Skip to main content
Free · Independent · Sourced to primary authority

Government contractor cybersecurity, explained clearly and implemented practically.

Plain-language guidance on the cybersecurity requirements that attach to federal contracts — FAR 52.204-21, DFARS 252.204-7012, CMMC, CUI, NIST SP 800-171, FedRAMP, incident reporting, and the clauses that turn cybersecurity into procurement risk.

Start Here: The Baseline You Already Owe

Before any FAR or DFARS clause applies, federal and state law already requires your business to secure data and report breaches — the FTC Act, all-50-state breach laws, and rules like GLBA and HIPAA. The contractor requirements build on top of that legal baseline. Make sure you meet it first.

See the Legal Baseline →

Recent Developments

August 2026Rule Updates

OMB Rescinded the Governmentwide Software Attestation Mandate — Now Each Agency Sets Its Own Terms

For two years, software producers selling to the federal government worked from a single assumption: sign the CISA Common Form or the agency cannot use your product. That assumption is no longer correct — and the replacement is harder to track, not easier.

Read more →
August 2026Rule Updates

GSA Already Moved to NIST 800-171 Rev. 3 — While DoD Is Still on Rev. 2

Most contractors track the CUI standard through the DFARS. That is not the only place it lives. On the civilian side, one agency has already pointed its contractor CUI requirements at Revision 3 — and the defense timetable had nothing to do with it.

Read more →
August 2026Rule Updates

NIST Rewrites Federal IoT Security Guidance — Comments Close August 24

If you sell connected hardware to a federal agency — cameras, sensors, badge readers, building controls, medical devices, fleet telematics — the document that shapes what agencies will demand of your product is open for comment for one more week.

Read more →
August 2026Case Law

Cyber-Fraud Enforcement Isn't Just a Defense Problem: The Verizon MTIPS Settlement

Most cyber-fraud settlements involve the Pentagon, NIST SP 800-171, and SPRS scores. This one involved the GSA, a civilian internet service, and a set of controls most defense contractors have never heard of — and it shows the enforcement risk reaches well beyond the defense industrial base.

Read more →

Not Sure Where to Start?

GovConCyber is a free legal reference — not a law firm. We cover the federal cybersecurity rules that apply to government contractors: what they require, who they apply to, and what you need to do. Start here if you're new to the site.

Research

Original, source-anchored analysis on the harder questions — where requirements, contracts, data-handling, and enforcement intersect.

Browse the Reference Library