Policy/Regulations

Safeguarding Covered Defense Information and Cyber Incident Reporting

NameDate 
Implementing the Cybersecurity Maturity Model Certification (CMMC) Program
02/2025View >>
Assessing Contractor Implementation of Cybersecurity Requirements (DFARS Case 2019-D041)11/2020View >>
DoD Instruction 5200.48 Controlled Unclassified Information (CUI)03/2020View >>
DoDI 8582.01, Security of Unclassified DoD Information on Non-DoD Information Systems (Under Revision)03/2020View >>
DFARS Rule 204.73 - Safeguarding Covered Defense Information and Cyber Incident Reporting06/2017View >>
DFARS Provision 252.204-7008 - Compliance with Safeguarding Covered Defense Information Controls06/2017View >>
DFARS Clause 252.204-7009 - Limitations on the Use or Disclosure of Third-Party Contractor Reported Cyber Incident Information06/2017View >>
DFARS Clause 252.204-7012 - Safeguarding Covered Defense Information and Cyber Incident Reporting06/2017View >>
DFARS Case 2013-D018, Network Penetration Reporting and Contracting for Cloud Services, Final Rule, dated October 21, 201610/2016View >>
DFARS Case 2013-D018, Network Penetration Reporting and Contracting for Cloud Services, Interim Rule, dated December 30, 201512/2015View >>
DFARS Case 2013-D018, Network Penetration Reporting and Contracting for Cloud Services, Interim Rule, August 26, 201508/2015View >>
DFARS Case 2011–D039, Safeguarding Unclassified Controlled Technical Information, Final rule, dated November 18, 201311/2013View >>

Cloud Computing Services

NameDate 
DFARS Rule 239.76 - Cloud Computing06/2017View >>
DFARS Provision 252.239-7009 - Representation of Use of Cloud Computing06/2017View >>
DFARS Clause 252.239-7010 - Cloud Computing Services06/2017View >>

Other

NameDate 
NIST SP 800-171 DoD Assessment Methodology06/2020View >>
NIST Special Publication 800-171, Revision 2 - Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations Final Rule, February 202002/2020View >>
Assessing Contractor Implementation of Cybersecurity Requirements11/2019View >>
NIST SP 800-171A, Assessing Security Requirements for Controlled Unclassified Information10/2018View >>
NIST SP 800-18 Rev 1, Guide for Developing Security Plans for Federal Information Systems12/2017View >>
PGI 204.73, Revised Dec 1, 201712/2017View >>
Note Regarding NIST Special Publication 800-171, Revision 1 -  Security Requirement 3.12.4, System Security Plan11/2017View >>
FAR Case 2011-020, Basic Safeguarding of Contractor Information Systems06/2017View >>
DoDI 5000.02, Enclosure 14, Cybersecurity in the Defense Acquisition System02/2017View >>
32 CFR Part 236, DoD Defense Industrial Base Cybersecurity Activities10/2016View >>
32 CFR Part 2002, Controlled Unclassified Information09/2016View >>

Additional Resources