Overview
If your company does business with any U.S. federal agency, FAR 52.204-21 is your first contractor-specific cybersecurity obligation — but it is not your first cybersecurity obligation. Long before you bid on a contract, a backdrop of generally-applicable federal and state law already requires your business to protect the data it holds. Those duties — the FTC Act, state breach-notification and data-security statutes, and sector rules like the GLBA Safeguards Rule or HIPAA Security Rule — apply to any company that handles data, contractor or not. We map them on The Legal Baseline page, and you should already meet them.
FAR 52.204-21 is the clause that gets added when you take federal money: the one cybersecurity requirement that applies government-wide, regardless of agency, contract size, or industry. It requires "basic safeguarding" of any Federal Contract Information (FCI) that lives on your systems.
Federal Contract Information (FCI): information provided by or generated for the Government under a contract that is not intended for public release. It is a broader, lower-sensitivity category than Controlled Unclassified Information (CUI).
The clause is included in nearly every federal contract except those solely for commercially available off-the-shelf (COTS) items. If FCI touches your network, you are expected to meet all 15 requirements below — on top of the general-business obligations you already carry.
The 15 Basic Safeguarding Requirements
FAR 52.204-21(b)(1) lists fifteen safeguards drawn from a subset of NIST SP 800-171. In plain terms, sub-paragraphs (i) through (xv) require you to:
1. Limit system access to authorized users, processes acting on their behalf, and devices. 2. Limit access to the types of transactions and functions that authorized users are permitted to execute (least privilege). 3. Verify and control or limit connections to — and use of — external systems. 4. Control information posted or processed on publicly accessible systems. 5. Identify system users, processes acting on behalf of users, and devices. 6. Authenticate (or verify) the identities of those users, processes, and devices before granting access. 7. Sanitize or destroy media containing FCI before disposal or release for reuse. 8. Limit physical access to systems, equipment, and operating environments to authorized individuals. 9. Escort visitors and monitor their activity, maintain audit logs of physical access, and control and manage physical access devices. 10. Monitor, control, and protect communications at the external boundaries and key internal boundaries of your systems. 11. Implement subnetworks for publicly accessible system components that are separated from internal networks. 12. Identify, report, and correct system and information flaws in a timely manner. 13. Provide protection from malicious code at appropriate locations within your systems. 14. Update malicious-code protection mechanisms when new releases are available. 15. Perform periodic scans of your systems and real-time scans of files from external sources as they are downloaded, opened, or executed.
Who Must Comply
Every prime contractor and subcontractor at any tier whose information systems handle FCI. When the clause is included in a contract, it applies broadly across agencies with no dollar threshold, and it flows down to covered subcontractors at every tier — the main carve-out being subcontracts (and contracts) solely for commercially available off-the-shelf (COTS) items. The obligation arises through clause inclusion and contract scope, not from contractor status alone.
Where It Sits in the Stack
FAR 52.204-21 is a floor for contractors, not the floor for your business. Picture the full stack from the ground up:
1. The legal baseline — the FTC Act, state breach-notification and data-security laws, and sector rules like the GLBA Safeguards Rule or HIPAA Security Rule. These bind any business that handles data, contractor or not. You should already meet them before you ever pursue a contract. See The Legal Baseline. 2. FAR 52.204-21 — the 15 basic FCI safeguards every federal contractor adds on top once it wins federal work. 3. CUI protections — when your work involves the more sensitive Controlled Unclassified Information (CUI), NIST SP 800-171 applies, and for the Department of Defense, CMMC verifies it.
So FAR 52.204-21 is the starting point of your contractor obligations — not the finish line, and not the start of your legal duty to secure data.
| Related requirement | Relationship |
|---|---|
| The Legal Baseline | Generally-applicable laws (FTC Act, state breach/data-security, GLBA, HIPAA) every business must already meet — the layer beneath this clause |
| NIST SP 800-171 | Source of the 15 safeguards; full standard applies when you handle CUI |
| DFARS 252.204-7012 | DoD clause adding CUI protections and incident reporting |
| CMMC Level 1 | DoD verification layer for FAR 52.204-21 compliance; CMMC determines how covered DoD contractors demonstrate the required status via annual self-assessment |
| Proposed FAR CUI Rule (FAR Case 2026-001) | Reissued and reopened for comment June 23, 2026 (originally FAR Case 2017-016); comments due July 23, 2026. Would extend standardized CUI requirements government-wide — see "FAR Case 2026-001 — What Changed" below. Proposed rule; not yet in effect. |
FAR Case 2026-001 — What Changed for the Proposed CUI Rule
On June 23, 2026, the FAR Council reissued its proposed FAR CUI rule under a new docket, FAR Case 2026-001 (originally proposed January 15, 2025 as FAR Case 2017-016), as part of the broader Revolutionary FAR Overhaul rulemaking (FAR Parts 1, 2, 4, 22, 39, 40, and 53). Comments are due July 23, 2026.
The reissued version differs from the January 2025 draft in four ways:
1. Longer incident-reporting window. The clock to report a CUI incident moves from 8 hours to 72 hours from discovery, filed through a CISA portal (DoD contracts continue to use the DoD portal; FedRAMP incidents keep their own existing procedure). 2. NIST SP 800-171 Revision 3, not Revision 2. Non-federal systems handling CUI would need to meet NIST SP 800-171 Rev. 3, not the Rev. 2 baseline this FAR 52.204-21 page describes. DoD contracts currently require Rev. 2 under a standing class deviation, so a divergence period between DoD and civilian-agency requirements is possible while both rules are pending. 3. A deleted clause. The rule drops FAR 52.240-YY, which would have required identifying and reporting potential CUI on contracts where no CUI is actually involved. 4. A new conflict-of-law notice. Contractors would be able to notify the Contracting Officer within 72 hours of identifying a conflict between this clause and another law or regulation.
This is a proposed rule — it is not yet in effect, and none of the above changes any obligation today. Revisit this section once a final rule publishes.
What to Do Next
First, make sure you already meet the generally-applicable legal baseline — most of FAR 52.204-21's safeguards overlap with what those laws already expect. Then confirm whether FCI, CUI, or both flow through your contracts, map your environment to the 15 safeguards, and close any gaps. Use the Find My Requirements tool to see your full obligation set, and the Educational Self-Check to work through the controls.