← All FR Documents ·← Back to 2025-24248
Notice

Information Collection Requirements; Defense Federal Acquisition Regulation Supplement (DFARS); Cyber Incident Reporting and Cloud Computing

In Plain English

What is this Federal Register notice?

This is a notice published in the Federal Register by Defense Department, Defense Acquisition Regulations System. Notices communicate information, guidance, or policy interpretations but may not create new binding obligations.

Is this rule final?

This document is classified as a notice. It may or may not create enforceable regulatory obligations depending on its specific content.

Who does this apply to?

Consult the full text of this document for specific applicability provisions. The affected parties depend on the regulatory scope defined within.

When does it take effect?

No specific effective date is indicated. Check the full text for date provisions.

Why it matters: This notice communicates agency policy or guidance regarding applicable regulations.

Document Details

Document Number2026-00544
TypeNotice
PublishedJan 14, 2026
Effective Date-
RIN-
Docket IDDocket Number DARS-2025-0006
Text FetchedYes

Agencies & CFR References

CFR References:
None

Linked CFR Parts

PartNameAgency
No linked CFR parts

Paired Documents

TypeProposedFinalMethodConf
No paired documents

Related Documents (by RIN/Docket)

Doc #TypeTitlePublished
2025-24248 Notice Information Collection Requirements; Def... Jan 5, 2026
2025-10277 Notice Information Collection Requirements; Def... Jun 6, 2025

External Links

⏳ Requirements Extraction Pending

This document's regulatory requirements haven't been extracted yet. Extraction happens automatically during background processing (typically within a few hours of document ingestion).

Federal Register documents are immutable—once extracted, requirements are stored permanently and never need re-processing.

Full Document Text (696 words · ~4 min read)

Text Preserved
<NOTICE> DEPARTMENT OF DEFENSE <SUBAGY>Defense Acquisition Regulations System</SUBAGY> <DEPDOC>[Docket Number DARS-2025-0006; OMB Control Number 0704-0478]</DEPDOC> <SUBJECT>Information Collection Requirements; Defense Federal Acquisition Regulation Supplement (DFARS); Cyber Incident Reporting and Cloud Computing</SUBJECT> <HD SOURCE="HED">AGENCY:</HD> Defense Acquisition Regulations System; Department of Defense (DoD). <HD SOURCE="HED">ACTION:</HD> Supplemental notice. <SUM> <HD SOURCE="HED">SUMMARY:</HD> The Defense Acquisition Regulations System has submitted to OMB for clearance the following proposal for collection of information under the provisions of the Paperwork Reduction Act. This document updates the instructions for submission of comments. </SUM> <DATES> <HD SOURCE="HED">DATES:</HD> DoD will consider all comments received by January 14, 2026. </DATES> <HD SOURCE="HED">ADDRESSES:</HD> Written comments and recommendations for the proposed information collection should be sent within 30 days of publication of this notice to <E T="03">https://www.reginfo.gov/public/do/PRAMain.</E> Find this particular information collection by selecting “Currently under 30-day Review—Open for Public Comments” or by using the search function. You may also submit comments, identified by docket number and title, by the following method: Federal eRulemaking Portal: <E T="03">https://www.regulations.gov.</E> Follow the instructions for submitting comments. <FURINF> <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD> Mr. Reginald T. Lucas, 571-372-7574, or <E T="03">whs.mc-alex.esd.mbx.dd-dod-information-collections@mail.mil.</E> </FURINF> <SUPLINF> <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD> In the <E T="04">Federal Register</E> of January 5, 2026, in FR Doc. 2025-24248, on page 255, this supplemental notice adds an <E T="02">ADDRESSES</E> caption to include public comment instructions. <E T="03">Title and OMB Number:</E> Safeguarding Covered Defense Information, Cyber Incident Reporting, and Cloud Computing; OMB Control Number 0704-0478. <E T="03">Affected Public:</E> Businesses or other for-profit and not-for-profit institutions. <E T="03">Respondent's Obligation:</E> Required to obtain or retain benefits. <E T="03">Reporting Frequency:</E> On occasion. <E T="03">Number of Respondents:</E> 1,971. <E T="03">Responses per Respondent:</E> 8.2, approximately. <E T="03">Annual Responses:</E> 16,223. <E T="03">Average Burden per Response:</E> 0.42 hours. <E T="03">Annual Burden Hours:</E> 6,770. <E T="03">Needs and Uses:</E> Offerors and contractors must report cyber incidents on unclassified networks or information systems, within cloud computing services, and when they affect contractors designated as providing operationally critical support, as required by statute. a. The clause at DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting, covers cyber incident reporting requirements for incidents that affect a covered contractor information system or the covered defense information residing therein, or that affects the contractor's ability to perform the requirements of the contract that are designated as operationally critical support and identified in the contract. b. The provision at DFARS 252.204-7008, Compliance with Safeguarding Covered Defense Information Controls, requires an offeror that proposes to vary from any of the security controls of National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171 in effect at the time the solicitation is issued to submit to the contracting officer a written explanation of how the specified security control is not applicable or an alternative control or protective measure is used to achieve equivalent protection. c. The provision at DFARS 252.239-7009, Representation of Use of Cloud Computing, requires offerors to report that they “anticipate” or “do not anticipate” utilizing cloud computing service in performance of a contract resulting from a solicitation containing the provision. The representation will notify contracting officers of the applicability of the cloud computing requirements of the DFARS 252.239-7010 clause of the contract. d. The clause at DFARS 252.239-7010, Cloud Computing Services, requires reporting of cyber incidents that occur when DoD is purchasing cloud computing services. These DFARS provisions and clauses facilitate mandatory cyber incident reporting requirements in accordance with statutory regulations. When reports are submitted, DoD will analyze the reported information for cyber threats and vulnerabilities in order to develop response measures as well as improve U.S. Government understanding of advanced cyber threat activity. In addition, the security requirements in NIST SP 800-171 are specifically tailored for use in protecting sensitive information residing in contractor information systems and generally reduce the burden placed on contractors by eliminating Federal-centric processes and requirements. The information provided will inform DoD in assessing the overall risk to DoD covered defense information on unclassified contractor systems and networks. <E T="03">DoD Clearance Officer:</E> Mr. Reginald T. Lucas. Requests for copies of the information collection proposal should be sent to Mr. Lucas at <E T="03">whs.mc-alex.esd.mbx.dd-dod-information-collections@mail.mil.</E> <SIG> <NAME>Kimberly R. Ziegler,</NAME> Editor/Publisher, Defense Acquisition Regulations System. </SIG> </SUPLINF> <FRDOC>[FR Doc. 2026-00544 Filed 1-13-26; 8:45 am]</FRDOC> </NOTICE>
This text is preserved for citation and comparison. View the official version for the authoritative text.