Skip to main content
Category: Contracting & Acquisition

FAR 52.204-21

Also known as: Basic Safeguarding of Covered Contractor Information Systems, Basic Safeguarding of Contractor Information Systems
Simply put

FAR 52.204-21 is a contract clause that requires government contractors to apply a set of basic security measures to the information systems that handle certain federal contract information. It generally establishes a minimum, baseline level of protection intended to provide basic intrusion protection rather than comprehensive security. Contractors are typically expected to meet these requirements as of the date of contract award.

Formal definition

FAR 52.204-21, titled 'Basic Safeguarding of Covered Contractor Information Systems,' is a Federal Acquisition Regulation clause finalized in a rule published May 16, 2016, that prescribes a set of basic safeguarding requirements, commonly described as 15 basic security controls, for covered contractor information systems that process, store, or transmit Federal Contract Information (FCI). In most implementations these controls are intended as a minimum baseline for basic intrusion protection and limited transfer of Federal contract information, and the clause is directed to flow down to subcontracts at all levels. This entry addresses the clause conceptually and does not cover the specific control text, contractual tailoring, or the distinct and generally more extensive CUI-protection requirements imposed by separate authorities; practitioners should verify the current authoritative FAR text and confirm applicability, flowdown, and control specifics against official sources.

Why it matters

FAR 52.204-21 establishes the floor for cybersecurity obligations across a broad swath of federal contracting. Because it applies to information systems that process, store, or transmit Federal Contract Information (FCI), it reaches contractors and subcontractors who may not otherwise handle Controlled Unclassified Information (CUI) or fall under more stringent defense-specific requirements. The clause is directed to flow down to subcontracts at all levels, which means prime contractors generally cannot treat these safeguards as an internal-only concern; they must consider how the requirements propagate through their supply chains.

A critical point for practitioners is that this clause sets a minimum baseline for basic intrusion protection, it is not comprehensive security, and meeting its requirements should not be equated with being secure or with satisfying other, more extensive obligations. FCI protection under FAR 52.204-21 is distinct from the generally more demanding requirements for safeguarding CUI imposed by separate authorities. Assuming that compliance with this baseline discharges CUI-protection duties, or that it substitutes for defense-specific requirements, is a common and consequential error. Contractors are typically expected to meet these safeguarding requirements as of the date of contract award, so the obligation is not something that can be deferred to a later performance milestone.

Who it's relevant to

Prime Contractors and Subcontractors
Any contractor whose information systems process, store, or transmit Federal Contract Information is generally subject to these basic safeguarding requirements. Because the clause is directed to flow down to subcontracts at all levels, prime contractors should assess how the obligation propagates to their subcontractors, and subcontractors should not assume they are exempt simply because they lack a direct relationship with the government.
Contract and Compliance Managers
Those responsible for reviewing and administering contract terms need to identify when this clause is incorporated and confirm that safeguarding measures are in place as of the date of contract award. They should also distinguish this FCI baseline from the separate and generally more extensive CUI-protection requirements, since the two are frequently confused.
Information System Security Managers and IT Staff
Personnel implementing safeguards should treat the commonly cited 15 basic security controls as a minimum floor for basic intrusion protection, not as a comprehensive security program. Meeting the clause does not, by itself, establish that a system is secure or that other applicable requirements are satisfied. Confirm the current control specifics against the authoritative FAR text.
Auditors and Assessors
Those evaluating contractor compliance should verify applicability and flowdown against official sources and avoid conflating this baseline clause with more demanding authorities governing CUI. Assessment against the clause's requirements is distinct from any broader security determination or authorization.

Inside FAR 52.204-21

Basic Safeguarding Clause
FAR 52.204-21 is the Federal Acquisition Regulation contract clause titled 'Basic Safeguarding of Covered Contractor Information Systems.' It establishes a baseline set of security requirements applicable to contractor information systems that process, store, or transmit Federal contract information (FCI). The clause is maintained within the FAR system, which is jointly administered by the FAR Council; practitioners should verify the current text against the official FAR.
Federal Contract Information (FCI) Scope
The clause generally applies to information systems that handle Federal Contract Information, information provided by or generated for the Government under a contract that is not intended for public release. It is distinct from Controlled Unclassified Information (CUI); FCI is a broader, lower-sensitivity category, and the clause's protections are correspondingly baseline in nature.
Set of Basic Safeguarding Requirements
The clause enumerates a set of basic safeguarding requirements addressing fundamental security hygiene, for example, controlling access, limiting information system connections, and protecting information at appropriate points. The exact requirements and their number should be confirmed against the current FAR text rather than assumed, as the authoritative wording governs.
Relationship to Other Authorities
FAR 52.204-21 is a FAR-based requirement and is separate from DFARS clause 252.204-7012 (which addresses safeguarding of covered defense information and CUI in the defense context) and from CMMC. Practitioners should treat these as distinct authorities with different scopes, issuing bodies, and information categories rather than as interchangeable.
Contractual Flow-Down Nature
As a contract clause, its obligations arise through incorporation into applicable federal contracts and generally may need to be flowed down to subcontractors when they handle FCI. The specific flow-down conditions and any exceptions should be confirmed against the current clause text and the governing contract.

Common questions

Answers to the questions practitioners most commonly ask about FAR 52.204-21.

Does complying with FAR 52.204-21 mean a contractor also satisfies DFARS 252.204-7012 or CMMC requirements?
No. FAR 52.204-21 establishes a set of basic safeguarding requirements for covered contractor information systems, and it should not be treated as equivalent to the DFARS clause or CMMC. The DFARS 252.204-7012 clause and the CMMC framework are DoD-specific authorities that generally impose additional and more extensive obligations, typically tied to the protection of Controlled Unclassified Information (CUI). Meeting the basic safeguarding requirements of FAR 52.204-21 does not by itself demonstrate compliance with those separate DoD requirements. Contractors should confirm which clauses appear in their specific contracts and verify the current authoritative text of each.
Is FAR 52.204-21 a full information security compliance program that makes a system 'secure'?
It should not be understood that way. FAR 52.204-21 sets out basic safeguarding measures for covered contractor information systems that process, store, or transmit Federal contract information (FCI), rather than a comprehensive security program. Compliance with these baseline safeguards is not the same as being secure, and it does not address the broader control sets, continuous monitoring, or higher-impact protections that other frameworks may require. Organizations should treat it as a minimum baseline and evaluate whether additional requirements apply to their systems and data.
Which contracts include FAR 52.204-21, and how do we know if it applies to us?
As a Federal Acquisition Regulation clause, FAR 52.204-21 is generally incorporated into applicable federal contracts through the contracting process, and its applicability depends on the specific solicitation and award. Because inclusion is contract-specific and subject to the contracting officer's determination, contractors should review the actual clauses in each contract and consult their contracting officer rather than assuming applicability. Verify against the current authoritative FAR text for the precise applicability language.
What type of information does FAR 52.204-21 apply to, and how does that scope our implementation?
The clause is generally directed at covered contractor information systems that process, store, or transmit Federal contract information (FCI). Scoping implementation therefore begins with identifying which of your systems handle FCI, since those systems are typically where the safeguarding requirements apply. Note that data classified as CUI, or systems subject to defense or national security requirements, may carry additional obligations under other authorities. Confirm the current definitions and scope in the authoritative FAR text before finalizing your system boundary.
Who within our organization is responsible for implementing the safeguarding requirements?
The clause places safeguarding responsibilities on the contractor for its covered information systems, but it does not prescribe a specific internal role or governance structure. In most implementations, responsibility is shared across IT, information security, and contract management functions, with coordination needed to map requirements to the systems that handle Federal contract information. This entry does not address organization-specific staffing, contractual, or legal assignment of responsibility, which you should confirm internally and against current official sources.
How should we document and maintain evidence of compliance with FAR 52.204-21?
Because the clause focuses on implementing basic safeguarding measures for covered systems, organizations generally maintain documentation showing how each required safeguard is applied to systems handling Federal contract information. Since requirements and expectations can be interpreted differently across agencies and can change across revisions, contractors should align documentation practices with the current authoritative text and any contract-specific direction. This entry does not cover audit, contractual reporting, or agency-specific evidentiary standards, which should be verified against current official sources and your contracting officer's guidance.

Common misconceptions

Meeting FAR 52.204-21 means a contractor is compliant with all federal cybersecurity requirements, including DoD requirements.
The clause establishes only a baseline for protecting Federal Contract Information. It does not, by itself, satisfy DFARS 252.204-7012, CMMC, or other requirements that apply to CUI or covered defense information. Contractors handling more sensitive information generally must meet additional, more stringent obligations under separate authorities.
FAR 52.204-21 and DFARS 252.204-7012 are the same requirement or address the same information.
They are distinct clauses issued under different regulatory frameworks (the FAR versus the DFARS) and cover different information categories, FCI for the FAR clause versus covered defense information/CUI for the DFARS clause. Conflating them can lead to under- or over-scoping of safeguarding obligations.
Implementing the basic safeguarding controls makes a contractor's systems fully secure.
The clause reflects baseline safeguarding requirements and represents a compliance floor, not a comprehensive security posture. Compliance with these basic measures is not equivalent to being secure; organizations should assess and address risks beyond the minimum requirements.

Best practices

Verify the current, authoritative text of FAR 52.204-21 in the official FAR before relying on any specific requirement, since clause wording and enumerated items govern and may be updated.
Identify and inventory the information systems that process, store, or transmit Federal Contract Information so the scope of the clause is accurately defined for your organization.
Distinguish FCI from CUI when scoping obligations, and separately confirm whether more stringent requirements such as DFARS 252.204-7012 or CMMC apply based on the information you handle.
Review subcontracts and supply-chain arrangements to ensure the safeguarding requirements are appropriately flowed down where subcontractors handle FCI, confirming flow-down terms against the current clause and contract.
Treat the basic safeguarding requirements as a compliance floor rather than a complete security program, and address residual risks through additional controls where warranted.
Consult contracting and legal counsel to confirm contractual, implementation, and applicability specifics, as these fall outside the general definition and depend on the governing contract.