Skip to main content
DEARAgency supplement

Department of Energy

DOE's procurement supplement — notable for national-security and nuclear-related work.

Last reviewedJune 9, 2026Version v1

Cybersecurity rules in this supplement

The Department of Energy Acquisition Regulation (DEAR) addresses computer security and sensitive information at DOE sites:

DEAR clause 952.204-77 — Computer Security. Requires contractors using DOE computer systems or networks to comply with DOE computer-security requirements and protect DOE information.

DEAR Section 970.0370 / clauses 970.5203-1, 970.5204-1, 970.5204-3 — Management Controls, Counterintelligence, and Access to/Ownership of Records. Apply to DOE's management-and-operating (M&O) contractors at national laboratories and sites, covering security management, counterintelligence, and control of records.

DEAR Subsection 970.0371-5 — Use of Privileged Information. Restricts use of privileged or sensitive DOE information.

In plain terms

DOE's rules reflect its national-security mission. Anyone using DOE computer systems must follow DOE computer-security requirements, and the management-and-operating contractors that run DOE's national labs carry extra obligations for security management, counterintelligence, and records control.

Who it applies to

Contractors and subcontractors using DOE computer systems, and (for the Part 970 clauses) management-and-operating contractors at DOE laboratories and sites.

What it requires

Follow the FAR baseline, then: comply with DOE computer-security requirements, protect DOE and privileged information, and (for M&O contractors) meet the management-control, counterintelligence, and records requirements.

Why it matters

DOE work can involve nuclear and national-security information, so its computer-security and counterintelligence requirements carry heightened consequences for noncompliance.

Citation

Department of Energy Acquisition Regulation (DEAR), codified at 48 C.F.R. Chapter 9.