Skip to main content
Free · Independent · Sourced to primary authority

Government contractor cybersecurity, explained clearly and implemented practically.

Plain-language guidance on the cybersecurity requirements that attach to federal contracts — FAR 52.204-21, DFARS 252.204-7012, CMMC, CUI, NIST SP 800-171, FedRAMP, incident reporting, and the clauses that turn cybersecurity into procurement risk.

Start Here: The Baseline You Already Owe

Before any FAR or DFARS clause applies, federal and state law already requires your business to secure data and report breaches — the FTC Act, all-50-state breach laws, and rules like GLBA and HIPAA. The contractor requirements build on top of that legal baseline. Make sure you meet it first.

See the Legal Baseline →

Recent Developments

September 2026Compliance Guidance

What Your Contract Actually Requires You to Log

FAR 52.204-21 addresses only physical access logs and DFARS 252.204-7012 names no event types or retention period. The real logging obligation is NIST SP 800-171 section 3.3, which leaves six parameters for the contractor to define and sets no retention number at all. Here is what to write down, and why the 90-day incident preservation duty is not a retention policy.

Read more →
September 2026Compliance Guidance

Verify the Validator: What a C3PAO's Authorization Actually Means

Choosing a CMMC Third-Party Assessment Organization is a due-diligence decision, and 32 C.F.R. 170.8 and 170.9 tell you exactly what to check. Authorized and accredited are two different regulatory states, the government vets C3PAOs for foreign ownership and background investigations, and a consultant who prepped you cannot assess you for three years. Here is how to verify the firm that will judge your program.

Read more →
August 2026Rule Updates

Maryland Just Widened Which State Contracts Carry Cyber and Privacy Clauses — Effective October 1

The Maryland Data Privacy and Protection Act of 2026 (Chapter 435, House Bill 264) takes effect October 1, 2026 and rewrites State Finance and Procurement § 13-115. Collecting, storing, or processing personal information is now an independent trigger for mandatory security, data collection, and privacy requirements in Maryland State contracts — no connection to a State system required — and the statutory definition of personal information expanded at the same time.

Read more →
August 2026Rule Updates

CISA Published the Logging Reference Architecture — and Contractor-Operated Systems Are In Scope

CISA published the Logging Reference Architecture on August 20, 2026, implementing OMB Memorandum M-26-14, which rescinded M-21-31 and put federal civilian agencies on a maturity clock for how they log, retain, and produce network data. The memorandum reaches systems operated “by third parties on the agency’s behalf” — so contractor-run systems are inside the agency’s plan, and the obligation will arrive through contract terms rather than the memo itself.

Read more →

Not Sure Where to Start?

GovConCyber is a free legal reference — not a law firm. We cover the federal cybersecurity rules that apply to government contractors: what they require, who they apply to, and what you need to do. Start here if you're new to the site.

Research

Original, source-anchored analysis on the harder questions — where requirements, contracts, data-handling, and enforcement intersect.

Browse the Reference Library