48 CFR · Federal Acquisition Regulation and Defense supplement

FAR and DFARS navigator

The codified text (eCFR, as of 2026-10-02). Under the Revolutionary FAR Overhaul ↗, agencies follow class deviations with new text for many parts while the formal rules go through the Federal Register: check the solicitation and your contract's clauses, which rule.

Ask the FAR

Try: · · ·

Clear

46 sections with “risk assessment”: the first 40

  • DFARS 252.204-7024 Notice on the Use of the Supplier Performance Risk System.
    … in 204.7604, use the following provision: Notice on the Use of the Supplier Performance Risk System (MAR 2023) (a) Definitions. As used in this provision— Item risk means the probability that a product, based on intended use, will intro…
  • FAR 39.102 Management of risk.
    …a) Prior to entering into a contract for information technology, an agency should analyze risks, benefits, and costs. (See part 7 for additional information regarding requirements definition.) Reasonable risk taking is appropriate as long a…
  • FAR 2.101 Definitions.
    …t provides otherwise, the seller or consignor is responsible for the cost of shipping and risk of loss. For use in the clause at 52.247-34, see the definition at 52.247-34(a). F.o.b. origin means free on board at origin; i.e., the seller o…
  • FAR 15.404-1 Proposal analysis techniques.
    …lted in quality or service shortfalls. Results of the analysis may be used in performance risk assessments and responsibility determinations. However, proposals shall be evaluated using the criteria in the solicitation, and the offered pric…
  • DFARS 204.7603 Procedures.
    The contracting officer shall consider price risk and supplier risk, if available in SPRS, as a part of the award decision. For procurement of an end product identified by a material identifier that is available as described at PGI 204.7603…
  • DFARS 208.405 Ordering procedures for Federal Supply Schedules.
    (1) Include an evaluation factor regarding supply chain risk (see subpart 239.73) when acquiring information technology, whether as a service or as a supply, that is a covered system, is a part of a covered system, or is in support of a cov…
  • DFARS 216.505 Ordering.
    …hold. (S-71) See 204.7603 for procedures on the required use of the Supplier Performance Risk System (SPRS) risk assessments. (i) The contracting officer shall ensure SPRS assessments of price risk and supplier risk are considered as a pa…
  • DFARS 217.7404-6 Allowable profit.
    … the contracting activity shall ensure the profit allowed reflects— (a) Any reduced cost risk to the contractor for costs incurred during contract performance before negotiation of the final price. However, if a contractor submits a qualif…
  • DFARS 239.7304 Determination and notification.
    …ainment and the Chief Information Officer of the Department of Defense, on the basis of a risk assessment by the Under Secretary of Defense for Intelligence, that there is a significant supply chain risk to a covered system; (b) Making a d…
  • DFARS 242.1104 Surveillance requirements.
    …icer; and (iii) When production surveillance is required, shall— (A) Conduct a periodic risk assessment of the contractor to determine the degree of production surveillance needed for all contracts awarded to that contractor. The risk ass…
  • FAR 16.103 Negotiating contract type.
    …ract type and price (or estimated cost and fee) that will result in reasonable contractor risk and provide the contractor with the greatest incentive for efficient and economical performance. (b) A firm-fixed-price contract, which best uti…
  • FAR 52.245-1 Government Property.
    …ve management and control of Government property under this contract, or present an undue risk to the Government, the Contractor shall prepare a corrective action plan when requested by the Property Administrator and take all necessary corr…
  • DFARS 215.304 Evaluation factors and significant subfactors.
    …or defense acquisition programs. (v) Include an evaluation factor regarding supply chain risk (see subpart 239.73) when acquiring information technology, whether as a service or as a supply, that is a covered system, is a part of a covered…
  • DFARS 215.404-1 Proposal analysis techniques.
    …escribed at PGI 204.7603, the contracting officer shall consider the Supplier Performance Risk System price risk assessments in determining if a proposed price is consistent with historical prices paid for an item or otherwise creates a ris…
  • DFARS 243.204-70-6 Allowable profit.
    … the contracting activity shall ensure the profit allowed reflects— (a) Any reduced cost risk to the contractor for costs incurred during contract performance before negotiation of the final price; (b) Any reduced cost risk to the contrac…
  • FAR 7.105 Contents of written acquisition plans.
    …of trade-offs among the various cost, capability or performance, and schedule goals. (7) Risks. Discuss technical, cost, and schedule risks and describe what efforts are planned or underway to reduce risk and the consequences of failure to…
  • FAR 42.708 Quick-closeout procedure.
    …l contract, task order, or delivery order amount; (3) The contracting officer performs a risk assessment and determines that the use of the quick-closeout procedure is appropriate. The risk assessment shall include— (i) Consideration of t…
  • DFARS 204.7600 Scope of subpart.
    This subpart provides policies and procedures for use of the Supplier Performance Risk System (SPRS) risk assessments in the evaluation of a quotation or offer.
  • DFARS 204.7602 Applicability.
    Use of SPRS risk assessments is required for the evaluation of quotations or offers in response to solicitations for supplies and services, including solicitations using FAR part 12 procedures for the acquisition of commercial products and …
  • DFARS 209.105-1 Obtaining information.
    …mining contractor responsibility. (iii) Contracting officers shall consider the supplier risk assessment available in the Supplier Performance Risk System at https://piee.eb.mil/ when determining responsibility. See 204.7603(c).
  • DFARS 212.203 Procedures for solicitation, evaluation, and award.
    …afety items. (3) See 204.7603 for procedures on the required use of Supplier Performance Risk System risk assessments as part of the award decision. (4) See subpart 212.70 for acquisitions resulting from a commercial solutions opening. (…
  • DFARS 212.301 Solicitation provisions and contract clauses for the acquisition of commercial products and commercial services.
    (c) Include an evaluation factor regarding supply chain risk (see subpart 239.73) when acquiring information technology, whether as a service or as a supply, that is a covered system, is a part of a covered system, or is in support of a cov…
  • DFARS 213.106-2 Evaluation of quotations or offers.
    …r procedures on the requirement for contracting officers to consider Supplier Performance Risk System risk assessments as a basis of award.
  • DFARS 252.204-7019 Notice of NIST SP 800-171 DoD Assessment Requirements.
    …ss a lesser time is specified in the solicitation) are posted in the Supplier Performance Risk System (SPRS) (https://www.sprs.csd.disa.mil/) for all covered contractor information systems relevant to the offer. (2) If the Offeror does not…
  • DFARS 252.204-7020 NIST SP 800-171 DoD Assessment Requirements.
    …ures. Summary level scores for all assessments will be posted in the Supplier Performance Risk System (SPRS) (https://www.sprs.csd.disa.mil/) to provide DoD Components visibility into the summary level scores of strategic assessments. (1) …
  • FAR 32.202-4 Security for Government financing.
    …ctor; or (4) Title to identified contractor assets of adequate worth. (e) Management of risk and security. In establishing contract financing terms, the contracting officer must be aware of certain risks. For example, very high amounts of…
  • FAR 37.115-2 General policy.
    …ost realism analysis). When acquiring these services, contracting officers must conduct a risk assessment and evaluate, for award on that basis, any proposals received that reflect factors such as: (1) Unrealistically low labor rates or ot…
  • FAR 52.237-10 Identification of Uncompensated Overtime.
    …w labor rates, or that do not otherwise demonstrate cost realism, will be considered in a risk assessment and will be evaluated for award in accordance with that assessment. (e) The offeror shall include a copy of its policy addressing unc…
  • DFARS 209.571-1 Definitions.
    …erforming technology assessments; (C) Developing acquisition strategies; (D) Conducting risk assessments; (E) Developing cost estimates; (F) Determining specifications; (G) Evaluating contractor performance and conducting independent v…
  • DFARS 217.170 General.
    …ntract cancellation are not included in the budget for the contract; and (C) A financial risk assessment of not including budgeting for costs of contract cancellation (10 U.S.C. 3501(g) and 10 U.S.C. 3531(d)); and (ii) The head of the age…
  • DFARS 217.172 Multiyear contracts for supplies.
    …ntract cancellation are not included in the budget for the contract; and (3) A financial risk assessment of not including the budgeting for costs of contract cancellation (10 U.S.C. 3501(g)); and (B) The head of the agency shall provide c…
  • DFARS 242.7203 Review procedures.
    …ficer (ACO), with advice from the auditor, determines an MMAS review is needed based on a risk assessment of the contractor's past experience and current vulnerability. (b) Qualifying sales. Qualifying sales are sales for which certified c…
  • DFARS 242.7302 Requirements.
    …A insurance/pension specialists and DCAA auditors, determines a CIPR is needed based on a risk assessment of the contractor's past experience and current vulnerability. (2) Qualifying sales are sales for which certified cost or pricing dat…
  • FAR 34.202 Integrated Baseline Reviews.
    …dgets, resources, and schedules. It should provide a mutual understanding of the inherent risks in offerors'/contractors' performance plans and the underlying management control systems, and it should formulate a plan to handle these risks.…
  • FAR 52.203-13 Contractor Code of Business Ethics and Conduct.
    …em, especially if criminal conduct has been detected; and (3) Periodic assessment of the risk of criminal conduct, with appropriate steps to design, implement, or modify the business ethics awareness and compliance program and the internal…
  • DFARS 225.7019-3 Waiver.
    …llation; and (2) National security requirements have been balanced against the potential risk associated with reliance upon the Russian Federation for furnished energy. (b) Submission of waiver notice. (1) Not later than 14 days before th…
  • DFARS 252.204-7012 Safeguarding Covered Defense Information and Cyber Incident Reporting.
    …s security requirements equivalent to those established by the Government for the Federal Risk and Authorization Management Program (FedRAMP) Moderate baseline (https://www.fedramp.gov/documents-templates/) and that the cloud service provid…
  • DFARS 252.204-7021 Contractor Compliance With the Cybersecurity Maturity Model Certification Level Requirements.
    …ric characters assigned to each CMMC assessment and reflected in the Supplier Performance Risk System (SPRS) for each contractor information system. Federal contract information (FCI) means information, not intended for public release, tha…
  • DFARS 252.239-7010 Cloud Computing Services.
    …. As used in this clause— Authorizing official, as described in DoD Instruction 8510.01, Risk Management Framework (RMF) for DoD Information Technology (IT), means the senior Federal official or executive with the authority to formally ass…
  • FAR 15.305 Proposal evaluation.
    …, and ordinal rankings. The relative strengths, deficiencies, significant weaknesses, and risks supporting proposal evaluation shall be documented in the contract file. (1) Cost or price evaluation. Normally, competition establishes price …

FAR (chapter 1)

DFARS (chapter 2, Defense)

Source: eCFR, 48 CFR chapters 1 and 2 (GPO GovInfo bulk data) ↗. Rule changes in progress: FAR, DFARS. Terms: glossary.