48 CFR · Federal Acquisition Regulation and Defense supplement

FAR and DFARS navigator

The codified text (eCFR, as of 2026-10-02). Under the Revolutionary FAR Overhaul ↗, agencies follow class deviations with new text for many parts while the formal rules go through the Federal Register: check the solicitation and your contract's clauses, which rule.

Ask the FAR

Try: · · ·

Clear

38 sections with “security assessment”

  • DFARS 204.470-2 National security exclusion.
    …vities, or locations or information associated with such activities, with direct national security significance. (b) In order to ensure that all relevant activities are reviewed for direct national security significance, both current and f…
  • DFARS 252.204-7021 Contractor Compliance With the Cybersecurity Maturity Model Certification Level Requirements.
    …prescribed in 204.7504(a), use the following clause: CONTRACTOR COMPLIANCE WITH THE CYBERSECURITY MATURITY MODEL CERTIFICATION LEVEL REQUIREMENTS (NOV 2025) (a) Definitions. As used in this clause- Controlled unclassified information mea…
  • FAR 32.202-4 Security for Government financing.
    …a) Policy. (1) 10 U.S.C. 3805and 41 U.S.C. 4505 require the Government to obtain adequate security for Government financing. The contracting officer shall specify in the solicitation the type of security the Government will accept. If the G…
  • DFARS 252.204-7019 Notice of NIST SP 800-171 DoD Assessment Requirements.
    …ic Assessments to SPRS. (i) The email shall include the following information: (A) Cybersecurity standard assessed (e.g., NIST SP 800-171 Rev 1). (B) Organization conducting the assessment (e.g., Contractor self-assessment). (C) For eac…
  • DFARS 252.204-7020 NIST SP 800-171 DoD Assessment Requirements.
    …ntation of NIST SP 800-171 that— (1) Is based on the Contractor's review of their system security plan(s) associated with covered contractor information system(s); (2) Is conducted in accordance with the NIST SP 800-171 DoD Assessment Met…
  • DFARS 252.204-7025 Notice of Cybersecurity Maturity Model Certification Level Requirements.
    As prescribed in 204.7504(b), use the following provision: Notice of Cybersecurity Maturity Model Certification Level Requirements (NOV 2025) (a) Definitions. As used in this provision, controlled unclassified information (CUI), current, …
  • DFARS 252.204-7010 Requirement for Contractor To Notify DoD if the Contractor's Activities are Subject to Reporting Under the U.S.-International Atomic Energy Agency Additional Protocol.
    …ccordance with paragraph (a) of this clause, the DoD Program Manager will— (1) Conduct a security assessment to determine if and by what means access may be granted to the IAEA; or (2) Provide written justification to the component or age…
  • DFARS 204.7501 Definitions.
    …ination controls (32 CFR 2002.4(h)). Current means— (1) With regard to Conditional Cybersecurity Maturity Model Certification (CMMC) Status— (i) Not older than 180 days for Conditional Level 2 (Self) assessments and Conditional Level 2 (…
  • FAR 2.101 Definitions.
    …aking over by the contractor to a bank, trust company, or other financing institution, as security for a loan to the contractor, of its right to be paid by the Government for contract performance. Assisted acquisition means a type of inter…
  • FAR 50.201 Definitions.
    …irements or such other requirements as defined and specified by the Secretary of Homeland Security: (1) Is unlawful. (2) Causes harm, including financial harm, to a person, property, or entity, in the United States, or in the case of a do…
  • FAR 52.250-3 SAFETY Act Block Designation/Certification.
    …irements or such other requirements as defined and specified by the Secretary of Homeland Security: (1) Is unlawful. (2) Causes harm, including financial harm, to a person, property, or entity, in the United States, or in the case of a do…
  • FAR 52.250-4 SAFETY Act Pre-qualification Designation Notice.
    …irements or such other requirements as defined and specified by the Secretary of Homeland Security: (1) Is unlawful. (2) Causes harm, including financial harm, to a person, property, or entity, in the United States, or in the case of a do…
  • FAR 52.250-5 SAFETY Act—Equitable Adjustment.
    …irements or such other requirements as defined and specified by the Secretary of Homeland Security: (1) Is unlawful. (2) Causes harm, including financial harm, to a person, property, or entity, in the United States, or in the case of a do…
  • DFARS 204.7302 Policy.
    (a)(1) Contractors and subcontractors are required to provide adequate security on all covered contractor information systems. (2) Contractors required to implement NIST SP 800-171, in accordance with the clause at 252.204-7012, Safeguardi…
  • DFARS 225.772-4 Exception.
    … Defense for Policy, without power of redelegation, determines that it is in the national security interest of the United States to enter into such contract; and (2) Not later than seven days before entering into such contract, the Under S…
  • DFARS 252.204-7012 Safeguarding Covered Defense Information and Cyber Incident Reporting.
    …d Cyber Incident Reporting (MAY 2024) (a) Definitions. As used in this clause— Adequate security means protective measures that are commensurate with the consequences and probability of loss, misuse, or unauthorized access to, or modifica…
  • DFARS 252.239-7010 Cloud Computing Services.
    …Compromise means disclosure of information to unauthorized persons, or a violation of the security policy of a system, in which unauthorized intentional or unintentional disclosure, modification, destruction, or loss of an object, or the co…
  • FAR 7.503 Policy.
    …) The conduct of administrative hearings to determine the eligibility of any person for a security clearance, or involving actions that affect matters of personal reputation or eligibility to participate in Government programs. (15) The ap…
  • FAR 7.105 Contents of written acquisition plans.
    …uirements to be included in the solicitation and contract (see 11.002 and part 23). (18) Security considerations. (i) For acquisitions dealing with classified matters, discuss how adequate security will be established, maintained, and moni…
  • FAR 22.1702 Definitions.
    …tor of his or her personal services or of those of a person under his or her control as a security for debt, if the value of those services as reasonably assessed is not applied toward the liquidation of the debt or the length and nature of…
  • FAR 52.222-50 Combating Trafficking in Persons.
    …tor of his or her personal services or of those of a person under his or her control as a security for debt, if the value of those services as reasonably assessed is not applied toward the liquidation of the debt or the length and nature of…
  • DFARS 212.301 Solicitation provisions and contract clauses for the acquisition of commercial products and commercial services.
    …ent Requirements, as prescribed in 204.7304(e). (L) Use the clause at 252.204-7021, Cybersecurity Maturity Model Certification Requirements, as prescribed in 204.7504(a). (M) Use the clause at 252.204-7022, Expediting Contract Closeout, a…
  • DFARS 252.232-7010 Levies on Contract Payments.
    …ion; and (3) Advice as to whether the inability to perform may adversely affect national security, including rationale and adequate supporting documentation. (c) DoD shall promptly review the Contractor's assessment, and the Procuring Con…
  • DFARS 253.209-1 Responsible prospective contractors.
    …nts including preservation, unit pack, packing, marking, and unitizing for shipment. (D) Security clearance. A determination that the prospective contractor's facility security clearance is adequate and current. (When checked, the surveyin…
  • FAR 52.245-1 Government Property.
    …-71.20). Sensitive property means property potentially dangerous to the public safety or security if stolen, lost, or misplaced, or that shall be subject to exceptional physical security, protection, control, and accountability. Examples i…
  • DFARS 239.7304 Determination and notification.
    …t— (1) Use of the authority in 239.7305(a), (b), or (c) is necessary to protect national security by reducing supply chain risk; (2) Less intrusive measures are not reasonably available to reduce such supply chain risk; and (3) In a case…
  • FAR 15.101-2 Lowest price technically acceptable source selection process.
    … that is predominantly for the acquisition of— (1) Information technology services, cybersecurity services, systems engineering and technical assistance services, advanced electronic testing, audit or audit readiness services, health care …
  • FAR 15.407-1 Defective certified cost or pricing data.
    …e subcontractors, upon request. If release of the information would compromise Government security or disclose trade secrets or confidential business information, the contracting officer shall release it only under conditions that will prot…
  • FAR 25.702-4 Waiver.
    …val. Upon receipt of the waiver request, OFPP shall consult with the President's National Security Council, Office of African Affairs, and the Department of State Sudan Office and Sanctions Office to assess foreign policy aspects of making …
  • FAR 25.703-4 Waiver.
    …onal Emergency Economic Powers Act, provide rationale why it is essential to the national security interests of the United States for the President to waive the prohibition on contracting with this offeror, as required by section 6(b)(5) of…
  • FAR 28.203-1 Acceptability of individual sureties.
    … individual surety shall execute the SF 28, Affidavit of Individual Surety, and provide a security interest. One individual surety is adequate support for a bond, provided the net adjusted value of unencumbered assets pledged by that indivi…
  • DFARS 212.371 Inapplicability of certain provisions and clauses to contracts for the acquisition of commercially available off-the-shelf items.
    …. (e) 252.204-7020, NIST SP 800-171 DoD Assessment Requirements. (f) 252.204-7021, Cybersecurity Maturity Model Certification Requirements. (g) 252.205-7000, Provision of Information to Cooperative Agreement Holders. (h) 252.270-7000, P…
  • DFARS 217.172 Multiyear contracts for supplies.
    …onditions listed in FAR 17.105-1(b), the use of such a contract will promote the national security of the United States (10 U.S.C. 3501(a)(6)). (c) Multiyear contracts in amounts exceeding $900 million must be specifically authorized by la…
  • DFARS 217.207 Exercise of options.
    …ted (see 204.7303); and (ii) If there is a requirement for the contractor to have a Cybersecurity Maturity Model Certification (CMMC) status at a specific CMMC level, the contractor has a current CMMC status at the CMMC level required by t…
  • DFARS 219.7102 General.
    …ance program for a protégé firm; (c) A preliminary assessment of the protégé firm's cybersecurity readiness. The DoD Office of Small Business Programs (OSBP), Office of the Under Secretary of Defense, Acquisition and Sustainment (OUSD(A&S)…
  • DFARS 225.7019-3 Waiver.
    …quate supply of furnished energy for the covered military installation; and (2) National security requirements have been balanced against the potential risk associated with reliance upon the Russian Federation for furnished energy. (b) Su…
  • DFARS 247.573 General.
    …ility of U.S.-flag vessels. (4) Follow the procedures at PGI 247.573(b)(4) to accomplish security background checks pursuant to clause 252.247-7027, Riding Gang Member Requirements. (5)(i) In accordance with 10 U.S.C. 2631(d), contracting…
  • DFARS 252.204-7018 Prohibition on the Acquisition of Covered Defense Telecommunications Equipment or Services.
    …rolled— (i) Pursuant to multilateral regimes, including for reasons relating to national security, chemical and biological weapons proliferation, nuclear nonproliferation, or missile technology; or (ii) For reasons relating to regional st…

FAR (chapter 1)

DFARS (chapter 2, Defense)

Source: eCFR, 48 CFR chapters 1 and 2 (GPO GovInfo bulk data) ↗. Rule changes in progress: FAR, DFARS. Terms: glossary.