FAR 52.204-21
FAR 52.204-21 is a contract clause that requires government contractors to apply a set of basic security measures to the information systems that handle certain federal contract information. It generally establishes a minimum, baseline level of protection intended to provide basic intrusion protection rather than comprehensive security. Contractors are typically expected to meet these requirements as of the date of contract award.
FAR 52.204-21, titled 'Basic Safeguarding of Covered Contractor Information Systems,' is a Federal Acquisition Regulation clause finalized in a rule published May 16, 2016, that prescribes a set of basic safeguarding requirements, commonly described as 15 basic security controls, for covered contractor information systems that process, store, or transmit Federal Contract Information (FCI). In most implementations these controls are intended as a minimum baseline for basic intrusion protection and limited transfer of Federal contract information, and the clause is directed to flow down to subcontracts at all levels. This entry addresses the clause conceptually and does not cover the specific control text, contractual tailoring, or the distinct and generally more extensive CUI-protection requirements imposed by separate authorities; practitioners should verify the current authoritative FAR text and confirm applicability, flowdown, and control specifics against official sources.
Why it matters
FAR 52.204-21 establishes the floor for cybersecurity obligations across a broad swath of federal contracting. Because it applies to information systems that process, store, or transmit Federal Contract Information (FCI), it reaches contractors and subcontractors who may not otherwise handle Controlled Unclassified Information (CUI) or fall under more stringent defense-specific requirements. The clause is directed to flow down to subcontracts at all levels, which means prime contractors generally cannot treat these safeguards as an internal-only concern; they must consider how the requirements propagate through their supply chains.
A critical point for practitioners is that this clause sets a minimum baseline for basic intrusion protection, it is not comprehensive security, and meeting its requirements should not be equated with being secure or with satisfying other, more extensive obligations. FCI protection under FAR 52.204-21 is distinct from the generally more demanding requirements for safeguarding CUI imposed by separate authorities. Assuming that compliance with this baseline discharges CUI-protection duties, or that it substitutes for defense-specific requirements, is a common and consequential error. Contractors are typically expected to meet these safeguarding requirements as of the date of contract award, so the obligation is not something that can be deferred to a later performance milestone.
Who it's relevant to
Inside FAR 52.204-21
Common questions
Answers to the questions practitioners most commonly ask about FAR 52.204-21.