Skip to main content
Free · Independent · Sourced to primary authority

Government contractor cybersecurity, explained clearly and implemented practically.

Plain-language guidance on the cybersecurity requirements that attach to federal contracts — FAR 52.204-21, DFARS 252.204-7012, CMMC, CUI, NIST SP 800-171, FedRAMP, incident reporting, and the clauses that turn cybersecurity into procurement risk.

Start Here: The Baseline You Already Owe

Before any FAR or DFARS clause applies, federal and state law already requires your business to secure data and report breaches — the FTC Act, all-50-state breach laws, and rules like GLBA and HIPAA. The contractor requirements build on top of that legal baseline. Make sure you meet it first.

See the Legal Baseline →

Recent Developments

September 2026Rule Updates

DFARS 252.240-7992: DoD Now Bars Contractors From Selling or Transferring Its Personnel's Data

A two-paragraph clause with a flowdown that reaches your payroll vendor, your SaaS stack, and every commercial subcontract.

Read more →
September 2026Case Law

Pannek v. ADM: A Cyber-FCA Complaint Dismissed on Materiality — and What the Court Left Standing

The government caring about cybersecurity in general is not the same as the government caring about your cybersecurity when it decides to pay you.

Read more →
September 2026Rule Updates

NIST Reopens OT Security Guidance: SP 800-82 Rev. 4 Draft Lands, Comments Due November 30

If your contract performance involves a machine shop, a shipyard, a test stand, a building control system, or a water treatment skid, the federal government's reference document for securing that equipment is open for comment — and it just got substantially broader.

Read more →
September 2026Rule Updates

NIST Finalizes IR 8587: What Token Security Guidance Means for Federal Cloud Vendors

NIST and CISA finalized joint guidance on protecting identity and access tokens. If you sell cloud services to a federal agency, it describes what your customer will expect you to deliver.

Read more →

Not Sure Where to Start?

GovConCyber is a free legal reference — not a law firm. We cover the federal cybersecurity rules that apply to government contractors: what they require, who they apply to, and what you need to do. Start here if you're new to the site.

Research

Original, source-anchored analysis on the harder questions — where requirements, contracts, data-handling, and enforcement intersect.

Browse the Reference Library