Skip to main content
DLADAgency supplement

Defense Logistics Agency

DLA's acquisition supplement for defense supply and logistics contracts.

Last reviewedJune 9, 2026Version v1

Cybersecurity rules in this supplement

The DLA Acquisition Directive (DLAD) applies the DoD-wide DFARS cyber rules with logistics-specific additions:

DLAD Subpart 4.73 — Safeguarding Covered Defense Information and Cyber Incident Reporting. Implements DFARS Subpart 204.73 for DLA acquisitions.

DLAD Subsection 4.1303-90 — Personal Identity Verification of Contractor Personnel; 4.1303-91 — Operations Security (OPSEC) for On-site Contractors. Add identity-verification and OPSEC requirements for DLA work.

In plain terms

DLA follows the DoD defense cyber rulebook — NIST SP 800-171, SPRS scores, and CMMC — and adds identity-verification and operations-security requirements for contractors working at or for DLA.

Who it applies to

DLA contractors and subcontractors handling Federal Contract Information or Covered Defense Information, and on-site contractor personnel.

What it requires

Everything in the DoD/DFARS cyber baseline (NIST SP 800-171 Rev 2, SPRS, CMMC, 72-hour incident reporting), plus personal-identity-verification and OPSEC requirements.

Why it matters

DLA's supply-chain role makes both the DoD cyber baseline and its OPSEC/identity rules important to protecting the defense logistics pipeline.

Citation

Defense Logistics Acquisition Directive (DLAD), codified at 48 C.F.R. Chapter 54; see also DFARS at 48 C.F.R. Chapter 2.