Cybersecurity rules in this supplement
The Commerce Acquisition Regulation (CAR) adds IT-security and information-handling rules:
CAR Subsection 1339.107-70 / clause 1352.239-72 — Security Requirements for Information Technology Resources. Requires contractors that handle Commerce IT or sensitive information to meet Commerce IT-security policy, FISMA, and NIST requirements, and to maintain an IT security plan and authorization.
CAR clauses 1352.209-72 / -75 — Restrictions Against Disclosure; Title 13 Non-Disclosure. Protect confidential and Title 13 (Census) data from disclosure.
In plain terms
Commerce is the home of NIST, and its IT-security clause holds contractors to recognized federal standards: secure the IT you use for Commerce, keep a security plan and authorization, and protect confidential data — including Census Title 13 information, which carries strict non-disclosure rules.
Who it applies to
Contractors and subcontractors that operate or access Commerce information technology or handle Commerce sensitive or Title 13 data.
What it requires
Follow the FAR baseline, then: meet Commerce IT-security requirements (FISMA/NIST), maintain a security plan and authorization for IT resources, and honor the disclosure restrictions on confidential and Title 13 data.
Why it matters
Commerce bureaus (including the Census Bureau and NOAA) handle data with statutory confidentiality, so its IT-security and non-disclosure clauses are central to compliant performance.
Citation
Commerce Acquisition Regulation (CAR), codified at 48 C.F.R. Chapter 13.