Reference Library
Industry cybersecurity requirement guides
Every federal contractor faces the FAR 52.204-21 baseline. These guides explain the sector-specific cybersecurity obligations that layer on top of it — mapped to the frameworks, clauses, and agency-specific rules most relevant to your industry.
Agriculture & Food
Producers, processors, and the food & agriculture critical-infrastructure sector.
Chemical
Chemical manufacturers, distributors, and high-risk-chemical facilities.
Construction
Contractors and firms delivering construction, infrastructure, and facilities work for federal and public-sector owners.
Defense Industrial Base
Prime contractors, subcontractors, and suppliers to the DoD.
Education
Educational institutions and EdTech contractors handling student, child, and federal research data (FERPA, COPPA).
Energy
Energy producers, grid operators, and the bulk-electric and pipeline critical-infrastructure sector.
Entertainment
Media, production, and entertainment firms contracting with — or handling data for — government clients.
Finance
Banks, financial institutions, and firms handling customer financial data and federal financial programs (GLBA, BSA).
Government Contracting & Professional Services
Federal contractors, consultants, and professional-services firms.
Healthcare
Healthcare providers, payers, and contractors handling protected health information (HIPAA) and federal health data.
Information Technology & Cloud Services
Software, managed-service, and cloud-service providers (incl. FedRAMP).
Insurance
Insurers and providers handling policyholder data and federal insurance and benefits programs.
International Trade
Importers, exporters, and trade-services firms subject to export controls (EAR/ITAR) and customs requirements.
Legal Services
Law firms and legal-services providers handling government/sensitive matters.
Manufacturing
Manufacturers and suppliers, including the defense industrial base and the critical-manufacturing sector.
Nuclear Energy & Materials
NRC/DOE licensees, reactor operators, and radioactive-materials handlers.
Securities
Broker-dealers, investment advisers, and market participants subject to SEC and FINRA cybersecurity and data rules.
Telecommunications
Carriers, network providers, and the communications critical-infrastructure sector.
Transportation
Transportation operators and providers across the surface, aviation, and maritime sectors (TSA, SSI).
Utilities
Water, gas, and electric utilities and the public-utility critical-infrastructure sector.
Water & Wastewater
Drinking-water and wastewater utilities and treatment operators.
Not sure which sector rules apply to you?
The Find My Requirements tool walks through your contract type, agency, data categories, and industry to produce a plain-language summary of the cybersecurity obligations most likely to apply.