Skip to main content
NFSAgency supplement

National Aeronautics & Space Administration

NASA's procurement supplement for space and aeronautics contracts.

Last reviewedJune 9, 2026Version v1

Cybersecurity rules in this supplement

The NASA FAR Supplement (NFS) protects NASA's unclassified IT and sensitive technical information:

NFS Section 1804.470 / clause 1852.204-76 — Security Requirements for Unclassified Information Technology Resources. Requires contractors that handle, use, or operate NASA IT to implement an IT security plan consistent with NASA and federal IT-security policy (FISMA, NIST).

NFS clause 1852.223-75 — Major Breach of Safety or Security. Requires reporting of major safety or security breaches affecting NASA.

NFS clauses 1852.237-72 / -73 — Access to / Release of Sensitive Information. Control contractor access to, and release of, NASA sensitive information.

NFS Subpart 1846.70 / clause 1852.246-74 — Counterfeit Electronic Part Detection and Avoidance. Supply-chain integrity requirement for electronic parts.

In plain terms

If you run or touch NASA IT systems, you must secure them to NASA's IT-security standards and keep a security plan; if you handle NASA's sensitive technical data, you must control access and report major breaches. A separate rule guards against counterfeit electronic parts entering NASA hardware.

Who it applies to

Contractors and subcontractors that operate or access NASA information technology resources or handle NASA sensitive information.

What it requires

Follow the FAR baseline, then: implement an IT security plan for NASA IT resources, control access to and release of sensitive information, report major safety/security breaches, and meet counterfeit-part detection requirements where applicable.

Why it matters

NASA work often involves export-controlled and sensitive technical data, so its access-control and breach-reporting rules carry both security and export-compliance weight.

Citation

NASA FAR Supplement (NFS), codified at 48 C.F.R. Chapter 18.