Skip to main content
Free · Independent · Sourced to primary authority

Government contractor cybersecurity, explained clearly and implemented practically.

Plain-language guidance on the cybersecurity requirements that attach to federal contracts — FAR 52.204-21, DFARS 252.204-7012, CMMC, CUI, NIST SP 800-171, FedRAMP, incident reporting, and the clauses that turn cybersecurity into procurement risk.

Start Here: The Baseline You Already Owe

Before any FAR or DFARS clause applies, federal and state law already requires your business to secure data and report breaches — the FTC Act, all-50-state breach laws, and rules like GLBA and HIPAA. The contractor requirements build on top of that legal baseline. Make sure you meet it first.

See the Legal Baseline →

Recent Developments

August 2026Case Law

The Georgia Tech Case Ends at $875K: How a 'Fictitious' Network Resolved a Landmark Cyber-Fraud Fight

Georgia Tech Research Corporation will pay $875,000 to resolve one of the few litigated Civil Cyber-Fraud Initiative cases — built on missing anti-malware, no system security plan, and a false campus-wide score of 98 premised on a "fictitious" network. Here's how the landmark fight ended and what it means for contractor self-assessments.

Read more →
August 2026Case Law

A Machine Shop, a $421K Settlement, and Proof That Cyber Rules Reach the Supply Chain's Bottom Rung

A precision machine shop that never held a direct DoD contract paid $421,234 to resolve cyber-fraud allegations over technical drawings it supplied to defense primes. The Swiss Automation settlement is the clearest recent proof that NIST 800-171 cybersecurity flowdown reaches the bottom of the supply chain.

Read more →
July 2026Analysis

Selling Cyber Services You're Not Cleared to Sell: The GSA Schedule Scope Trap

Most cyber-fraud enforcement is a failed-NIST-800-171 story. There is a second False Claims Act vector: billing the government for cybersecurity services you were never qualified or authorized to sell. The $14.75M Hill ASC settlement shows how GSA Schedule scope becomes a compliance control.

Read more →
July 2026Compliance Guidance

The System Security Plan: The One Document That Anchors Your Entire Compliance Posture

If a contractor asks which single document matters most for DFARS and CMMC compliance, the answer is almost always the System Security Plan. It's the control auditors check first, the basis of your SPRS score, and — increasingly — the document the government points to when a compliance representation turns out to be false.

Read more →

Not Sure Where to Start?

GovConCyber is a free legal reference — not a law firm. We cover the federal cybersecurity rules that apply to government contractors: what they require, who they apply to, and what you need to do. Start here if you're new to the site.

Research

Original, source-anchored analysis on the harder questions — where requirements, contracts, data-handling, and enforcement intersect.

Browse the Reference Library