Cybersecurity rules in this supplement
The DLA Acquisition Directive (DLAD) applies the DoD-wide DFARS cyber rules with logistics-specific additions:
DLAD Subpart 4.73 — Safeguarding Covered Defense Information and Cyber Incident Reporting. Implements DFARS Subpart 204.73 for DLA acquisitions.
DLAD Subsection 4.1303-90 — Personal Identity Verification of Contractor Personnel; 4.1303-91 — Operations Security (OPSEC) for On-site Contractors. Add identity-verification and OPSEC requirements for DLA work.
In plain terms
DLA follows the DoD defense cyber rulebook — NIST SP 800-171, SPRS scores, and CMMC — and adds identity-verification and operations-security requirements for contractors working at or for DLA.
Who it applies to
DLA contractors and subcontractors handling Federal Contract Information or Covered Defense Information, and on-site contractor personnel.
What it requires
Everything in the DoD/DFARS cyber baseline (NIST SP 800-171 Rev 2, SPRS, CMMC, 72-hour incident reporting), plus personal-identity-verification and OPSEC requirements.
Why it matters
DLA's supply-chain role makes both the DoD cyber baseline and its OPSEC/identity rules important to protecting the defense logistics pipeline.
Citation
Defense Logistics Acquisition Directive (DLAD), codified at 48 C.F.R. Chapter 54; see also DFARS at 48 C.F.R. Chapter 2.