Skip to main content
Free · Independent · Sourced to primary authority

Government contractor cybersecurity, explained clearly and implemented practically.

Plain-language guidance on the cybersecurity requirements that attach to federal contracts — FAR 52.204-21, DFARS 252.204-7012, CMMC, CUI, NIST SP 800-171, FedRAMP, incident reporting, and the clauses that turn cybersecurity into procurement risk.

Start Here: The Baseline You Already Owe

Before any FAR or DFARS clause applies, federal and state law already requires your business to secure data and report breaches — the FTC Act, all-50-state breach laws, and rules like GLBA and HIPAA. The contractor requirements build on top of that legal baseline. Make sure you meet it first.

See the Legal Baseline →

Recent Developments

August 2026Case Law

When Your Own Security Plan Becomes the Government's Evidence: The Health Net/Centene TRICARE Settlement

The government did not measure this contractor against an outside benchmark. It measured the contractor against the remediation deadlines the contractor wrote for itself — and that was enough to support an $11.25 million False Claims Act resolution.

Read more →
August 2026Rule Updates

OMB Rescinded the Governmentwide Software Attestation Mandate — Now Each Agency Sets Its Own Terms

For two years, software producers selling to the federal government worked from a single assumption: sign the CISA Common Form or the agency cannot use your product. That assumption is no longer correct — and the replacement is harder to track, not easier.

Read more →
August 2026Rule Updates

GSA Already Moved to NIST 800-171 Rev. 3 — While DoD Is Still on Rev. 2

Most contractors track the CUI standard through the DFARS. That is not the only place it lives. On the civilian side, one agency has already pointed its contractor CUI requirements at Revision 3 — and the defense timetable had nothing to do with it.

Read more →
August 2026Rule Updates

NIST Rewrites Federal IoT Security Guidance — Comments Close August 24

If you sell connected hardware to a federal agency — cameras, sensors, badge readers, building controls, medical devices, fleet telematics — the document that shapes what agencies will demand of your product is open for comment for one more week.

Read more →

Not Sure Where to Start?

GovConCyber is a free legal reference — not a law firm. We cover the federal cybersecurity rules that apply to government contractors: what they require, who they apply to, and what you need to do. Start here if you're new to the site.

Research

Original, source-anchored analysis on the harder questions — where requirements, contracts, data-handling, and enforcement intersect.

Browse the Reference Library