Skip to main content
Agency supplement

Office of Personnel Management

OPM's procurement rules — notable after its history with personnel-data security.

Last reviewedJune 9, 2026Version v1

Cybersecurity rules in this supplement

OPM's acquisition rules do not publish a general agency-specific cybersecurity-safeguarding clause in the supplement itself. Cybersecurity obligations come from the government-wide FAR baseline and contract-specific terms.

Note: After the 2015 breach of federal personnel records, OPM imposes strong security requirements through individual contract terms and IT-security policy, even though the acquisition supplement does not codify a single cyber clause.

In plain terms

OPM doesn't add one broad cyber clause, so the FAR baseline sets your general duties — but given OPM's history with personnel-data security, expect strong security requirements written directly into the contract.

Who it applies to

OPM contractors and subcontractors, especially those handling federal personnel or background-investigation data.

What it requires

Follow the FAR baseline for safeguarding information and systems, and meet the contract-specific IT-security and personnel-data requirements OPM imposes.

Why it matters

OPM holds highly sensitive personnel data and has been the target of a major breach, so its contract-level security expectations are typically rigorous even without a codified supplement clause.

Citation

OPM acquisition rules, codified at 48 C.F.R. Chapter 17.