Skip to main content
HSARAgency supplement

Department of Homeland Security

DHS's procurement supplement, with its own safeguarding and IT-security clauses.

Last reviewedJune 9, 2026Version v1

Cybersecurity rules in this supplement

The Homeland Security Acquisition Regulation (HSAR) finalized its CUI safeguarding rule in 2023:

HSAR clause 3052.204-72 — Safeguarding of Controlled Unclassified Information. Requires contractors handling DHS CUI to apply security and privacy controls, encrypt CUI in transit using a FIPS-validated cryptographic module, and report any cyber incident affecting CUI within 8 hours of discovery.

HSAR clause 3052.204-73 — Notification and Credit Monitoring Requirements for PII Incidents. Where an incident involves personally identifiable information, reporting is required within 1 hour, and the contractor must provide notification and credit monitoring.

HSAR clause 3052.204-71 — Contractor Employee Access. Governs background vetting and access for contractor employees who handle DHS information or enter DHS facilities/systems.

HSAR Subpart 3004.4 — Safeguarding Classified and Controlled Unclassified Information Within Industry. Sets the policy framework behind the clauses above.

In plain terms

If you handle DHS controlled unclassified information, HSAR gives you hard deadlines: report a cyber incident within 8 hours, and within 1 hour if personal data is involved — then provide credit monitoring. CUI must be encrypted with government-validated cryptography, and your staff must be vetted for access.

Who it applies to

Contractors and subcontractors whose employees access DHS CUI, or where CUI is collected or maintained on the agency's behalf.

What it requires

Follow the FAR baseline, then: safeguard DHS CUI with required security/privacy controls and FIPS-validated encryption, vet personnel for access, and meet the 8-hour (CUI) / 1-hour (PII) incident-reporting and credit-monitoring obligations.

Why it matters

DHS's reporting windows are among the tightest in government contracting, and the PII credit-monitoring requirement carries direct cost. These are firm, final-rule obligations, not guidance.

Citation

Homeland Security Acquisition Regulation (HSAR), codified at 48 C.F.R. Chapter 30.