48 CFR · Federal Acquisition Regulation and Defense supplement

FAR and DFARS navigator

The codified text (eCFR, as of 2026-10-02). Under the Revolutionary FAR Overhaul ↗, agencies follow class deviations with new text for many parts while the formal rules go through the Federal Register: check the solicitation and your contract's clauses, which rule.

Ask the FAR

Try: · · ·

Clear

52 sections with “security classified information”: the first 40

  • FAR 53.204-1 Safeguarding classified information within industry (DD Form 254, DD Form 441).
    …ponents and those nondefense agencies with which DoD has agreements to provide industrial security services for the National Industrial Security Program if contractor access to classified information is required, as specified in subpart 4.4…
  • FAR 52.204-2 Security Requirements.
    As prescribed in 4.404(a), insert the following clause: Security Requirements (MAR 2021) (a) This clause applies to the extent that this contract involves access to information classified Confidential, Secret, or Top Secret. (b) The Cont…
  • FAR 52.204-28 Federal Acquisition Supply Chain Security Act Orders—Federal Supply Schedules, Governmentwide Acquisition Contracts, and Multi-Agency Contracts.
    …s prescribed in 4.2306(a), insert the following clause: Federal Acquisition Supply Chain Security Act Orders—Federal Supply Schedules, Governmentwide Acquisition Contracts, and Multi-Agency Contracts (DEC 2023) (a) Definitions. As used in…
  • FAR 52.204-30 Federal Acquisition Supply Chain Security Act Orders—Prohibition.
    …s prescribed in 4.2306(c), insert the following clause: Federal Acquisition Supply Chain Security Act Orders—Prohibition (DEC 2023) (a) Definitions. As used in this clause— Covered article, as defined in 41 U.S.C. 4713(k), means— (1) In…
  • DFARS 252.204-7008 Compliance with safeguarding covered defense information controls.
    …204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting. (b) The security requirements required by contract clause 252.204-7012, shall be implemented for all covered defense information on all covered contractor inf…
  • DFARS 252.204-7012 Safeguarding Covered Defense Information and Cyber Incident Reporting.
    …d Cyber Incident Reporting (MAY 2024) (a) Definitions. As used in this clause— Adequate security means protective measures that are commensurate with the consequences and probability of loss, misuse, or unauthorized access to, or modifica…
  • DFARS 252.204-7021 Contractor Compliance With the Cybersecurity Maturity Model Certification Level Requirements.
    …prescribed in 204.7504(a), use the following clause: CONTRACTOR COMPLIANCE WITH THE CYBERSECURITY MATURITY MODEL CERTIFICATION LEVEL REQUIREMENTS (NOV 2025) (a) Definitions. As used in this clause- Controlled unclassified information mea…
  • DFARS 252.204-7025 Notice of Cybersecurity Maturity Model Certification Level Requirements.
    As prescribed in 204.7504(b), use the following provision: Notice of Cybersecurity Maturity Model Certification Level Requirements (NOV 2025) (a) Definitions. As used in this provision, controlled unclassified information (CUI), current, …
  • DFARS 252.239-7016 Telecommunications security equipment, devices, techniques, and services.
    As prescribed in 239.7411(d), use the following clause: Telecommunications Security Equipment, Devices, Techniques, and Services (DEC 1991) (a) Definitions. As used in this clause— (1) Securing means the application of Government-approve…
  • FAR 2.101 Definitions.
    …aking over by the contractor to a bank, trust company, or other financing institution, as security for a loan to the contractor, of its right to be paid by the Government for contract performance. Assisted acquisition means a type of inter…
  • FAR 4.402 General.
    …Order 12829, January 6, 1993 (58 FR 3479, January 8, 1993), entitled “National Industrial Security Program” (NISP), establishes a program to safeguard Federal Government classified information that is released to contractors, licensees, and…
  • FAR 4.403 Responsibilities of contracting officers.
    …ncy is covered by the NISP; and (ii) Follow that agency's procedures for determining the security clearances of firms to be solicited. (2) If the classified information required is from the contracting officer's agency, the contracting of…
  • FAR 4.2301 Definitions.
    …order means any of the following orders issued under the Federal Acquisition Supply Chain Security Act (FASCSA) requiring the removal of covered articles from executive agency information systems or the exclusion of one or more named source…
  • FAR 52.204-21 Basic Safeguarding of Covered Contractor Information Systems.
    …xtual, numerical, graphic, cartographic, narrative, or audiovisual (Committee on National Security Systems Instruction (CNSSI) 4009). Information system means a discrete set of information resources organized for the collection, processing…
  • DFARS 204.7302 Policy.
    (a)(1) Contractors and subcontractors are required to provide adequate security on all covered contractor information systems. (2) Contractors required to implement NIST SP 800-171, in accordance with the clause at 252.204-7012, Safeguardi…
  • DFARS 252.204-7019 Notice of NIST SP 800-171 DoD Assessment Requirements.
    …ic Assessments to SPRS. (i) The email shall include the following information: (A) Cybersecurity standard assessed (e.g., NIST SP 800-171 Rev 1). (B) Organization conducting the assessment (e.g., Contractor self-assessment). (C) For eac…
  • DFARS 252.204-7020 NIST SP 800-171 DoD Assessment Requirements.
    …ntation of NIST SP 800-171 that— (1) Is based on the Contractor's review of their system security plan(s) associated with covered contractor information system(s); (2) Is conducted in accordance with the NIST SP 800-171 DoD Assessment Met…
  • DFARS 252.239-7010 Cloud Computing Services.
    …Compromise means disclosure of information to unauthorized persons, or a violation of the security policy of a system, in which unauthorized intentional or unintentional disclosure, modification, destruction, or loss of an object, or the co…
  • FAR 8.405-6 Limiting sources.
    …iv) This posting requirement does not apply when disclosure would compromise the national security (e.g., would result in disclosure of classified information) or create other security risks. (b) Items peculiar to one manufacturer. An item…
  • FAR 16.505 Ordering.
    …(a)(4)(iii)(A) of this section do not apply when disclosure would compromise the national security (e.g., would result in disclosure of classified information) or create other security risks. (D) The justification is subject to the screeni…
  • FAR 51.101 Policy.
    …t 8.7). (b) Contractors with fixed-price Government contracts that require protection of security classified information may acquire security equipment through GSA sources (see 41 CFR 101-26.507). (c) Contracting officers shall authorize …
  • DFARS 204.7500 Scope of subpart.
    (a) This subpart prescribes policies and procedures for including the Cybersecurity Maturity Model Certification (CMMC) level requirements in DoD contracts. CMMC is a framework (see 32 CFR part 170) for assessing a contractor's information …
  • DFARS 204.7501 Definitions.
    …ination controls (32 CFR 2002.4(h)). Current means— (1) With regard to Conditional Cybersecurity Maturity Model Certification (CMMC) Status— (i) Not older than 180 days for Conditional Level 2 (Self) assessments and Conditional Level 2 (…
  • DFARS 225.872-7 Industrial security for qualifying countries.
    …ormance of contracts awarded to qualifying country sources are in the National Industrial Security Program Operating Manual, 32 CFR part 117 (implemented for the Army by AR 380-49; for the Navy by SECNAV Instruction 5510.1H; for the Air For…
  • DFARS 252.204-7000 Disclosure of information.
    …y definition cannot involve any covered defense information), in accordance with National Security Decision Directive 189, National Policy on the Transfer of Scientific, Technical and Engineering Information, in effect on the date of contra…
  • DFARS 252.204-7009 Limitations on the Use or Disclosure of Third-Party Contractor Reported Cyber Incident Information.
    …Compromise means disclosure of information to unauthorized persons, or a violation of the security policy of a system, in which unauthorized intentional or unintentional disclosure, modification, destruction, or loss of an object, or the co…
  • FAR 5.102 Availability of solicitations.
    … in paragraph (a)(4) of this section, when— (i) Disclosure would compromise the national security (e.g., would result in disclosure of classified information, or information subject to export controls) or create other security risks. The f…
  • FAR 7.105 Contents of written acquisition plans.
    …uirements to be included in the solicitation and contract (see 11.002 and part 23). (18) Security considerations. (i) For acquisitions dealing with classified matters, discuss how adequate security will be established, maintained, and moni…
  • FAR 27.203-1 General.
    …e and Censorship), and related statutes, and may be contrary to the interests of national security. (b) Upon receipt of a patent application under paragraph (a) or (b) of the clause at 52.227-10, Filing of Patent Applications—Classified Su…
  • DFARS 204.7300 Scope.
    … or transits through covered contractor information systems by applying specified network security requirements. It also requires reporting of cyber incidents. (b) This subpart does not abrogate any other requirements regarding contractor …
  • DFARS 239.7301 Definitions.
    …ly chain risk for a covered system (see 10 U.S.C. 3252). Covered system means a national security system, as that term is defined at 44 U.S.C. 3552(b) (see 10 U.S.C. 3252). It is any information system, including any telecommunications sys…
  • DFARS 252.226-7003 Drug-Free Work Force.
    …ormation; or employees in other positions that the Contractor determines involve national security, health or safety, or functions other than the foregoing requiring a high degree of trust and confidence. Illegal drugs means controlled sub…
  • FAR 4.404 Contract clause.
    (a) The contracting officer shall insert the clause at 52.204-2, Security Requirements, in solicitations and contracts when the contract may require access to classified information, unless the conditions specified in paragraph (d) of this …
  • FAR 5.404-1 Release procedures.
    …e agency head shall ensure that— (1) Classified information is released through existing security channels in accordance with agency security regulations; (2) The information is publicized as widely as practicable to all parties simultane…
  • FAR 27.302 Policy.
    …ination of the right to retain title to any subject invention is necessary to protect the security of such activities; (iv) When the contract includes the operation of a Government-owned, contractor-operated facility of the Department of E…
  • FAR 32.1103 Applicability.
    …assified contract could compromise the safeguarding of classified information or national security, or arrangements for appropriate EFT payments would be impractical due to security considerations; (e) A contract is awarded by a deployed c…
  • FAR 52.204-10 Reporting Executive Compensation and First-Tier Subcontract Awards.
    …986. (To determine if the public has access to the compensation information, see the U.S. Security and Exchange Commission total compensation filings at http://www.sec.gov/answers/execomp.htm.). (2) First-tier subcontract information. Unle…
  • FAR 52.209-13 Violation of Arms Control Treaties or Agreements—Certification.
    … https://www.state.gov/bureaus-offices/under-secretary-for-arms-control-and-international-security-affairs/bureau-of-arms-control-verification-and-compliance/; and (ii) No entity owned or controlled by the Offeror has engaged in any activi…
  • DFARS 239.7304 Determination and notification.
    …t— (1) Use of the authority in 239.7305(a), (b), or (c) is necessary to protect national security by reducing supply chain risk; (2) Less intrusive measures are not reasonably available to reduce such supply chain risk; and (3) In a case…
  • DFARS 252.209-7002 Disclosure of Ownership or Control by a Foreign Government.
    …eof. (4) Proscribed information means— (i) Top Secret information; (ii) Communications security (COMSEC) material, excluding controlled cryptographic items when unkeyed or utilized with unclassified keys; (iii) Restricted Data as define…

FAR (chapter 1)

DFARS (chapter 2, Defense)

Source: eCFR, 48 CFR chapters 1 and 2 (GPO GovInfo bulk data) ↗. Rule changes in progress: FAR, DFARS. Terms: glossary.