What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Read the solicitation and contract clauses first: there is no single cybersecurity certification that automatically applies to every federal contract. The agency, incorporated clauses, information involved, and systems used to perform the work determine what you must do. FAR Part 40 covers government-wide information and supply-chain security, while agency supplements and contract-specific terms may add requirements. DoD-specific DFARS clauses can impose additional requirements, including NIST SP 800-171 assessments or a CMMC status when the solicitation calls for them.

What cybersecurity requirements apply to federal contractors?

Start with the actual opportunity, not a general checklist or a claim that every contractor needs the same certification. The Federal Acquisition Regulation (FAR) provides government-wide acquisition rules; agency supplements and solicitation-specific clauses can add terms. FAR Part 40 is the current FAR location for information security and supply-chain security. The scope of a rule or order can depend on the contracting office, acquisition, funding, information systems, and the order’s terms.

GSA’s IT security procedural guides apply to GSA’s own systems and acquisition context. They can illustrate the kinds of terms an agency may use, but they are not government-wide requirements and do not replace the solicitation.

Before bidding, make an opportunity-specific inventory:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Identify the agency, contract vehicle, and every cybersecurity clause or provision incorporated into the solicitation and resulting contract.
  • Identify the information the work will involve: Federal Contract Information (FCI), Controlled Unclassified Information (CUI), covered defense information, or other sensitive information.
  • Map the contractor systems and services that will store, process, or transmit that information; do not assume every company system is automatically in scope.
  • Record any required assessment, certification status, affirmation, or date by which it must be current.
  • Identify external cloud services and subcontractors that will handle the information, and check relevant contract terms and flow-downs.

These obligations are time-sensitive and solicitation-specific. Use the current solicitation and official clause text for a bid decision.

What is the difference between FCI and CUI?

Federal Contract Information

DFARS defines FCI as information not intended for public release that is provided by or generated for the Government under a contract to develop or deliver a product or service. The definition excludes public information and simple transactional information, such as information necessary to process payments.

Controlled Unclassified Information

CUI is a controlled information category with its own safeguarding or dissemination rules. It is not simply another name for all FCI. Check the contract’s markings and instructions, applicable definitions, and clauses to determine what information is controlled and what duties apply. DoD’s small-business cybersecurity guidance focuses on protecting defense-relevant information and points contractors to NIST SP 800-171, but the contract terms establish the relevant obligation.

When does NIST SP 800-171 apply?

NIST SP 800-171 applies when an applicable contract clause makes its requirements relevant to the covered contractor information systems. Under DFARS 252.204-7012, covered contractor information systems must meet the clause’s security requirements; for systems not operated on behalf of the Government, the clause references NIST SP 800-171, subject to its exceptions and contract terms. The clause and solicitation determine which systems are covered. Do not assume that every system owned by the company is in scope—or that a system handling contract information can be excluded without a defensible scope decision.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For relevant DoD awards, DFARS 204.7302 describes the Basic NIST SP 800-171 DoD Assessment and currentness requirements. The general currency limit is a relevant assessment no more than three years old unless the solicitation specifies a shorter period. That is an assessment-record rule, distinct from any CMMC level or annual affirmation the contract may require.

Do I need CMMC to bid on a DoD contract?

Not automatically for every DoD opportunity. When the solicitation specifies a CMMC level, DFARS Subpart 204.75 requires the offeror to have current status at the required level for award. The rule states that a contracting officer may not award a contract, task order, or delivery order to an offeror without the required current status. The solicitation’s specified level and the applicable systems determine whether CMMC is an award gate.

DFARS 252.204-7025 tells offerors the required level and makes current status and current affirmation for each applicable system relevant to award eligibility. Under the cited provisions, Level 1 requires final status for award. Levels 2 and 3 may have conditional status for a period of no more than 180 days, subject to the framework’s terms; conditional status requires successful closure of the relevant plan of action and milestones to reach final status. Check the solicitation and the current Supplier Performance Risk System (SPRS) record rather than relying on an old assessment or an assumed grace period.

What assessments or SPRS entries are required?

Do not treat assessment, status, affirmation, and currentness as interchangeable. The required record depends on the clause, CMMC level, and applicable system.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Record or requirement What to check
Basic NIST SP 800-171 DoD Assessment For relevant awards, check the assessment and its SPRS record under DFARS 204.7302 and the solicitation. The general currency limit is no more than three years unless the solicitation sets a shorter period.
CMMC status Where the solicitation specifies a CMMC level, check that the applicable system has current status at that level in SPRS. DFARS 252.204-7025 addresses the required status and current affirmation for each applicable system.
Annual affirmation Where DFARS 252.204-7021 applies, an affirming official must annually affirm continuous compliance in SPRS for each applicable CMMC unique identifier.

Track each applicable system and identifier separately, along with its assessment or status date, affirmation date, and any solicitation-specific deadline. A current assessment does not by itself establish a required CMMC status or replace an annual affirmation.

Does my cloud provider need FedRAMP?

Check the clause and information being handled. Under DFARS 252.204-7012, when a contractor intends to use an external cloud service provider to store, process, or transmit covered defense information, the contractor must ensure the provider meets security requirements equivalent to the FedRAMP Moderate baseline and satisfies the clause’s other requirements. This is a DoD clause-specific condition; it is not a blanket rule that every federal contractor or every cloud service needs FedRAMP. Nor does meeting that cloud condition alone establish that the contractor has satisfied every other contract requirement.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What should I check in a cybersecurity contract clause?

Review the clause as an operational commitment, not just a compliance label. Before signing or submitting a bid, confirm:

  • Scope: Which information is covered, which systems must protect it, and whether the contract defines covered contractor information systems or covered defense information.
  • Required controls and standard: Whether the clause invokes NIST SP 800-171 or another specified requirement, and what exceptions or conditions it states.
  • Assessment and status: Whether an assessment, CMMC level, SPRS entry, current status, or affirmation is required, and by what point in the acquisition or performance period.
  • Cloud use: Whether an external cloud provider will handle covered information and what security baseline and other clause requirements apply.
  • Supply-chain terms: Whether FAR Part 40 provisions or an applicable FASCSA order restrict a product, service, or source. FAR 4.2304 describes acquisition-specific factors for FASCSA-order applicability, including contracting office, scope, funding, and certain information-system conditions.
  • Reporting and administration: What the clause requires the contractor to do if a covered supply-chain concern or other specified event arises, and whom to notify.
  • Subcontract flow-downs: Which requirements must pass to subcontractors based on their work, information access, and system role.

For applicable contexts, GSA’s contractor guide advises reasonable inquiries and reporting covered discoveries to the contracting officer. Apply the relevant acquisition terms rather than treating that agency guide as a universal rule.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How should primes handle subcontractors and performance readiness?

Identify subcontractors that will handle FCI, CUI, or covered defense information before sharing it. Determine the relevant clauses, required status, system scope, and flow-down for each subcontractor’s role; DoD clauses include flow-down provisions for CMMC levels and covered cybersecurity requirements. The precise level and flow-down depend on the contract and the systems involved.

Check readiness before bid submission and before performance begins. A contractor that cannot receive or process information on the required systems may be unable to start the work as planned. During performance, maintain any required status and keep assessment records and affirmations current under the applicable clauses.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.