Skip to main content
Free · Independent · Sourced to primary authority

Government contractor cybersecurity, explained clearly and implemented practically.

Plain-language guidance on the cybersecurity requirements that attach to federal contracts — FAR 52.204-21, DFARS 252.204-7012, CMMC, CUI, NIST SP 800-171, FedRAMP, incident reporting, and the clauses that turn cybersecurity into procurement risk.

Start Here: The Baseline You Already Owe

Before any FAR or DFARS clause applies, federal and state law already requires your business to secure data and report breaches — the FTC Act, all-50-state breach laws, and rules like GLBA and HIPAA. The contractor requirements build on top of that legal baseline. Make sure you meet it first.

See the Legal Baseline →

Recent Developments

July 2026Analysis

Selling Cyber Services You're Not Cleared to Sell: The GSA Schedule Scope Trap

Most cyber-fraud enforcement is a failed-NIST-800-171 story. There is a second False Claims Act vector: billing the government for cybersecurity services you were never qualified or authorized to sell. The $14.75M Hill ASC settlement shows how GSA Schedule scope becomes a compliance control.

Read more →
July 2026Compliance Guidance

The System Security Plan: The One Document That Anchors Your Entire Compliance Posture

If a contractor asks which single document matters most for DFARS and CMMC compliance, the answer is almost always the System Security Plan. It's the control auditors check first, the basis of your SPRS score, and — increasingly — the document the government points to when a compliance representation turns out to be false.

Read more →
July 2026Rule Updates

The CMMC Reform RFI Is Open: Contractors Have Until August 14 to Shape What Replaces Phase 2

When the Department of War suspended CMMC Phase 2, the more consequential document was the one it posted the same day: a Request for Information asking the Defense Industrial Base what should replace it. Responses close August 14, 2026 — the window for contractors to put their real cost-and-burden data on the record.

Read more →
July 2026Compliance Guidance

The POA&M Process Under CMMC: What You Can — and Can't — Fix Later

A Plan of Action and Milestones sounds like a compliance escape hatch: fail a few controls, promise to fix them, get certified anyway. The actual rule is much narrower — and with CMMC Phase 2 paused and self-attestation carrying more weight than ever, knowing exactly what a POA&M can and can't cover matters more than it did a month ago.

Read more →

Not Sure Where to Start?

GovConCyber is a free legal reference — not a law firm. We cover the federal cybersecurity rules that apply to government contractors: what they require, who they apply to, and what you need to do. Start here if you're new to the site.

Research

Original, source-anchored analysis on the harder questions — where requirements, contracts, data-handling, and enforcement intersect.

Browse the Reference Library