Cybersecurity rules in this supplement
SOFARS supplements the DoD-wide DFARS cyber rules for SOCOM:
SOFARS Part 5639 — Acquisition of Information Technology. Sets SOCOM IT-acquisition and security policy.
SOFARS clause 5652.204-9003 — Disclosure of Unclassified Information. Controls disclosure of unclassified-but-sensitive SOCOM information.
SOFARS Subpart 5604.4 — Safeguarding Classified Information Within Industry. Sets requirements for handling classified information.
In plain terms
SOCOM applies the DoD defense cyber rulebook — NIST SP 800-171, SPRS scores, and CMMC — and adds its own IT-acquisition, information-disclosure, and classified-handling rules given the sensitivity of special-operations work.
Who it applies to
SOCOM contractors and subcontractors handling Federal Contract Information, Covered Defense Information, or classified information.
What it requires
Everything in the DoD/DFARS cyber baseline (NIST SP 800-171 Rev 2, SPRS, CMMC, 72-hour incident reporting), plus SOCOM IT, disclosure, and classified-safeguarding requirements.
Why it matters
Special-operations procurements are highly sensitive, so the DoD cyber baseline is reinforced by stricter disclosure and classified-handling controls.
Citation
Special Operations Federal Acquisition Regulation Supplement (SOFARS); see also DFARS at 48 C.F.R. Chapter 2.