FAR and DFARS › DFARS Part 204

DFARS Part 204: Administrative and Information Matters

The codified text (eCFR, as of 2026-10-02). Under the Revolutionary FAR Overhaul ↗, agencies follow class deviations with new text for many parts while the formal rules go through the Federal Register: check the solicitation and your contract's clauses, which rule.

In plain English

DFARS Part 204 covers administrative and information matters for DoD contracts, including contract distribution, electronic data access, reporting requirements, and various clauses. It matters to contractors because it dictates how contracts are signed, distributed, reported, and closed out, and imposes specific requirements for safeguarding information, reporting contracted services, and complying with cybersecurity and other mandates.

Key rules

  • Contracting officers must distribute one signed copy or reproduction of the signed contract to the contractor, instead of following the FAR requirement. (204.201)
  • The Electronic Data Access (EDA) system is DoD's primary tool for electronic distribution of contract documents and contract data, and contract attachments must be uploaded to EDA. (204.270-1)
  • Contracting officers must use the clause at 252.204-7000, Disclosure of Information, when the contractor will have access to or generate unclassified information that may be sensitive and inappropriate for release to the public. (204.404-70)
  • Service contractor reporting is required in the System for Award Management (SAM) when a contract or order has a total estimated value exceeding $3 million and is for specified services. (204.1703)
  • The contracting officer shall not procure or obtain covered defense telecommunications equipment or services unless a waiver is granted. (204.2102)
  • Contractors and subcontractors must provide adequate security on all covered contractor information systems, and contracting officers must verify a current NIST SP 800-171 DoD Assessment summary level score. (204.7302, 204.7303)
  • Contracting officers must include the required Cybersecurity Maturity Model Certification (CMMC) level in solicitations and contracts, and shall not award to a contractor without the required CMMC level. (204.7502, 204.7503)
  • Use of Supplier Performance Risk System (SPRS) risk assessments is required for evaluation of quotations or offers for supplies and services, and the contracting officer must consider price risk and supplier risk as part of the award decision. (204.7602, 204.7603)

Who does what

Contracting officers
  • Distribute one signed copy of the contract to the contractor.
  • Ensure solicitations comply with PGI 204.403(1).
  • Verify that the summary level score of a current NIST SP 800-171 DoD Assessment is available.
  • Include the required CMMC level in solicitations and contracts, and check award eligibility.
Contractors
  • Complete Level I antiterrorism awareness training within a specified time if requiring routine physical access to a Federally-controlled facility or military installation.
  • Provide adequate security on covered contractor information systems.
  • Report contracted services information in SAM when thresholds are met.
  • Notify DoD if activities are subject to reporting under the U.S.-International Atomic Energy Agency Additional Protocol.
Agencies
  • Use the Federal Procurement Data System (FPDS) to meet reporting requirements.
  • Retain contract files for the period specified in General Records Schedules.
  • Follow procedures for closeout of contract files.

In practice

  • When bidding, ensure you understand the reporting and cybersecurity requirements, as they may affect your eligibility and performance.
  • During performance, maintain adequate security for covered defense information and comply with CMMC level requirements if applicable.
  • Be aware that contract documents and data in EDA are considered accurate representations and may be used for official purposes.
  • For service contracts over $3 million, be prepared to report information in SAM.

Common pitfalls

  • Do not include classified or sensitive information in EDA, as it is accessible by multiple parties including the contractor.
  • Do not reuse a Procurement Instrument Identifier (PIID) once assigned, and do not assign the same PIID to more than one task or delivery order.
  • Do not procure covered defense telecommunications equipment or services from Huawei or ZTE without a waiver.
  • Do not assume the FAR taxpayer identification procedure applies if the contract includes FAR 52.204-7; the payment office obtains the information from SAM.

Written by AI from this part's codified text (2026-10-04); cited sections are checked against the part. A guide, not legal advice: the regulation text, the solicitation and your contract rule.

Rule changes for DFARS Part 204

Subparts and sections

Subpart 204.1: Contract Execution

Subpart 204.2: Contract Distribution

Subpart 204.4: Safeguarding Classified Information Within Industry

Subpart 204.6: Contract Reporting

Subpart 204.8: Contract Files

Subpart 204.9: Taxpayer Identification Number Information

Subpart 204.11: System For Award Management

Subpart 204.12: Annual Representations and Certifications

Subpart 204.16: Uniform Procurement Instrument Identifiers

Subpart 204.17: SUBPART 204.17—SERVICE CONTRACTS INVENTORY

Subpart 204.18: Commercial and Government Entity Code

Subpart 204.21: Prohibition on Contracting for Certain Telecommunications and Video Surveillance Services or Equipment

Subpart 204.71: Uniform Contract Line Item Numbering System

Subpart 204.72: Antiterrorism Awareness Training

Subpart 204.73: Safeguarding Covered Defense Information and Cyber Incident Reporting

Subpart 204.74: Disclosure of information to litigation support contractors

Subpart 204.75: Cybersecurity Maturity Model Certification

Subpart 204.76: Supplier Performance Risk System

← Part 203: Improper Business Practices and Personal Conflicts of InterestPart 205: Publicizing Contract Actions →

All DFARS parts

Source: eCFR, 48 CFR chapters 1 and 2 (GPO GovInfo bulk data) ↗.

DFARS Part 204: Administrative and Information Matters · SpendQuery