Skip to main content
Category: Contracting & Acquisition

Basic Safeguarding of Covered Contractor Information Systems

Also known as: Basic Safeguarding Clause, FAR 52.204-21, FAR Clause 52.204-21
Simply put

The Basic Safeguarding Clause is a Federal Acquisition Regulation (FAR) requirement, codified at FAR 52.204-21, that directs government contractors to apply a set of basic cybersecurity measures to their information systems that handle certain federal contract information. It establishes a minimum baseline of protection rather than a comprehensive security program. Contractors are generally expected to have these safeguards in place for covered systems as of the date of contract award, though readers should verify current contractual and applicability details against the official text.

Formal definition

FAR 52.204-21, titled 'Basic Safeguarding of Covered Contractor Information Systems,' is a Federal Acquisition Regulation clause requiring contractors to implement a set of basic security controls (identified in the evidence as fifteen safeguarding requirements) for any covered contractor information system that processes, stores, or transmits Federal contract information. The final rule was published in the Federal Register on May 16, 2016; contractors should confirm the applicable effective date and current clause text against the official Federal Register document and current FAR, as the safeguarding obligation generally attaches to covered systems as of the date of contract award. This clause establishes a minimum civilian-acquisition baseline and should not be conflated with DFARS 252.204-7012, which addresses safeguarding of Covered Defense Information and imposes 'adequate security' and additional requirements on DoD contractors; the FAR clause does not by itself satisfy DFARS, CUI-specific NIST SP 800-171 obligations, or CMMC requirements. This entry does not cover implementation specifics, the full text of the individual safeguarding requirements, or contract-specific applicability, which readers must confirm against current authoritative sources.

Why it matters

The Basic Safeguarding Clause (FAR 52.204-21) represents the minimum cybersecurity floor for contractors doing business with the federal government. Because it applies broadly across civilian acquisitions, it functions as a baseline expectation rather than a comprehensive security mandate. For compliance officers and contractors, its significance lies in what it establishes and what it does not: meeting the fifteen safeguarding requirements identified in the clause satisfies a starting-point obligation, but it does not, by itself, demonstrate a mature or comprehensive security posture. Treating compliance with these basic safeguards as equivalent to being secure is a common and consequential mistake.

Who it's relevant to

Government contractors and subcontractors
Any contractor whose information systems process, store, or transmit Federal contract information should understand this clause as the baseline safeguarding obligation, generally applicable as of the date of contract award. Contractors should not assume that meeting these basic requirements satisfies DoD, CUI-specific NIST SP 800-171, or CMMC obligations, and should verify which requirements attach to each specific contract.
Compliance officers and ISSMs
Those responsible for tracking contractual cybersecurity obligations need to distinguish FAR 52.204-21 from DFARS 252.204-7012 and related requirements, and to guard against equating baseline compliance with comprehensive security. They should confirm applicability, current clause text, and effective dates against the current FAR and the official Federal Register document.
Contracting and acquisition professionals
Personnel drafting, reviewing, or administering federal contracts should confirm when this clause is required to be included and how its baseline requirements interact with agency-specific and defense-specific safeguarding clauses, recognizing that the FAR clause establishes only a minimum civilian-acquisition floor.
Auditors and assessors
Those evaluating contractor security should treat the fifteen safeguarding requirements as a minimum baseline to verify, not as evidence of a mature security program, and should confirm the current authoritative requirements before rendering conclusions, since clause text and applicability may change across revisions.

Inside Basic Safeguarding of Covered Contractor Information Systems

FAR 52.204-21 Designation
The Basic Safeguarding Clause is codified at Federal Acquisition Regulation (FAR) 52.204-21, titled 'Basic Safeguarding of Covered Contractor Information Systems.' It is a governmentwide FAR clause and should not be confused with DFARS clause 252.204-7012, which imposes more extensive obligations on DoD contractors handling Controlled Unclassified Information (CUI).
Covered Contractor Information System
The clause applies to information systems that are owned or operated by a contractor and that process, store, or transmit Federal contract information (FCI). Readers should confirm the current FAR definitions of 'covered contractor information system' and 'Federal contract information' against the authoritative FAR text, as tailoring and definitions can evolve across revisions.
Federal Contract Information (FCI) Scope
The clause is oriented toward protecting FCI, generally information provided by or generated for the Government under a contract that is not intended for public release. It is scoped to FCI rather than the broader CUI protections addressed under NIST SP 800-171 and DoD-specific requirements; the reader should verify which information categories apply to a given contract.
Set of Basic Safeguarding Requirements
The clause enumerates a limited set of basic security safeguarding requirements considered baseline hygiene measures (such as controlling access, limiting authorized users, and similar fundamental protections). These are generally regarded as a subset that overlaps with, but is narrower than, the security requirements in NIST SP 800-171. Practitioners should consult the current clause text for the exact enumerated requirements rather than relying on paraphrase.
Flowdown Consideration
As a FAR clause, its applicability and any subcontractor flowdown depend on the contract and current acquisition regulations. Whether and how the clause must be included in subcontracts should be verified against the applicable prescription in the FAR.
Effective Status
The final rule establishing the basic safeguarding requirements was published in the Federal Register on May 16, 2016, and became effective June 15, 2016. Because FAR provisions are subject to amendment, the reader should verify the current authoritative FAR text for any subsequent revisions.

Common questions

Answers to the questions practitioners most commonly ask about Basic Safeguarding of Covered Contractor Information Systems.

Does meeting the Basic Safeguarding Clause mean my contract is fully compliant with federal cybersecurity requirements?
No. The Basic Safeguarding Clause (FAR 52.204-21) establishes a set of baseline safeguarding requirements for covered contractor information systems, but satisfying it does not by itself demonstrate compliance with other, more stringent obligations that may apply. Contracts involving Controlled Unclassified Information (CUI) generally trigger additional requirements such as DFARS clause 252.204-7012 and the NIST SP 800-171 control set, and Department of Defense contracts may involve CMMC assessment obligations. The FAR clause should be understood as a floor rather than a complete compliance program. Readers should confirm which additional clauses and standards apply to their specific contract against the current authoritative text.
Are the Basic Safeguarding Clause requirements the same as the NIST SP 800-171 controls?
No, these should not be conflated. The Basic Safeguarding Clause sets out a limited number of basic safeguarding measures for covered contractor information systems, whereas NIST SP 800-171, published by NIST, contains a substantially broader and more detailed set of security requirements for protecting CUI. The FAR clause's requirements are generally narrower in scope, and its applicability differs from the DFARS-driven obligation to implement NIST SP 800-171. Treating the two as interchangeable is a common error; contractors should verify the precise requirements and applicability of each against the governing regulation and publication.
How do I determine whether the Basic Safeguarding Clause applies to a given contract?
Applicability generally depends on whether the contract involves a covered contractor information system as defined in the clause and on the flowdown and inclusion rules in the FAR. In most implementations the clause is incorporated by the contracting agency into applicable solicitations and contracts. Because agency tailoring and specific acquisition circumstances can affect inclusion, you should review the actual contract terms and consult your contracting officer rather than assuming applicability. This entry does not address the contractual or legal specifics of any individual acquisition, which must be confirmed against the current contract and authoritative FAR text.
Does the Basic Safeguarding Clause flow down to subcontractors?
Flowdown obligations depend on the clause's own flowdown language and the nature of the subcontracted work. In most implementations, safeguarding requirements are intended to extend to lower-tier entities whose systems process, store, or transmit the relevant information, but the precise flowdown mechanics can vary. Prime contractors should review the current clause text and their subcontract terms, and confirm flowdown obligations with their contracting and legal advisors. This entry does not resolve specific flowdown disputes or tailored contractual arrangements.
What kinds of safeguarding measures does the clause generally call for?
The clause generally directs contractors to apply a set of basic safeguarding measures to covered contractor information systems, addressing common protective practices for information security. Because the exact enumerated requirements and their interpretation can be affected by the applicable version of the FAR and by agency guidance, contractors should read the current clause text directly to confirm the specific measures required. This entry describes the concept rather than reproducing the enumerated requirements, which the reader should verify against the authoritative source.
How should the Basic Safeguarding Clause be reconciled with other cybersecurity clauses in the same contract?
When a contract includes the Basic Safeguarding Clause alongside more stringent requirements, such as DFARS clause 252.204-7012 or NIST SP 800-171 obligations, the more comprehensive requirements generally govern the systems and information within their scope, while the FAR clause continues to set a baseline for covered contractor information systems. Because these authorities are issued and maintained by different bodies and have distinct scopes, contractors should map each requirement to the systems and information it covers rather than assuming one supersedes the other in all respects. Confirm the interplay of applicable clauses with your compliance and contracting advisors against current authoritative sources.

Common misconceptions

Meeting FAR 52.204-21 satisfies DoD CUI protection requirements.
FAR 52.204-21 is a basic, governmentwide safeguarding baseline oriented toward Federal contract information. It does not, on its own, satisfy the more extensive obligations imposed on DoD contractors under DFARS 252.204-7012 and NIST SP 800-171, nor any applicable CMMC requirements. These are distinct authorities and scopes; contractors should confirm which apply to a specific contract.
The basic safeguarding requirements are equivalent to the full NIST SP 800-171 control set.
The clause's requirements generally represent a narrower subset that overlaps with, but does not replicate, the broader set of security requirements in NIST SP 800-171. Compliance with the basic clause should not be treated as equivalent to CUI safeguarding, and practitioners should review the exact enumerated requirements in the current clause text.
Implementing the enumerated safeguards means the contractor's systems are secure.
Compliance with the basic safeguarding requirements is not the same as security. The clause establishes a baseline of fundamental protections; it does not guarantee protection against all threats, and organizations should treat it as a minimum floor rather than a comprehensive security program.

Best practices

Verify the exact enumerated safeguarding requirements against the current authoritative FAR 52.204-21 text rather than relying on summaries, as FAR provisions can be amended over time.
Determine whether a contract involves only Federal contract information under FAR 52.204-21 or also Controlled Unclassified Information triggering DFARS 252.204-7012 and NIST SP 800-171, and scope safeguards accordingly.
Do not assume FAR 52.204-21 compliance satisfies DoD-specific or CMMC obligations; confirm which authorities apply to each contract with contracting officials or counsel.
Treat the basic safeguarding requirements as a minimum baseline and layer additional controls where the sensitivity of the data or the threat environment warrants, since compliance does not equate to security.
Review subcontractor flowdown obligations against the applicable FAR prescription before assuming the clause must or must not be included in subcontracts.
Document how each enumerated safeguard is implemented and maintain evidence, and periodically reassess as the clause and related requirements evolve across revisions.