Skip to main content
GSARAgency supplement

General Services Administration

GSA's procurement supplement — central because of the GSA Schedules many contractors use.

Last reviewedJune 9, 2026Version v1

Cybersecurity rules in this supplement

The GSA Acquisition Regulation (GSAR) sets requirements for GSA information systems:

GSAR Section 511.171 — Requirements for GSA Information Systems. Requires contractors that handle GSA information or operate GSA systems to meet GSA IT-security and information-handling requirements (consistent with FISMA and NIST).

GSAR Section 511.170 — Information Technology Coordination and Standards. Sets IT coordination and standards policy for GSA acquisitions.

GSAR clause 552.239-71-type IT-security terms and the personal-identity-verification requirements at 552.204-9 support system access and credentialing.

(Note: GSA's proposed CUI/cyber clauses continue to evolve; the requirements above are the established GSAR provisions.)

In plain terms

GSA is a hub for governmentwide buying, so when you handle GSA's own information or run a GSA system, you must meet GSA's IT-security and information-handling standards and credential your people properly.

Who it applies to

Contractors and subcontractors that operate GSA information systems or handle GSA information — distinct from selling through a GSA Schedule, though Schedule holders providing IT may also be covered.

What it requires

Follow the FAR baseline, then: meet GSA information-system security requirements, follow GSA IT standards, and satisfy identity-verification/credentialing rules for system access.

Why it matters

Because so many agencies buy through GSA vehicles, GSA's system-security expectations can flow through to a wide range of contractors.

Citation

GSA Acquisition Regulation (GSAR), codified at 48 C.F.R. Chapter 5.