Covered Contractor Information System
A Covered Contractor Information System is a computer system that a government contractor owns or operates and that handles certain government information. Because these systems touch Federal contract information, the contractor generally must apply basic safeguarding measures to protect them. The specific protections come from the Federal Acquisition Regulation clause governing basic safeguarding.
Under FAR 52.204-21, a covered contractor information system is defined as an information system that is owned or operated by a contractor that processes, stores, or transmits Federal contract information. When this clause applies, it generally requires the contractor to implement a set of basic safeguarding requirements (identified in the clause as a defined number of security control-type requirements) on such systems. This definition is scoped to the FAR basic safeguarding context and Federal contract information; it is distinct from, and should not be conflated with, the broader safeguarding obligations for Controlled Unclassified Information (CUI) addressed under DFARS 252.204-7012 and NIST SP 800-171. Readers should verify the current authoritative text of FAR 52.204-21, as regulatory language and associated requirements may be revised.
Why it matters
The concept of a covered contractor information system establishes the trigger for basic cybersecurity safeguarding obligations across a wide swath of federal contracts. Because the definition turns on whether a contractor-owned or operated system processes, stores, or transmits Federal contract information, it can reach many contractors who might not otherwise consider themselves subject to formal cybersecurity requirements. Identifying which systems fall within this scope is therefore a foundational step for compliance, since misjudging the boundary can leave in-scope systems unprotected or lead a contractor to overlook applicable clause obligations.
This definition also matters because it is frequently confused with the broader safeguarding regime for Controlled Unclassified Information (CUI). FAR 52.204-21 and its basic safeguarding requirements are distinct from, and should not be conflated with, the obligations under DFARS 252.204-7012 and NIST SP 800-171, which address CUI and generally impose more extensive requirements. A contractor that treats the FAR basic safeguarding requirements as sufficient for CUI-handling systems may fall short of its DFARS obligations, so understanding what a covered contractor information system is, and what it is not scoped to, helps prevent costly compliance gaps.
Because regulatory language and associated requirements may be revised over time, contractors should not assume the scope or the specific safeguarding measures are static. Verifying the current authoritative text of FAR 52.204-21 is essential when determining whether a given system is covered and what protections apply.
Who it's relevant to
Inside Covered Contractor Information System
Common questions
Answers to the questions practitioners most commonly ask about Covered Contractor Information System.