FAR and DFARS › FAR Part 52: Solicitation Provisions and Contract Clauses › Subpart 52.2
FAR 52.204-23 Prohibition on Contracting for Hardware, Software, and Services Developed or Provided by Kaspersky Lab Covered Entities.
The codified text (eCFR, as of 2026-10-02). Under the Revolutionary FAR Overhaul ↗, agencies follow class deviations with new text for many parts while the formal rules go through the Federal Register: check the solicitation and your contract's clauses, which rule.
In plain English
This clause prohibits contractors from providing or using any hardware, software, or services developed or provided by Kaspersky Lab covered entities in performance of a Government contract. It also requires contractors to report any such covered articles they identify or are notified about during contract performance, and to flow the clause down to subcontracts.
Applies to: Contractors and subcontractors performing Government contracts that include this clause.
What it requires
- Do not provide any Kaspersky Lab covered article that the Government will use on or after October 1, 2018.
- Do not use any Kaspersky Lab covered article on or after October 1, 2018, in the development of data or deliverables first produced in the performance of the contract.
- Report in writing to the Contracting Officer or, for DoD, to https://dibnet.dod.mil if you identify or are notified of a Kaspersky Lab covered article provided to the Government during contract performance.
- Insert the substance of this clause, including paragraph (d), in all subcontracts, including those for commercial products or commercial services.
Key terms: Kaspersky Lab covered article · Kaspersky Lab covered entity · Contracting Officer · subcontractor · indefinite delivery contract
Written by AI from this section's text. A guide, not legal advice: the text below rules.
The text
As prescribed in 4.2004, insert the following clause:
Prohibition on Contracting for Hardware, Software, and Services Developed or Provided by Kaspersky Lab Covered Entities (DEC 2023)
(a) Definitions. As used in this clause—
Kaspersky Lab covered article means any hardware, software, or service that—
(1) Is developed or provided by a Kaspersky Lab covered entity;
(2) Includes any hardware, software, or service developed or provided in whole or in part by a Kaspersky Lab covered entity; or
(3) Contains components using any hardware or software developed in whole or in part by a Kaspersky Lab covered entity.
Kaspersky Lab covered entity means—
(1) Kaspersky Lab;
(2) Any successor entity to Kaspersky Lab, including any change in name, e.g., “Kaspersky”;
(3) Any entity that controls, is controlled by, or is under common control with Kaspersky Lab; or
(4) Any entity of which Kaspersky Lab has a majority ownership.
(b) Prohibition. Section 1634 of Division A of the National Defense Authorization Act for Fiscal Year 2018 (Pub. L. 115-91) prohibits Government use of any Kaspersky Lab covered article. The Contractor is prohibited from—
(1) Providing any Kaspersky Lab covered article that the Government will use on or after October 1, 2018; and
(2) Using any Kaspersky Lab covered article on or after October 1, 2018, in the development of data or deliverables first produced in the performance of the contract.
(c) Reporting requirement. (1) In the event the Contractor identifies a Kaspersky Lab covered article provided to the Government during contract performance, or the Contractor is notified of such by a subcontractor at any tier or any other source, the Contractor shall report, in writing, to the Contracting Officer or, in the case of the Department of Defense, to the website at https://dibnet.dod.mil. For indefinite delivery contracts, the Contractor shall report to the Contracting Officer for the indefinite delivery contract and the Contracting Officer(s) for any affected order or, in the case of the Department of Defense, identify both the indefinite delivery contract and any affected orders in the report provided at https://dibnet.dod.mil.
(2) The Contractor shall report the following information pursuant to paragraph (c)(1) of this clause:
(i) Within 3 business days from the date of such identification or notification: The contract number; the order number(s), if applicable; supplier name; brand; model number (Original Equipment Manufacturer (OEM) number, manufacturer part number, or wholesaler number); item description; and any readily available information about mitigation actions undertaken or recommended.
(ii) Within 10 business days of submitting the report pursuant to paragraph (c)(1) of this clause: Any further available information about mitigation actions undertaken or recommended. In addition, the Contractor shall describe the efforts it undertook to prevent use or submission of a Kaspersky Lab covered article, any reasons that led to the use or submission of the Kaspersky Lab covered article, and any additional efforts that will be incorporated to prevent future use or submission of Kaspersky Lab covered articles.
(d) Subcontracts. The Contractor shall insert the substance of this clause, including this paragraph (d), in all subcontracts including subcontracts for the acquisition of commercial products or commercial services.
(End of clause)
Sections it refers to
- 4.2004 Contract clause.
Sections that refer to it
- 4.2003 Notification.
- 4.2004 Contract clause.
- 52.212-5 Contract Terms and Conditions Required To Implement Statutes or Executive Orders—Commercial Products and Commercial Services.
- 52.213-4 Terms and Conditions—Simplified Acquisitions (Other Than Commercial Products and Commercial Services).
- 52.244-6 Subcontracts for Commercial Products and Commercial Services.
← 52.204-22 Alternative Line Item Proposal. · 52.204-24 Representation Regarding Certain Telecommunications and Video Surveillance Services or Equipment. →
Rule changes for FAR Part 52
- Federal Acquisition Regulation: Revolutionary FAR Overhaul Parts 8, 12, 13, 15, 38, 44, and 51 ↗ · proposed 2026-09-18 · comments due 2026-10-19
- Federal Acquisition Regulation: Revolutionary Federal Acquisition Regulation Overhaul Parts 16, 17, and 35 ↗ · proposed 2026-09-18 · comments due 2026-10-19
- Federal Acquisition Regulation: Revolutionary Federal Acquisition Regulation Overhaul Parts 9, 27, and 47 ↗ · proposed 2026-09-18 · comments due 2026-10-19
- Federal Acquisition Regulation: Revolutionary Federal Acquisition Regulation Overhaul Parts 14, 28, 36, and 52 ↗ · proposed 2026-09-18 · comments due 2026-10-19
- Federal Acquisition Regulation: Revolutionary Federal Acquisition Regulation Overhaul Parts 3 and 49 ↗ · proposed 2026-06-23 · comments due 2026-07-23
- Federal Acquisition Regulation: Revolutionary Federal Acquisition Regulation Overhaul Parts 5, 24, and 29 ↗ · proposed 2026-06-23 · comments due 2026-07-23
- Federal Acquisition Regulation: Revolutionary Federal Acquisition Regulation Overhaul Parts 6, 7, 10, 18, 26, 37, and 41 ↗ · proposed 2026-06-23 · comments due 2026-07-23
- Federal Acquisition Regulation: Revolutionary Federal Acquisition Regulation Overhaul Parts 1, 2, 4, 33, 39, 40, and 53 ↗ · proposed 2026-06-23 · comments due 2026-07-23
Source: eCFR, 48 CFR chapters 1 and 2 (GPO GovInfo bulk data) ↗. Plain words for the terms: glossary.