Skip to main content
UAIAgency supplement

Army Corps of Engineers

The Army Corps of Engineers' acquisition instructions for its engineering and construction work.

Last reviewedJune 9, 2026Version v1

Cybersecurity rules in this supplement

The Corps' acquisition instructions (UAI) do not add agency-specific cybersecurity-safeguarding clauses of their own. The published instruction addresses privacy:

UAI Subpart 5124.1 — Protection of Individual Privacy. Applies Privacy Act handling to covered work.

Because the Corps is a Department of the Army component, defense cybersecurity requirements reach its work through DoD/DFARS flow-down (NIST SP 800-171, SPRS, CMMC) when Covered Defense Information is involved; otherwise the FAR baseline applies.

In plain terms

The Corps' own instructions add privacy handling, not a separate cyber clause. On defense work, the DoD cyber rules flow down through DFARS; on other work, the FAR baseline governs.

Who it applies to

Army Corps of Engineers contractors and subcontractors; defense cyber rules apply where DFARS flows down.

What it requires

Follow the FAR baseline; where the work involves Covered Defense Information, meet the DoD/DFARS cyber requirements; and comply with Privacy Act handling where applicable.

Why it matters

Identifying the right source of obligations — FAR baseline vs. DFARS flow-down — keeps Corps contractors from over- or under-scoping their cybersecurity duties.

Citation

USACE Acquisition Instruction (UAI); see also DFARS at 48 C.F.R. Chapter 2 for defense flow-down.