Skip to main content
TARAgency supplement

Department of Transportation

DOT's procurement supplement.

Last reviewedJune 9, 2026Version v1

Cybersecurity rules in this supplement

The Transportation Acquisition Regulation (TAR) carries one of the most detailed agency cyber clause sets outside DoD:

TAR Subpart 1239.70 / clause 1252.239-74 — Safeguarding DOT Sensitive Data and Cyber Incident Reporting. Requires you to protect DOT-sensitive data and report cyber incidents to DOT within defined timeframes (see 1252.239-83).

TAR 1252.239-72 — Compliance with Safeguarding DOT Sensitive Data Controls. A representation, included in solicitations, that you will meet DOT's data-safeguarding controls.

TAR 1252.239-73 — Limitations on Use or Disclosure of Third-Party Contractor Reported Cyber Incident Information. Protects incident information you report.

TAR Subpart 1239.72 / clauses 1252.239-76 through -91 — Cloud Computing and security controls. A large block covering cloud services, data jurisdiction, validated cryptography, data integrity and non-repudiation, audit-record retention, multi-factor authentication, media transport, trusted-internet-connection boundary protection, protection of information at rest, and records management.

TAR clause 1252.239-70 — Security Requirements for Unclassified Information Technology Resources; 1252.239-71 — IT Security Plan and Accreditation. Require a security plan and accreditation for IT resources used on the contract.

In plain terms

DOT spells out, clause by clause, how to secure its sensitive data and any cloud or IT systems you use on its behalf — from encryption and multi-factor authentication to how fast you must report an incident. If you build, host, or operate IT for DOT, this is an unusually prescriptive set of controls.

Who it applies to

Contractors and subcontractors that handle DOT-sensitive data or provide IT or cloud services to DOT.

What it requires

Follow the FAR baseline, then: safeguard DOT-sensitive data, maintain an IT security plan and accreditation, meet the detailed cloud-computing controls (encryption, MFA, audit logging, data jurisdiction, boundary protection), and report cyber incidents within DOT's timeframes.

Why it matters

DOT's clause set is detailed and specific, so gaps are easy to spot in an audit. The cloud and incident-reporting requirements in particular are conditions of doing IT work for the department.

Citation

Transportation Acquisition Regulation (TAR), codified at 48 C.F.R. Chapter 12.