Skip to main content
SOFARSAgency supplement

Special Operations Command

SOCOM's acquisition supplement for special-operations procurements.

Last reviewedJune 9, 2026Version v1

Cybersecurity rules in this supplement

SOFARS supplements the DoD-wide DFARS cyber rules for SOCOM:

SOFARS Part 5639 — Acquisition of Information Technology. Sets SOCOM IT-acquisition and security policy.

SOFARS clause 5652.204-9003 — Disclosure of Unclassified Information. Controls disclosure of unclassified-but-sensitive SOCOM information.

SOFARS Subpart 5604.4 — Safeguarding Classified Information Within Industry. Sets requirements for handling classified information.

In plain terms

SOCOM applies the DoD defense cyber rulebook — NIST SP 800-171, SPRS scores, and CMMC — and adds its own IT-acquisition, information-disclosure, and classified-handling rules given the sensitivity of special-operations work.

Who it applies to

SOCOM contractors and subcontractors handling Federal Contract Information, Covered Defense Information, or classified information.

What it requires

Everything in the DoD/DFARS cyber baseline (NIST SP 800-171 Rev 2, SPRS, CMMC, 72-hour incident reporting), plus SOCOM IT, disclosure, and classified-safeguarding requirements.

Why it matters

Special-operations procurements are highly sensitive, so the DoD cyber baseline is reinforced by stricter disclosure and classified-handling controls.

Citation

Special Operations Federal Acquisition Regulation Supplement (SOFARS); see also DFARS at 48 C.F.R. Chapter 2.