Skip to main content
Free · Independent · Sourced to primary authority

Government contractor cybersecurity, explained clearly and implemented practically.

Plain-language guidance on the cybersecurity requirements that attach to federal contracts — FAR 52.204-21, DFARS 252.204-7012, CMMC, CUI, NIST SP 800-171, FedRAMP, incident reporting, and the clauses that turn cybersecurity into procurement risk.

Start Here: The Baseline You Already Owe

Before any FAR or DFARS clause applies, federal and state law already requires your business to secure data and report breaches — the FTC Act, all-50-state breach laws, and rules like GLBA and HIPAA. The contractor requirements build on top of that legal baseline. Make sure you meet it first.

See the Legal Baseline →

Recent Developments

September 2026Rule Updates

NIST Finalizes IR 8587: What Token Security Guidance Means for Federal Cloud Vendors

NIST and CISA finalized joint guidance on protecting identity and access tokens. If you sell cloud services to a federal agency, it describes what your customer will expect you to deliver.

Read more →
September 2026Compliance Guidance

Putting CUI in the Cloud: What DFARS 7012 Actually Requires of Your Provider

Most defense contractors store covered defense information somewhere they do not own. DFARS 252.204-7012 has a specific paragraph about that, and it asks for more than a vendor's assurance.

Read more →
September 2026Rule Updates

NIST Just Published an Assessment Primer for Small Contractors — and Confirmed CMMC Still Runs on Revision 2

NIST's new SP 1352 walks small contractors through how a CUI security assessment actually works - and states expressly that CMMC still leverages SP 800-171 Revision 2 and SP 800-171A Revision 2, not Revision 3.

Read more →
September 2026Rule Updates

A New Supply-Chain Prohibition Regime Just Opened Its Comment Window — and a FAR Rule Is Already Scheduled

Most contractors read "bulk-power system" and stop. That is a mistake. The executive order behind this rulemaking defines "procurement" in federal-acquisition terms, tasks the FAR Council with a rule, and reaches installation services — which is to say, it reaches contractors.

Read more →

Not Sure Where to Start?

GovConCyber is a free legal reference — not a law firm. We cover the federal cybersecurity rules that apply to government contractors: what they require, who they apply to, and what you need to do. Start here if you're new to the site.

Research

Original, source-anchored analysis on the harder questions — where requirements, contracts, data-handling, and enforcement intersect.

Browse the Reference Library