Skip to main content
DOSARAgency supplement

Department of State

The State Department's procurement supplement.

Last reviewedJune 9, 2026Version v1

Cybersecurity rules in this supplement

The Department of State Acquisition Regulation (DOSAR) addresses IT security for unclassified systems:

DOSAR Part 639 — Acquisition of Information Technology. Sets State's policy for acquiring and securing IT.

DOSAR provision 652.239-70 — Information Technology Security Plan and Accreditation. Requires offerors to submit an IT security plan and obtain accreditation for systems used on the contract.

DOSAR clause 652.239-71 — Security Requirements for Unclassified Information Technology Resources. Requires contractors to secure unclassified IT resources to State and federal standards.

DOSAR clause 652.204-70 — Personal Identification Card Policy and Procedures. Governs identity credentials for contractor personnel.

In plain terms

State requires that any unclassified IT you use on its behalf be secured and formally accredited, with a security plan submitted up front, and that your personnel carry proper identity credentials.

Who it applies to

Contractors and subcontractors that provide or operate unclassified information technology for the Department of State.

What it requires

Follow the FAR baseline, then: submit an IT security plan and obtain accreditation, secure unclassified IT resources to State/federal standards, and meet personal-identity-credential requirements.

Why it matters

State's global IT footprint and sensitive diplomatic information make accreditation and IT-security compliance prerequisites for performance.

Citation

Department of State Acquisition Regulation (DOSAR), codified at 48 C.F.R. Chapter 6.