← Back to Library
DFAR 52.204-21

DFAR 52.204-21 (v1)

Full Name: FAR 52.204-21 Basic Safeguarding of Covered Contractor Information Systems

Acronym: DFAR 52.204-21

Type: US Federal Standard

Organization: U.S. General Services Administration

Version: 1

Year Published: 2022

Popularity: High

Overview of FAR 52.204-21 Basic Safeguarding

Federal Acquisition Regulation (FAR) clause 52.204-21, titled "Basic Safeguarding of Covered Contractor Information Systems," establishes mandatory cybersecurity requirements for federal contractors handling Federal Contract Information (FCI). This contract clause, incorporated into virtually all federal contracts exceeding the micro-purchase threshold, requires contractors to implement 15 basic security controls protecting FCI from unauthorized access, disclosure, and cyber threats. FAR 52.204-21 represents the federal government's baseline cybersecurity expectation for contractors across all agencies—from defense to civilian departments—creating consistent security standards throughout the federal contracting ecosystem.

The clause addresses a critical vulnerability in federal supply chains: contractors with weak cybersecurity practices create pathways for adversaries to access federal information, disrupt government operations, and steal sensitive data. By mandating basic cybersecurity hygiene for all contractors handling FCI, FAR 52.204-21 raises the federal contractor community's minimum security posture. The 15 requirements derive from NIST SP 800-171's basic security controls, adapted for the less sensitive Federal Contract Information compared to Controlled Unclassified Information. Contractors must implement these controls, report cyber incidents involving FCI, and flow down requirements to subcontractors processing FCI.

Understanding Federal Contract Information (FCI)

Federal Contract Information means information provided by or generated for the government under contract that is not intended for public release. FCI includes procurement-sensitive information such as source selection decisions, contractor bids and proposals, indirect cost rates, and other competition-sensitive data. FCI also encompasses information generated during contract performance that isn't publicly releasable, including draft deliverables, internal project documentation, and communications with contracting officers containing sensitive details.

Critically, FCI does NOT include Controlled Unclassified Information (CUI)—a more sensitive designation requiring the more comprehensive NIST SP 800-171 implementation. Contractors must properly classify information to determine whether FAR 52.204-21 alone applies or whether NIST SP 800-171 is required. When doubt exists, contractors should treat information as CUI and implement NIST SP 800-171 rather than risk inadequate protection. Misclassification exposes contractors to compliance violations, contract termination, and potential criminal liability if CUI is inadequately protected.

The 15 Basic Safeguarding Requirements

FAR 52.204-21 mandates 15 fundamental security controls based on NIST SP 800-171's basic security requirements, covering access control, authentication, media protection, physical protection, system and communications protection, and system and information integrity.

Access Control Requirements (3 controls): Limit system access to authorized users only, limit access to specific transactions and functions based on job roles, and verify/control connections to external systems. Implementation requires authentication systems, role-based access control, firewall configurations, and network access policies.

Authentication Requirements (2 controls): Identify information system users uniquely and authenticate users before granting access. Implementation requires unique user accounts (no shared credentials), password policies, and authentication systems. Multi-factor authentication, while not explicitly required, represents best practice for remote access.

Media Protection Requirements (3 controls): Protect information on system media, limit access to system media containing FCI, and sanitize or destroy media before disposal or reuse. Implementation requires media inventories, secure media storage, access restrictions, and certified sanitization procedures using NIST-approved methods.

Physical Protection Requirements (3 controls): Limit physical access to organizational information systems and environments, escort visitors in facilities containing FCI, and maintain audit logs of physical access. Implementation requires badge access systems, visitor management, security cameras, and physical security logs.

System and Communications Protection Requirements (2 controls): Monitor and control communications at system boundaries and implement subnetworks for publicly accessible components. Implementation requires firewalls, DMZ architectures, network monitoring, and separation of public-facing systems from internal networks processing FCI.

System and Information Integrity Requirements (2 controls): Identify and correct system flaws timely and provide malware protection. Implementation requires vulnerability scanning, patch management, anti-malware software with automatic updates, and periodic security assessments.

Cyber Incident Reporting Requirements

FAR 52.204-21 requires contractors to report cyber incidents affecting FCI to contracting officers rapidly. Contractors must report incidents within hours of discovery (72 hours for preservation of forensic data), provide details about affected systems and information, submit malware discovered during incidents to appropriate federal entities, and cooperate with damage assessments. Incident reporting enables federal threat intelligence and helps agencies understand contractor risk exposure. Contractors should establish incident detection capabilities, document reporting procedures, and ensure personnel understand reporting obligations.

Implementation Approach for Contractors

Federal contractors should approach FAR 52.204-21 implementation systematically, documenting all controls and maintaining evidence of compliance.

Identify FCI Systems: Contractors must identify all information systems that process, store, or transmit FCI. System identification informs where security controls must be implemented. Contractors should consider network segmentation isolating FCI systems to minimize the environment requiring full FAR 52.204-21 implementation.

Implement 15 Requirements: Contractors should address each requirement systematically, documenting how it's implemented. Many requirements can be satisfied through basic IT security practices—commercial anti-malware, Windows authentication, firewall configurations—but contractors must document implementations and maintain evidence.

Document Everything: While FAR 52.204-21 doesn't explicitly require extensive documentation, contractors should document policies, procedures, and control implementations. Documentation supports consistent practices, enables evidence presentation if questioned, and facilitates audits or investigations following incidents. System Security Plans describing FCI system boundaries and how each requirement is satisfied represent best practice.

Train Personnel: All personnel with access to FCI systems should understand security requirements, proper FCI handling procedures, and incident reporting obligations. Security awareness training reduces user-introduced risks like phishing, weak passwords, and improper data handling.

Relationship to Other Federal Contractor Requirements

FAR 52.204-21 represents the lowest tier of federal contractor cybersecurity requirements. Contractors handling more sensitive information face additional requirements. Organizations handling Controlled Unclassified Information must implement NIST SP 800-171's 110 requirements. Defense contractors must achieve CMMC Level 1 for FCI or CMMC Level 2 for CUI. Contractors implementing NIST SP 800-171 automatically satisfy FAR 52.204-21, as the 15 requirements are subset of NIST's 110 controls.

Frequently Asked Questions

What is FAR 52.204-21 and who must comply?

FAR 52.204-21 is a Federal Acquisition Regulation clause requiring federal contractors to implement 15 basic cybersecurity safeguards for systems processing Federal Contract Information. The clause applies to federal contracts exceeding the micro-purchase threshold (currently $10,000) where contractors will handle FCI. Virtually all federal contractors encounter FAR 52.204-21 in their contracts, making compliance necessary for participating in federal marketplace. The clause flows down to subcontractors—prime contractors must ensure subs handling FCI implement the 15 requirements.

What are the 15 basic safeguarding requirements?

The 15 requirements address access control (limiting who can access systems and what they can do), authentication (verifying user identities), media protection (protecting and sanitizing storage media), physical protection (controlling physical access to systems), system and communications protection (firewalls, network monitoring, DMZ), and system integrity (patching vulnerabilities, malware protection). These requirements represent fundamental security hygiene applicable to most information systems regardless of federal contracting obligations—contractors should view FAR 52.204-21 as baseline security, not just compliance requirement.

Is FAR 52.204-21 the same as CMMC Level 1?

FAR 52.204-21 and CMMC Level 1 have substantial overlap but differ in assessment approach. FAR 52.204-21 applies broadly to all federal contracts involving FCI, while CMMC Level 1 applies specifically to DoD contracts involving FCI. Both require implementing 15-17 basic security controls. However, CMMC requires formal self-assessment with senior executive affirmation and reporting in SPRS, while FAR 52.204-21 implementation is contractual obligation without formal assessment process. Defense contractors must satisfy both FAR 52.204-21 and CMMC Level 1 when handling FCI on DoD contracts.

Can contractors self-assess FAR 52.204-21 compliance?

Yes, FAR 52.204-21 does not require third-party assessment or formal certification. Contractors self-assess compliance and must honestly represent compliance status if questioned by contracting officers. However, contractors should maintain evidence supporting compliance claims including policies, procedures, configuration screenshots, anti-malware reports, and access control documentation. Contracting officers may request evidence during contract administration or following cyber incidents. False compliance representations can result in False Claims Act liability, contract termination, and suspension from federal contracting.

How does FAR 52.204-21 incident reporting work?

Contractors must report cyber incidents involving FCI within 72 hours of discovery to enable forensic data preservation. Reporting goes to the contracting officer for the affected contract, with incident details including affected systems, types of information compromised, and preliminary damage assessment. Contractors must submit malware to DoD Cyber Crime Center or other designated federal entities for analysis. Incident reporting enables federal threat intelligence and multi-agency coordination when threats affect multiple contractors. Contractors should implement incident detection, establish reporting procedures, and designate incident response personnel familiar with federal reporting obligations.