FAR and DFARS › FAR Part 39

FAR Part 39: Acquisition of Information Technology

The codified text (eCFR, as of 2026-10-02). Under the Revolutionary FAR Overhaul ↗, agencies follow class deviations with new text for many parts while the formal rules go through the Federal Register: check the solicitation and your contract's clauses, which rule.

In plain English

FAR Part 39 establishes policies and procedures for acquiring information technology (IT) and information and communication technology (ICT). It emphasizes risk management, modular contracting, privacy, and accessibility for individuals with disabilities. Contractors need to understand these rules because they affect how IT acquisitions are structured, what requirements are included in solicitations, and what obligations contractors may have regarding privacy and accessibility.

Key rules

  • Agencies must identify IT requirements considering security, privacy, national security, accessibility, energy efficiency, and sustainable products and services. (39.101)
  • Agencies should use modular contracting for major IT systems to reduce risk and accommodate rapidly changing technology. (39.103)
  • Solicitations for IT services must not include minimum experience or education requirements for personnel unless the agency determines they are necessary or that a performance-based approach cannot meet its needs. (39.104)
  • Contracts for IT must address privacy protection, and contracts for systems of records must include rules of conduct, threats, safeguards, and inspection requirements. (39.105)
  • The contracting officer must insert the clause at 52.239-1, Privacy or Security Safeguards, in IT solicitations and contracts that require security or involve systems of records. (39.106)
  • Acquisitions of ICT supplies and services must meet applicable accessibility standards unless an exception or exemption applies. (39.203)
  • Exceptions to ICT accessibility requirements include national security systems, incidental contract items, and maintenance or monitoring spaces. (39.204)
  • Exemptions from ICT accessibility requirements may be granted for undue burden, fundamental alteration, or nonavailability of conforming commercial products and services. (39.205)

Who does what

Contracting officers
  • Consider the rapidly changing nature of IT and technology refreshment when developing acquisition strategy.
  • Consult with the requiring official to ensure appropriate IT security policies and requirements are included.
  • Insert the clause at 52.239-1 in applicable IT solicitations and contracts.
  • Receive written confirmation from the requiring activity when an exception to ICT accessibility applies.
Contractors
  • Follow agency rules of conduct and guard against anticipated threats and hazards when operating a system of records.
  • Provide safeguards as described in the contract.
  • Ensure ICT supplies and services meet accessibility standards unless an exception or exemption applies.
Agencies
  • Identify IT requirements pursuant to OMB Circular A-130 and other policies.
  • Analyze risks, benefits, and costs before entering into an IT contract.
  • Use modular contracting to the maximum extent practicable for major IT systems.
  • Ensure contracts address privacy protection and include required clauses.

In practice

  • When bidding on IT contracts, expect requirements for privacy safeguards, security configurations, and accessibility standards.
  • Modular contracting may mean that a large IT project is divided into smaller increments, so you might compete for individual modules rather than the entire system.
  • If you are providing IT services, your personnel requirements may be performance-based rather than defined by minimum experience or education, unless the agency justifies otherwise.
  • For ICT acquisitions, you must indicate which products and services are compliant with accessibility standards and provide details of compliance.

Common pitfalls

  • Assuming that all IT acquisitions require strict adherence to accessibility standards; exceptions and exemptions exist, but they must be documented.
  • Overlooking the requirement to include privacy safeguards and the clause at 52.239-1 in contracts for systems of records.
  • Failing to consider that modular contracting may require delivering workable increments that are not dependent on future increments.
  • Including minimum experience or education requirements for IT services personnel without a proper determination by the contracting officer.

Written by AI from this part's codified text (2026-10-04); cited sections are checked against the part. A guide, not legal advice: the regulation text, the solicitation and your contract rule.

Rule changes for FAR Part 39

Subparts and sections

Subpart 39.1: General

Subpart 39.2: Information and Communication Technology

← Part 38: Federal Supply Schedule ContractingPart 40: Information Security and Supply Chain Security →

All FAR parts

Source: eCFR, 48 CFR chapters 1 and 2 (GPO GovInfo bulk data) ↗.

FAR Part 39: Acquisition of Information Technology · SpendQuery