Skip to main content
Free · Independent · Sourced to primary authority

Government contractor cybersecurity, explained clearly and implemented practically.

Plain-language guidance on the cybersecurity requirements that attach to federal contracts — FAR 52.204-21, DFARS 252.204-7012, CMMC, CUI, NIST SP 800-171, FedRAMP, incident reporting, and the clauses that turn cybersecurity into procurement risk.

Start Here: The Baseline You Already Owe

Before any FAR or DFARS clause applies, federal and state law already requires your business to secure data and report breaches — the FTC Act, all-50-state breach laws, and rules like GLBA and HIPAA. The contractor requirements build on top of that legal baseline. Make sure you meet it first.

See the Legal Baseline →

Recent Developments

August 2026Case Law

Penn State's $1.25M Settlement: When the POA&M Dates You Promised Become the Fraud You Pay For

Penn State agreed to pay $1.25 million to resolve False Claims Act allegations across fifteen DoD and NASA contracts — but the core theory was not a false cybersecurity score. It was allegedly false POA&M milestone dates: promising when gaps would be fixed and then not doing the work. Here is why an unworked plan of action, and an unvetted cloud, are each independent FCA exposure.

Read more →
August 2026Case Law

A Machine Shop, a $421K Settlement, and Proof That Cyber Rules Reach the Supply Chain's Bottom Rung

A precision machine shop that never held a direct DoD contract paid $421,234 to resolve cyber-fraud allegations over technical drawings it supplied to defense primes. The Swiss Automation settlement is the clearest recent proof that NIST 800-171 cybersecurity flowdown reaches the bottom of the supply chain.

Read more →
August 2026Case Law

The Georgia Tech Case Ends at $875K: How a 'Fictitious' Network Resolved a Landmark Cyber-Fraud Fight

Georgia Tech Research Corporation will pay $875,000 to resolve one of the few litigated Civil Cyber-Fraud Initiative cases — built on missing anti-malware, no system security plan, and a false campus-wide score of 98 premised on a "fictitious" network. Here's how the landmark fight ended and what it means for contractor self-assessments.

Read more →
July 2026Analysis

Selling Cyber Services You're Not Cleared to Sell: The GSA Schedule Scope Trap

Most cyber-fraud enforcement is a failed-NIST-800-171 story. There is a second False Claims Act vector: billing the government for cybersecurity services you were never qualified or authorized to sell. The $14.75M Hill ASC settlement shows how GSA Schedule scope becomes a compliance control.

Read more →

Not Sure Where to Start?

GovConCyber is a free legal reference — not a law firm. We cover the federal cybersecurity rules that apply to government contractors: what they require, who they apply to, and what you need to do. Start here if you're new to the site.

Research

Original, source-anchored analysis on the harder questions — where requirements, contracts, data-handling, and enforcement intersect.

Browse the Reference Library