FAR and DFARS › DFARS Part 239

DFARS Part 239: Acquisition of Information Technology

The codified text (eCFR, as of 2026-10-02). Under the Revolutionary FAR Overhaul ↗, agencies follow class deviations with new text for many parts while the formal rules go through the Federal Register: check the solicitation and your contract's clauses, which rule.

In plain English

DFARS Part 239 implements DoD-specific policies for acquiring information technology, including national security systems, and covers information assurance, supply chain risk, telecommunications services, and cloud computing. It matters to contractors because it imposes unique requirements beyond the FAR, such as restrictions on non-commercial IT purchases, mandatory contract clauses, and data storage location rules.

Key rules

  • For IT products or services that are not commercial, the contracting officer cannot award a contract above the simplified acquisition threshold unless the head of the contracting activity determines in writing that no commercial items are suitable. (239.101)
  • Agencies must ensure information assurance for IT in accordance with specified policies, including the National Security Act, Clinger-Cohen Act, and DoD directives. (239.7102-1)
  • For acquisitions requiring protection against compromising emanations, the requiring activity must provide the contracting officer with the required protections, identification markings, and inspection and acceptance requirements. (239.7102-2)
  • For acquisitions involving information assurance functional services or contractor access to DoD information systems, the requiring activity must provide a list of information assurance functional responsibilities and information about training and certification. (239.7102-3)
  • Contracting officers must include the clause at 252.239-7000, Protection Against Compromising Emanations, in solicitations and contracts for IT that requires such protection. (239.7103)
  • Contracting officers must include the clause at 252.239-7001, Information Assurance Contractor Training and Certification, in solicitations and contracts involving contractor performance of information assurance functions. (239.7103)
  • For covered systems, the government may exclude a source that fails to meet qualification standards or achieve an acceptable rating to reduce supply chain risk, after obtaining a joint recommendation and making a written determination. (239.7304, 239.7305)
  • Cloud computing service providers must maintain Government data within the 50 states, the District of Columbia, or outlying areas of the United States unless otherwise authorized by the authorizing official. (239.7602-2)

Who does what

Contracting officers
  • Ensure that all applicable Federal Information Processing Standards are incorporated into solicitations.
  • Include required clauses in solicitations and contracts, such as 252.239-7000, 252.239-7001, 252.239-7009, and 252.239-7010.
  • Provide written notification to the contractor when Government data is permitted to be maintained outside the United States.
Contractors
  • Comply with information assurance requirements, including training and certification for personnel performing information assurance functions.
  • Maintain Government data within the United States or outlying areas unless authorized otherwise.
  • Adhere to supply chain risk requirements and potential exclusion based on qualification standards.
Agencies
  • Ensure that information assurance is provided for information technology in accordance with current policies, procedures, and statutes.
  • Follow procedures in DoD Manual 4140.01 when considering exchange or sale of Government-owned IT.
  • For acquisitions requiring protection against compromising emanations, provide required protections, markings, and inspection requirements to the contracting officer.

In practice

  • When bidding on DoD IT contracts, check if the acquisition is for a covered system or requires information assurance, as additional clauses and requirements will apply.
  • For cloud computing services, be prepared to store Government data within the United States unless you receive written authorization to do otherwise.
  • If you are a non-commercial IT provider, understand that contracts above the simplified acquisition threshold may be difficult to win unless the agency determines no commercial items are suitable.

Common pitfalls

  • Assuming FAR Part 39 rules alone apply; DFARS Part 239 adds stricter requirements, such as the commercial item preference for IT acquisitions.
  • Overlooking the need to provide information assurance training and certification documentation when required by the solicitation.
  • Failing to include required DFARS clauses in subcontracts or basic agreements for telecommunications services, which can lead to noncompliance.

Written by AI from this part's codified text (2026-10-04); cited sections are checked against the part. A guide, not legal advice: the regulation text, the solicitation and your contract rule.

Rule changes for DFARS Part 239

Subparts and sections

Subpart 239.1: General

Subpart 239.70: Exchange or Sale of Information Technology

Subpart 239.71: Security and Privacy for Computer Systems

Subpart 239.72: Standards

Subpart 239.73: Requirements for Information Relating to Supply Chain Risk

Subpart 239.74: Telecommunications Services

Subpart 239.76: Cloud Computing

← Part 237: Service ContractingPart 241: Acquisition of Utility Services →

All DFARS parts

Source: eCFR, 48 CFR chapters 1 and 2 (GPO GovInfo bulk data) ↗.

DFARS Part 239: Acquisition of Information Technology · SpendQuery