FAR and DFARS › DFARS Part 204: Administrative and Information Matters › Subpart 204.73
DFARS 204.7300 Scope.
The codified text (eCFR, as of 2026-10-02). Under the Revolutionary FAR Overhaul ↗, agencies follow class deviations with new text for many parts while the formal rules go through the Federal Register: check the solicitation and your contract's clauses, which rule.
In plain English
This section defines the scope of DFARS subpart 204.73. It applies to contracts and subcontracts that require contractors and subcontractors to safeguard covered defense information on covered contractor information systems using specified network security requirements, and it requires reporting of cyber incidents. It also clarifies that this subpart does not override other security requirements or the National Industrial Security Program.
Applies to: Contracts and subcontracts requiring safeguarding of covered defense information and cyber incident reporting
What it requires
- Safeguard covered defense information that resides in or transits through covered contractor information systems by applying specified network security requirements
- Report cyber incidents
Key terms: covered defense information · covered contractor information systems · network security requirements · cyber incidents · National Industrial Security Program
Written by AI from this section's text. A guide, not legal advice: the text below rules.
The text
(a) This subpart applies to contracts and subcontracts requiring contractors and subcontractors to safeguard covered defense information that resides in or transits through covered contractor information systems by applying specified network security requirements. It also requires reporting of cyber incidents.
(b) This subpart does not abrogate any other requirements regarding contractor physical, personnel, information, technical, or general administrative security operations governing the protection of unclassified information, nor does it affect requirements of the National Industrial Security Program.
← 204.7203 Contract clause. · 204.7301 Definitions. →
Rule changes for DFARS Part 204
- Defense Federal Acquisition Regulation Supplement: Assessing Contractor Implementation of Cybersecurity Requirements (DFARS Case 2019-D041) ↗ · final rule 2025-09-10 · effective 2025-11-10
- Defense Federal Acquisition Regulation Supplement: Inapplicability of Additional Defense-Unique Laws and Certain Non-Statutory DFARS Clauses to Commercial Item Contracts (DFARS Case 2018-D074) ↗ · final rule 2024-11-15 · effective 2024-11-25
- Defense Federal Acquisition Regulation Supplement; Technical Amendments ↗ · final rule 2024-09-26 · effective 2024-10-01
- Defense Federal Acquisition Regulation Supplement: Data Universal Numbering System to Unique Entity Identifier Transition (DFARS Case 2022-D023) ↗ · final rule 2024-09-26 · effective 2024-10-01
- Defense Federal Acquisition Regulation Supplement: Modification of Notification of Intent To Transport Supplies by Sea (DFARS Case 2020-D026) ↗ · final rule 2024-09-26 · effective 2024-10-01
- Defense Federal Acquisition Regulation Supplement: Assessing Contractor Implementation of Cybersecurity Requirements (DFARS Case 2019-D041) ↗ · proposed 2024-08-15 · comments due 2024-10-15
- Defense Federal Acquisition Regulation Supplement; Technical Amendments ↗ · final rule 2024-07-29 · effective 2024-07-29
- Defense Federal Acquisition Regulation Supplement: Modification of Notification of Intent To Transport Supplies by Sea (DFARS Case 2020-D026) ↗ · proposed 2024-03-26 · comments due 2024-05-28
Source: eCFR, 48 CFR chapters 1 and 2 (GPO GovInfo bulk data) ↗. Plain words for the terms: glossary.