Skip to main content
Free · Independent · Sourced to primary authority

Government contractor cybersecurity, explained clearly and implemented practically.

Plain-language guidance on the cybersecurity requirements that attach to federal contracts — FAR 52.204-21, DFARS 252.204-7012, CMMC, CUI, NIST SP 800-171, FedRAMP, incident reporting, and the clauses that turn cybersecurity into procurement risk.

Start Here: The Baseline You Already Owe

Before any FAR or DFARS clause applies, federal and state law already requires your business to secure data and report breaches — the FTC Act, all-50-state breach laws, and rules like GLBA and HIPAA. The contractor requirements build on top of that legal baseline. Make sure you meet it first.

See the Legal Baseline →

Recent Developments

August 2026Rule Updates

NIST Rewrites Federal IoT Security Guidance — Comments Close August 24

If you sell connected hardware to a federal agency — cameras, sensors, badge readers, building controls, medical devices, fleet telematics — the document that shapes what agencies will demand of your product is open for comment for one more week.

Read more →
August 2026Rule Updates

GSA Already Moved to NIST 800-171 Rev. 3 — While DoD Is Still on Rev. 2

Most contractors track the CUI standard through the DFARS. That is not the only place it lives. On the civilian side, one agency has already pointed its contractor CUI requirements at Revision 3 — and the defense timetable had nothing to do with it.

Read more →
August 2026Case Law

Cyber-Fraud Enforcement Isn't Just a Defense Problem: The Verizon MTIPS Settlement

Most cyber-fraud settlements involve the Pentagon, NIST SP 800-171, and SPRS scores. This one involved the GSA, a civilian internet service, and a set of controls most defense contractors have never heard of — and it shows the enforcement risk reaches well beyond the defense industrial base.

Read more →
August 2026Case Law

Penn State's $1.25M Settlement: When the POA&M Dates You Promised Become the Fraud You Pay For

Penn State agreed to pay $1.25 million to resolve False Claims Act allegations across fifteen DoD and NASA contracts — but the core theory was not a false cybersecurity score. It was allegedly false POA&M milestone dates: promising when gaps would be fixed and then not doing the work. Here is why an unworked plan of action, and an unvetted cloud, are each independent FCA exposure.

Read more →

Not Sure Where to Start?

GovConCyber is a free legal reference — not a law firm. We cover the federal cybersecurity rules that apply to government contractors: what they require, who they apply to, and what you need to do. Start here if you're new to the site.

Research

Original, source-anchored analysis on the harder questions — where requirements, contracts, data-handling, and enforcement intersect.

Browse the Reference Library