Cybersecurity rules in this supplement
OPM's acquisition rules do not publish a general agency-specific cybersecurity-safeguarding clause in the supplement itself. Cybersecurity obligations come from the government-wide FAR baseline and contract-specific terms.
Note: After the 2015 breach of federal personnel records, OPM imposes strong security requirements through individual contract terms and IT-security policy, even though the acquisition supplement does not codify a single cyber clause.
In plain terms
OPM doesn't add one broad cyber clause, so the FAR baseline sets your general duties — but given OPM's history with personnel-data security, expect strong security requirements written directly into the contract.
Who it applies to
OPM contractors and subcontractors, especially those handling federal personnel or background-investigation data.
What it requires
Follow the FAR baseline for safeguarding information and systems, and meet the contract-specific IT-security and personnel-data requirements OPM imposes.
Why it matters
OPM holds highly sensitive personnel data and has been the target of a major breach, so its contract-level security expectations are typically rigorous even without a codified supplement clause.
Citation
OPM acquisition rules, codified at 48 C.F.R. Chapter 17.