← Custodia
Definition

FAR 52.204-21

Also known as: Basic Safeguarding of Covered Contractor Information Systems, FAR 52.204-21(b)(1)

FAR 52.204-21 is the Federal Acquisition Regulation clause that requires federal contractors to apply 15 basic safeguarding requirements to systems that process, store, or transmit Federal Contract Information (FCI). It is the regulatory basis for CMMC Level 1 — the 15 Level 1 practices are drawn directly from paragraph (b)(1) of this clause.

In more detail

FAR 52.204-21 has been in effect since 2016 and applies to nearly all federal contracts above the micro-purchase threshold, not just DoD. It establishes a minimum floor of cybersecurity practices for any contractor that comes into possession of non-public information generated for or under a government contract.

Paragraph (b)(1) lists 15 distinct safeguarding requirements: limiting system access to authorized users, identifying and authenticating those users, sanitizing media, controlling physical access, monitoring boundary communications, running antivirus, and applying security updates, among others.

Inside CMMC, FAR 52.204-21(b)(1) is renumbered into 17 CMMC practice IDs (a few requirements split into two practices each). The official requirement count from the rule itself is 15.

Primary source
Acquisition.gov — FAR 52.204-21

Related terms

Read more in the Library

Stop reading. Start filing.

Find your SPRS score in 4 minutes. Then file it in 7 days.

Take the free SPRS quiz to see exactly where you stand on the 15 FAR 52.204-21 safeguarding requirements — no signup, no card. If you like what you see, the 7-day Custodia trial picks up where the quiz leaves off and walks you to a signed, bid-ready package.

7-day free trial · No credit card required · $249/mo Self Service ($2,496/yr on annual — two months free)