Skip to main content
Free · Independent · Sourced to primary authority

Government contractor cybersecurity, explained clearly and implemented practically.

Plain-language guidance on the cybersecurity requirements that attach to federal contracts — FAR 52.204-21, DFARS 252.204-7012, CMMC, CUI, NIST SP 800-171, FedRAMP, incident reporting, and the clauses that turn cybersecurity into procurement risk.

Start Here: The Baseline You Already Owe

Before any FAR or DFARS clause applies, federal and state law already requires your business to secure data and report breaches — the FTC Act, all-50-state breach laws, and rules like GLBA and HIPAA. The contractor requirements build on top of that legal baseline. Make sure you meet it first.

See the Legal Baseline →

Recent Developments

September 2026Compliance Guidance

Putting CUI in the Cloud: What DFARS 7012 Actually Requires of Your Provider

Most defense contractors store covered defense information somewhere they do not own. DFARS 252.204-7012 has a specific paragraph about that, and it asks for more than a vendor's assurance.

Read more →
September 2026Rule Updates

NIST Just Published an Assessment Primer for Small Contractors — and Confirmed CMMC Still Runs on Revision 2

NIST's new SP 1352 walks small contractors through how a CUI security assessment actually works - and states expressly that CMMC still leverages SP 800-171 Revision 2 and SP 800-171A Revision 2, not Revision 3.

Read more →
September 2026Rule Updates

A New Supply-Chain Prohibition Regime Just Opened Its Comment Window — and a FAR Rule Is Already Scheduled

Most contractors read "bulk-power system" and stop. That is a mistake. The executive order behind this rulemaking defines "procurement" in federal-acquisition terms, tasks the FAR Council with a rule, and reaches installation services — which is to say, it reaches contractors.

Read more →
September 2026Compliance Guidance

The 72-Hour Clock: What DFARS 252.204-7012 Actually Requires You to Do

Nearly every defense contractor can recite the 72-hour reporting deadline. Far fewer have the credential required to file the report — and that credential cannot be obtained in 72 hours.

Read more →

Not Sure Where to Start?

GovConCyber is a free legal reference — not a law firm. We cover the federal cybersecurity rules that apply to government contractors: what they require, who they apply to, and what you need to do. Start here if you're new to the site.

Research

Original, source-anchored analysis on the harder questions — where requirements, contracts, data-handling, and enforcement intersect.

Browse the Reference Library