← Custodia
FAR 52.204-21

Basic Safeguarding of Covered Contractor Information Systems

Effective: June 15, 2016

In plain English

FAR 52.204-21 requires every federal contractor that has Federal Contract Information (FCI) on its systems to implement 15 basic safeguarding requirements covering access control, identification and authentication, media protection, physical protection, system and communications protection, and system and information integrity. It is the entire substantive content of CMMC Level 1.

Who must comply

Any contractor or subcontractor at any tier whose information system processes, stores, or transmits Federal Contract Information.

What it requires

  1. 01Limit information system access to authorized users, processes acting on behalf of authorized users, and devices.
  2. 02Limit information system access to the types of transactions and functions authorized users are permitted to execute.
  3. 03Verify and control / limit connections to and use of external information systems.
  4. 04Control information posted or processed on publicly accessible information systems.
  5. 05Identify information system users, processes acting on behalf of users, and devices.
  6. 06Authenticate the identities of those users, processes, or devices, as a prerequisite to allowing access.
  7. 07Sanitize or destroy information system media containing FCI before disposal or release for reuse.
  8. 08Limit physical access to organizational information systems, equipment, and respective operating environments to authorized individuals.
  9. 09Escort visitors and monitor visitor activity; maintain audit logs of physical access; control and manage physical access devices.
  10. 10Monitor, control, and protect organizational communications at the external boundaries and key internal boundaries of the information systems.
  11. 11Implement subnetworks for publicly accessible system components that are physically or logically separated from internal networks.
  12. 12Identify, report, and correct information and information system flaws in a timely manner.
  13. 13Provide protection from malicious code at appropriate locations within organizational information systems.
  14. 14Update malicious code protection mechanisms when new releases are available.
  15. 15Perform periodic scans of the information system and real-time scans of files from external sources as files are downloaded, opened, or executed.

Key points

  • The clause itself contains 15 numbered requirements. CMMC renumbers them into 17 practice IDs (a few requirements are split into two practices), but the regulatory count is 15.
  • Flow-down is mandatory: primes must include the clause in subcontracts at any tier where FCI will be handled.
  • FAR 52.204-21 applies to all federal contracts (not just DoD) above the micro-purchase threshold, with limited exceptions for COTS items.
Primary source
Read FAR 52.204-21 at its source

Related clauses

Related terms

Read more in the Library

Stop reading. Start filing.

Find your SPRS score in 4 minutes. Then file it in 7 days.

Take the free SPRS quiz to see exactly where you stand on the 15 FAR 52.204-21 safeguarding requirements — no signup, no card. If you like what you see, the 7-day Custodia trial picks up where the quiz leaves off and walks you to a signed, bid-ready package.

7-day free trial · No credit card required · $249/mo Self Service ($2,496/yr on annual — two months free)