DFARS 7012 commonly refers to DFARS clause 252.204-7012, a U.S. defense acquisition contract clause covering safeguarding of covered defense information and cyber incident reporting. In manufacturing, it is most relevant to defense contractors and suppliers that handle controlled unclassified defense information in systems, files, production records, quality records, or supplier exchanges.
The clause is often discussed in relation to cybersecurity controls, customer flowdowns, CUI or CDI handling, incident reporting obligations, and the use of external service providers such as cloud platforms. It is commonly associated with NIST SP 800-171 for protecting covered defense information in nonfederal systems, but DFARS 7012 itself is a contract clause, not a software feature, audit result, or standalone certification.
DFARS 7012 should not be treated as authorization to store classified information in ordinary MES, QMS, PLM, ERP, email, supplier portal, or commercial cloud systems. Classified program information is subject to separate program, contract, and customer requirements. DFARS 7012 also differs from ITAR export control rules and from CMMC assessment requirements, although these topics often overlap in defense manufacturing environments.