• SecurePath for Auto Dealers
  • Services
    • SOC Reporting Services
      • SOC 2® Readiness Assessment
      • SOC 2® Reports
      • SOC 3® Reports
      • SOC for Cybersecurity® Reports
    • IT Advisory Services
      • IT Vulnerability Assessment
      • Network Penetration Testing
      • Privileged Access Management
      • Social Engineering Testing
      • Virtual CISO (vCISO)
      • Written Information Security Program (“WISP”)
      • IT General Controls Audit & Compliance
    • IT Government Compliance
      • CMMC Cybersecurity Services & Compliance
      • DFARS Compliance
      • FTC Safeguards Compliance
  • Industries
    • Financial Services
    • Government
    • Auto Dealerships
    • Enterprise
  • Blog
  • About Us
    • Meet The Team
    • Jobs
  • Contact Us

Call us today! 844-OCD-TECH

Find our Location
OCD TechOCD Tech
  • SecurePath for Auto Dealers
  • Services
    • SOC Reporting Services
      • SOC 2® Readiness Assessment
      • SOC 2® Reports
      • SOC 3® Reports
      • SOC for Cybersecurity® Reports
    • IT Advisory Services
      • IT Vulnerability Assessment
      • Network Penetration Testing
      • Privileged Access Management
      • Social Engineering Testing
      • Virtual CISO (vCISO)
      • Written Information Security Program (“WISP”)
      • IT General Controls Audit & Compliance
    • IT Government Compliance
      • CMMC Cybersecurity Services & Compliance
      • DFARS Compliance
      • FTC Safeguards Compliance
  • Industries
    • Financial Services
    • Government
    • Auto Dealerships
    • Enterprise
  • Blog
  • About Us
    • Meet The Team
    • Jobs
  • Contact Us

Prepare Now for Cyber Incident Reporting DFARS Requirements!

June 20, 2017 Posted by Nick DeLena cyber intel, Cybersecurity, IT Security

One requirement that often gets overlooked by companies subject to Defense Federal Acquisition Requirement Supplement (DFARS) Covered Defense Information (CDI) protection requirements is the Cyber Incident Reporting regulation. Part of 252.204-7012, the reporting requirement often gets glossed over as prime and subprime contractors are distracted with implementing the security requirements of NIST Special Publication 800-171 as required in 252.204-7008.

In short, 7012 requires any company in the possession of CDI to “rapidly report” any “cyber incidents” to the Department of Defense office of the CIO through DIBnet. “Rapidly report” is defined as within 72 hours of discovery of the incident. It should be noted that the ability to submit a cyber incident report requires a DoD-approved medium assurance certificate. Procuring a medium assurance certificate takes some time, so do not assume you can procure one after an incident has taken place and still meet the 72-hour requirement as defined in clause 7012.

For subcontractors – you are required to notify the prime contractor or next higher-up subcontractor of the incident and to provide them the incident report number.

If you are subject to 252.204-7012, you should have a Cyber Incident Reporting policy and procedure in place, along with a medium assurance certificate, so if the unspeakable occurs, you are not going to place your contract in jeopardy. Contact OCD-Tech today! 844-OCDTECH

Share
0
Avatar photo

About Nick DeLena

Nick leads engagements across the division’s primary practice areas, including audit, security, and advisory services. He’s a 19-year veteran of IT and IT risk management, having audited, consulted, and managed IT teams in a variety of industries. He holds several leading certifications, including CISSP, CISA, CRISC, and Security+, among others, and has an MBA from Brown University.

You also might be interested in

FRAUD AWARENESS WEEK

FRAUD AWARENESS WEEK

Nov 14, 2022

In the realm of information technology, cybersecurity refers to the[...]

SOC REPORTS

SOC® Reports

Jun 6, 2024

Boost Customer Trust and Security For businesses that handle customer[...]

OCD TECH CYBER JOB VACANCIES

Cyber job vacancies

Aug 9, 2023

On July 31st, the Biden-Harris Administration unveiled the National Cyber[...]

Find us on

Contact Us

We're not around right now. But you can send us an email and we'll get back to you, asap.

Send Message
OCD Tech logo Audit. Security. Assurance.

IT Audit | Cybersecurity | IT Assurance | IT Security Consultants – OCD Tech is a technology consulting firm serving the IT security and consulting needs of businesses in Boston (MA), Braintree (MA) and across New England. We primarily serve Fortune 500 companies including auto dealers, financial institutions, higher education, government contractors, and not-for-profit organizations with SOC 2 reporting, CMMC readiness, IT Security Audits, Penetration Testing and Vulnerability Assessments. We also provide dark web monitoring, DFARS compliance, and IT general controls review.

Contact Info

  • OCD Tech
  • 25 BHOP, Suite 407, Braintree MA, 02184
  • 844-623-8324
  • https://ocd-tech.com

Follow Us

Videos

Check Out the Latest Videos From OCD Tech!

Services

SOC Reporting Services
– SOC 2 ® Readiness Assessment
– SOC 2 ®
– SOC 3 ®
– SOC for Cybersecurity ®

IT Advisory Services
– IT Vulnerability Assessment
– Penetration Testing
– Privileged Access Management
– Social Engineering
– WISP
– General IT Controls Review

IT Government Compliance Services
– CMMC
– DFARS Compliance
– FTC Safeguards vCISO

Industries

  • Financial Services
  • Government
  • Enterprise
  • Auto Dealerships

© 2025 — OCD Tech: IT Audit - Cybersecurity - IT Assurance

  • OCD Tech
  • About Us
  • Contact Us
Prev Next