FAR 52.204-21 — Basic Safeguarding of Covered Contractor Information Systems
This clause sets the floor for federal cybersecurity obligations. It requires 15 basic safeguarding controls whenever your systems process, store, or transmit Federal Contract Information, and it is the foundation CMMC Level 1 is built on.
- Clause
- FAR 52.204-21
- Applies to
- Contracts where contractors handle Federal Contract Information
- Flows down to subs
- Yes
- Primary risk
- Cybersecurity noncompliance findings
Key takeaways
- Read the clause as incorporated in your contract — tailoring and alternates change obligations.
- Flowdown obligations are your responsibility; a noncompliant subcontractor is your problem.
- Document compliance contemporaneously; after-the-fact reconstruction rarely satisfies auditors.
- When a clause is unclear, ask the contracting officer in writing before award, not after.
What the clause requires
The 15 requirements cover access control, authentication, media protection, physical protection, boundary protection, and system integrity — essentially limiting who can access systems, protecting media and facilities, and keeping systems patched and monitored.
How to comply in practice
Map each of the 15 controls to a specific implemented technical or administrative measure and keep evidence: access lists, MFA configuration, patching records, disposal logs, and network diagrams. Do this once well and reuse it for every contract.
Common mistakes
Firms most often fail on offboarding hygiene (accounts left active), unmanaged personal devices touching contract data, and no record of who authorized access. Absence of documentation is treated as absence of control.
FAQ
Is this the same as NIST 800-171?
No. This is a 15-control basic subset; NIST SP 800-171 with its 110 requirements applies to Controlled Unclassified Information.
Does it apply to commercial item contracts?
It applies broadly, including many commercial acquisitions, when covered information is handled.
Do I need a third-party assessment?
Not for this clause alone; CMMC determines assessment requirements.
Draft a compliant response for $2
RFP Scribe builds your compliance matrix and first draft from the solicitation and your Company Brain.
Get startedServices that help with this
Buy just the piece you need — most start at a few dollars, no subscription required.
Compliance & Readability Scan
$2Verify every FAR requirement is addressed in your proposal.
Buy NowRFP Plain-English Summary
$3Translate dense solicitations with FAR references into actionable checklists.
Buy NowContract Modification Writer
$10Generate compliant modification requests with proper FAR citations.
Buy Now