# FAR (Federal Acquisition Regulation) | Secureframe

> The FAR governs federal acquisitions. FAR 52.204-21 lists 15 basic safeguarding requirements for FCI. How the FAR relates to DFARS and CMMC Level 1.

canonical: https://secureframe.com/glossary/federal-acquisition-regulation

The Federal Acquisition Regulation is the rulebook for how every federal executive branch agency buys goods and services with appropriated funds. Codified in Title 48 CFR. Jointly maintained by DoD, GSA, and NASA. DFARS adds DoD-specific rules on top of the FAR. If you're a defense contractor, you read both.

### What the FAR Covers

The FAR runs from Part 1 (System and Scope) through Part 53 (Forms). It covers solicitation and contract formation, competition requirements, contract types (fixed-price vs cost-reimbursement vs time-and-materials), small business programs, cost accounting, inspection and acceptance, termination, and disputes. Most defense contractors spend time in Parts 9, 15, 31, 42, and 52.

### FAR 52.204-21: The Cybersecurity Clause for FCI

FAR 52.204-21 (Basic Safeguarding of Covered Contractor Information Systems) is the one cybersecurity clause in the FAR that matters for most contractors. It lists 15 basic safeguarding requirements for systems that process, store, or transmit Federal Contract Information (FCI). CMMC Level 1 maps directly to these 15 requirements.

- **Limit **access to authorized users and to the transactions those users are authorized to perform.
- **Authenticate** users before allowing access to an information system.
- **Sanitize** or destroy media containing FCI before disposal or reuse.
- **Limit** physical access to information systems and operating environments to authorized individuals.
- **Monitor**, control, and protect communications at external boundaries.
- **Implement** subnetworks for publicly accessible components physically or logically separated from internal networks.
- **Identify,** report, and correct information and information system flaws in a timely manner.
- **Provide** protection from malicious code.
- **Update** malicious code protection mechanisms when new releases are available.
- **Perform** periodic scans of information systems and real-time scans of external files as they are downloaded, opened, or executed.
- **Limit** use of portable storage devices on external systems.
- **Escort** visitors and monitor visitor activity.
- **Maintain** audit logs of physical access.
- **Control** and manage physical access devices.
- **Enforce** a limit of consecutive invalid logon attempts by a user during a time period.

### FAR vs DFARS

FAR applies to every federal agency. DFARS is the DoD's supplement. A DoD contract includes FAR clauses plus DFARS clauses. FAR 52.204-21 gives you the 15-practice baseline. DFARS 252.204-7012 adds NIST SP 800-171 (110 practices) on top when CUI is involved.

### How FAR Changes

The FAR Council (a group of DoD, GSA, and NASA representatives) proposes changes. Rules go through the Federal Register with public comment periods. OIRA inside OMB reviews significant rules. After final publication, new clauses appear in solicitations. The CMMC acquisition rule and the pending FAR CUI rule both followed this pipeline.
