FAR and DFARS › DFARS Part 204
DFARS Part 204: Administrative and Information Matters
The codified text (eCFR, as of 2026-10-02). Under the Revolutionary FAR Overhaul ↗, agencies follow class deviations with new text for many parts while the formal rules go through the Federal Register: check the solicitation and your contract's clauses, which rule.
In plain English
DFARS Part 204 covers administrative and information matters for DoD contracts, including contract distribution, electronic data access, reporting requirements, and various clauses. It matters to contractors because it dictates how contracts are signed, distributed, reported, and closed out, and imposes specific requirements for safeguarding information, reporting contracted services, and complying with cybersecurity and other mandates.
Key rules
- Contracting officers must distribute one signed copy or reproduction of the signed contract to the contractor, instead of following the FAR requirement. (204.201)
- The Electronic Data Access (EDA) system is DoD's primary tool for electronic distribution of contract documents and contract data, and contract attachments must be uploaded to EDA. (204.270-1)
- Contracting officers must use the clause at 252.204-7000, Disclosure of Information, when the contractor will have access to or generate unclassified information that may be sensitive and inappropriate for release to the public. (204.404-70)
- Service contractor reporting is required in the System for Award Management (SAM) when a contract or order has a total estimated value exceeding $3 million and is for specified services. (204.1703)
- The contracting officer shall not procure or obtain covered defense telecommunications equipment or services unless a waiver is granted. (204.2102)
- Contractors and subcontractors must provide adequate security on all covered contractor information systems, and contracting officers must verify a current NIST SP 800-171 DoD Assessment summary level score. (204.7302, 204.7303)
- Contracting officers must include the required Cybersecurity Maturity Model Certification (CMMC) level in solicitations and contracts, and shall not award to a contractor without the required CMMC level. (204.7502, 204.7503)
- Use of Supplier Performance Risk System (SPRS) risk assessments is required for evaluation of quotations or offers for supplies and services, and the contracting officer must consider price risk and supplier risk as part of the award decision. (204.7602, 204.7603)
Who does what
- Distribute one signed copy of the contract to the contractor.
- Ensure solicitations comply with PGI 204.403(1).
- Verify that the summary level score of a current NIST SP 800-171 DoD Assessment is available.
- Include the required CMMC level in solicitations and contracts, and check award eligibility.
- Complete Level I antiterrorism awareness training within a specified time if requiring routine physical access to a Federally-controlled facility or military installation.
- Provide adequate security on covered contractor information systems.
- Report contracted services information in SAM when thresholds are met.
- Notify DoD if activities are subject to reporting under the U.S.-International Atomic Energy Agency Additional Protocol.
- Use the Federal Procurement Data System (FPDS) to meet reporting requirements.
- Retain contract files for the period specified in General Records Schedules.
- Follow procedures for closeout of contract files.
In practice
- When bidding, ensure you understand the reporting and cybersecurity requirements, as they may affect your eligibility and performance.
- During performance, maintain adequate security for covered defense information and comply with CMMC level requirements if applicable.
- Be aware that contract documents and data in EDA are considered accurate representations and may be used for official purposes.
- For service contracts over $3 million, be prepared to report information in SAM.
Common pitfalls
- Do not include classified or sensitive information in EDA, as it is accessible by multiple parties including the contractor.
- Do not reuse a Procurement Instrument Identifier (PIID) once assigned, and do not assign the same PIID to more than one task or delivery order.
- Do not procure covered defense telecommunications equipment or services from Huawei or ZTE without a waiver.
- Do not assume the FAR taxpayer identification procedure applies if the contract includes FAR 52.204-7; the payment office obtains the information from SAM.
Written by AI from this part's codified text (2026-10-04); cited sections are checked against the part. A guide, not legal advice: the regulation text, the solicitation and your contract rule.
Rule changes for DFARS Part 204
- Defense Federal Acquisition Regulation Supplement: Assessing Contractor Implementation of Cybersecurity Requirements (DFARS Case 2019-D041) ↗ · final rule 2025-09-10 · effective 2025-11-10
- Defense Federal Acquisition Regulation Supplement: Inapplicability of Additional Defense-Unique Laws and Certain Non-Statutory DFARS Clauses to Commercial Item Contracts (DFARS Case 2018-D074) ↗ · final rule 2024-11-15 · effective 2024-11-25
- Defense Federal Acquisition Regulation Supplement; Technical Amendments ↗ · final rule 2024-09-26 · effective 2024-10-01
- Defense Federal Acquisition Regulation Supplement: Data Universal Numbering System to Unique Entity Identifier Transition (DFARS Case 2022-D023) ↗ · final rule 2024-09-26 · effective 2024-10-01
- Defense Federal Acquisition Regulation Supplement: Modification of Notification of Intent To Transport Supplies by Sea (DFARS Case 2020-D026) ↗ · final rule 2024-09-26 · effective 2024-10-01
- Defense Federal Acquisition Regulation Supplement: Assessing Contractor Implementation of Cybersecurity Requirements (DFARS Case 2019-D041) ↗ · proposed 2024-08-15 · comments due 2024-10-15
- Defense Federal Acquisition Regulation Supplement; Technical Amendments ↗ · final rule 2024-07-29 · effective 2024-07-29
- Defense Federal Acquisition Regulation Supplement: Modification of Notification of Intent To Transport Supplies by Sea (DFARS Case 2020-D026) ↗ · proposed 2024-03-26 · comments due 2024-05-28
Subparts and sections
Subpart 204.1: Contract Execution
Subpart 204.2: Contract Distribution
Subpart 204.4: Safeguarding Classified Information Within Industry
Subpart 204.6: Contract Reporting
Subpart 204.8: Contract Files
Subpart 204.9: Taxpayer Identification Number Information
Subpart 204.11: System For Award Management
Subpart 204.12: Annual Representations and Certifications
Subpart 204.16: Uniform Procurement Instrument Identifiers
Subpart 204.17: SUBPART 204.17—SERVICE CONTRACTS INVENTORY
Subpart 204.18: Commercial and Government Entity Code
Subpart 204.21: Prohibition on Contracting for Certain Telecommunications and Video Surveillance Services or Equipment
Subpart 204.71: Uniform Contract Line Item Numbering System
- 204.7100 Scope.
- 204.7101 Definitions.
- 204.7102 Policy.
- 204.7103 Contract line items.
- 204.7103-1 Criteria for establishing.
- 204.7103-2 Numbering procedures.
- 204.7104 Contract subline items.
- 204.7104-1 Criteria for establishing.
- 204.7104-2 Numbering procedures.
- 204.7105 Contract exhibits and attachments.
- 204.7106 Contract modifications.
- 204.7107 Contract accounting classification reference number (ACRN) and agency accounting identifier (AAI).
- 204.7108 Payment instructions.
- 204.7109 Contract clauses.
Subpart 204.72: Antiterrorism Awareness Training
Subpart 204.73: Safeguarding Covered Defense Information and Cyber Incident Reporting
Subpart 204.74: Disclosure of information to litigation support contractors
Subpart 204.75: Cybersecurity Maturity Model Certification
Subpart 204.76: Supplier Performance Risk System
← Part 203: Improper Business Practices and Personal Conflicts of InterestPart 205: Publicizing Contract Actions →
All DFARS parts
- Part 201 Federal Acquisition Regulations System
- Part 202 Definitions of Words and Terms
- Part 203 Improper Business Practices and Personal Conflicts of Interest
- Part 204 Administrative and Information Matters
- Part 205 Publicizing Contract Actions
- Part 206 Competition Requirements
- Part 207 Acquisition Planning
- Part 208 Required Sources of Supplies and Services
- Part 209 Contractor Qualifications
- Part 210 Market Research
- Part 211 Describing Agency Needs
- Part 212 Acquisition of Commercial Products and Commercial Services
- Part 213 Simplified Acquisition Procedures
- Part 214 Sealed Bidding
- Part 215 Contracting by Negotiation
- Part 216 Types of Contracts
- Part 217 Special Contracting Methods
- Part 218 Emergency Acquisitions
- Part 219 Small Business Programs
- Part 222 Application of Labor Laws to Government Acquisitions
- Part 223 Environment, Sustainable Acquisition, and Material Safety
- Part 224 Protection of Privacy and Freedom of Information
- Part 225 Foreign Acquisition
- Part 226 Other Socioeconomic Programs
- Part 227 Patents, Data, and Copyrights
- Part 228 Bonds and Insurance
- Part 229 Taxes
- Part 230 Cost Accounting Standards Administration
- Part 231 Contract Cost Principles and Procedures
- Part 232 Contract Financing
- Part 233 Protests, Disputes, and Appeals
- Part 234 Major System Acquisition
- Part 235 Research and Development Contracting
- Part 236 Construction and Architect-engineer Contracts
- Part 237 Service Contracting
- Part 239 Acquisition of Information Technology
- Part 241 Acquisition of Utility Services
- Part 242 Contract Administration and Audit Services
- Part 243 Contract Modifications
- Part 244 Subcontracting Policies and Procedures
- Part 245 Government Property
- Part 246 Quality Assurance
- Part 247 Transportation
- Part 249 Termination of Contracts
- Part 250 Extraordinary Contractual Actions and the Safety Act
- Part 251 Use of Government Sources by Contractors
- Part 252 Solicitation Provisions and Contract Clauses
- Part 253 Forms
- Part 270 Defense Contracting Programs
Source: eCFR, 48 CFR chapters 1 and 2 (GPO GovInfo bulk data) ↗.