Aerospace & Defense | Sierra Nevada Company (SNC) | Employees Working
Aerospace & Defense | Sierra Nevada Company (SNC) | Employees Working
The DOD published DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Reporting in an effort to prevent improper access of important unclassified information in the supply base. The DFARS 252.204-7012 clause includes the following key requirements:
This is some text inside of a div block.
Aerospace & Defense | Sierra Nevada Company (SNC) | Employees Working

Adequate Security

Contractors must provide adequate security on all covered contractor information systems. A “covered contractor information system” is defined as an unclassified information system that is owned or operated by or for, a contractor and that processes, stores or transmits covered defense information.

Cyber incident reporting process for defense contractors

Cyber Incident Reporting

When a cyber incident is discovered, contractors must conduct a review for evidence of compromise of covered defense information and report to the DoD at http://dibnet.dod.mil and SNC within 72 hours. A “cyber incident” is defined as actions taken through the use of computer networks that result in a compromise or an actual or potentially adverse effect on an information system and/or the information residing therein.

Aerospace & Defense | Sierra Nevada Company (SNC) | Employees Working

Supplier Flow Down

When engaging with other suppliers that require access to covered defense information in performance of a contract, include the DFARS 252.204-7012 clause in any subcontracts or similar contractual instruments with those suppliers.

Aerospace & Defense | Sierra Nevada Company (SNC) | Employees Working

CMMC 2.0 DFARS 252.204-7021

The DoD published DFARS 252.204-7021, Contractor Compliance with the Cybersecurity Maturity Model Certification (CMMC) Program, as a crucial step to bolster the cybersecurity posture of the defense industrial base (DIB) and protect sensitive unclassified information. This clause introduces a standardized, tiered approach to cybersecurity, moving beyond self-attestation to include third-party assessments for many contractors. The DFARS 252.204-7021 clause includes the following key requirements:

Aerospace & Defense | Sierra Nevada Company (SNC) | Employees Working

CMMC Certification Requirement

Contractors must possess a current (not older than three years) CMMC certificate at the level specified in the contract and maintain this certification throughout the contract's duration. The required CMMC level (Level 1, 2, or 3) depends on the type and sensitivity of information processed, stored or transmitted, specifically Federal Contract Information (FCI) and Controlled Unclassified Information (CUI).

Aerospace & Defense | Sierra Nevada Company (SNC) | Employees Working

Annual Affirmation of Continous Compliance

Beyond the initial certification, contractors are required to provide an annual affirmation by a senior company official, verifying continuous compliance with the cybersecurity requirements applicable to their CMMC level.

Contractor reporting of lapses in information security or CMMC status

Lapse in Information Security and CMMC Status Reporting

Contractors must notify the contracting officer within 72 hours of any "lapses in information security" or changes in the status of their CMMC certificate or CMMC self-assessment levels during the performance of the contract. This emphasizes ongoing vigilance and immediate reporting of any potential compromise.

Aerospace & Defense | Sierra Nevada Company (SNC) | Employees Working

Continued Dilligence

It is imperative that all SNC subcontractors and/or suppliers meet DFARS requirements as necessary. Together our continued diligence will protect vital information, minimize risks and secure competitive advantage for all parties.