- A current list of active contracts and which carry DFARS 252.204-7012 or similar clauses — built before any incident
- The incident timeline worksheet (ATL-022), as the source of every factual answer
- Counsel's contact details and, where reporting may ever apply, DIBNet access arrangements (including the medium-assurance certificate) set up in advance
72-Hour Reporting Decision Worksheet
A structured decision aid for the hardest three days in defense contracting: does an affected contract carry DFARS 252.204-7012, is covered defense information or operationally critical support affected, when did the discovery clock start, and who decided what on which evidence. It organizes the decision; the contract and counsel make it.
Purpose, inputs, and completion
Purpose. When a cyber incident may touch covered defense information, DFARS 252.204-7012 puts a 72-hour rapid-reporting clock on contractors whose contracts carry it — and the worst time to work out whether yours do is after the clock may already be running. This worksheet structures the questions, ties every answer to evidence from the incident timeline, and records who decided what. It exists so the decision is organized, documented, and made by the right people.
When to use it. Prepare the worksheet's inputs in calm weather: the contract-clause list, the counsel relationship, and any DIBNet access arrangements all predate their need. During an incident, work the decision table top to bottom with the timeline worksheet (ATL-022) open beside it, then take the completed sheet to counsel before any decision is recorded. File the finished worksheet with the incident record whatever the outcome — a documented decision not to report is evidence of diligence; an undocumented one is a gap.
- Answer the contract question first — whether a reporting clause exists at all determines whether this clock matters.
- Give every answer an evidence pointer, not a recollection; a blank evidence cell means the answer is a guess.
- Record when the discovery clock started and why you chose that moment; the rationale will be examined later, by people with more time than you have now.
- Take the completed worksheet to counsel before deciding — this document organizes the decision, it does not make it.
Evidence, validation, and failure modes
- A dated record of the reporting questions asked, the answers given, and their evidence
- A documented discovery-clock rationale
- A decision record showing who decided and who was consulted
- Run a tabletop: hand this worksheet to the people who would use it and time how long the contract-clause question takes — if the answer takes hours, build the contract-clause list now, not during an incident.
- Confirm the named counsel contact has actually agreed to take this call and understands the 72-hour context.
- Nobody knows which contracts carry the clause, so the first day of a real 72-hour window is spent reading contracts instead of responding.
- The discovery moment is recorded loosely — 'sometime Tuesday' — leaving the clock start indefensible.
- The worksheet is treated as the decision itself; reporting obligations come from the contract and counsel's reading of it, not from a template.
Practices and requirements this artifact relates to
Brilliant at the Basics practices
NIST SP 800-171 Rev. 2
NIST SP 800-171 Rev. 3
Relationships are mapped support, not equivalence: completing this artifact documents work relevant to these requirements and does not by itself address any of them. Retention: Retain every completed worksheet with its incident record; the reasoning behind a report-or-not decision matters as much as the decision, and counsel may direct longer retention.
Preview — exactly what prints
72-Hour Reporting Decision Worksheet
Brilliant at the Basics Resource Center · brilliantatthebasics.us · published by inDirectIT, Inc.
Independent educational material. Not affiliated with, sponsored by, approved by, or endorsed by the U.S. Department of War. Does not establish compliance, certification, or contractual standing.
Purpose
When a cyber incident may touch covered defense information, DFARS 252.204-7012 puts a 72-hour rapid-reporting clock on contractors whose contracts carry it — and the worst time to work out whether yours do is after the clock may already be running. This worksheet structures the questions, ties every answer to evidence from the incident timeline, and records who decided what. It exists so the decision is organized, documented, and made by the right people.
How to use it
Prepare the worksheet's inputs in calm weather: the contract-clause list, the counsel relationship, and any DIBNet access arrangements all predate their need. During an incident, work the decision table top to bottom with the timeline worksheet (ATL-022) open beside it, then take the completed sheet to counsel before any decision is recorded. File the finished worksheet with the incident record whatever the outcome — a documented decision not to report is evidence of diligence; an undocumented one is a gap.
Read this before using the worksheet
Reporting obligations come from your contracts and from counsel's reading of them — not from this or any template. This worksheet organizes the decision; it does not make it, and it is not legal advice. Clause applicability, the definition of a reportable incident, what a rapid report must contain, and where it goes are contract-dependent questions for your contracts manager and your counsel. If reporting may apply to you, the DIBNet reporting path and the medium-assurance certificate it requires must be arranged before an incident, because 72 hours is not enough time to acquire one.
The 72-hour window under DFARS 252.204-7012 is measured from discovery. That makes two preparations decisive: knowing in advance which contracts carry the clause, and keeping a timeline (ATL-022) disciplined enough to establish the discovery moment credibly.
Decision table
Work top to bottom. Every answer cites evidence — a contract page, a timeline entry, a named conversation — or it is a guess wearing a suit.
Rows beginning EXAMPLE: show the expected shape — replace them with your own.
| Question | Answer | Evidence pointer | What the answer means for the decision |
|---|---|---|---|
| EXAMPLE: Does any affected contract carry DFARS 252.204-7012? | Yes — clause listed in section I | Contract 4700-22, clause listing, p. 41 | Reporting analysis continues; counsel engaged same day |
| Does any affected contract carry DFARS 252.204-7012 or another cyber incident reporting clause? | |||
| Is covered defense information stored, processed, or transmitted on the affected systems — or potentially affected? | |||
| Does the incident affect the company's ability to provide operationally critical support? | |||
| Has counsel reviewed the facts against the clause language? | |||
Discovery clock
Record the moment you treat as discovery and the reasoning for it, anchored to a timeline entry. A defensible clock start is a written one.
Clock start
| Discovery date and time (with timezone) | Discovered by | What made this the discovery moment | Timeline entry reference (ATL-022) |
|---|---|---|---|
Weeks later, someone with perfect hindsight will ask why the clock started when it did and not at the first faint alert three days earlier. The honest answer — what was actually known, and when it became credible — should already be written here, in ink that predates the question.
Decision record
Decision
| Decision (report / do not report / continue assessing) | Decided by | Counsel consulted (name and date) | Date and time of decision | If reporting: who submits, via what path |
|---|---|---|---|---|
Whatever the decision, file this worksheet with the incident record and revisit it if new facts move the analysis — the decision table can be run more than once as an incident develops.
Document control, version history, and approval
An artifact without an owner, a review date, and an approval trail is a snapshot, not a record. Complete this section before the document is used, and update it at every review.
| Field | Entry |
|---|---|
| Document owner (named person) | |
| Suggested owner role | Compliance lead or contracts manager |
| Approval authority | Executive sponsor, after consulting counsel |
| Review frequency | Annual, at every new contract award or modification, and after every use |
| Next scheduled review | |
| Storage location of the completed document | |
| Retention | Retain every completed worksheet with its incident record; the reasoning behind a report-or-not decision matters as much as the decision, and counsel may direct longer retention. |
Version history
| Version | Date | Author | Summary of change | Approved by |
|---|---|---|---|---|
Review and approval
| Reviewed by | Role | Date | Signature / initials |
|---|---|---|---|
Fill this in inside your own environment, not on any public website or unapproved cloud tool. A completed copy may reveal your security posture: never include CUI, export-controlled data, credentials or keys, unremediated vulnerability details, network diagrams, or customer-sensitive information beyond what the artifact strictly needs, and store the completed document with the same care as the systems it describes.
This is independent educational material. Completing it documents your work and produces records a reviewer can examine — it does not, by itself, implement a safeguard, satisfy any NIST SP 800-171 requirement, establish compliance with DFARS or CMMC, or replace your own analysis within your defined system boundary. Requirement references are mapped relationships, not equivalence claims. Tailor every section to your technical, operational, contractual, regulatory, and safety requirements.