FAR and DFARS › DFARS Part 239
DFARS Part 239: Acquisition of Information Technology
The codified text (eCFR, as of 2026-10-02). Under the Revolutionary FAR Overhaul ↗, agencies follow class deviations with new text for many parts while the formal rules go through the Federal Register: check the solicitation and your contract's clauses, which rule.
In plain English
DFARS Part 239 implements DoD-specific policies for acquiring information technology, including national security systems, and covers information assurance, supply chain risk, telecommunications services, and cloud computing. It matters to contractors because it imposes unique requirements beyond the FAR, such as restrictions on non-commercial IT purchases, mandatory contract clauses, and data storage location rules.
Key rules
- For IT products or services that are not commercial, the contracting officer cannot award a contract above the simplified acquisition threshold unless the head of the contracting activity determines in writing that no commercial items are suitable. (239.101)
- Agencies must ensure information assurance for IT in accordance with specified policies, including the National Security Act, Clinger-Cohen Act, and DoD directives. (239.7102-1)
- For acquisitions requiring protection against compromising emanations, the requiring activity must provide the contracting officer with the required protections, identification markings, and inspection and acceptance requirements. (239.7102-2)
- For acquisitions involving information assurance functional services or contractor access to DoD information systems, the requiring activity must provide a list of information assurance functional responsibilities and information about training and certification. (239.7102-3)
- Contracting officers must include the clause at 252.239-7000, Protection Against Compromising Emanations, in solicitations and contracts for IT that requires such protection. (239.7103)
- Contracting officers must include the clause at 252.239-7001, Information Assurance Contractor Training and Certification, in solicitations and contracts involving contractor performance of information assurance functions. (239.7103)
- For covered systems, the government may exclude a source that fails to meet qualification standards or achieve an acceptable rating to reduce supply chain risk, after obtaining a joint recommendation and making a written determination. (239.7304, 239.7305)
- Cloud computing service providers must maintain Government data within the 50 states, the District of Columbia, or outlying areas of the United States unless otherwise authorized by the authorizing official. (239.7602-2)
Who does what
- Ensure that all applicable Federal Information Processing Standards are incorporated into solicitations.
- Include required clauses in solicitations and contracts, such as 252.239-7000, 252.239-7001, 252.239-7009, and 252.239-7010.
- Provide written notification to the contractor when Government data is permitted to be maintained outside the United States.
- Comply with information assurance requirements, including training and certification for personnel performing information assurance functions.
- Maintain Government data within the United States or outlying areas unless authorized otherwise.
- Adhere to supply chain risk requirements and potential exclusion based on qualification standards.
- Ensure that information assurance is provided for information technology in accordance with current policies, procedures, and statutes.
- Follow procedures in DoD Manual 4140.01 when considering exchange or sale of Government-owned IT.
- For acquisitions requiring protection against compromising emanations, provide required protections, markings, and inspection requirements to the contracting officer.
In practice
- When bidding on DoD IT contracts, check if the acquisition is for a covered system or requires information assurance, as additional clauses and requirements will apply.
- For cloud computing services, be prepared to store Government data within the United States unless you receive written authorization to do otherwise.
- If you are a non-commercial IT provider, understand that contracts above the simplified acquisition threshold may be difficult to win unless the agency determines no commercial items are suitable.
Common pitfalls
- Assuming FAR Part 39 rules alone apply; DFARS Part 239 adds stricter requirements, such as the commercial item preference for IT acquisitions.
- Overlooking the need to provide information assurance training and certification documentation when required by the solicitation.
- Failing to include required DFARS clauses in subcontracts or basic agreements for telecommunications services, which can lead to noncompliance.
Written by AI from this part's codified text (2026-10-04); cited sections are checked against the part. A guide, not legal advice: the regulation text, the solicitation and your contract rule.
Rule changes for DFARS Part 239
- Defense Federal Acquisition Regulation Supplement: Disclosure of Information Regarding Foreign Obligations (DFARS Case 2018-D064) ↗ · proposed 2024-11-15 · comments due 2025-01-14
Subparts and sections
Subpart 239.1: General
Subpart 239.70: Exchange or Sale of Information Technology
Subpart 239.71: Security and Privacy for Computer Systems
Subpart 239.72: Standards
Subpart 239.73: Requirements for Information Relating to Supply Chain Risk
Subpart 239.74: Telecommunications Services
- 239.7400 Scope.
- 239.7401 Definitions.
- 239.7402 Policy.
- 239.7403-239.7404 [Reserved]
- 239.7405 Delegated authority for telecommunications resources.
- 239.7406 Certified cost or pricing data and data other than certified cost or pricing data.
- 239.7407 Type of contract.
- 239.7408 Special construction.
- 239.7408-1 General.
- 239.7408-2 Applicability of construction labor standards for special construction.
- 239.7409 Special assembly.
- 239.7410 Cancellation and termination.
- 239.7411 Contract clauses.
Subpart 239.76: Cloud Computing
← Part 237: Service ContractingPart 241: Acquisition of Utility Services →
All DFARS parts
- Part 201 Federal Acquisition Regulations System
- Part 202 Definitions of Words and Terms
- Part 203 Improper Business Practices and Personal Conflicts of Interest
- Part 204 Administrative and Information Matters
- Part 205 Publicizing Contract Actions
- Part 206 Competition Requirements
- Part 207 Acquisition Planning
- Part 208 Required Sources of Supplies and Services
- Part 209 Contractor Qualifications
- Part 210 Market Research
- Part 211 Describing Agency Needs
- Part 212 Acquisition of Commercial Products and Commercial Services
- Part 213 Simplified Acquisition Procedures
- Part 214 Sealed Bidding
- Part 215 Contracting by Negotiation
- Part 216 Types of Contracts
- Part 217 Special Contracting Methods
- Part 218 Emergency Acquisitions
- Part 219 Small Business Programs
- Part 222 Application of Labor Laws to Government Acquisitions
- Part 223 Environment, Sustainable Acquisition, and Material Safety
- Part 224 Protection of Privacy and Freedom of Information
- Part 225 Foreign Acquisition
- Part 226 Other Socioeconomic Programs
- Part 227 Patents, Data, and Copyrights
- Part 228 Bonds and Insurance
- Part 229 Taxes
- Part 230 Cost Accounting Standards Administration
- Part 231 Contract Cost Principles and Procedures
- Part 232 Contract Financing
- Part 233 Protests, Disputes, and Appeals
- Part 234 Major System Acquisition
- Part 235 Research and Development Contracting
- Part 236 Construction and Architect-engineer Contracts
- Part 237 Service Contracting
- Part 239 Acquisition of Information Technology
- Part 241 Acquisition of Utility Services
- Part 242 Contract Administration and Audit Services
- Part 243 Contract Modifications
- Part 244 Subcontracting Policies and Procedures
- Part 245 Government Property
- Part 246 Quality Assurance
- Part 247 Transportation
- Part 249 Termination of Contracts
- Part 250 Extraordinary Contractual Actions and the Safety Act
- Part 251 Use of Government Sources by Contractors
- Part 252 Solicitation Provisions and Contract Clauses
- Part 253 Forms
- Part 270 Defense Contracting Programs
Source: eCFR, 48 CFR chapters 1 and 2 (GPO GovInfo bulk data) ↗.