Cybersecurity rules in this supplement
The GSA Acquisition Regulation (GSAR) sets requirements for GSA information systems:
GSAR Section 511.171 — Requirements for GSA Information Systems. Requires contractors that handle GSA information or operate GSA systems to meet GSA IT-security and information-handling requirements (consistent with FISMA and NIST).
GSAR Section 511.170 — Information Technology Coordination and Standards. Sets IT coordination and standards policy for GSA acquisitions.
GSAR clause 552.239-71-type IT-security terms and the personal-identity-verification requirements at 552.204-9 support system access and credentialing.
(Note: GSA's proposed CUI/cyber clauses continue to evolve; the requirements above are the established GSAR provisions.)
In plain terms
GSA is a hub for governmentwide buying, so when you handle GSA's own information or run a GSA system, you must meet GSA's IT-security and information-handling standards and credential your people properly.
Who it applies to
Contractors and subcontractors that operate GSA information systems or handle GSA information — distinct from selling through a GSA Schedule, though Schedule holders providing IT may also be covered.
What it requires
Follow the FAR baseline, then: meet GSA information-system security requirements, follow GSA IT standards, and satisfy identity-verification/credentialing rules for system access.
Why it matters
Because so many agencies buy through GSA vehicles, GSA's system-security expectations can flow through to a wide range of contractors.
Citation
GSA Acquisition Regulation (GSAR), codified at 48 C.F.R. Chapter 5.