FAR and DFARS › DFARS Part 239: Acquisition of Information Technology › Subpart 239.71
DFARS 239.7102-1 General.
The codified text (eCFR, as of 2026-10-02). Under the Revolutionary FAR Overhaul ↗, agencies follow class deviations with new text for many parts while the formal rules go through the Federal Register: check the solicitation and your contract's clauses, which rule.
In plain English
This section requires agencies to ensure information assurance is provided for information technology in line with listed policies, procedures, and statutes. It also assigns the requiring activity responsibility for giving the contracting officer certain information assurance-related documents and determinations for all acquisitions. This matters to contractors because it shapes what information assurance requirements may appear in solicitations and contracts.
Applies to: Agencies and requiring activities in DoD acquisitions involving information technology
What it requires
- Agencies shall ensure information assurance is provided for information technology in accordance with current policies, procedures, and statutes.
- The requiring activity must provide the contracting officer statements of work, specifications, or statements of objectives that meet information assurance requirements.
- The requiring activity must provide the contracting officer inspection and acceptance contract requirements.
- The requiring activity must provide the contracting officer a determination as to whether the information technology requires protection against compromising emanations.
Key terms: information assurance · information technology · requiring activity · contracting officer · compromising emanations
Written by AI from this section's text. A guide, not legal advice: the text below rules.
The text
(a) Agencies shall ensure that information assurance is provided for information technology in accordance with current policies, procedures, and statutes, to include—
(1) The National Security Act;
(2) The Clinger-Cohen Act;
(3) National Security Telecommunications and Information Systems Security Policy No. 11;
(4) Federal Information Processing Standards;
(5) DoD Directive 8500.1, Information Assurance;
(6) DoD Instruction 8500.2, Information Assurance Implementation;
(7) DoD Directive 8140.01, Cyberspace Workforce Management; and
(8) DoD Manual 8570.01-M, Information Assurance Workforce Improvement Program.
(b) For all acquisitions, the requiring activity is responsible for providing to the contracting officer—
(1) Statements of work, specifications, or statements of objectives that meet information assurance requirements as specified in paragraph (a) of this subsection;
(2) Inspection and acceptance contract requirements; and
(3) A determination as to whether the information technology requires protection against compromising emanations.
← 239.7102 Policy and responsibilities. · 239.7102-2 Compromising emanations—TEMPEST or other standard. →
Rule changes for DFARS Part 239
- Defense Federal Acquisition Regulation Supplement: Disclosure of Information Regarding Foreign Obligations (DFARS Case 2018-D064) ↗ · proposed 2024-11-15 · comments due 2025-01-14
Source: eCFR, 48 CFR chapters 1 and 2 (GPO GovInfo bulk data) ↗. Plain words for the terms: glossary.