Reading FAR and DFARS Cyber Clauses: A Guide for Non-Lawyers

Contracts bury cyber requirements in clause numbers. Learn what FAR 52.204-21 and DFARS 252.204-7012 generally cover and how to find them in your contracts.

3 min readBy Ironfield Cyber Team

Many contractors first hear about cybersecurity obligations from a contracting officer or a prime contractor's procurement team, and the requirements arrive as clause numbers: 52.204-21, 252.204-7012 and others. Owners and project managers are not expected to be lawyers, but they do need to know which clauses are in their contracts and what those clauses generally demand. This guide offers a plain-language orientation. It is not legal advice, so always read your actual contract and involve counsel for interpretation.

Why clauses matter

A clause is a contractual obligation. If you accept a contract that includes a cybersecurity clause, you have agreed to meet it, and you may be asked to demonstrate that you do. Your customers can also be required to flow certain clauses down to you. Ignoring them does not make them go away, and misrepresenting your compliance can have serious consequences.

FAR 52.204-21: basic safeguarding

The Federal Acquisition Regulation clause 52.204-21 addresses basic safeguarding of covered contractor information systems that process, store or transmit federal contract information. It lists a set of fundamental safeguards, often described as a short list of basic cyber hygiene practices. In general terms they cover:

  • Limiting system access to authorized users and devices
  • Limiting access to the types of transactions and functions users are permitted to perform
  • Controlling information posted on public systems
  • Identifying and authenticating users and devices
  • Sanitizing or destroying media containing federal contract information before disposal
  • Limiting physical access to systems and facilities
  • Escorting and monitoring visitors
  • Monitoring and protecting communications at system boundaries
  • Separating public-facing systems from internal networks
  • Identifying and correcting system flaws in a timely manner
  • Protecting against malicious code, with updates
  • Running periodic scans

For many small contractors, this is the baseline. It is not exotic, and it overlaps with what a good managed IT provider already does. The practical task is to document how you meet each item and keep evidence.

DFARS 252.204-7012: covered defense information

The Defense Federal Acquisition Regulation Supplement clause 252.204-7012 applies to defense contracts involving covered defense information. In general terms, it:

  • Requires adequate security on covered contractor information systems, which includes implementing NIST SP 800-171
  • Requires reporting of cyber incidents within a set time frame, generally 72 hours from discovery
  • Requires preservation of relevant images and data for investigators
  • Includes requirements when using external cloud service providers to store or process covered defense information
  • Requires flowing the clause down to subcontractors that handle such information

If CUI is part of your work, this clause is the main reason NIST SP 800-171 matters to you.

Other related clauses and requirements

You may also see clauses about assessing and reporting your NIST SP 800-171 status and clauses tied to CMMC 2.0. The CMMC program rule under 32 CFR Part 170 took effect on December 16, 2024. The related acquisition rule under 48 CFR, which allows CMMC requirements to appear in contracts, took effect on November 10, 2025, with requirements phased in over time. The specific requirement for a given contract is spelled out in its solicitation and clauses, so check each one.

How to find clauses in your contracts

  1. Ask for the full contract, including attachments and flow-down documents, not only the purchase order.
  2. Search for clause numbers beginning with 52.204 and 252.204, and for terms such as controlled unclassified information, covered defense information, CMMC and NIST.
  3. Look at the statement of work and any data-handling attachments.
  4. Check subcontract flow-downs from your prime contractor.
  5. List every active contract with these clauses in a simple register.

Turn clauses into tasks

For each clause, make a short entry.

  • What does it require?
  • Which systems and data does it cover?
  • Who is responsible internally?
  • What evidence shows we comply?
  • What deadlines or reporting obligations does it create?

This register becomes your roadmap and your answer when a customer asks.

Questions to ask your customer

  • Which information in this work is CUI, and how will it be marked and delivered?
  • What level of CMMC, if any, is expected and when?
  • Are there specific reporting contacts for incidents?
  • Do our subcontractors need to be included?

Clear answers early prevent expensive rework.

When to involve counsel

Seek legal advice for questions about interpretation, liability, representations to the government and incident notification decisions. Technical staff can implement controls, but legal interpretation belongs with counsel.

How Ironfield Cyber helps

Ironfield Cyber helps contractors translate clause language into a practical task list, then implement and document the controls. If you are staring at a contract and are not sure what it requires of your IT, send it to us and we will help you sort it into actions.