The Federal Acquisition Regulation (FAR) clause known as “Basic Safeguarding of Covered Contractor Information Systems.” It establishes the minimum cybersecurity requirements for contractors that handle Federal Contract Information (FCI). These safeguards apply to any contractor information system that processes, stores, or transmits FCI, even if the organization does not handle Controlled Unclassified Information (CUI). The FAR clause 52.204-21 is crucial in defining these standards.
The clause requires 15 basic safeguarding measures, including limiting access to authorized users, sanitizing or destroying media before disposal, updating malicious code protection mechanisms, and patching system vulnerabilities in a timely manner. FAR 52.204-21 sets the foundation for contractor cybersecurity and forms the baseline requirements reflected in CMMC Level 1 (Foundational) certification. Understanding the FAR 52.204-21 cybersecurity principles is essential for compliance.