Safeguarding Covered Defense Information, Cyber Incident Reporting, and Cloud Computing
Reinstatement without change of a previously approved collection
No
Regular
03/04/2026
Requested
Previously Approved
36 Months From Approved
01/31/2026
16,233
16,760
6,770
7,695
697,310
638,685
This collection implements mandatory tracking and reporting of intrusions on unclassified networks or contractor information technology systems that process DoD information or those contractors designated as providing operationally critical support. DoD is required by statute to establish programs and activities to protect DoD information and DoD information systems, including information and information systems operated and maintained by contractors or others in support of DoD activities. Offerors and contractors must report cyber incidents on unclassified networks or information systems, within cloud computing services, and when they affect contractors designated as providing operationally critical support, as required by statute.
On behalf of this Federal agency, I certify that the collection of information encompassed by this request complies with 5 CFR 1320.9 and the related provisions of 5 CFR 1320.8(b)(3).
The following is a summary of the topics, regarding the proposed collection of information, that the certification covers:
(i) Why the information is being collected;
(ii) Use of information;
(iii) Burden estimate;
(iv) Nature of response (voluntary, required for a benefit, or mandatory);
(v) Nature and extent of confidentiality; and
(vi) Need to display currently valid OMB control number;
If you are unable to certify compliance with any of these provisions, identify the item by leaving the box unchecked and explain the reason in the Supporting Statement.
03/04/2026
Something went wrong when downloading this file. If you have any questions, please send an email to risc@gsa.gov.