Skip to main content
Free · Independent · Sourced to primary authority

Government contractor cybersecurity, explained clearly and implemented practically.

Plain-language guidance on the cybersecurity requirements that attach to federal contracts — FAR 52.204-21, DFARS 252.204-7012, CMMC, CUI, NIST SP 800-171, FedRAMP, incident reporting, and the clauses that turn cybersecurity into procurement risk.

Start Here: The Baseline You Already Owe

Before any FAR or DFARS clause applies, federal and state law already requires your business to secure data and report breaches — the FTC Act, all-50-state breach laws, and rules like GLBA and HIPAA. The contractor requirements build on top of that legal baseline. Make sure you meet it first.

See the Legal Baseline →

Recent Developments

September 2026Rule Updates

A New Supply-Chain Prohibition Regime Just Opened Its Comment Window — and a FAR Rule Is Already Scheduled

Most contractors read "bulk-power system" and stop. That is a mistake. The executive order behind this rulemaking defines "procurement" in federal-acquisition terms, tasks the FAR Council with a rule, and reaches installation services — which is to say, it reaches contractors.

Read more →
September 2026Compliance Guidance

The 72-Hour Clock: What DFARS 252.204-7012 Actually Requires You to Do

Nearly every defense contractor can recite the 72-hour reporting deadline. Far fewer have the credential required to file the report — and that credential cannot be obtained in 72 hours.

Read more →
September 2026Case Law

One Network, Four Years, $2 Million: The Honeywell Aerospace Cyber-Fraud Settlement

A single non-compliant network, a qui tam complaint filed in 2022, and a corporate spin-off that closed two months before the settlement — the Honeywell resolution is a compact lesson in how long cybersecurity exposure lasts and who ends up carrying it.

Read more →
September 2026Compliance Guidance

What Your Contract Actually Requires You to Log

FAR 52.204-21 addresses only physical access logs and DFARS 252.204-7012 names no event types or retention period. The real logging obligation is NIST SP 800-171 section 3.3, which leaves six parameters for the contractor to define and sets no retention number at all. Here is what to write down, and why the 90-day incident preservation duty is not a retention policy.

Read more →

Not Sure Where to Start?

GovConCyber is a free legal reference — not a law firm. We cover the federal cybersecurity rules that apply to government contractors: what they require, who they apply to, and what you need to do. Start here if you're new to the site.

Research

Original, source-anchored analysis on the harder questions — where requirements, contracts, data-handling, and enforcement intersect.

Browse the Reference Library