Takeaway: Before any agency can award you a contract, a contracting officer has to find your company responsible under FAR Subpart 9.1. Cybersecurity is now an input to that finding: a weak or misrepresented security posture can cost you the award itself — even when you are the lowest bidder — through a determination that is hard to challenge after the fact.
The Core Question
"Responsibility" is a term of art. It does not mean honesty in the everyday sense. It means the government has affirmatively decided that you are capable of performing the contract and eligible to receive it — that you have the money, the capacity, the track record, the integrity, and the legal standing to do the work. Federal law forbids awarding to anyone the contracting officer has not found responsible, and the burden to demonstrate it sits on the contractor.
The thesis of this page: a contractor's cybersecurity posture now feeds directly into whether it is found responsible. A weak security position is no longer just a performance problem to manage after award. It can cost you the award itself, and it can do so through a determination courts and the GAO rarely disturb.
Where the Rule Lives (and a Common Mix-Up)
Contractor responsibility is governed by FAR Subpart 9.1 — Responsible Prospective Contractors. (It is a frequent assumption that responsibility sits in FAR Part 2; Part 2 is only definitions. The operative standards are in Part 9.) Two provisions to know:
- FAR 9.103 — Policy. No award may be made unless the contracting officer makes an affirmative determination of responsibility, and "in the absence of information clearly indicating that the prospective contractor is responsible, the contracting officer shall make a determination of nonresponsibility." Responsibility is not presumed — silence cuts against you.
- FAR 9.104-1 — General standards. The seven things every prospective contractor must satisfy.
The Seven General Standards
To be found responsible, FAR 9.104-1 says a prospective contractor must: (a) have adequate financial resources, or the ability to obtain them; (b) be able to meet the delivery or performance schedule; (c) have a satisfactory performance record; (d) have a satisfactory record of integrity and business ethics; (e) have the necessary organization, experience, accounting and operational controls, and technical skills, or the ability to obtain them; (f) have the necessary production and technical equipment and facilities, or the ability to obtain them; and (g) be otherwise qualified and eligible to receive an award under applicable laws and regulations.
These are deliberately broad. Before deciding, the contracting officer must have enough information to be satisfied that the contractor currently meets these standards (FAR 9.105-1) — drawing on the offeror's representations, past-performance records, the Federal Awardee Performance and Integrity Information System (FAPIIS) and SAM exclusions (FAR 9.104-6), and, where needed, a preaward survey (FAR 9.106). Note the present tense: responsibility is about your posture now, not your intentions.
Where Cybersecurity Enters the Determination
Cybersecurity does not appear by name in FAR 9.104-1. It does not need to. It reaches the determination through at least four of the seven standards, plus the contracting officer's power to set special standards.
Standard (g) — "otherwise qualified and eligible" — is the cleanest bridge. To be responsible, a contractor must be eligible to receive an award under applicable laws and regulations, and a growing set of cyber rules are exactly that:
- DFARS 252.204-7019 / -7020 (SPRS). For DoD solicitations involving covered defense information, an offeror must have a current NIST SP 800-171 assessment score posted in SPRS — not more than three years old — before it is eligible for award, and primes must verify their subcontractors have a score on file. No score, no award.
- DFARS 252.204-7021 / -7025 (CMMC). As CMMC phases into DoD contracts (the acquisition rule took effect November 10, 2025), the required CMMC status becomes an eligibility provision — lacking the specified certification makes a contractor ineligible for award of the affected contract.
- FAR 52.204-21. The 15 basic safeguarding requirements nearly every federal contractor handling Federal Contract Information owes — the universal floor.
A nuance worth keeping straight: the SPRS-score and CMMC-status rules are best understood as pass/fail eligibility and representation requirements that sit alongside the contracting officer's discretionary responsibility judgment, not inside its core. But the destination is identical — no award — and standard (g) is what folds "eligible under applicable laws" into the responsibility finding.
Standard (d) — integrity and business ethics — is the enforcement bridge. When a contractor certifies a security posture it does not have — an inflated SPRS score, a control never implemented, a CMMC self-assessment that does not reflect reality — that misrepresentation goes to integrity directly. It is also the core theory of the DOJ Civil Cyber-Fraud Initiative, which uses the False Claims Act against contractors that knowingly misstate cybersecurity practices or fail to report incidents. Adverse findings flow into FAPIIS, which the contracting officer must consult before award — so one overstated certification can echo into future responsibility determinations. See Enforcement.
Standard (c) — satisfactory performance record. Past cyber performance counts as performance. Mishandled covered information, a missed DFARS 252.204-7012 72-hour incident report, or unremediated known vulnerabilities can follow you through CPARS into the next competition. FAR 9.104-3(b) goes further: a contractor that "is or recently has been seriously deficient in contract performance" is presumed nonresponsible unless the deficiency was beyond its control or corrected.
Standards (a), (e), and (f) — can you actually do it? Meeting NIST SP 800-171, maintaining a System Security Plan, funding continuous monitoring, and acquiring compliant infrastructure require financial resources, the right organization and technical skills, and adequate facilities. Where a solicitation's security requirements are substantial, a contractor that cannot show it has — or can obtain — the means to satisfy them may fall short on these capability standards independent of any score.
Special standards (FAR 9.104-2). When an acquisition needs unusual expertise or safeguards, the contracting officer may set special standards of responsibility and must state them in the solicitation so they apply to every offeror. Agencies increasingly use this authority to make specific security capabilities an explicit condition of being found responsible. Read solicitations for these — they convert "good cyber hygiene" into a stated, enforceable bar.
Subcontractors and Small Businesses
Primes own their subcontractors' responsibility (FAR 9.104-4). The prime generally determines whether its proposed subcontractors are responsible, and a subcontractor's weakness can affect the government's determination of the prime's responsibility. With cyber flowdowns — the SPRS-verification duty under DFARS 252.204-7020 being the sharpest — a prime's responsibility is now partly a function of its supply chain's security posture.
Small businesses get a second look. If a contracting officer finds a small business nonresponsible, the matter is referred to the Small Business Administration under the Certificate of Competency (COC) program (FAR 9.104-3(d), Subpart 19.6). An SBA COC overrides the finding and compels award — a real appeal path, though far better never to draw the finding.
How Hard Is the Determination to Challenge?
Responsibility determinations are largely committed to the contracting officer's business judgment, and the bar for review is high. The GAO generally will not disturb an affirmative determination of responsibility absent a showing of possible bad faith or that the officer ignored available information; definitive responsibility criteria stated in the solicitation are the more reviewable exception. A nonresponsibility finding is likewise hard to overturn where the record shows a reasonable basis. The lesson cuts one way: build the record before award — once the determination is made, there is little daylight to reverse it.
What to Do With This
- Treat your SPRS score and CMMC status as award-eligibility assets, not IT metrics. Keep them current and honest; a stale or missing score can disqualify you before price is read.
- Never let a proposal overstate your security posture. The gap between what you certify and what you do reaches both integrity (standard d) and False Claims Act exposure.
- Carry a clean cyber performance record. Report incidents within the required windows, document remediation in a POA&M, and assume past cyber performance will be read next time.
- Fund the capability you claim. If a solicitation's security requirements are real, be able to show the resources, skills, and infrastructure to meet them.
- Read solicitations for special standards. Cyber requirements stated as conditions of responsibility apply to every offeror and are more readily enforced.
- Vet your subcontractors' cyber standing — their weaknesses can become your nonresponsibility.
Source Notes
Primary sources: FAR Subpart 9.1 — 9.103 (Policy), 9.104-1 (General standards), 9.104-2 (Special standards), 9.104-3 (Application of standards, including the COC referral), 9.104-4 (Subcontractor responsibility), 9.104-5 (Representations and certifications regarding responsibility matters), 9.104-6 (FAPIIS), and 9.105-1 (Determination procedures) — with FAR Subpart 19.6 (Certificates of Competency). Cyber rules referenced: FAR 52.204-21; DFARS 252.204-7012, -7019, -7020, -7021, and -7025; and NIST SP 800-171. Enforcement context (DOJ Civil Cyber-Fraud Initiative; False Claims Act, 31 U.S.C. 3729-3733) is summarized on the Enforcement page. Protest-standard summaries reflect long-standing GAO practice on review of responsibility determinations. Regulatory status is summarized as of the review date below and can change. Educational analysis, not legal advice, and not a substitute for review of your specific contracts and facts by qualified counsel.