Federal Requirements
Industry-Based Requirements
FAR 52.204-21 applies to nearly every federal contractor. But your industry, the agencies you serve, and the data you handle stack additional obligations on top of that baseline. This section maps the most common industry-specific layers.
Industry-specific requirements do not replace the government-wide baseline — they layer on top of it. A defense contractor handling CUI must meet the FAR 52.204-21 baseline and DFARS 252.204-7012 and CMMC. A health contractor must meet the FAR baseline and HIPAA/HITECH. Use Find My Requirements to map the full obligation set for your specific contract and data type.
Defense
DoD contractors handling CUI or working on covered contracts
- DFARS 252.204-7012 — cybersecurity and cyber incident reporting
- NIST SP 800-171 Rev. 2 / Rev. 3 — 110 CUI security requirements
- CMMC Level 1 or 2 — DoD verification layer for FAR/DFARS compliance
- SPRS self-assessment and score submission
- 72-hour cyber incident reporting to DoD
Healthcare
Contractors and subcontractors handling protected health information (PHI)
- HIPAA Security Rule — administrative, physical, and technical safeguards for ePHI
- HITECH Act — expanded HIPAA enforcement and breach notification
- HHS Business Associate Agreements — required before PHI access
- 60-day breach notification to HHS and affected individuals
- VA-specific IT and data-security requirements for VA contractors
Financial Services
Financial institutions, fintech vendors, and contractors handling nonpublic personal financial information
- GLBA Safeguards Rule — information security program for customer financial data
- SEC cybersecurity rules — disclosure and incident reporting for public companies
- Bank Secrecy Act / AML requirements for transaction-processing contractors
- FINRA cybersecurity guidance for broker-dealer technology providers
- FedRAMP authorization for cloud services to financial regulators
Education
Contractors accessing student records or supporting educational institutions under federal funding
- FERPA — restrictions on disclosure of student education records
- Department of Education IT security requirements for ED-funded systems
- COPPA — parental consent and privacy protections for services used by children under 13
- State student-data privacy laws layered on top of FERPA
Energy & Utilities
Critical infrastructure operators and contractors supporting electric, oil, gas, and water systems
- NERC CIP standards — mandatory cybersecurity for bulk electric system operators
- CIRCIA — cyber incident reporting for designated critical infrastructure sectors
- TSA security directives — pipeline and surface transportation cybersecurity requirements
- DOE cybersecurity requirements for national-lab and energy-infrastructure contractors
- CISA critical infrastructure partnership and information-sharing programs