<html>
<head>
<title>Federal Register, Volume 91 Issue 2 (Monday, January 5, 2026)</title>
</head>
<body><pre>
[Federal Register Volume 91, Number 2 (Monday, January 5, 2026)]
[Notices]
[Pages 255-256]
From the Federal Register Online via the Government Publishing Office [<a href="http://www.gpo.gov">www.gpo.gov</a>]
[FR Doc No: 2025-24248]
-----------------------------------------------------------------------
DEPARTMENT OF DEFENSE
Defense Acquisition Regulations System
[Docket Number DARS-2025-0006; OMB Control Number 0704-0478]
Information Collection Requirements; Defense Federal Acquisition
Regulation Supplement (DFARS); Cyber Incident Reporting and Cloud
Computing
AGENCY: Defense Acquisition Regulations System; Department of Defense
(DoD).
ACTION: Notice.
-----------------------------------------------------------------------
SUMMARY: The Defense Acquisition Regulations System has submitted to
OMB for clearance the following proposal for collection of information
under the provisions of the Paperwork Reduction Act.
DATES: DoD will consider all comments received by February 4, 2026.
SUPPLEMENTARY INFORMATION:
Title and OMB Number: Safeguarding Covered Defense Information,
Cyber Incident Reporting, and Cloud Computing; OMB Control Number 0704-
0478.
Affected Public: Businesses or other for-profit and not-for-profit
institutions.
Respondent's Obligation: Required to obtain or retain benefits.
Reporting Frequency: On occasion.
Number of Respondents: 1,971.
Responses per Respondent: 8.2, approximately.
Annual Responses: 16,223.
Average Burden per Response: 0.42 hours.
Annual Burden Hours: 6,770.
Needs and Uses: Offerors and contractors must report cyber
incidents on unclassified networks or information systems, within cloud
computing services, and when they affect contractors designated as
providing operationally critical support, as required by statute.
a. The clause at DFARS 252.204-7012, Safeguarding Covered Defense
Information and Cyber Incident Reporting, covers cyber incident
reporting requirements for incidents that affect a covered contractor
information system or the covered defense information residing therein,
or that affects the contractor's ability to perform the requirements of
the contract that are designated as operationally critical support and
identified in the contract.
b. The provision at DFARS 252.204-7008, Compliance with
Safeguarding Covered Defense Information Controls, requires an offeror
that proposes to vary from any of the security controls of National
Institute of Standards and Technology (NIST) Special Publication (SP)
800-171 in effect at the time the solicitation is issued to submit to
the contracting officer a written explanation of how the specified
security control is not applicable or an alternative control or
protective measure is used to achieve equivalent protection.
c. The provision at DFARS 252.239-7009, Representation of Use of
Cloud Computing, requires offerors to report that they ``anticipate''
or ``do not anticipate'' utilizing cloud computing service in
performance of a contract resulting from a solicitation containing the
provision. The representation will notify contracting officers of the
applicability of the cloud computing
[[Page 256]]
requirements of the DFARS 252.239-7010 clause of the contract.
d. The clause at DFARS 252.239-7010, Cloud Computing Services,
requires reporting of cyber incidents that occur when DoD is purchasing
cloud computing services.
These DFARS provisions and clauses facilitate mandatory cyber
incident reporting requirements in accordance with statutory
regulations. When reports are submitted, DoD will analyze the reported
information for cyber threats and vulnerabilities in order to develop
response measures as well as improve U.S. Government understanding of
advanced cyber threat activity. In addition, the security requirements
in NIST SP 800-171 are specifically tailored for use in protecting
sensitive information residing in contractor information systems and
generally reduce the burden placed on contractors by eliminating
Federal-centric processes and requirements. The information provided
will inform DoD in assessing the overall risk to DoD covered defense
information on unclassified contractor systems and networks.
Comments and recommendations on the proposed information collection
should be sent to Ms. Susan Minson, DoD Desk Officer, at
<a href="/cdn-cgi/l/email-protection#357a5c47546a464057585c46465c5a5b755a58571b505a451b525a43"><span class="__cf_email__" data-cfemail="400f2932211f3335222d293333292f2e002f2d226e252f306e272f36">[email protected]</span></a>. Please identify the proposed information
collection by DoD Desk Officer and the Docket ID number and title of
the information collection.
You may also submit comments, identified by docket number and
title, by the following method: Federal eRulemaking Portal: <a href="https://www.regulations.gov">https://www.regulations.gov</a>. Follow the instructions for submitting comments.
DoD Clearance Officer: Mr. Reginald T. Lucas. Requests for copies
of the information collection proposal should be sent to Mr. Lucas at
<a href="/cdn-cgi/l/email-protection#b5c2ddc69bd8d698d4d9d0cd9bd0c6d19bd8d7cd9bd1d198d1dad198dcdbd3dac7d8d4c1dcdadb98d6dad9d9d0d6c1dcdadbc6f5d8d4dcd99bd8dcd9"><span class="__cf_email__" data-cfemail="fc8b948fd2919fd19d909984d2998f98d2919e84d29898d1989398d195929a938e919d88959392d19f939090999f889593928fbc919d9590d2919590">[email protected]</span></a>.
Kimberly R. Ziegler,
Editor/Publisher, Defense Acquisition Regulations System.
[FR Doc. 2025-24248 Filed 1-2-26; 8:45 am]
BILLING CODE 6001-FR-P
</pre><script data-cfasync="false" src="/cdn-cgi/scripts/5c5dd728/cloudflare-static/email-decode.min.js"></script></body>
</html>
Document
Information Collection Requirements; Defense Federal Acquisition Regulation Supplement (DFARS); Cyber Incident Reporting and Cloud Computing
The Defense Acquisition Regulations System has submitted to OMB for clearance the following proposal for collection of information under the provisions of the Paperwork Reductio...
Legal Citation
Federal Register Citation
Use this for formal legal and research references to the published document.
91 FR 255
Web Citation
Suggested Web Citation
Use this when citing the archival web version of the document.
“Information Collection Requirements; Defense Federal Acquisition Regulation Supplement (DFARS); Cyber Incident Reporting and Cloud Computing,” thefederalregister.org (January 5, 2026), https://thefederalregister.org/documents/2025-24248/information-collection-requirements-defense-federal-acquisition-regulation-supplement-dfars-cyber-incident-reporting-and.