A community resource for the acquisition workforce not a .gov website
part52.dev Federal Acquisition Clause Monitor
DFARS Clause ACTIVE

252.204-7008

Compliance with safeguarding covered defense information controls.
Search on acquisition.gov · View on eCFR.gov
Effective Date
OCT 2016
Active Deviations
4
Versions
1 (since 2016-12-22)
DEV
This clause is modified by 4 active class deviations
  • 2026-O0043 — DFARS RFO Implementation (Part 4)
    Modified by RFO class deviation
  • 2026-O0028 — DFARS RFO Implementation (Part 12)
    Add clause 252.204-7008
  • 2026-O0025 — DFARS RFO Implementation (Part 40)
    Add clause 252.204-7008
  • 2026-O0002 — DFARS RFO Implementation (Part 1)
View per-deviation details →
252.204-7008 Compliance with safeguarding covered defense information controls.

As prescribed in 204.7304(a), use the following provision:

Compliance With Safeguarding Covered Defense Information Controls (OCT 2016)

(a)
Definitions.
As used in this provision—

Controlled technical information, covered contractor information system,

covered defense information, cyber incident,

information system,
and
technical information
are defined in clause 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting.

(b) The security requirements required by contract clause 252.204-7012, shall be implemented for all covered defense information on all covered contractor information systems that support the performance of this contract.

(c) For covered contractor information systems that are not part of an information technology service or system operated on behalf of the Government (see 252.204-7012(b)(2))—

(1) By submission of this offer, the Offeror represents that it will implement the security requirements specified by National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171, "Protecting Controlled Unclassified Information in Nonfederal Information Systems and Organizations" (see
http://dx.doi.org/10.6028/NIST.SP.800-171
)that are in effect at the time the solicitation is issued or as authorized by the contracting officer, not later than December 31, 2017.

(2)(i) If the Offeror proposes to vary from any of the security requirements specified by NIST SP 800-171 that are in effect at the time the solicitation is issued or as authorized by the Contracting Officer, the Offeror shall submit to the Contracting Officer, for consideration by the DoD Chief Information Officer (CIO), a written explanation of—

(A) Why a particular security requirement is not applicable; or

(B) How an alternative but equally effective, security measure is used to compensate for the inability to satisfy a particular requirement and achieve equivalent protection.

(ii) An authorized representative of the DoD CIO will adjudicate offeror requests to vary from NIST SP 800-171 requirements in writing prior to contract award. Any accepted variance from NIST SP 800-171 shall be incorporated into the resulting contract.

(End of provision)

[80 FR 51744, Aug. 26, 2015, as amended at 80 FR 81473, Dec. 30, 2015; 81 FR 72999, Oct. 21, 2016]

Change History

Date Authority Type Summary
2026-02-01 2026-O0025 RFO_CLAUSE_MODIFIED R-DFARS 252.204-7008 Compliance with safeguarding covered defense information updated from deviation 2026-O0025.
2026-02-01 2026-O0025 RFO_CLAUSE_MODIFIED R-DFARS 252.204-7008 Compliance with safeguarding covered defense information updated from deviation 2026-O0025.
2026-02-01 2026-O0028 RFO_CLAUSE_MODIFIED R-DFARS 252.204-7008 Contracts Providing Access to DoD Section 1632 of FY updated from deviation 2026-O0028.
2026-02-01 2026-O0002 RFO_CLAUSE_ADDED R-DFARS 252.204-7008 0704-0478 added from deviation 2026-O0002.
RFO
Prescription superseded under the RFO

The prescription shown below is from the codified eCFR. The Revolutionary FAR Overhaul relocates this clause's prescription as follows:

  • 204.7304240.370-5 (prescriptive text also revised)
  • 212.301212.205-70 (prescriptive text also revised)

See the deviation memorandum for the current prescription authority.

View deviation: 2026-O0043 → · View deviation: 2026-O0028 → · View deviation: 2026-O0025 → · View deviation: 2026-O0002 →

R-DFARS Prescription Source

This clause is prescribed in the R-DFARS by the following deviations:

  • 2026-O0028 — DFARS RFO Implementation (Part 12) (DFARS Part 212)
    Add clause 252.204-7008
  • 2026-O0025 — DFARS RFO Implementation (Part 40) (DFARS Part 240)
    Add clause 252.204-7008
204.7304(a)
(a) Use the provision at 252.204-7008 , Compliance with Safeguarding Covered Defense Information Controls, in all solicitations, including solicitations using FAR part 12 procedures for the acquisition of commercial products and commercial services, except for solicitations solely for the acquisition of commercially available off-the-shelf (COTS) items.
Prescription data sourced from eCFR as of 2026-06-15 02:15 UTC. Cross-references within the prescription are not resolved automatically.

Regulatory Stack

The layers of regulation that govern this clause, from the FAR prescription through agency-specific supplements and any active deviations.

R-DFARS R-DFARS Prescription Per Deviation 2026-O0028 (DFARS Part 212/240)
2026-O0028: DFARS RFO Implementation (Part 12) — DFARS Part 212
2026-O0025: DFARS RFO Implementation (Part 40) — DFARS Part 240

View Deviation 2026-O0028 → · View Deviation 2026-O0025 →

DFARS DFARS Supplement (eCFR) ⚠ May be superseded by RFO 204.7304(a)
(a) Use the provision at 252.204-7008 , Compliance with Safeguarding Covered Defense Information Controls, in all solicitations, including solicitations using FAR part 12 procedures for the acquisition of commercial products and commercial services, except for solicitations solely for the acquisition of commercially available off-the-shelf (COTS) items.

Search on acquisition.gov · View on eCFR.gov

Version History

Version history is sourced from the codified eCFR. Changes published only as class deviations or by the Revolutionary FAR Overhaul do not appear here until they are incorporated into the eCFR. For RFO-driven changes see the RFO Version tab and any active deviations cited above.

No version history available from eCFR.

Active Class Deviations

DFARS RFO Implementation (Part 4) Modified by RFO class deviation
MODIFIED
DFARS RFO Implementation (Part 12) Add clause 252.204-7008
MODIFIED
DFARS RFO Implementation (Part 40) Add clause 252.204-7008
MODIFIED
DFARS RFO Implementation (Part 1) Modify clause 252.204-7008
MODIFIED

Related Clauses

References

252.204-7012
Use with AI assistant
Copy a link and prompt for use with Gemini or another AI assistant.