CMMC & DFARS DFARS
DFARS guide

DFARS 252.204-7012 and the subcontractor security questionnaire

The clause that requires primes to protect covered defense information also requires them to flow that obligation down to you — and the questionnaire is how they do it.

DFARS 252.204-7012, "Safeguarding Covered Defense Information and Cyber Incident Reporting," is the clause that drives most of the cybersecurity requirements in DoD contracting below the classified level. If your prime has it in their contract — and most do — they are required to include it in any subcontract where your work may involve covered defense information (CDI). That requirement is why you received a security questionnaire.

What the clause actually requires

The clause has three main obligations for contractors and their subcontractors:

  1. Adequate security. Contractors must provide "adequate security" for CDI on all information systems used in contract performance. Adequate security is defined by reference to NIST SP 800-171, the 110-control framework for protecting controlled unclassified information (CUI).
  2. Cyber incident reporting. If a cyber incident occurs that affects a covered contractor information system or CDI, the contractor must report it to DoD within 72 hours of discovery. Subcontractors who experience an incident must report rapidly to the prime so the prime can meet their reporting deadline.
  3. Subcontract flow-down. Primes must include the clause in all subcontracts where the subcontractor will handle CDI. They must also ensure their subcontractors provide adequate security — which means verifying your posture, usually through a questionnaire.

The 72-hour reporting window. DFARS 252.204-7012 requires reporting of cyber incidents within 72 hours of discovery, not 72 hours after you determine the full scope. If your incident response documentation doesn't capture this timeline explicitly — including the internal escalation path that enables external reporting to meet that window — your questionnaire response may not accurately reflect your posture.

How primes implement this as a questionnaire

Primes have discretion in how they verify subcontractor posture, but in practice most use one of three approaches:

  • Standard framework questionnaires. SIG Lite and CAIQ are the most common. These are broad-based security questionnaires covering access control, change management, incident response, data handling, and dozens of other domains. Primes who use these often don't need to build their own questions.
  • DFARS-specific custom questionnaires. Primes with large defense portfolios often build their own questionnaires that map directly to NIST SP 800-171 control families. These may ask about your SPRS score, your POA&M status, and specific incident reporting procedures by name.
  • Documentation review. Some primes ask for your SSP and POA&M directly, rather than a questionnaire. This is less common for routine annual reviews but can occur for high-value or high-sensitivity subcontracts.

The 110 NIST SP 800-171 controls as questionnaire fodder

NIST SP 800-171 Rev 2 contains 110 security requirements across 14 control families: access control, awareness and training, audit and accountability, configuration management, identification and authentication, incident response, maintenance, media protection, personnel security, physical protection, risk assessment, security assessment, system and communications protection, and system and information integrity.

When a prime asks about your "access control practices," they're asking about controls like multi-factor authentication, least privilege, session termination, and remote access restrictions — all of which are covered in the AC (Access Control) family. When they ask about incident response, they're asking about IR controls including the 72-hour reporting procedure specifically required by DFARS. Your questionnaire answers need to map to the controls you've actually implemented, as documented in your SSP.

If your SSP has gaps or your controls aren't fully implemented, the right response isn't to overstate your posture. It's to accurately represent where you are and reference your POA&M for controls you're still implementing. Primes understand that perfect NIST 800-171 compliance is a journey — what they need to see is that you're taking it seriously and documenting your path.

What "adequate security" documentation looks like

For a DFARS questionnaire response to hold up to scrutiny, your answers should be backed by documentation that exists and is current. The core documents are:

  • System Security Plan (SSP). This is the primary document describing your security posture. It identifies the systems in scope, the controls you've implemented, and how each NIST 800-171 requirement is met. When your questionnaire answer says "yes, we encrypt data at rest," that claim should be traceable to a specific section of your SSP.
  • Plan of Action and Milestones (POA&M). For any control you haven't fully implemented, the POA&M documents what you're doing about it and when you expect to complete remediation. An honest questionnaire response for an unmet control references the POA&M entry.
  • Incident Response Runbook. This documents your actual response procedures, including the timeline for internal escalation and external reporting. Your questionnaire answers about incident response should reference the runbook — specifically the version and section number.
  • Supporting policies. Access control policy, data handling policy, configuration management procedures — these back up the answers you give about specific control domains.

Reply Engine turns your SSP and policies into cited questionnaire answers.

Import your SSP, incident response runbook, access control policies, and prior questionnaire responses. Reply Engine drafts answers to your prime's DFARS questionnaire from that documentation, cites the exact document and section for every response, and holds everything in your security team's approval queue until they sign off. Drafts, not attestations.

Get started