# FAR Basic Safeguarding of Covered Contractor Information Systems
Short Answer
FAR 52.204-21 is the government-wide baseline safeguarding clause for Federal Contract Information. It matters because it is often the first cybersecurity obligation a federal contractor owes even when the contract does not involve CUI, classified information, or a DoD-specific requirement.
Why this matters for government contractors
FAR 52.204-21 is the federal contracting floor for protecting nonpublic information that is provided by or generated for the government under a contract. It is not limited to defense work, CUI, or high-risk systems. When a contractor or subcontractor may have Federal Contract Information residing in or transiting through its information system, FAR Subpart 4.19 directs contracting officers to insert the clause.
This makes the clause important for small businesses and commercial-item contractors that may not think of themselves as “cyber regulated.” A contract can be relatively ordinary and still involve nonpublic schedules, drawings, statements of work, deliverables, internal communications, or other FCI. The clause establishes minimum safeguarding requirements for covered contractor information systems.
What the clause does
The clause requires contractors to apply fifteen basic safeguarding requirements. These include limiting system access to authorized users and functions; controlling external system connections; controlling information posted or processed on publicly accessible systems; identifying and authenticating users, processes, and devices; sanitizing or destroying media before disposal or reuse; limiting physical access; escorting visitors and maintaining physical-access logs; monitoring and protecting communications at boundaries; separating publicly accessible components from internal networks; identifying and correcting flaws; protecting against malicious code; updating malicious-code protections; and performing periodic and real-time scans.
The clause is written as a minimum baseline. It does not provide a complete security program for CUI, cloud services, classified work, export-controlled technical data, health information, education records, or other regulated data. It is the starting point, not the ceiling.
How it reaches contractors
FAR 52.204-21 reaches contractors through incorporation in federal solicitations and contracts, including many civilian-agency contracts. It can also flow to subcontractors when their systems will hold or transmit FCI. The contract trigger is not whether the contractor considers the information sensitive; it is whether FCI resides in or transits through a contractor information system.
Procurement and cybersecurity significance
For procurement teams, the clause should be treated as a baseline contract requirement to identify during intake. For cybersecurity teams, it should be mapped to basic access control, identity, media protection, physical security, boundary protection, flaw remediation, malware protection, and vulnerability scanning procedures. For executives, it is a reminder that “we do not handle CUI” does not mean “we have no federal cybersecurity obligations.”
Relationship to other GovConCyber requirements
FAR 52.204-21 is related to CMMC Level 1 because 32 C.F.R. Part 170 incorporates the FAR 52.204-21 safeguarding requirements for CMMC Level 1. It is distinct from DFARS 252.204-7012, which addresses covered defense information, NIST SP 800-171, DoD incident reporting, and flowdown. It is also distinct from the proposed FAR CUI rule, which should remain labeled as proposed unless finalized.
What contractors should do
- Check every federal solicitation and contract for FAR 52.204-21 or an agency supplement based on FAR Subpart 4.19.
- Identify where FCI resides or transits, including email, shared drives, ticketing systems, cloud storage, and subcontractor systems.
- Map the fifteen safeguards to actual policies, configurations, and operating procedures.
- Avoid treating the clause as satisfied by a generic IT policy that does not address the covered system.
- Flow the requirement when subcontractors handle FCI.
- Escalate separately when the contract involves CUI, CDI, classified information, export-controlled data, PHI, student records, or other regulated data.
Current status
Current FAR clause. The live site and FMR should distinguish this clause from any proposed FAR Part 40 reorganization or proposed CUI clause. If FAR recodification changes numbering, preserve historical crosswalks and do not remove existing clause references without schema review.
Primary citations
- FAR 52.204-21.
- FAR Subpart 4.19.
- 48 C.F.R. § 52.204-21.
- 32 C.F.R. § 170.14(c), for CMMC Level 1 incorporation.
---
Source type: acquisition_clause. Implementation status: in_force.