Table of contents

DFARS cyber incident reporting should begin promptly when a cyber incident may be reportable under DFARS 252.204-7012. The reporting process and technical investigation should continue in parallel. The contractor does not need to finish the entire forensic investigation before making a required report. The goal is to report the information reasonably available within the required timeframe, clearly identify what remains unknown, preserve evidence, and provide additional information as the investigation develops.

Quick Summary #

Situation What to Do
A reportable DFARS cyber incident is discovered Begin the reporting process immediately.
The investigation is still underway Report available information and continue investigating.
The organization has the required Medium Assurance Certificate Use the current DCISE Incident Collection Format reporting process.
The organization does not have the required certificate Contact DCISE immediately for reporting assistance.
New information is discovered after the initial report Provide the new information through a follow-on ICF.
A subcontractor receives a DoD incident report number Provide it to the prime or next higher tier as soon as practicable.

Key Point

The 72-hour requirement is a reporting deadline. It is not a deadline for completing the forensic investigation. Reporting and investigation should continue in parallel.

DFARS Cyber Incident Reporting Process at a Glance #

  • Confirm Applicability: Determine which contract or subcontract requirements apply.
  • Record Discovery: Preserve when the cyber incident was discovered.
  • Prepare: Gather the organization, contract, incident, and technical information currently available.
  • Access DCISE: Use the secure reporting process or contact DCISE for assistance.
  • Submit: Report the information available within the required timeframe.
  • Continue Investigating: Keep collecting and validating evidence.
  • Update: Provide new or corrected information through follow-on reporting.
  • Preserve: Maintain required system images and relevant monitoring or packet-capture data.
  • Coordinate: Address prime-contractor and other separate notification requirements.

The initial report starts the reporting process. It does not end the investigation.

Reference Note: This article is educational guidance. The current contract or subcontract, applicable DFARS clauses, current DCISE instructions, actual incident facts, legal requirements, and other applicable reporting obligations remain the source of truth.

What Is DCISE? #

The DoD-Defense Industrial Base Collaborative Information Sharing Environment, commonly called DCISE, is part of the Department of Defense Cyber Crime Center, or DC3. DCISE is the DoD focal point for Defense Industrial Base cyber incident reporting and information sharing. It supports mandatory reporting under DFARS 252.204-7012 as well as voluntary cyber threat reporting. Current reporting guidance and assistance are available through the DC3 / DCISE Cyber Incident Reporting page.

If you are still determining whether an event may require reporting, start with Cyber Incident Response for DoD Contractors: DFARS, CUI, and the First 72 Hours.

What Is the Incident Collection Format? #

The Incident Collection Format (ICF) is the reporting format DCISE uses to collect information about a cyber incident. It is not the same thing as a completed forensic report. The ICF captures information about the organization, affected contract, incident, potential impact, compromise method, incident outcome, technical indicators, and current understanding of what occurred. Current DCISE guidance identifies 21 information fields for DFARS 252.204-7012 cyber incident reporting.

Before Reporting, Confirm the Contract Requirement #

Determine which contract or subcontract is connected to the potentially affected work as early as practical.

Review the applicable:

  • contract or subcontract;
  • purchase order;
  • incorporated DFARS clauses;
  • supplier terms and conditions;
  • cybersecurity addenda; and
  • prime-contractor requirements.

For subcontractors, identify the prime contractor or next higher-tier subcontractor associated with the affected work.

Do Not Let Contract Research Consume the Reporting Window

Contract review should occur while containment, investigation, and evidence preservation continue. Do not delay urgent response actions or allow an approaching reporting deadline to expire simply because every contractual question has not yet been resolved.

When Does the 72-Hour Reporting Period Begin? #

For a cyber incident that meets the reporting requirements of DFARS 252.204-7012, the clause defines rapidly report as reporting within 72 hours of discovery.  The attack may have started earlier than the organization’s discovery. For example, suspicious activity may occur on Monday but not be discovered and validated as a cyber incident until Tuesday. Preserve both timestamps when they are known.

Important timestamps can include:

  • suspected attack activity;
  • initial security alert;
  • discovery of the cyber incident;
  • start of investigation;
  • containment actions; and
  • report submission.

The clause uses 72 hours, not three business days. Organizations should not assume weekends or holidays pause the reporting period.

The Investigation Does Not Need to Be Finished Before Reporting #

DCISE currently instructs contractors to report as much of the required information as can be obtained within the 72-hour period. If additional information is discovered after the initial ICF is submitted, DCISE instructs the contractor to provide the new or updated information through a follow-on ICF.

Reporting Stage Purpose
Initial ICF Reports the information reasonably available within the required reporting period.
Follow-On ICF Adds or corrects information discovered as the investigation continues.

Unknown Is Better Than Guessing

Do not turn an unknown fact into a definitive answer simply to complete the report. State what is known. Identify what remains under investigation. Update the report when additional evidence becomes available.

How Is a Cyber Incident Reported? #

The normal reporting path is the secure DCISE Incident Collection Format portal. DCISE Incident Collection Format Portal

A DoD-approved Medium Assurance Certificate is required for normal access to the secure reporting portal. Current DCISE reporting instructions should always be checked before submitting an incident because operational reporting processes can change even when the underlying DFARS requirement remains the same.

What Is a DoD-Approved Medium Assurance Certificate? #

DFARS 252.204-7012 requires the contractor or subcontractor to have or acquire a DoD-approved Medium Assurance Certificate for cyber incident reporting. The certificate is a Public Key Infrastructure identity credential used to authenticate an individual to protected DoD systems.

It is not the same thing as:

  • a PIEE account;
  • an SPRS account;
  • a CMMC certification;
  • Microsoft MFA;
  • a Microsoft passkey;
  • Windows Hello for Business; or
  • a FIDO2 security key such as a YubiKey.

The current DoD External Certification Authority program identifies two approved ECA vendors:

Current DoD ECA information is available through the DoD External Certification Authority Program.

Preparedness Recommendation #

Organizations subject to DFARS incident reporting should consider maintaining both a primary authorized certificate holder and a trained backup.

This is an operational preparedness recommendation. DFARS does not require two certificate holders.

The purpose is to reduce the risk that travel, leave, employee turnover, certificate expiration, or another single-person dependency delays incident reporting.

What If the Company Does Not Have a Medium Assurance Certificate? #

Do not wait for the certificate procurement process to finish if a reporting deadline may apply.

Current DCISE guidance instructs organizations without the required certificate to contact DCISE for reporting assistance:

  • Email: DC3.DCISE@us.af.mil
  • Hotline: 410-981-0104

DCISE currently provides 24/7 hotline support for incident reporting and assistance.

Follow the Reporting Instructions DCISE Provides

Do not assume that contacting the hotline or sending an email, by itself, always completes the required report. Explain that the organization needs to report a cyber incident, follow the reporting instructions DCISE provides for that situation, and preserve documentation showing when each reporting step occurred.

What Information Is Needed for the ICF? #

The current ICF contains 21 reporting fields. The information can be organized into several practical groups:

Information Group Examples of Information Requested
Organization Company name, UEI, facility CAGE code, facility clearance level, and company point of contact.
Contract Contract or PIID, affected agreements, Government Program Manager, Contracting Officer, and agreement clearance level.
Impact Impact to CDI, ability to provide operationally critical support, affected DoD programs, platforms, or systems.
Discovery and Location Discovery date, locations of compromise, and incident-location CAGE code.
Compromise Type of compromise, technique or method used, and incident outcome.
Narrative Chronology, threat-actor techniques, indicators of compromise, targeting, mitigation, and other relevant findings.
Certificate expiration tracking Reduces the risk of discovering an expired reporting credential during an incident.

The current complete list of 21 fields is maintained on the DCISE reporting page.

Understand the Difference Between Compromise and CDI Impact #

The ICF separates several findings that should not be combined.

For example, DCISE separately asks about:

  • impact to Covered Defense Information;
  • type of compromise;
  • technique or method used;
  • incident outcome; and
  • the incident narrative.

The current ICF incident-outcome choices include:

  • Successful compromise
  • Failed attempt
  • Unknown

Successful Compromise Does Not Automatically Mean CDI Was Stolen

An organization may confirm that an identity or system was successfully compromised while finding no evidence that CDI was accessed or exfiltrated.

Those are separate findings and should be reported separately.

Use Evidence-Based Reporting Language #

Cyber investigations develop over time. Reporting language should reflect the evidence available when the statement is made.

Avoid Prefer
Nothing happened. No additional unauthorized activity has been identified as of [date/time].
No data was stolen. No evidence of data exfiltration has been identified as of [date/time].
CUI was not affected. No evidence of unauthorized access to the reviewed CUI/CDI environment has been identified as of [date/time].
The attacker only accessed email. The confirmed unauthorized activity identified to date is limited to [specific activity].

The goal is to distinguish among confirmed, not observed, unknown, and not applicable.

Writing the Incident Narrative #

The incident narrative should allow another investigator to understand the event without overstating what the evidence proves.

A useful narrative generally explains:

  1. Discovery: How and when was the incident identified?
  2. Activity: What suspicious or unauthorized activity was confirmed?
  3. Scope: Which identities, systems, applications, or information were involved?
  4. Containment: What actions were taken to stop continued unauthorized activity?
  5. Impact: What is currently known about CDI, contract performance, or other affected information?
  6. Indicators: What IP addresses, domains, files, authentication methods, or other indicators were identified?
  7. Unknowns: What remains under investigation?

Current DCISE guidance identifies chronology, threat-actor tactics, techniques and procedures, indicators of compromise, targeting, mitigation strategies, and other relevant information as examples of useful narrative content.

What Happens After the Initial Report? #

The initial report does not end the incident-response process.

Continue appropriate:

  • log collection;
  • endpoint investigation;
  • identity review;
  • cloud audit review;
  • evidence preservation;
  • contract review;
  • containment validation; and
  • recovery activities.

If additional or corrected information becomes available, DCISE instructs contractors to provide it through a follow-on ICF.

The incident record should clearly distinguish the original report from later findings and corrections.

The DoD Incident Report Number Matters #

DoD assigns an incident report number to the reported incident.

That number becomes an important reference for:

  • DCISE follow-up;
  • related reporting communications;
  • malware-submission assistance; and
  • subcontractor notification to the prime or next higher tier.

When Does a Subcontractor Notify the Prime? #

There are two separate requirements to consider.

DFARS Requirement #

When a subcontractor reports a cyber incident to DoD as required by DFARS 252.204-7012, the subcontractor must provide the DoD-assigned incident report number to the prime contractor or next higher-tier subcontractor as soon as practicable.

Contract-Specific Requirement #

The subcontract may impose an additional or earlier notification requirement.

For example, the subcontract may require:

  • immediate notice;
  • notification within a specified number of hours;
  • notification to a specific security or contracting contact; or
  • additional incident information before the DoD report number is available.

Do Not Assume One Notification Satisfies the Other

Providing the DoD incident report number satisfies the DFARS flow-down requirement described in the clause.

The subcontract may contain separate notification requirements that must also be followed.

Can an MSP, MSSP, or Consultant Submit the Report? #

An outsourced IT provider, MSP, MSSP, consultant, or incident-response firm can perform substantial work during the reporting process.

This may include:

  • investigation;
  • containment;
  • evidence preservation;
  • incident documentation;
  • preparing ICF information;
  • contacting DCISE for assistance; and
  • coordinating reporting communications with the impacted organization.

However, current DCISE guidance states that a vendor or customer cannot submit the impacted company’s mandatory ICF on its behalf.

The service provider can help run the process. The impacted contractor owns the reporting obligation.

Mandatory and Voluntary Reporting Are Different #

Reporting Type Purpose
Mandatory Meets an applicable contractual reporting obligation, including qualifying DFARS 252.204-7012 cyber incidents.
Voluntary Shares potentially useful cyber threat activity with DoD even when mandatory reporting does not apply.

DCISE currently identifies examples of useful voluntary reporting such as suspected advanced persistent threat activity, reconnaissance, exploitation attempts, threat-actor infrastructure, phishing messages, suspicious files, and network activity.

Voluntary reporting does not convert every security alert into a mandatory DFARS incident.

What If Malicious Software Is Discovered? #

If malicious software is discovered and isolated in connection with a reported cyber incident, DFARS 252.204-7012 requires it to be submitted to DC3 according to instructions provided by DC3 or the Contracting Officer.

Never Email Malware

Do not attach malicious files to an email sent to DCISE, the Contracting Officer, or another recipient.

Use the approved secure malware-submission process or another secure method provided by DCISE.

Current DCISE options include the Electronic Malware Submission portal and secure one-time upload methods available through DCISE assistance.

Evidence Preservation Continues After Reporting #

For a cyber incident subject to DFARS 252.204-7012, the contractor must preserve and protect:

  • images of all known affected information systems identified through the required incident review; and
  • relevant monitoring or packet-capture data.

The required preservation period is at least 90 days from submission of the cyber incident report.

The 90 days are a minimum, not a maximum.

Longer preservation may be appropriate because of continuing DoD requests, legal holds, insurance requirements, other contracts, ongoing investigation, or internal retention requirements.

A separate Client University article covers cyber incident evidence preservation in greater detail.

DoD May Request Additional Information or Equipment #

DFARS 252.204-7012 allows DoD to request access to additional information or equipment necessary to conduct forensic analysis.

DoD may also conduct a cyber incident damage assessment and request supporting information gathered during the incident-response process.

Preserve the original evidence and maintain a clear incident record rather than treating the initial report as the end of the matter.

Other Reporting Obligations May Still Apply #

Submitting a DCISE report does not automatically satisfy every other notification requirement.

Separate obligations may include:

  • prime-contractor or subcontract requirements;
  • other Government agencies;
  • cyber-insurance policies;
  • privacy or breach-notification laws;
  • ITAR or EAR requirements;
  • customer contracts; and
  • law-enforcement reporting.

DFARS 252.204-7012 specifically states that its safeguarding and cyber incident reporting requirements do not remove other applicable safeguarding or reporting responsibilities.

Common DFARS Cyber Incident Reporting Mistakes #

Mistake Better Approach
Waiting for the entire forensic investigation to finish Report available information within the required timeframe and update it later.
Waiting to obtain a Medium Assurance Certificate Contact DCISE immediately for reporting assistance.
Assuming a phone call or email always completes the report Follow the reporting instructions DCISE provides for the incident.
Guessing at unknown facts Identify what remains unknown and provide follow-up information later.
Treating successful compromise as proof of CDI theft Evaluate compromise and CDI impact as separate findings.
Emailing malware Use the approved secure DC3 submission process.
Forgetting the prime contractor Review the subcontract and provide the DoD incident number when required.
Treating 90 days as the maximum retention period Preserve required evidence for at least 90 days and longer when appropriate.

Prepare Before a Cyber Incident Happens #

The reporting process becomes much easier when critical information is prepared before the 72-hour clock starts.

Prepare in Advance Why It Matters
Applicable DFARS contract list Helps determine which agreements may be affected.
CAGE and UEI information Supports required organization identification.
Contract / PIID information Identifies affected DoD work.
Prime and Government contacts Supports timely contractual coordination.
Current CUI/CDI scope and data flows Helps determine potential incident impact.
Medium Assurance Certificate Provides normal secure reporting access.
Backup trained reporting contact Reduces single-person dependency.
DCISE contact information Prevents searching for help during an emergency.
Legal, export-control, and insurance contacts Supports parallel reporting and legal obligations.
Incident and evidence workflow Creates a consistent central incident record.

Preparedness Recommendation

Test the reporting workflow before an actual incident.

Periodically verify certificate access, expiration dates, internal reporting authority, contract information, prime contacts, DCISE contacts, and evidence-preservation procedures.

Authoritative Resources and References #

This article was developed using primary Government sources. Direct source material should always take precedence when determining requirements for a specific contract or incident.

Frequently Asked Questions #

Do we need the entire forensic investigation completed before reporting? #

No. DFARS requires rapid reporting within the applicable 72-hour period. Current DCISE guidance allows additional information to be provided later through follow-on reporting.

Does the 72-hour period mean three business days? #

No. DFARS states 72 hours. Organizations should not assume weekends or holidays pause the reporting period.

Does sending the first email to DCISE always satisfy the 72-hour reporting requirement? #

No universal rule should be assumed. If the organization cannot use the normal secure reporting process, contact DCISE before the deadline and follow the instructions provided for that incident. Preserve the email, call records, timestamps, and any instructions received so the reporting path is documented.

What if we do not know whether CDI was accessed? #

Continue investigating, but do not allow uncertainty alone to consume the reporting period. Provide the information known when reporting is required and clearly identify what remains under investigation.

What if we do not have a Medium Assurance Certificate? #

Contact DCISE immediately for reporting assistance. Current DCISE guidance instructs organizations without the required certificate to email DC3.DCISE@us.af.mil or call 410-981-0104 for assistance.

Is a PIEE or SPRS login the same as a Medium Assurance Certificate? #

No. A Medium Assurance Certificate is a DoD-approved PKI identity credential obtained through an approved External Certification Authority.

Is a YubiKey or Microsoft passkey a Medium Assurance Certificate? #

No. FIDO2 security keys and passkeys are authentication technologies used for other security purposes. They do not replace the ECA certificate required for normal DCISE reporting access.

Which vendors currently provide approved ECA certificates? #

Current DoD guidance identifies IdenTrust and WidePoint as approved ECA vendors.

What if some information requested by the ICF is unknown? #

Do not guess. Provide the information available, clearly identify uncertainties, continue the investigation, and submit follow-up information when it becomes available.

Does “successful compromise” mean CUI or CDI was stolen? #

No. The success of the compromise and the impact to CDI are separate findings. A successful identity or system compromise does not automatically establish that CDI was accessed or exfiltrated.

Can our MSP or MSSP submit the mandatory ICF for us? #

Current DCISE guidance states that a third-party vendor or customer cannot submit the impacted company’s mandatory ICF on its behalf. The provider can substantially support investigation, documentation, preparation, and coordination. The impacted contractor retains the reporting obligation.

Does a subcontractor report directly to DoD or only to the prime? #

When DFARS 252.204-7012 applies and requires reporting, the subcontractor reports the cyber incident directly to DoD rather than relying on the prime contractor to submit the report for it. The subcontractor must then provide the DoD-assigned incident report number to the prime contractor or next higher-tier subcontractor as soon as practicable. The subcontract may contain additional or earlier prime-notification requirements.

What happens if we learn something important after the initial report? #

Provide the new or corrected information through a follow-on ICF. The investigation should continue after the initial report.

Can malicious files be attached to an email to DCISE? #

No. Use the approved Electronic Malware Submission process or another secure submission method provided by DCISE.

How long must incident evidence be preserved? #

DFARS requires images of known affected systems identified through the required incident review and relevant monitoring or packet-capture data to be preserved for at least 90 days from submission of the cyber incident report. Other legal, contractual, insurance, or investigative requirements may require longer retention.

Does reporting to the FBI, cyber insurer, prime contractor, or another agency replace DCISE reporting? #

No. Each reporting obligation should be evaluated separately. DFARS reporting does not eliminate other contractual, statutory, regulatory, insurance, or customer requirements.

What are your feelings