Skip to main content
DARSAgency supplement

Defense Information Systems Agency

DISA's acquisition supplement for defense IT and communications buys.

Last reviewedJune 9, 2026Version v1

Cybersecurity rules in this supplement

DISA's acquisition supplement does not publish standalone cybersecurity clauses of its own. As a Department of Defense component, DISA applies the DoD-wide DFARS cyber rules:

DFARS Subpart 204.73 / 252.204-7012, 252.204-7019/7020, and Subpart 204.75 / 252.204-7021 (CMMC). Flow down to DISA acquisitions when Federal Contract Information or Covered Defense Information is involved.

In plain terms

DISA buys defense IT and communications, and it applies the standard DoD cyber rulebook — NIST SP 800-171, SPRS scores, and CMMC — rather than a separate DISA-only clause.

Who it applies to

DISA contractors and subcontractors handling Federal Contract Information or Covered Defense Information.

What it requires

Meet the DoD/DFARS cyber baseline: implement NIST SP 800-171 Rev 2, post an SPRS score, hold the required CMMC level, and report cyber incidents within 72 hours.

Why it matters

DISA's IT and communications work sits at the center of defense networks, so the DoD cyber requirements apply directly even without a DISA-specific clause.

Citation

DISA applies the Defense Federal Acquisition Regulation Supplement (DFARS), 48 C.F.R. Chapter 2.