Skip to main content

Reference Library

Industry cybersecurity requirement guides

Every federal contractor faces the FAR 52.204-21 baseline. These guides explain the sector-specific cybersecurity obligations that layer on top of it — mapped to the frameworks, clauses, and agency-specific rules most relevant to your industry.

Ag/Food

Agriculture & Food

Producers, processors, and the food & agriculture critical-infrastructure sector.

Explore Agriculture & Food
Chemical

Chemical

Chemical manufacturers, distributors, and high-risk-chemical facilities.

Explore Chemical

Construction

Contractors and firms delivering construction, infrastructure, and facilities work for federal and public-sector owners.

Explore Construction
DIB

Defense Industrial Base

Prime contractors, subcontractors, and suppliers to the DoD.

Explore Defense Industrial Base

Education

Educational institutions and EdTech contractors handling student, child, and federal research data (FERPA, COPPA).

Explore Education

Energy

Energy producers, grid operators, and the bulk-electric and pipeline critical-infrastructure sector.

Explore Energy

Entertainment

Media, production, and entertainment firms contracting with — or handling data for — government clients.

Explore Entertainment

Finance

Banks, financial institutions, and firms handling customer financial data and federal financial programs (GLBA, BSA).

Explore Finance
GovCon

Government Contracting & Professional Services

Federal contractors, consultants, and professional-services firms.

Explore Government Contracting & Professional Services

Healthcare

Healthcare providers, payers, and contractors handling protected health information (HIPAA) and federal health data.

Explore Healthcare
IT/Cloud

Information Technology & Cloud Services

Software, managed-service, and cloud-service providers (incl. FedRAMP).

Explore Information Technology & Cloud Services

Insurance

Insurers and providers handling policyholder data and federal insurance and benefits programs.

Explore Insurance

International Trade

Importers, exporters, and trade-services firms subject to export controls (EAR/ITAR) and customs requirements.

Explore International Trade
Legal

Legal Services

Law firms and legal-services providers handling government/sensitive matters.

Explore Legal Services

Manufacturing

Manufacturers and suppliers, including the defense industrial base and the critical-manufacturing sector.

Explore Manufacturing
Nuclear

Nuclear Energy & Materials

NRC/DOE licensees, reactor operators, and radioactive-materials handlers.

Explore Nuclear Energy & Materials

Securities

Broker-dealers, investment advisers, and market participants subject to SEC and FINRA cybersecurity and data rules.

Explore Securities

Telecommunications

Carriers, network providers, and the communications critical-infrastructure sector.

Explore Telecommunications

Transportation

Transportation operators and providers across the surface, aviation, and maritime sectors (TSA, SSI).

Explore Transportation

Utilities

Water, gas, and electric utilities and the public-utility critical-infrastructure sector.

Explore Utilities
Water

Water & Wastewater

Drinking-water and wastewater utilities and treatment operators.

Explore Water & Wastewater

Not sure which sector rules apply to you?

The Find My Requirements tool walks through your contract type, agency, data categories, and industry to produce a plain-language summary of the cybersecurity obligations most likely to apply.

Start the tool →