DI-SCRE-82258
Contractor's Record of Tier 1 Level Suppliers Receiving/Developing Covered Defense Information
Specifies the Contractor's Record of Tier 1 Level Suppliers Receiving/Developing Covered Defense Information, used to demonstrate the Contractor's ability to restrict and safeguard covered defense information disseminated to tier 1 level suppliers under DFARS Clause 252.204-7012.
Approval DateMarch 13, 2019
AMSC Number10008
Preparing ActivityRS
Project NumberMGMT-2019-010
OPR—
DTIC ApplicableNo
GIDEP ApplicableNo
Limitation—
Applicable FormsNone
Approval Limitation—
Form Version—
DID Formatfree_text
963C CompliantYes
DISTRIBUTION STATEMENT A: Approved for public release; distribution is unlimited.
Application & Interrelationship
—
Use & Relationship
When Defense Federal Acquisition Regulation Supplement (DFARS) Clause 252.204-7012 is included in a contract for which covered defense information - as defined in DFARS Clause 252.204-7012 - will be processed, stored, or transmitted on a tier 1 level supplier's internal unclassified information system. (DFARS Clause 252.204-7012 can be found at https://www.acq.osd.mil/dpap/dars/dfars/html/current/252204.htm)
a. This Data Item Description (DID) contains the information that is required of the Contractor's Record of Tier 1 Level Suppliers Receiving/Developing Covered Defense Information. This information will be used by the government as critical inputs to an overall risk management decision to process, store, or transmit covered defense information on an unclassified information system that is owned or operated by, or for, the contractor (i.e. contractor's internal unclassified information system). This information will:
(1) Demonstrate to the government the Contractor's ability to restrict the dissemination of covered defense information specified in, or developed under, the contract to subcontractors that execute requirements that involve the covered defense information.
(2) Demonstrate to the government the Contractor's ability to ensure that their tier 1 level suppliers safeguard covered defense information in accordance with DFARS Clause 252.204-7012.
b. This DID contains the format, content, and intended use information for the data deliverable resulting from the work task described in the contract.
Preparation Instructions
1Reference DocumentsThe applicable issue of the documents cited herein, including approval dates and dates of applicable amendments, notices and revisions, shall be specified in the contract.
2FormatContractor's format is acceptable.
3ContentThe Contractor's Record of Tier 1 Level Suppliers Receiving/Developing Covered Defense Information must include a description of how the Contractor will identify and restrict the dissemination of covered defense information to subcontractors who require the covered defense information to execute the requirements in their contract and how the Contractor will ensure that their tier 1 level suppliers safeguard covered defense information with the requirements of DFARS Clause 252.204-7012. The Contractor's Record of Tier 1 Level Suppliers Receiving/Developing Covered Defense Information shall include the following:
3.1Cover PageThe cover page of the Contractor's Record of Tier 1 Level Suppliers Receiving/Developing Covered Defense Information shall include:
aTitle of the document(i.e., [Name of Contractor] Record of Tier 1 Level Suppliers Receiving/Developing Covered Defense Information
bContractor's Data Universal Numbering Systems (DUNS) and Commercial and Government Entity (CAGE) code numbers
cContract number(s) or other type of agreement (if available)
3.2Tier 1 Level Supplier Information(for each Tier 1 Level Supplier receiving/developing covered defense information associated with this contract)
bSupplier contract and/or agreement number (if available)
cSupplier Point of Contactname, email, and phone number
dDate the Tier 1 Level Supplier sub contract was put in place
eNumber of sub contracts with Tier 1 Level Supplier
fSupplier contract and/or agreement contains or will contain substance of DFARS Clause 252.204-7012Y/N
gSupplier contract and/or agreement contains or will contain cyber security measures and/or requirements other than those identified in DFARS Clause 252.204-7012 and National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171 Rev 1Y/N (NIST SP 800-171 can be found at https://csrc.nist.gov/publications/detail/sp/800-171/rev-1/final)
hContractor's DUNS and CAGE numbers
iSupplier has conducted or will conduct a self-assessment in accordance with NIST SP 800-171AY/N (NIST SP 800-171A can be found at https://csrc.nist.gov/publications/detail/sp/800-171a/final)
jSupplier System Security Plan and Associated Plans of Action in accordance with NIST SP 800-171 Rev 1 Security Requirement 3.12.4 and 3.12.2
kList of Supplier's Tier 1 Level Suppliers receiving and/or developing covered defense information
Schema v3.0Community-maintained · Verify against ASSIST