Skip to main content
Category: Contracting & Acquisition

Contracting Officer's Representative

Also known as: COR, COTR, Contracting Officer's Technical Representative, TO, PO
Simply put

A Contracting Officer's Representative (COR) is an individual designated in writing by a Contracting Officer to help oversee a contract's technical and administrative aspects. Often described as the 'eyes and ears' of the Contracting Officer, the COR observes, documents, and communicates contractor performance. The COR does not replace the Contracting Officer and generally may only perform the specific functions authorized in their appointment.

Formal definition

A Contracting Officer's Representative (COR) is an individual designated and authorized in writing by a Contracting Officer (CO/KO), typically through a COR Appointment/Designation Memo, to perform specific technical and/or administrative functions in support of contract administration. The COR's core role is to observe, document, and communicate contractor performance to both the Contracting Officer and the contractor, serving as a monitoring and reporting extension of the CO. The COR's authority is limited to the functions expressly stated in the appointment and generally does not include authority to modify contract terms, direct changes, or otherwise obligate the Government, actions that remain reserved to the Contracting Officer. Related or synonymous titles used in some contexts include Contracting Officer's Technical Representative (COTR), Task Order (TO) representative, and Project Officer (PO). Note: this entry addresses the general acquisition role and does not cover agency-specific certification requirements (for example, FAC-COR levels), delegation limits, or cybersecurity/compliance duties that a reader should verify against the applicable appointment memo, agency policy, and current authoritative acquisition guidance.

Why it matters

The Contracting Officer's Representative (COR) is a critical link in federal acquisition oversight because the Contracting Officer (CO/KO) cannot personally monitor the day-to-day technical execution of every contract. By serving as the 'eyes and ears' of the Contracting Officer, the COR observes, documents, and communicates contractor performance, giving the Government timely and accurate visibility into whether deliverables and services meet the terms of the contract. Well-documented COR monitoring supports informed acceptance decisions, payment approvals, and performance evaluations, while gaps in COR oversight can leave the Government without a reliable record of contractor performance.

Who it's relevant to

Contracting Officers (CO/KO)
Contracting Officers designate CORs in writing and rely on their monitoring and reporting to administer contracts. COs should define the COR's authorized functions clearly in the appointment memo, recognizing that authority to modify terms, direct changes, or obligate the Government remains with the CO.
Individuals appointed as CORs (including COTRs, TO reps, and POs)
Those designated to oversee contracts must operate strictly within the functions stated in their appointment. Their core duties are to observe, document, and communicate contractor performance, and they should avoid actions, such as directing changes, that fall outside their written authority.
Government contractors
Contractors interact regularly with the COR as the Government's monitoring point of contact, but should recognize that a COR generally cannot modify contract terms or authorize additional work. Direction that appears to change the contract should be confirmed with the Contracting Officer to avoid unauthorized commitments.
Program and project managers
Program staff supporting acquisitions depend on COR documentation of contractor performance to inform technical acceptance, payment, and evaluation decisions, making clear COR appointments and accurate performance records important to program execution.

Inside COR

Delegated Authority
A COR is a government employee formally designated in writing by a Contracting Officer (CO) to perform specific contract administration and monitoring functions. The scope of a COR's authority is limited to what the CO explicitly delegates in the appointment letter and does not extend beyond it.
Technical and Performance Oversight
The COR generally monitors the contractor's technical performance, inspects and accepts deliverables where authorized, and provides the CO with information used to verify that work conforms to contract requirements. In cybersecurity contexts this may include tracking whether security-related deliverables and controls are addressed as required.
Appointment Letter / Designation Memorandum
The written instrument that establishes the COR relationship, defines the specific duties delegated, and states the limitations on the COR's authority. This document is the authoritative source for what a given COR may and may not do on a particular contract.
Liaison Function
The COR often serves as the primary technical point of contact between the government and the contractor, communicating requirements and issues while routing matters that affect price, terms, or scope back to the CO for action.
Documentation and Reporting
CORs are generally expected to maintain records of contractor performance, surveillance activities, and communications, and to report findings to the CO. These records may support performance evaluations and contract administration decisions.
Scope Limitations
A COR typically cannot make or authorize changes to the contract, obligate additional funds, modify terms, or direct work outside the contract's scope. Such actions remain the responsibility of the Contracting Officer.

Common questions

Answers to the questions practitioners most commonly ask about COR.

Does a Contracting Officer's Representative (COR) have authority to modify the terms of a contract or direct changes that affect price, scope, or schedule?
Generally no. A COR is delegated technical oversight and monitoring responsibilities by the Contracting Officer (CO), but that delegation typically does not include authority to change the contract's terms, price, scope, or period of performance. Only the CO, acting within the limits of their warrant, generally has authority to bind the Government contractually. A common and costly mistake is treating COR direction as if it were a contract modification; changes that affect the agreement usually must be issued by the CO. CORs should confirm the precise limits of their authority in their written appointment or delegation letter, and readers should verify specifics against the governing acquisition regulations and agency policy.
Is the COR responsible for making the security authorization decision or issuing an Authority to Operate (ATO) for a contractor system?
No. The COR role is an acquisition oversight function and should not be conflated with the security roles defined under the Risk Management Framework (RMF). Authorization decisions, including issuing or denying an ATO, generally rest with the designated Authorizing Official (AO), not the COR. A COR may help monitor whether a contractor is meeting cybersecurity or compliance obligations reflected in the contract, but monitoring compliance is distinct from performing a security assessment and distinct again from making an authorization decision. Readers should keep these functions separate and confirm the assigned roles for a given system against current RMF and agency guidance.
How does a COR's delegated authority typically get established and documented?
In most implementations, a COR's authority is established through a written designation or delegation from the Contracting Officer, often referred to as an appointment or delegation letter, that specifies the scope, limits, and duration of the delegated responsibilities. The COR generally cannot act beyond what that document authorizes. Because the exact form, content, and required qualifications can vary by agency and by the applicable acquisition regulations, the COR and the contractor should both work from the current, signed delegation and verify its terms against agency policy rather than assuming a standard scope.
What role can a COR play in monitoring a contractor's cybersecurity or CUI-related obligations?
A COR typically supports the CO by monitoring contractor performance against the requirements written into the contract, which can include cybersecurity or Controlled Unclassified Information (CUI) handling obligations where those are incorporated as contract terms. This monitoring is an oversight and documentation function; it generally does not make the COR the arbiter of whether a technical control is adequate, nor does it substitute for a formal assessment. Where compliance concerns arise, the COR generally documents observations and coordinates with the CO and appropriate security personnel. The specific obligations depend on the clauses actually included in the contract, which readers should confirm against the current contract text.
How should a COR document contractor performance and compliance observations?
As a general practice, a COR maintains records of monitoring activities, communications, and performance observations to support the CO's administration of the contract and to create an auditable trail. The specific documentation methods, retention expectations, and reporting formats are typically set by agency policy and the terms of the COR's delegation. Because requirements differ across agencies and contract types, a COR should follow the documentation procedures identified in the applicable agency guidance and delegation letter rather than assuming a uniform standard.
What should a COR do when a compliance or performance issue exceeds the limits of their delegated authority?
When an issue falls outside the COR's delegated responsibilities, such as a matter requiring a contract change, a formal determination, or an authorization decision, the COR generally should refer the matter to the Contracting Officer or the appropriate authority rather than acting unilaterally. Because a COR cannot exercise authority the CO has not delegated, attempting to resolve such issues directly can create risk for both the Government and the contractor. The correct escalation path is typically defined in the delegation letter and agency policy, which the COR should follow and verify against current guidance.

Common misconceptions

A COR can direct the contractor to perform additional or changed work.
A COR's authority is limited to what the Contracting Officer delegates in writing and generally excludes the power to change scope, terms, price, or funding. Directing out-of-scope work can create unauthorized commitments; only the CO has authority to make such changes.
The COR role and the Contracting Officer role are interchangeable.
The CO holds the contractual authority to bind the government and to modify or administer the contract, while the COR performs delegated monitoring and technical oversight functions. The two roles are distinct, and the COR's authority derives entirely from the CO's written delegation.
COR oversight of contractor performance is the same as verifying that cybersecurity or compliance requirements are met.
Performance monitoring is not equivalent to a security assessment or authorization. Confirming whether specific compliance obligations are satisfied generally involves separate assessment and authorization processes and the applicable authorities, which the reader should verify against the governing contract terms and current official sources.

Best practices

Read and retain the COR appointment letter and treat it as the definitive statement of your delegated authority; do not act beyond its stated scope.
Route any matter that affects price, schedule, terms, funding, or scope to the Contracting Officer rather than directing the contractor, to avoid creating unauthorized commitments.
Maintain contemporaneous documentation of surveillance activities, contractor performance, deliverable acceptance, and communications to support the CO's contract administration decisions.
Distinguish performance monitoring from formal security assessment and authorization functions, and coordinate with the appropriate authorities when cybersecurity or compliance requirements are in question.
Confirm the specific limitations on your authority before accepting deliverables or communicating direction, and escalate ambiguous situations to the Contracting Officer.
Verify current duties, delegation limits, and any agency-specific interpretations against the governing contract and applicable official guidance rather than relying on general assumptions about the role.