Skip to main content
Free · Independent · Sourced to primary authority

Government contractor cybersecurity, explained clearly and implemented practically.

Plain-language guidance on the cybersecurity requirements that attach to federal contracts — FAR 52.204-21, DFARS 252.204-7012, CMMC, CUI, NIST SP 800-171, FedRAMP, incident reporting, and the clauses that turn cybersecurity into procurement risk.

Start Here: The Baseline You Already Owe

Before any FAR or DFARS clause applies, federal and state law already requires your business to secure data and report breaches — the FTC Act, all-50-state breach laws, and rules like GLBA and HIPAA. The contractor requirements build on top of that legal baseline. Make sure you meet it first.

See the Legal Baseline →

Recent Developments

August 2026Case Law

The Certifier That Did Not Exist: AiNET, the SEC, and the Cost of a Fabricated Certification

DOJ announced a $1,800,000 False Claims Act settlement with AiNET Corp. and former CEO Deepak Jain over allegations that they certified a data center inspection by an entity the United States alleged was not an operating company and never performed the inspection. The standard at issue was infrastructure resilience, but the legal theory is the same one driving cyber enforcement — and it lands as third-party validation becomes the price of eligibility.

Read more →
August 2026Case Law

When Your Own Security Plan Becomes the Government's Evidence: The Health Net/Centene TRICARE Settlement

The government did not measure this contractor against an outside benchmark. It measured the contractor against the remediation deadlines the contractor wrote for itself — and that was enough to support an $11.25 million False Claims Act resolution.

Read more →
August 2026Rule Updates

OMB Rescinded the Governmentwide Software Attestation Mandate — Now Each Agency Sets Its Own Terms

For two years, software producers selling to the federal government worked from a single assumption: sign the CISA Common Form or the agency cannot use your product. That assumption is no longer correct — and the replacement is harder to track, not easier.

Read more →
August 2026Rule Updates

GSA Already Moved to NIST 800-171 Rev. 3 — While DoD Is Still on Rev. 2

Most contractors track the CUI standard through the DFARS. That is not the only place it lives. On the civilian side, one agency has already pointed its contractor CUI requirements at Revision 3 — and the defense timetable had nothing to do with it.

Read more →

Not Sure Where to Start?

GovConCyber is a free legal reference — not a law firm. We cover the federal cybersecurity rules that apply to government contractors: what they require, who they apply to, and what you need to do. Start here if you're new to the site.

Research

Original, source-anchored analysis on the harder questions — where requirements, contracts, data-handling, and enforcement intersect.

Browse the Reference Library