>(b)(2)(ii)(D) applies. While the flowdown provision in <span class=\"match\">252.204-7012</span> does not apply to the CSP in this case, the prime contractor is responsible to ensure that the CSP meets the requirements at <span class=\"match\">252.204-7012</span>(b)(2)(ii)(D).\n \n c. Reporting \n \n Comment: \n One respondent"},{"title":"Defense Federal Acquisition Regulation Supplement: Disclosure to Litigation Support Contractors (DFARS Case 2012-D029)","type":"Rule","abstract":"DoD is adopting as final, with changes, an interim rule amending the Defense Federal Acquisition Regulation Supplement (DFARS) to implement a section of the National Defense Authorization Act for Fiscal Year 2012 that provides DoD the authority to allow its litigation support contractors access to \"sensitive information\" subject to certain restrictions.","document_number":"2016-10822","html_url":"https://www.federalregister.gov/documents/2016/05/10/2016-10822/defense-federal-acquisition-regulation-supplement-disclosure-to-litigation-support-contractors-dfars","pdf_url":"https://www.govinfo.gov/content/pkg/FR-2016-05-10/pdf/2016-10822.pdf","public_inspection_pdf_url":"https://public-inspection.federalregister.gov/2016-10822.pdf?1462797936","publication_date":"2016-05-10","agencies":[{"raw_name":"DEPARTMENT OF DEFENSE","name":"Defense Department","id":103,"url":"https://www.federalregister.gov/agencies/defense-department","json_url":"https://www.federalregister.gov/api/v1/agencies/103","parent_id":null,"slug":"defense-department"},{"raw_name":"Defense Acquisition Regulations System","name":"Defense Acquisition Regulations System","id":97,"url":"https://www.federalregister.gov/agencies/defense-acquisition-regulations-system","json_url":"https://www.federalregister.gov/api/v1/agencies/97","parent_id":103,"slug":"defense-acquisition-regulations-system"}],"excerpts":"Technical Information \n \n Comment: \n One respondent questioned whether litigation support contractors, and their subcontractors, will be required to comply with the requirements at DFARS clause <span class=\"match\">252.204-7012</span>, formerly entitled “Safeguarding of Unclassified Controlled Technical Information.”\n \n \n Response: \n The requirements of the clause at DFARS <span class=\"match\">252.204-7012</span>, now entitled “Safeguarding Covered Defense Information and Cyber Incident Reporting,” will apply to contractors, and their subcontractors, as required by the clause.\n \n 3. Disposition of Litigation"},{"title":"Defense Federal Acquisition Regulation Supplement: Network Penetration Reporting and Contracting for Cloud Services (DFARS Case 2013-D018)","type":"Rule","abstract":"DoD is issuing an interim rule amending the Defense Federal Acquisition Regulation Supplement (DFARS) to provide contractors with additional time to implement security requirements specified by a National Institute of Standards and Technology Special Publication.","document_number":"2015-32869","html_url":"https://www.federalregister.gov/documents/2015/12/30/2015-32869/defense-federal-acquisition-regulation-supplement-network-penetration-reporting-and-contracting-for","pdf_url":"https://www.govinfo.gov/content/pkg/FR-2015-12-30/pdf/2015-32869.pdf","public_inspection_pdf_url":"https://public-inspection.federalregister.gov/2015-32869.pdf?1451396811","publication_date":"2015-12-30","agencies":[{"raw_name":"DEPARTMENT OF DEFENSE","name":"Defense Department","id":103,"url":"https://www.federalregister.gov/agencies/defense-department","json_url":"https://www.federalregister.gov/api/v1/agencies/103","parent_id":null,"slug":"defense-department"},{"raw_name":"Defense Acquisition Regulations System","name":"Defense Acquisition Regulations System","id":97,"url":"https://www.federalregister.gov/agencies/defense-acquisition-regulations-system","json_url":"https://www.federalregister.gov/api/v1/agencies/97","parent_id":103,"slug":"defense-acquisition-regulations-system"}],"excerpts":"requirements in DFARS provision 252.204-7009 and clause <span class=\"match\">252.204-7012</span> are amended to require, when applicable, inclusion of the clause without alteration, except to identify the parties. \n • The subcontractor flowdown requirement in DFARS clause <span class=\"match\">252.204-7012</span> is further amended to limit the requirement to flow down the clause only to subcontractors where their efforts will involve covered defense information or where they will provide operationally critical support. \n • DFARS clause <span class=\"match\">252.204-7012</span> is amended to remove the requirement for DoD CIO acceptance"},{"title":"Defense Federal Acquisition Regulation Supplement; Technical Amendments","type":"Rule","abstract":"DoD is making technical amendments to the Defense Federal Acquisition Regulation Supplement (DFARS) to provide needed editorial changes.","document_number":"2015-23517","html_url":"https://www.federalregister.gov/documents/2015/09/21/2015-23517/defense-federal-acquisition-regulation-supplement-technical-amendments","pdf_url":"https://www.govinfo.gov/content/pkg/FR-2015-09-21/pdf/2015-23517.pdf","public_inspection_pdf_url":"https://public-inspection.federalregister.gov/2015-23517.pdf?1442580335","publication_date":"2015-09-21","agencies":[{"raw_name":"DEPARTMENT OF DEFENSE","name":"Defense Department","id":103,"url":"https://www.federalregister.gov/agencies/defense-department","json_url":"https://www.federalregister.gov/api/v1/agencies/103","parent_id":null,"slug":"defense-department"},{"raw_name":"Defense Acquisition Regulations System","name":"Defense Acquisition Regulations System","id":97,"url":"https://www.federalregister.gov/agencies/defense-acquisition-regulations-system","json_url":"https://www.federalregister.gov/api/v1/agencies/97","parent_id":103,"slug":"defense-acquisition-regulations-system"}],"excerpts":"TECHNOLOGY \n \n 10. Amend section 239.7102-1 by revising paragraph (a)(7) to read as follows: \n \n 239.7102-1 \n \n (a) * * * \n (7) DoD Directive 8140.01, Cyberspace Workforce Management; and \n \n \n \n \n \n PART 252—SOLICITATION PROVISIONS AND CONTRACT CLAUSES \n \n <span class=\"match\">252.204-7012</span> \n \n \n \n 11. Amend section <span class=\"match\">252.204-7012</span> by— \n a. Removing the clause date “(AUG 2015)” and adding “(SEP 2015)” in its place; \n b. In paragraph (b)(1)(ii) introductory text, removing “service of system” and adding “service or system” in its place; \n c. In paragraph (b)(1)(ii)(A), adding a quotation"},{"title":"Defense Federal Acquisition Regulation Supplement: Network Penetration Reporting and Contracting for Cloud Services (DFARS Case 2013-D018)","type":"Rule","abstract":"DoD is issuing an interim rule amending the Defense Federal Acquisition Regulation Supplement (DFARS) to implement a section of the National Defense Authorization Act for Fiscal Year 2013 and a section of the National Defense Authorization Act for Fiscal Year 2015, both of which require contractor reporting on network penetrations. Additionally, this rule implements DoD policy on the purchase of cloud computing services.","document_number":"2015-20870","html_url":"https://www.federalregister.gov/documents/2015/08/26/2015-20870/defense-federal-acquisition-regulation-supplement-network-penetration-reporting-and-contracting-for","pdf_url":"https://www.govinfo.gov/content/pkg/FR-2015-08-26/pdf/2015-20870.pdf","public_inspection_pdf_url":"https://public-inspection.federalregister.gov/2015-20870.pdf?1440506723","publication_date":"2015-08-26","agencies":[{"raw_name":"DEPARTMENT OF DEFENSE","name":"Defense Department","id":103,"url":"https://www.federalregister.gov/agencies/defense-department","json_url":"https://www.federalregister.gov/api/v1/agencies/103","parent_id":null,"slug":"defense-department"},{"raw_name":"Defense Acquisition Regulations System","name":"Defense Acquisition Regulations System","id":97,"url":"https://www.federalregister.gov/agencies/defense-acquisition-regulations-system","json_url":"https://www.federalregister.gov/api/v1/agencies/97","parent_id":103,"slug":"defense-acquisition-regulations-system"}],"excerpts":"Reduction Act \n This rule affects the information collection requirements in the provisions at DFARS <span class=\"match\">252.204-7012</span>, currently approved under OMB Control Number 0704-0478, titled “Enhanced Safeguarding and Cyber Incident Reporting of Unclassified DoD Information Within Industry,” in accordance with the Paperwork Reduction Act (44 U.S.C. chapter 35). The rule revises the collection reporting requirements based on— \n • Changes to DFARS clause <span class=\"match\">252.204-7012</span>, which is now titled “Safeguarding Covered Defense Information and Cyber Incident Reporting”; \n \n"},{"title":"Defense Federal Acquisition Regulation Supplement; Technical Amendments","type":"Rule","abstract":"DoD is making technical amendments to the Defense Federal Acquisition Regulation Supplement (DFARS) to provide needed editorial changes.","document_number":"2014-29079","html_url":"https://www.federalregister.gov/documents/2014/12/16/2014-29079/defense-federal-acquisition-regulation-supplement-technical-amendments","pdf_url":"https://www.govinfo.gov/content/pkg/FR-2014-12-16/pdf/2014-29079.pdf","public_inspection_pdf_url":"https://public-inspection.federalregister.gov/2014-29079.pdf?1418651585","publication_date":"2014-12-16","agencies":[{"raw_name":"DEPARTMENT OF DEFENSE","name":"Defense Department","id":103,"url":"https://www.federalregister.gov/agencies/defense-department","json_url":"https://www.federalregister.gov/api/v1/agencies/103","parent_id":null,"slug":"defense-department"},{"raw_name":"Defense Acquisition Regulations System","name":"Defense Acquisition Regulations System","id":97,"url":"https://www.federalregister.gov/agencies/defense-acquisition-regulations-system","json_url":"https://www.federalregister.gov/api/v1/agencies/97","parent_id":103,"slug":"defense-acquisition-regulations-system"}],"excerpts":"information at PGI 204.7303. \n \n \n \n 4. Add section 204.7304 to read as follows: \n \n 204.7304 \n \n Use the clause at <span class=\"match\">252.204-7012</span>, Safeguarding of Unclassified Controlled Technical Information, in all solicitations and contracts, including solicitations and contracts using FAR part 12 procedures for the acquisition of commercial items. \n \n \n \n \n PART 252—SOLICITATION PROVISIONS AND CONTRACT CLAUSES \n \n <span class=\"match\">252.204-7012</span> \n \n \n \n 5. Amend section <span class=\"match\">252.204-7012</span> by removing, in the introductory text, “As prescribed in 204.7303” and adding “As prescribed in 204.7304”"},{"title":"Defense Federal Acquisition Regulation Supplement: Safeguarding Unclassified Controlled Technical Information (DFARS Case 2011-D039)","type":"Rule","abstract":"DoD is issuing a final rule amending the Defense Federal Acquisition Regulation Supplement (DFARS) to add a new subpart and associated contract clause to address requirements for safeguarding unclassified controlled technical information.","document_number":"2013-27313","html_url":"https://www.federalregister.gov/documents/2013/11/18/2013-27313/defense-federal-acquisition-regulation-supplement-safeguarding-unclassified-controlled-technical","pdf_url":"https://www.govinfo.gov/content/pkg/FR-2013-11-18/pdf/2013-27313.pdf","public_inspection_pdf_url":"https://public-inspection.federalregister.gov/2013-27313.pdf?1384523872","publication_date":"2013-11-18","agencies":[{"raw_name":"DEPARTMENT OF DEFENSE","name":"Defense Department","id":103,"url":"https://www.federalregister.gov/agencies/defense-department","json_url":"https://www.federalregister.gov/api/v1/agencies/103","parent_id":null,"slug":"defense-department"},{"raw_name":"Defense Acquisition Regulations System","name":"Defense Acquisition Regulations System","id":97,"url":"https://www.federalregister.gov/agencies/defense-acquisition-regulations-system","json_url":"https://www.federalregister.gov/api/v1/agencies/97","parent_id":103,"slug":"defense-acquisition-regulations-system"}],"excerpts":"classification is not a sufficient reason to allow a contractor to fail to protect technical information as required by clause <span class=\"match\">252.204-7012</span>. The contractor at a minimum must institute the NIST (SP) 800-53 security controls identified in the table at <span class=\"match\">252.204-7012</span>. If a control is not implemented, the contractor shall submit to the contracting officer a written explanation of how the required security control identified in the table at <span class=\"match\">252.204-7012</span> is not applicable, or how an alternative control or protective measure is used to achieve equivalent protection.\n"}]}