Skip to main content
Free · Independent · Sourced to primary authority

Government contractor cybersecurity, explained clearly and implemented practically.

Plain-language guidance on the cybersecurity requirements that attach to federal contracts — FAR 52.204-21, DFARS 252.204-7012, CMMC, CUI, NIST SP 800-171, FedRAMP, incident reporting, and the clauses that turn cybersecurity into procurement risk.

Start Here: The Baseline You Already Owe

Before any FAR or DFARS clause applies, federal and state law already requires your business to secure data and report breaches — the FTC Act, all-50-state breach laws, and rules like GLBA and HIPAA. The contractor requirements build on top of that legal baseline. Make sure you meet it first.

See the Legal Baseline →

Recent Developments

September 2026Compliance Guidance

The 72-Hour Clock: What DFARS 252.204-7012 Actually Requires You to Do

Nearly every defense contractor can recite the 72-hour reporting deadline. Far fewer have the credential required to file the report — and that credential cannot be obtained in 72 hours.

Read more →
September 2026Case Law

One Network, Four Years, $2 Million: The Honeywell Aerospace Cyber-Fraud Settlement

A single non-compliant network, a qui tam complaint filed in 2022, and a corporate spin-off that closed two months before the settlement — the Honeywell resolution is a compact lesson in how long cybersecurity exposure lasts and who ends up carrying it.

Read more →
September 2026Compliance Guidance

What Your Contract Actually Requires You to Log

FAR 52.204-21 addresses only physical access logs and DFARS 252.204-7012 names no event types or retention period. The real logging obligation is NIST SP 800-171 section 3.3, which leaves six parameters for the contractor to define and sets no retention number at all. Here is what to write down, and why the 90-day incident preservation duty is not a retention policy.

Read more →
September 2026Compliance Guidance

Verify the Validator: What a C3PAO's Authorization Actually Means

Choosing a CMMC Third-Party Assessment Organization is a due-diligence decision, and 32 C.F.R. 170.8 and 170.9 tell you exactly what to check. Authorized and accredited are two different regulatory states, the government vets C3PAOs for foreign ownership and background investigations, and a consultant who prepped you cannot assess you for three years. Here is how to verify the firm that will judge your program.

Read more →

Not Sure Where to Start?

GovConCyber is a free legal reference — not a law firm. We cover the federal cybersecurity rules that apply to government contractors: what they require, who they apply to, and what you need to do. Start here if you're new to the site.

Research

Original, source-anchored analysis on the harder questions — where requirements, contracts, data-handling, and enforcement intersect.

Browse the Reference Library