48 CFR · Federal Acquisition Regulation and Defense supplement

FAR and DFARS navigator

The codified text (eCFR, as of 2026-10-02). Under the Revolutionary FAR Overhaul ↗, agencies follow class deviations with new text for many parts while the formal rules go through the Federal Register: check the solicitation and your contract's clauses, which rule.

Ask the FAR

Try: · · ·

Clear

189 sections with “information security”: the first 40

  • DFARS 252.204-7012 Safeguarding Covered Defense Information and Cyber Incident Reporting.
    As prescribed in 204.7304(c), use the following clause: Safeguarding Covered Defense Information and Cyber Incident Reporting (MAY 2024) (a) Definitions. As used in this clause— Adequate security means protective measures that are commen…
  • DFARS 252.204-7021 Contractor Compliance With the Cybersecurity Maturity Model Certification Level Requirements.
    …EQUIREMENTS (NOV 2025) (a) Definitions. As used in this clause- Controlled unclassified information means information the Government creates or possesses, or information an entity creates or possesses for or on behalf of the Government, t…
  • FAR 52.204-21 Basic Safeguarding of Covered Contractor Information Systems.
    …scribed in 4.1903, insert the following clause: Basic Safeguarding of Covered Contractor Information Systems (NOV 2021) (a) Definitions. As used in this clause— Covered contractor information system means an information system that is ow…
  • FAR 52.204-28 Federal Acquisition Supply Chain Security Act Orders—Federal Supply Schedules, Governmentwide Acquisition Contracts, and Multi-Agency Contracts.
    …s. As used in this clause— Covered article, as defined in 41 U.S.C. 4713(k), means— (1) Information technology, as defined in 40 U.S.C. 11101, including cloud computing services of all types; (2) Telecommunications equipment or telecommu…
  • FAR 52.204-30 Federal Acquisition Supply Chain Security Act Orders—Prohibition.
    …s. As used in this clause— Covered article, as defined in 41 U.S.C. 4713(k), means— (1) Information technology, as defined in 40 U.S.C. 11101, including cloud computing services of all types; (2) Telecommunications equipment or telecommu…
  • DFARS 232.072-2 Appropriate information.
    (a) The contracting officer shall obtain the type and depth of financial and other information that is required to establish a contractor's financial capability or disclose a contractor's financial condition. While the contracting officer s…
  • DFARS 252.204-7000 Disclosure of information.
    As prescribed in 204.404-70(a), use the following clause: Disclosure of Information (OCT 2016) (a) The Contractor shall not release to anyone outside the Contractor's organization any unclassified information, regardless of medium (e.g., …
  • DFARS 252.204-7008 Compliance with safeguarding covered defense information controls.
    …n 204.7304(a), use the following provision: Compliance With Safeguarding Covered Defense Information Controls (OCT 2016) (a) Definitions. As used in this provision— Controlled technical information, covered contractor information system,…
  • DFARS 252.204-7009 Limitations on the Use or Disclosure of Third-Party Contractor Reported Cyber Incident Information.
    …: Limitations on the Use or Disclosure of Third-Party Contractor Reported Cyber Incident Information (JAN 2023) (a) Definitions. As used in this clause— Compromise means disclosure of information to unauthorized persons, or a violation o…
  • DFARS 252.204-7025 Notice of Cybersecurity Maturity Model Certification Level Requirements.
    …uirements (NOV 2025) (a) Definitions. As used in this provision, controlled unclassified information (CUI), current, Cybersecurity Maturity Model Certification (CMMC) status, Cybersecurity Maturity Model Certification unique identifier (CM…
  • DFARS 252.239-7016 Telecommunications security equipment, devices, techniques, and services.
    …devices, techniques, or services to contractor telecommunications systems. (2) Sensitive information means any information the loss, misuse, or modification of which, or unauthorized access to, could adversely affect the national interest …
  • FAR 2.101 Definitions.
    … agencies and by the Department of Defense for defense agencies. Adequate evidence means information sufficient to support the reasonable belief that a particular act or omission has occurred. Advisory and assistance services means those …
  • FAR 7.103 Agency-head responsibilities.
    …raining services, and automated self-service technical support) descriptions that address information and communication technology (ICT) accessibility standards (see 36 CFR 1194.1) in proposed acquisitions and that these standards are inclu…
  • FAR 7.105 Contents of written acquisition plans.
    …02(a), 16.103(d), and 16.505(a)(3)). (ii) For each order contemplated, discuss— (A) For information technology acquisitions, how the capital planning and investment control requirements of 40 U.S.C. 11312 and OMB Circular A-130 will be me…
  • FAR 40.000 Scope of part.
    …acquisitions of products and services. It prescribes policies and procedures for managing information security and supply chain security when acquiring products and services that include, but are not limited to, information and communicatio…
  • FAR 52.204-29 Federal Acquisition Supply Chain Security Act Orders—Representation and Disclosures.
    …lligence community, National security system, Reasonable inquiry, Sensitive compartmented information, Sensitive compartmented information system, and Source have the meaning provided in the clause 52.204-30, Federal Acquisition Supply Chai…
  • FAR 52.225-26 Contractors Performing Private Security Functions Outside the United States.
    …t agencies is required. Full cooperation— (1) Means disclosure to the Government of the information sufficient to identify the nature and extent of the incident and the individuals responsible for the conduct. It includes providing timely…
  • DFARS 204.7500 Scope of subpart.
    … in DoD contracts. CMMC is a framework (see 32 CFR part 170) for assessing a contractor's information security protections. (b) This subpart does not abrogate any other requirements regarding contractor physical, personnel, information, te…
  • DFARS 252.225-7039 Defense Contractors Performing Private Security Functions Outside the United States.
    …. As used in this clause— Full cooperation—(1) Means disclosure to the Government of the information sufficient to identify the nature and extent of the incident and the individuals responsible for the conduct. It includes providing timely…
  • FAR 4.402 General.
    …ecurity Program” (NISP), establishes a program to safeguard Federal Government classified information that is released to contractors, licensees, and grantees of the United States Government. Executive Order 12829 amends Executive Order 108…
  • FAR 4.803 Contents of contract files.
    … files: (a) Contracting office contract file. (1) Purchase request, acquisition planning information, and other presolicitation documents. (2) Justifications and approvals, determinations and findings, and associated documents. (3) Evide…
  • FAR 4.1102 Policy.
    … registration in SAM, or use of SAM data, could compromise the safeguarding of classified information or national security; (3) Contracts awarded by— (i) Deployed contracting officers in the course of military operations, including, but n…
  • FAR 4.1901 Definitions.
    As used in this subpart— Covered contractor information system means an information system that is owned or operated by a contractor that processes, stores, or transmits Federal contract information. Federal contract information means inf…
  • FAR 4.2301 Definitions.
    As used in this subpart— Covered article, as defined in 41 U.S.C. 4713(k), means— (1) Information technology, as defined in 40 U.S.C. 11101, including cloud computing services of all types; (2) Telecommunications equipment or telecommuni…
  • FAR 5.102 Availability of solicitations.
    …synopsized through the GPE, including specifications, technical data, and other pertinent information determined necessary by the contracting officer. Transmissions to the GPE must be in accordance with the interface description available v…
  • FAR 5.401 General.
    …rder to preserve the integrity of the acquisition process. When it is necessary to obtain information from potential contractors and others outside the Government for use in preparing Government estimates, contracting officers shall ensure …
  • FAR 5.404-1 Release procedures.
    …tion. The agency head, or a designee, may release long-range acquisition estimates if the information will— (1) Assist industry in its planning and facilitate meeting the acquisition requirements; (2) Not encourage undesirable practices (…
  • FAR 7.503 Policy.
    …er on performance evaluation boards. (13) The approval of agency responses to Freedom of Information Act requests (other than routine responses that, because of statute, regulation, or agency policy, do not require the exercise of judgment…
  • FAR 8.405-6 Limiting sources.
    … inspection. Contracting officers shall also be guided by the exemptions to disclosure of information contained in the Freedom of Information Act (5 U.S.C. 552) and the prohibitions against disclosure in 24.202 in determining whether other …
  • FAR 15.407-1 Defective certified cost or pricing data.
    …ng data, the contracting officer, in accordance with agency procedures, shall ensure that information relating to the contracting officer's final determination is reported in accordance with 42.1503(h). Agencies shall ensure updated informa…
  • FAR 15.605 Content of unsolicited proposals.
    Unsolicited proposals should contain the following information to permit consideration in an objective and timely manner: (a) Basic information including— (1) Offeror's name and address and type of organization; e.g., profit, nonprofit, e…
  • FAR 16.505 Ordering.
    …re would compromise the national security (e.g., would result in disclosure of classified information) or create other security risks. (D) The justification is subject to the screening requirement in paragraph (b)(2)(ii)(D)(4) of this sect…
  • FAR 25.702-4 Waiver.
    …iewed and cleared by the agency head. (3) All waiver requests must include the following information: (i) Agency name, complete mailing address, and point of contact name, telephone number, and email address; (ii) Offeror's name, complet…
  • FAR 39.001 Applicability.
    This part applies to the acquisition of— (a) Information technology by or for the use of agencies except for acquisitions of information technology for national security systems. However, acquisitions of information technology for national…
  • FAR 39.101 Policy.
    (a)(1) In acquiring information technology, agencies shall identify their requirements pursuant to— (i) OMB Circular A-130, including consideration of security of resources, protection of privacy, national security and emergency preparedne…
  • FAR 42.402 Visits to contractors' facilities.
    …nment contracts shall provide prior notification to the cognizant CAO, with the following information, sufficiently in advance to permit the CAO to make necessary arrangements. Such notification is for the purpose of eliminating duplicative…
  • FAR 52.204-2 Security Requirements.
    …s (MAR 2021) (a) This clause applies to the extent that this contract involves access to information classified Confidential, Secret, or Top Secret. (b) The Contractor shall comply with (1) the Security Agreement (DD Form 441), including …
  • FAR 52.204-10 Reporting Executive Compensation and First-Tier Subcontract Awards.
    …cutive during the Contractor's preceding fiscal year and includes the following (for more information see 17 CFR 229.402(c)(2)): (1) Salary and bonus. (2) Awards of stock, stock options, and stock appreciation rights. Use the dollar amoun…
  • FAR 52.204-25 Prohibition on Contracting for Certain Telecommunications and Video Surveillance Services or Equipment.
    …r of telephone provider A to a customer of telephone company B) or sharing data and other information resources. Reasonable inquiry means an inquiry designed to uncover any information in the entity's possession about the identity of the p…
  • FAR 52.204-27 Prohibition on a ByteDance Covered Application.
    …vice developed or provided by ByteDance Limited or an entity owned by ByteDance Limited. Information technology, as defined in 40 U.S.C. 11101(6)— (1) Means any equipment or interconnected system or subsystem of equipment, used in the aut…

FAR (chapter 1)

DFARS (chapter 2, Defense)

Source: eCFR, 48 CFR chapters 1 and 2 (GPO GovInfo bulk data) ↗. Rule changes in progress: FAR, DFARS. Terms: glossary.