Skip to main content

General educational information — not legal advice in any jurisdiction. Read the full disclaimer.

Find My Requirements

Answer a few questions about your organization, contract, customer, data, sector, and operating footprint to identify cybersecurity obligations that may require closer review.

Educational estimate only — general guidance, not legal advice or a definitive determination of your obligations.

  1. 1Org / Contract
  2. 2Where You Operate
  3. 3Data
  4. 4Company Size
  5. 5Industry

What kind of government-related work are you performing?

Select every relationship that fits. Cybersecurity requirements can come from prime contracts, subcontracts, flowdowns, task orders, grants, OTAs, and commercial contracts supporting federal work.

How This Tool Works

Each answer narrows a curated set of rules that map contract type, data category, and industry to specific FAR/DFARS clauses, frameworks, and statutes. A rule appears when every one of its conditions either matches your answer or stays open as a wildcard. We sort by priority so the highest-impact obligations show first, and we de-duplicate so the same clause never appears twice.

Practitioners maintain the rule set and update it whenever regulators finalize new federal rules. It is intentionally conservative — when in doubt, we surface the broader baseline rather than guess.