48 CFR 1252.239-83
1252.239-83 Incident Reporting Timeframes.
United States · 48 CFR — Federal Acquisition Regulations System · Status: effective
Cite this
- Citation
- 48 CFR 1252.239-83, 1252.239-83 Incident Reporting Timeframes, United States, version 1 as recorded 2026-07-09, yourstate.us, https://yourstate.us/provision/249150
- Permanent ID
ys:prov:249150@1- SHA-256
4d02121f389f46c9b2086553f2407ae831fb457a014c896a2162dc4ce35677fc
The hash is SHA-256 of this version's text, with every run of whitespace collapsed to a single space and the ends trimmed. The ID always leads back here, and checking it says whether the text you cited is still the current version.
Full text
As prescribed in 1239.7204(h), insert the following clause:
(a) The Contractor shall report all computer security incidents to the DOT Security Operations Center (SOC) in accordance with Subpart 1239.70—Information Security and Incident Response Reporting.
(b) Contractors and subcontractors are required to report cyber incidents directly to DOT via the DOT SOC 24 hours-a-day, 7 days-a-week, 365 days a year (24x7x365) at phone number: 571-209-3080 (Toll Free: 866-580-1852) within 2 hours of discovery, regardless of the incident category. See 1252.239-74, Safeguarding DOT Sensitive Data and Cyber Incident Reporting.
Legislative history
This is a federal regulation, adopted through agency rulemaking under the Administrative Procedure Act — not enacted by a recorded vote of Congress.