yourstate.us
48 CFR 1252.239-83

1252.239-83 Incident Reporting Timeframes.

United States · 48 CFR — Federal Acquisition Regulations System · Status: effective

Get this as JSONEmbed this
Cite this
Citation
48 CFR 1252.239-83, 1252.239-83 Incident Reporting Timeframes, United States, version 1 as recorded 2026-07-09, yourstate.us, https://yourstate.us/provision/249150
Permanent ID
ys:prov:249150@1
SHA-256
4d02121f389f46c9b2086553f2407ae831fb457a014c896a2162dc4ce35677fc

The hash is SHA-256 of this version's text, with every run of whitespace collapsed to a single space and the ends trimmed. The ID always leads back here, and checking it says whether the text you cited is still the current version.

Full text

As prescribed in 1239.7204(h), insert the following clause: (a) The Contractor shall report all computer security incidents to the DOT Security Operations Center (SOC) in accordance with Subpart 1239.70—Information Security and Incident Response Reporting. (b) Contractors and subcontractors are required to report cyber incidents directly to DOT via the DOT SOC 24 hours-a-day, 7 days-a-week, 365 days a year (24x7x365) at phone number: 571-209-3080 (Toll Free: 866-580-1852) within 2 hours of discovery, regardless of the incident category. See 1252.239-74, Safeguarding DOT Sensitive Data and Cyber Incident Reporting.

Legislative history

This is a federal regulation, adopted through agency rulemaking under the Administrative Procedure Act — not enacted by a recorded vote of Congress.