Skip to main content
Free · Independent · Sourced to primary authority

Government contractor cybersecurity, explained clearly and implemented practically.

Plain-language guidance on the cybersecurity requirements that attach to federal contracts — FAR 52.204-21, DFARS 252.204-7012, CMMC, CUI, NIST SP 800-171, FedRAMP, incident reporting, and the clauses that turn cybersecurity into procurement risk.

Start Here: The Baseline You Already Owe

Before any FAR or DFARS clause applies, federal and state law already requires your business to secure data and report breaches — the FTC Act, all-50-state breach laws, and rules like GLBA and HIPAA. The contractor requirements build on top of that legal baseline. Make sure you meet it first.

See the Legal Baseline →

Recent Developments

July 2026Compliance Guidance

The System Security Plan: The One Document That Anchors Your Entire Compliance Posture

If a contractor asks which single document matters most for DFARS and CMMC compliance, the answer is almost always the System Security Plan. It's the control auditors check first, the basis of your SPRS score, and — increasingly — the document the government points to when a compliance representation turns out to be false.

Read more →
July 2026Rule Updates

The CMMC Reform RFI Is Open: Contractors Have Until August 14 to Shape What Replaces Phase 2

When the Department of War suspended CMMC Phase 2, the more consequential document was the one it posted the same day: a Request for Information asking the Defense Industrial Base what should replace it. Responses close August 14, 2026 — the window for contractors to put their real cost-and-burden data on the record.

Read more →
July 2026Compliance Guidance

The POA&M Process Under CMMC: What You Can — and Can't — Fix Later

A Plan of Action and Milestones sounds like a compliance escape hatch: fail a few controls, promise to fix them, get certified anyway. The actual rule is much narrower — and with CMMC Phase 2 paused and self-attestation carrying more weight than ever, knowing exactly what a POA&M can and can't cover matters more than it did a month ago.

Read more →
July 2026Rule Updates

CMMC Phase 2 Suspended: What the Department of War's July 2026 Reversal Means for Contractors

The Department of War suspended CMMC Phase 2 certification requirements on July 13, 2026, launching a 60-day reform review while Phase 1 self-assessments and DFARS 252.204-7012 remain in force.

Read more →

Not Sure Where to Start?

GovConCyber is a free legal reference — not a law firm. We cover the federal cybersecurity rules that apply to government contractors: what they require, who they apply to, and what you need to do. Start here if you're new to the site.

Research

Original, source-anchored analysis on the harder questions — where requirements, contracts, data-handling, and enforcement intersect.

Browse the Reference Library