Skip to main content
Category: Contracting & Acquisition

48 CFR (Federal Acquisition Regulations System)

Also known as: FAR, Title 48 of the CFR, Federal Acquisition Regulation, Federal Acquisition Regulations System
Simply put

48 CFR is the part of the Code of Federal Regulations (CFR) that contains the rules the federal government follows when it buys goods and services. It is known as the Federal Acquisition Regulations System, and the core Federal Acquisition Regulation (FAR) is the first chapter within it. These rules govern government procurement, including reporting and recordkeeping requirements.

Formal definition

Title 48 of the Code of Federal Regulations is designated the Federal Acquisition Regulations System and addresses government procurement, including reporting and recordkeeping requirements. The Federal Acquisition Regulation (FAR) is Chapter 1 of Title 48; thus the FAR is a component of, not synonymous with, all of 48 CFR, which also contains agency-specific supplements in other chapters. Within the FAR, Part 2 defines words and terms frequently used in the FAR and provides cross-references to related definitions. Practitioners should note that the eCFR version is continuously updated but is not the official legal edition, and specific part, subpart, or clause numbers should be verified against the current authoritative text.

Why it matters

For anyone working in defense or public sector cybersecurity compliance, 48 CFR is the foundational regulatory home for the rules that govern how the federal government buys goods and services. Cybersecurity obligations imposed on contractors, including safeguarding requirements and reporting and recordkeeping duties, are frequently expressed as clauses and provisions that live within Title 48. Understanding that the Federal Acquisition Regulation (FAR) is Chapter 1 of Title 48, rather than the entirety of it, is essential because agency-specific supplements occupy other chapters and can add or modify requirements beyond the baseline FAR.

A common and consequential mistake is treating the terms interchangeably: 48 CFR, the Federal Acquisition Regulations System, and the FAR are related but distinct. The FAR is a component of 48 CFR, not synonymous with it. This distinction matters when a compliance officer or contracting professional must locate the exact controlling text, because citing "the FAR" when the applicable requirement actually resides in an agency supplement elsewhere in Title 48 can lead to overlooking obligations that apply to a given procurement.

Because procurement rules are updated over time, practitioners should also be aware that the eCFR version of Title 48 is continuously updated but is not the official legal edition. Relying on the eCFR for day-to-day reference is common, but specific part, subpart, or clause numbers should be verified against the current authoritative text before making compliance or contractual decisions.

Who it's relevant to

Government Contractors
Contractors doing business with the federal government must understand that their obligations, including procurement-related reporting and recordkeeping requirements, are set out within 48 CFR. Because the FAR is only Chapter 1 of Title 48, contractors should confirm whether agency-specific supplements in other chapters impose additional or modified requirements on their particular contract.
Compliance Officers and Auditors
Those responsible for verifying adherence to procurement rules need to cite the correct controlling text. Distinguishing the FAR from the broader 48 CFR, and recognizing that the eCFR is not the official legal edition, helps ensure that audit findings and compliance determinations rest on current, authoritative citations.
Contracting and Acquisition Professionals
Personnel drafting or administering federal solicitations and awards rely on Title 48 to structure procurements and incorporate the correct clauses. Part 2 of the FAR, which defines frequently used terms and cross-references related definitions, supports consistent interpretation of the provisions they apply.
Information System Security Managers and Authorizing Officials
Security requirements imposed on contractor systems are often expressed through clauses located within Title 48. Understanding where a given requirement resides, in the FAR versus an agency supplement elsewhere in 48 CFR, helps these practitioners trace obligations to their governing regulatory text and verify them against the current authoritative source.

Inside FAR

Federal Acquisition Regulation (FAR)
Codified at Title 48 of the Code of Federal Regulations, the FAR is the primary regulation governing the acquisition of supplies and services by executive agencies of the U.S. federal government. It is jointly maintained through the FAR Council and issued by the General Services Administration, the Department of Defense, and NASA.
Agency FAR Supplements
Title 48 also houses agency-specific supplements that tailor or add to the baseline FAR. The most relevant to defense practitioners is the Defense Federal Acquisition Regulation Supplement (DFARS), which implements DoD-specific acquisition requirements and generally applies in addition to, not in place of, the FAR.
Contract Clauses
The FAR and its supplements prescribe standard contract clauses and solicitation provisions that flow into government contracts. Cybersecurity-relevant obligations for contractors are frequently imposed through such clauses, though the specific clause governing a given requirement should be confirmed against the current official text rather than assumed.
Scope of Applicability
The FAR generally governs federal executive agency procurement. Requirements imposed on a contractor typically derive from the specific clauses incorporated into that contract, and applicability can differ across civilian and defense acquisitions depending on which regulation and supplement apply.

Common questions

Answers to the questions practitioners most commonly ask about FAR.

Does compliance with the FAR mean my systems are secure?
No. The FAR is a body of acquisition regulation, and satisfying its clauses is a compliance and contractual matter, not a guarantee of security. Meeting a regulatory requirement generally establishes that specified obligations were addressed contractually, but it does not by itself demonstrate that a system is protected against threats. Compliance and security are distinct concepts, and readers should treat FAR obligations as one input to a broader security program rather than a substitute for it.
Do the FAR's requirements automatically cover defense contracts, or are those handled separately?
The FAR provides the government-wide baseline for federal acquisition, but defense acquisitions are also subject to the Defense Federal Acquisition Regulation Supplement (DFARS), which supplements and in places tailors the FAR for DoD. The two should not be conflated: a defense contract generally requires attention to both the FAR and applicable DFARS provisions, and DFARS clauses may impose obligations beyond the FAR baseline. Readers should confirm which specific FAR and DFARS provisions apply to a given contract against the current official text.
How do I determine which FAR clauses apply to a specific contract?
Applicable clauses generally depend on factors such as the type of contract, dollar value thresholds, the nature of the acquisition, and any agency supplements. The clauses incorporated into a specific award are identified in the contract itself, often by reference. Because thresholds and prescriptions change across revisions, readers should verify the applicable provisions against the current authoritative text of the FAR and any relevant agency supplement rather than relying on prior contracts.
Where should I look to confirm the current text of a FAR provision?
The FAR is codified in Title 48 of the Code of Federal Regulations, and its provisions are updated over time through the rulemaking process. Because clause language and numbering can change across revisions, readers should consult the current official version rather than cached or summarized copies, and should confirm whether any agency-specific supplement modifies the government-wide provision for their acquisition.
Does the FAR itself specify detailed cybersecurity controls to implement?
The FAR is primarily an acquisition regulation and does not itself function as a technical control catalog. Where a contract imposes cybersecurity obligations, those may reference or incorporate separate standards and requirements maintained by other bodies. This entry does not cover the implementation specifics of any referenced control set; readers should identify the exact obligations flowed down in their contract and verify them against the current authoritative sources.
If a requirement appears in both the FAR and an agency supplement, which governs?
Agency supplements such as the DFARS are structured to work alongside the FAR, and a supplement may add to or tailor the government-wide baseline for that agency's acquisitions. Determining how the two interact for a particular provision generally requires reviewing both the FAR text and the applicable supplement as incorporated into the specific contract. Readers should confirm the interaction against the current official text and, where contractual or legal consequences turn on it, seek appropriate contracting or legal guidance.

Common misconceptions

The FAR and the DFARS are interchangeable regulatory sources.
They are distinct. The FAR is the government-wide baseline maintained through the FAR Council, while the DFARS is a DoD-specific supplement that implements or supplements the FAR for defense acquisitions. Defense cybersecurity obligations, such as those under DFARS clause 252.204-7012, arise from the supplement and should not be attributed to the base FAR.
Meeting FAR contract clause requirements is equivalent to being secure.
Compliance with contractual and regulatory clauses is not the same as achieving effective security. The FAR establishes acquisition obligations; satisfying an incorporated clause does not by itself guarantee that a system is protected, and practitioners should treat compliance and security as related but separate objectives.
Cybersecurity requirements apply uniformly to all federal contracts regardless of the clauses in the contract.
Obligations generally flow from the specific clauses and provisions incorporated into an individual contract. What applies to one award may differ from another based on the agency, applicable supplement, and the clauses actually included, so requirements must be confirmed contract by contract.

Best practices

Identify and review the specific FAR and applicable agency supplement clauses actually incorporated into each contract rather than assuming a uniform set of obligations applies.
Distinguish base FAR requirements from DFARS or other agency supplement requirements, and confirm which regulation governs the particular acquisition.
Verify clause numbers, applicability, and current wording against the authoritative Title 48 text, since regulatory provisions are revised over time.
Treat contractual compliance as distinct from operational security, and maintain a security posture that addresses risk beyond the minimum a clause specifies.
Coordinate with contracting and legal personnel to confirm the scope and interpretation of incorporated clauses before committing to obligations.
Re-check applicable clauses whenever contracts are modified or renewed, as incorporated requirements can change between the base regulation and its supplements.