FAR 52.204-21 requires federal contractors to implement 15 baseline cybersecurity controls on any information system that processes, stores, or transmits Federal Contract Information. The clause, formally titled Basic Safeguarding of Covered Contractor Information Systems, sits in nearly every federal contract that isn’t strictly for off-the-shelf products, and it also forms the technical basis for CMMC Level 1.1Acquisition.GOV. 48 CFR 52.204-21 – Basic Safeguarding of Covered Contractor Information Systems
Who the Clause Applies To
Two definitions determine whether you’re covered. Federal Contract Information (FCI) is information that isn’t intended for public release and is either provided by the government or generated for the government under a contract to develop or deliver a product or service. It excludes information the government has already published and simple transactional data used only to process payments. A covered contractor information system is any system you own or operate that processes, stores, or transmits FCI.1Acquisition.GOV. 48 CFR 52.204-21 – Basic Safeguarding of Covered Contractor Information Systems
That second definition sweeps in more than most contractors first realize. Email servers that carry contract correspondence, file shares holding project documents, laptops used to open government deliverables: all of them are covered systems.
Contracting officers must insert the clause into solicitations and contracts whenever the contractor or any subcontractor at any tier may have FCI in or transiting through its system.2eCFR. 48 CFR 4.1903 – Contract Clause The only exception is contracts solely for commercially available off-the-shelf items where the contractor never handles government information beyond payment processing.1Acquisition.GOV. 48 CFR 52.204-21 – Basic Safeguarding of Covered Contractor Information Systems If your contract isn’t in that narrow lane, assume the clause is in it.
FCI is the lowest tier of sensitive government data. It’s distinct from Controlled Unclassified Information (CUI), which triggers a much heavier set of requirements. Confirming which category your contract involves is the first step, because it decides which standard applies.
The 15 Safeguarding Controls
Each of these controls must be fully implemented. They aren’t goals to work toward.1Acquisition.GOV. 48 CFR 52.204-21 – Basic Safeguarding of Covered Contractor Information Systems
Access Control and Identification
Six controls limit who and what can reach your systems:
- Limit system access to authorized users, processes acting on their behalf, and approved devices.
- Restrict the transactions and functions authorized users can perform to those their role requires. A payroll clerk shouldn’t reach engineering deliverables.
- Verify and control connections to external networks and information systems.
- Actively manage information posted or processed on publicly accessible systems, so FCI doesn’t end up on a public site or portal.
- Identify users, processes, and devices before granting access.
- Authenticate those identities. In practice, this means passwords, multi-factor authentication, or comparable mechanisms.
Physical and Media Protection
Three controls address physical security and disposal of media:
- Limit physical access to information systems, equipment, and the spaces where they operate to authorized individuals.
- Escort visitors, monitor their activity, keep audit logs of physical access, and manage physical access devices like keys and badges.
- Sanitize or destroy media (hard drives, USB drives, printed documents) that contained FCI before disposal or reuse.
System and Communications Protection
Two controls govern communications and network segmentation:
- Monitor, control, and protect communications at external boundaries and key internal boundaries. Firewalls and intrusion detection do this work.
- Place publicly accessible system components on subnetworks physically or logically separated from internal networks. Your public web server and internal file share shouldn’t share a segment.
System Integrity
Three controls keep systems clean and current:
- Identify, report, and correct system flaws in a timely manner. This covers patching, misconfigurations, and known vulnerabilities.
- Provide protection from malicious code at appropriate locations within organizational systems.
- Update malicious code protection when new releases become available, and perform periodic scans plus real-time scans of files from external sources as they are downloaded, opened, or executed.
What the Clause Does Not Require
FAR 52.204-21 does not include a cyber incident reporting requirement. You must identify and correct flaws, but the clause sets no deadline for notifying the government about a breach.1Acquisition.GOV. 48 CFR 52.204-21 – Basic Safeguarding of Covered Contractor Information Systems Incident reporting obligations come from other clauses. Defense contractors handling CUI, for example, must report cyber incidents to the DoD within 72 hours under DFARS 252.204-7012.3eCFR. 48 CFR 252.204-7012 – Safeguarding Covered Defense Information and Cyber Incident Reporting Contractors working only under FAR 52.204-21 should still read their specific contract terms, since individual contracts can add reporting obligations.
The clause also doesn’t require formal government certification or third-party auditing. Compliance is self-assessed. Self-assessed doesn’t mean unenforced, as the sections below make clear.
Documentation and Subcontractor Flow-Down
You must document how each of the 15 controls is implemented. That usually takes the form of a system security plan or a self-assessment checklist that maps your policies, procedures, and technical configurations to each control. The documentation needs to show the control is in place, not just that a policy exists on paper.
Under CMMC Level 1, which mirrors this clause, a senior company official affirms compliance annually and submits results through the Supplier Performance Risk System (SPRS).4Department of Defense Chief Information Officer. CMMC Self-Assessment Guide Level 1 Plans of Action and Milestones are not permitted at Level 1. You can’t affirm while acknowledging gaps you plan to fix later. Every control must be met before the affirmation is signed.
The clause also requires flow-down. If a subcontractor at any tier will have FCI residing in or transiting through its system, the prime must include the substance of FAR 52.204-21 in that subcontract.1Acquisition.GOV. 48 CFR 52.204-21 – Basic Safeguarding of Covered Contractor Information Systems A small subcontractor handling a slice of the work is held to the same 15 controls the prime is.
Consequences of False Certification
Falsely certifying compliance creates exposure under the False Claims Act. When a contractor submits a claim for payment, it represents that it has met the contract’s terms, including FAR 52.204-21. If that representation is false, the government can pursue treble damages plus civil penalties per false claim.5Office of the Law Revision Counsel. 31 USC 3729 – False Claims
The Department of Justice’s Civil Cyber-Fraud Initiative has aggressively pursued contractors whose security documentation didn’t match reality, using whistleblower tips and audit findings. Settlements in 2025 covered a defense contractor that failed to implement controls on a DoD system, a company that falsely certified compliance while running an unsecured third-party email host, and a university research corporation that never installed or updated antivirus software on lab computers doing defense research. Beyond FCA liability, non-compliance can lead to contract termination, suspension or debarment, and reputational harm that affects future awards.
How This Clause Relates to CMMC Level 1
FAR 52.204-21 maps directly to CMMC Level 1. The Cybersecurity Maturity Model Certification program, finalized by the DoD in late 2024, formalizes enforcement through a tiered structure.6Federal Register. Cybersecurity Maturity Model Certification (CMMC) Program Level 1 covers contractors handling only FCI and requires the same safeguarding controls found in FAR 52.204-21, demonstrated through the annual self-assessment described above.4Department of Defense Chief Information Officer. CMMC Self-Assessment Guide Level 1
If a contract involves CUI rather than FCI, the requirements jump. Protecting CUI triggers CMMC Level 2, which requires compliance with the 110 security requirements in NIST Special Publication 800-171 Revision 2 and a third-party assessment by a Certified Third-Party Assessor Organization.7Computer Security Resource Center. NIST Special Publication 800-171 Revision 2 By October 2026, CMMC compliance is expected to be required for all new DoD contract awards.
Getting to Compliance
Organizations with an existing IT function and reasonable security hygiene can typically reach full compliance in three to six months. Companies starting from a weaker baseline should plan for up to nine months across scoping, gap assessment, control implementation, policy documentation, and executive sign-off.
Start by confirming Level 1 is the right target. If your contracts involve CUI, you need Level 2 instead, and the preparation effort is substantially different. Once scope is confirmed, inventory every system that touches FCI and build a checklist mapping each of the 15 controls to those systems. Gather evidence for each: screenshots of access control configurations, visitor logs, antivirus update records, network diagrams showing subnetwork separation, and documented policies for media disposal. Assess each control honestly and mark it met or not met. Remediate every gap before the self-assessment, since partial compliance doesn’t count.
After remediation, a senior official reviews the evidence and signs the annual affirmation, which is submitted through SPRS. Keep documentation in a secure repository and update it throughout the year. Review access lists quarterly, keep antivirus definitions current, and reflect any network changes in your security documentation. The self-assessment is an annual cycle with continuous maintenance between cycles, not a one-time exercise.