A 72-hour incident report playbook you can actually run
The 72-hour reporting obligation is the clause most likely to be breached quietly. Teams discover an incident, spend two days deciding whether it is reportable, and miss the window while still arguing.
The clock starts at discovery, not at confirmation
DFARS 252.204-7012 requires rapid reporting within 72 hours of discovery of a cyber incident that affects a covered contractor information system, the CUI on it, or your ability to perform operationally critical support.
Discovery means the moment someone in your organization has reason to believe an incident occurred. Waiting for forensic certainty is not a defense — the report is designed to be filed with incomplete information and updated later.
Decide reportability in the first hour
Answer three questions and record the answers with a timestamp: does this touch a system that stores, processes, or transmits CUI; is there any indication CUI was accessed or exfiltrated; and does this degrade operationally critical support?
Any yes, or any credible maybe, means report. The cost of an unnecessary report is minimal. The cost of a late one is contractual.
What you need in hand to file
DIBNet reporting requires a medium assurance certificate, so obtain it before you need it — not during an incident.
- Contract numbers and CAGE codes affected
- Incident discovery timestamp and a short factual narrative
- Systems and locations involved, and whether CUI was involved
- Preserved images and relevant monitoring data (retain for at least 90 days)
After the filing
Preserve and protect images of affected systems and packet capture for at least 90 days from submission, submit malicious software to the DoD Cyber Crime Center when requested, and keep a timeline that shows each action against the clock. That timeline is the artifact an assessor will ask for.