Skip to main content
DAFFARSAgency supplement

Department of the Air Force

The Air Force's procurement supplement, layered on the DoD-wide defense rules.

Last reviewedJune 9, 2026Version v1

Cybersecurity rules in this supplement

DAFFARS layers Air Force specifics on top of the DoD-wide DFARS cyber rules:

DAFFARS Subpart 5304.73 — Safeguarding Covered Defense Information and Cyber Incident Reporting. Implements and supplements DFARS Subpart 204.73 for Air Force acquisitions.

DAFFARS clause 5352.204-9002 — Security Incident Reporting and Procedures. Adds Air Force-specific security-incident reporting requirements.

DAFFARS Subpart 5339.73 — Use of Large Language Models (LLMs/AI tools). Addresses appropriate use of generative-AI tools in Air Force work.

In plain terms

The Air Force follows the full DoD defense cyber rulebook — NIST SP 800-171, SPRS scores, and CMMC — and adds its own incident-reporting steps plus guidance on using AI tools like ChatGPT.

Who it applies to

Air Force contractors and subcontractors handling Federal Contract Information or Covered Defense Information.

What it requires

Everything in the DoD/DFARS cyber baseline (NIST SP 800-171 Rev 2, SPRS, CMMC, 72-hour incident reporting), plus Air Force-specific security-incident procedures and AI-use rules.

Why it matters

Air Force awards apply the DoD cyber regime plus added reporting steps, so contractors must meet both the department-wide and the service-specific requirements.

Citation

Department of the Air Force FAR Supplement (DAFFARS); see also DFARS at 48 C.F.R. Chapter 2.