Updated September 29, 2026
You don't need a SOC, the security operations center that big companies staff around the clock. You need two named people, an IT contract that makes your MSP pick up the phone after hours, and one thing most small shops don't have: a DoD-approved digital certificate, already installed, before anything goes wrong.
Here's why that certificate matters. Nearly every defense contract includes a security clause that the CMMC pause left in place, DFARS 252.204-7012 ("7012"). If a cyber incident touches covered defense information (the sensitive technical data your contract says you're protecting), 7012 gives you 72 hours from discovery to report it to DoD. You can't file that report without a medium-assurance certificate, a digital ID that proves who you are to DoD's reporting site. You buy it from a DoD-approved External Certificate Authority (ECA) vendor, and getting one involves identity checks and takes time (DFARS 7012 (c)(1), (c)(3), DoD ECA program). Miss the 72 hours and you've broken the contract on top of being breached, and you'll be explaining both to your customer.
Reports go to the DoD Cyber Crime Center (DC3). The reporting address written into the clause now redirects to DC3's portal (DC3: mandatory incident reporting).
Order the certificate this month, for your incident lead and a backup.
The first hour, rehearsed
A tabletop exercise is a meeting where you walk through a made-up incident step by step and write down where people get stuck. You can run this one in 45 minutes with your owner, your office manager, and your MSP (managed service provider, the outside IT firm) on the phone.
The scenario: at 4:40 pm on a Thursday, an engineer says she approved a login prompt on her phone that she didn't start. She'd been working in the company's CUI file site all afternoon. (CUI is controlled unclassified information: the drawings, specs, and technical data the government marks as sensitive.)
At 4:40 she calls the incident lead, a named person, not "IT." Does she know who that is without asking around?
At 4:50 the lead calls the MSP. Is there an after-hours number in the contract, and does someone answer it?
At 5:00 the MSP signs her out everywhere and resets her password. Who is allowed to approve that? It will lock her out of the job she's finishing.
At 5:15 someone pulls her login and file-access history. Do the logs go back far enough? On Microsoft's free Entra ID tier, sign-in logs are kept for seven days (Microsoft). If the attacker got in two weeks ago, that trail is gone. Logging gaps
At 5:30 the owner decides whether this is reportable. The 72-hour clock started at 4:40, when she noticed, and it doesn't wait for a forensic answer.
Before anyone goes home, someone preserves the affected mailbox, the logs, and an image of the laptop. Nobody wipes and reinstalls the laptop tonight.
Every stall you find is a fix you make now, on a slow afternoon, instead of on a real Friday night.
After the report: a checklist for whoever files it
Once the report is in, 7012 asks for four more things. The owner needs to know they exist; the incident lead needs the details.
- Paragraph (d): submit any malicious software you isolate to DC3.
- Paragraph (e): keep images of the affected systems, plus the monitoring and packet-capture data, for at least 90 days from the day you submit the report.
- Paragraph (f): if DoD asks, give it access to what it needs for its forensic analysis.
- Paragraph (m): if you're a subcontractor, send your prime (the contractor above you) the incident report number DoD assigns, as soon as practicable.
The 90 days runs from the day you submit, not the day you discovered it. Put a calendar reminder on the report date so nobody recycles that laptop in week eight.
Your MSP's part
Your MSP does the containment and pulls the logs. Your company decides what's reportable and files the report. Write that split into the contract: an after-hours response time, who at the MSP can act without calling you first, and a promise to preserve logs and images when you ask. Dividing the work with an MSP
The security standard behind all this, NIST SP 800-171, covers incident handling in three requirements: have the capability (3.6.1), report incidents (3.6.2), and test the capability (3.6.3) (NIST SP 800-171 Rev. 2). Keep the tabletop notes: the date, who attended, where it stalled, and what you changed. That record is your proof for the testing requirement, and an assessor will find it more convincing than the plan itself.
