Report an incident in 72 hours, with the record behind it
Review, report, preserve and hand over the record DFARS 7012 asks for.
Requirements
| Clause | What it asks | ARRTECH |
|---|---|---|
| 7012 (c)(1)(i) | Review for evidence of compromise. | Search across classified events. → |
| 7012 (c)(1)(ii) | Report within 72 hours. | A case record and report. → |
| 7012 (e) | Preserve monitoring data for 90 days. | Retention set per source. → |
| 7012 (f) | Give DoD access for forensic analysis. | A signed export with a verifier. → |
Review
Review for compromise across sources
After an incident, the clause asks you to review for evidence of compromise. ARRTECH SIEM classification rules turn vendor codes into common event categories, graded Informational to Critical, so one search covers every vendor. MITRE ATT&CK tactic and technique are columns on each classified event.
Reporting
Write the 72-hour report from the case
You report to DoD within 72 hours of discovery. A case carries its type, severity, assignee, SLA, MITRE tactic and kill-chain phase, sub-cases and history, and downloads as a case report.
Preservation
Keep 90 days of monitoring data
The clause asks you to preserve monitoring data for 90 days from the incident report. In ARRTECH SIEM, retention is set per source or per group. Archived logs stay searchable and export as CSV or files.
Access
Hand DoD a record it can check
When DoD asks for forensic access, any log source exports with its signatures, the SIEM certificate and a standalone verification tool, so a third party checks it without your SIEM.
Limits
Know what stays with you
No ARRTECH product produces the record for these requirements.
7012 (e) images
System images. The forensic module rebuilds events from logs. No ARRTECH product images a disk.
7012 (d)
Submit malicious software to DoD. The record comes from your malware handling process.
7012 (b)(2)(ii)(D)
FedRAMP Moderate or equivalent for cloud services. ARRTECH holds no FedRAMP authorization.
7012 (m)
Flow the clause down to subcontractors. That stays with your contracts.
By rule
Naming a clause is not a claim of certification.
7012 (c)(1)(i)
Conduct a review for evidence of compromise of covered defense information. ARRTECH: classified events searched across every vendor in one query.
7012 (c)(1)(ii)
Rapidly report cyber incidents to DoD within 72 hours of discovery. ARRTECH: a case record with type, severity, MITRE tactic and history, downloadable as a case report. You file the report.
7012 (e)
Preserve and protect images and relevant monitoring and packet capture data for at least 90 days. ARRTECH: retention set per source or per group, with archived logs searchable.
7012 (f)
Provide DoD access to information and equipment for forensic analysis. ARRTECH: signed exports with a standalone verification tool.
Questions
Does ARRTECH file the report?
No. You report to DoD. The case record supports its content.
Does ARRTECH keep system images?
No. The SIEM keeps logs, not disk images.
Can our assessor check the logs without ARRTECH?
Yes. Any source exports with its signatures, the SIEM certificate and a standalone verification tool.
Is DFARS 7012 a certification?
No. It is a contract clause that binds the contractor.
Sources
Guide
What is DFARS 252.204-7012?
A DoD contract clause that requires adequate security for covered defense information and rapid reporting of cyber incidents.
What is covered defense information?
Unclassified controlled technical information or other CUI provided to or developed by a contractor for DoD.
What does the 72-hour rule require?
A report to DoD within 72 hours of discovering a cyber incident, then preserved data and forensic access on request.
Next steps

Spot unusual behavior early. Learns what normal looks like for every user, computer and application from your SIEM, and flags what changes.

Get the evidence fast. Investigates each finding with read-only queries and hands a person the evidence. It never approves its own work.

Prove every log. Collects and signs logs from more than 500 source types and links related events, with a verification tool for every export.

Keep sensitive data in. Checks email, uploads, USB drives and AI prompts before sensitive data leaves the computer.

Respond with a person in charge. Runs incident response steps through your existing tools, with a person approving each decision.