FAR 52.204-21 — Basic Safeguarding of Covered Contractor Information Systems

This clause sets the floor for federal cybersecurity obligations. It requires 15 basic safeguarding controls whenever your systems process, store, or transmit Federal Contract Information, and it is the foundation CMMC Level 1 is built on.

Clause
FAR 52.204-21
Applies to
Contracts where contractors handle Federal Contract Information
Flows down to subs
Yes
Primary risk
Cybersecurity noncompliance findings

Key takeaways

  • Read the clause as incorporated in your contract — tailoring and alternates change obligations.
  • Flowdown obligations are your responsibility; a noncompliant subcontractor is your problem.
  • Document compliance contemporaneously; after-the-fact reconstruction rarely satisfies auditors.
  • When a clause is unclear, ask the contracting officer in writing before award, not after.

What the clause requires

The 15 requirements cover access control, authentication, media protection, physical protection, boundary protection, and system integrity — essentially limiting who can access systems, protecting media and facilities, and keeping systems patched and monitored.

How to comply in practice

Map each of the 15 controls to a specific implemented technical or administrative measure and keep evidence: access lists, MFA configuration, patching records, disposal logs, and network diagrams. Do this once well and reuse it for every contract.

Common mistakes

Firms most often fail on offboarding hygiene (accounts left active), unmanaged personal devices touching contract data, and no record of who authorized access. Absence of documentation is treated as absence of control.

FAQ

Is this the same as NIST 800-171?

No. This is a 15-control basic subset; NIST SP 800-171 with its 110 requirements applies to Controlled Unclassified Information.

Does it apply to commercial item contracts?

It applies broadly, including many commercial acquisitions, when covered information is handled.

Do I need a third-party assessment?

Not for this clause alone; CMMC determines assessment requirements.

Draft a compliant response for $2

RFP Scribe builds your compliance matrix and first draft from the solicitation and your Company Brain.

Get started

Services that help with this

Buy just the piece you need — most start at a few dollars, no subscription required.

Browse all services