Guide

FAR 52.204-21 in plain English: the 15 basic safeguarding requirements

ByBrent Callari, founder of CommandKey AIUpdatedOctober 1, 2026

If your contract includes FAR 52.204-21, it requires 15 basic safeguarding measures on any system that processes, stores or transmits federal contract information. Here's what each one means for a small shop.

When it applies

The clause covers any information system you own or operate that processes, stores, or transmits federal contract information (FCI).

FCI is information that isn't meant for public release and is provided by or generated for the government under a contract to develop or deliver a product or service. It doesn't include information the government has made public, like what's posted on public websites, or simple transactional information, like what's needed to process a payment.

In practice, a non-public drawing, site schedule or job contact list the government sends you may well be FCI. If it is, the systems it passes through, like laptops, email and cloud storage, are covered.

It also flows down. Contractors at every tier have to put the substance of the clause in subcontracts where the sub may have FCI on its systems, except subcontracts only for commercially available off-the-shelf items.

The 15 requirements

The right-hand column is examples, not a checklist. No single product or setting proves a requirement is met.

#What the clause says (short)Examples of what that can look like
iLimit access to authorized users, processes and devicesEveryone has their own named login, and shared user accounts are avoided. Access is removed when someone leaves.
iiLimit access to the transactions and functions users are permitted to runPeople get the access their job needs, not admin on everything.
iiiVerify and control connections to external systemsKnow which outside systems and personal devices connect to yours or handle FCI, and decide which are allowed.
ivControl information posted on publicly accessible systemsSomeone reviews what goes on public systems, like your website and social accounts, before it's posted.
vIdentify users, processes and devicesNamed accounts, and a way to tell which devices and programs are allowed on your system.
viAuthenticate them before allowing accessUsers, devices and programs prove who they are before they get in. Multi-factor wherever you can.
viiSanitize or destroy media with FCI before disposal or reuseWipe or shred drives, laptops and phones before you sell, toss or hand them down.
viiiLimit physical access to systems and equipmentLocked office and locked equipment areas. Only authorized people get in.
ixEscort visitors, log physical access, control access devicesVisitors don't wander alone. Keep a sign-in log. Track keys and badges.
xMonitor, control and protect communications at external and key internal boundariesA firewall at the edge of your network, plus controls between key parts of the network inside.
xiSeparate public-facing systems from internal networksAnything the public can reach sits on its own network segment, physical or logical, away from your business machines.
xiiIdentify, report and correct flaws in a timely mannerTrack known flaws and fix them on time. Install security updates.
xiiiProtect against malicious code at appropriate locationsMalware protection where it counts, which for most small shops means every computer.
xivUpdate that protection when new releases are availableKeep it current. Automatic updates make that easy.
xvRun periodic scans, plus real-time scans of outside filesScheduled scans, plus scanning files from outside sources when they're downloaded, opened or run.

What it isn't

These 15 are the basic floor. The clause says plainly that it doesn't relieve you of other safeguarding requirements, including the rules for controlled unclassified information (CUI). If the work involves CUI, check your contract for the rules that apply. For many Defense Department contracts that's NIST SP 800-171, which is a much bigger lift.

Where CMMC Level 1 fits

This clause on its own doesn't require CMMC. CMMC applies when a Defense Department solicitation, contract or covered subcontract calls for it. When one calls for Level 1, it's built on these same 15 requirements.

Level 1 means a self-assessment every year, with the results entered in SPRS. A senior official of your company, called the Affirming Official, also has to enter an affirmation in SPRS every year. All 15 have to be fully in place. Level 1 doesn't allow a plan to fix gaps later.

The department, which now calls itself the Department of War, began putting CMMC requirements into solicitations on November 10, 2025. In July 2026 it suspended the next phase of the rollout for a program review, but Level 1 self-assessments stayed in place. This is moving, so check each new solicitation for whether it asks for CMMC and at what level.

Where to start this week

  1. Figure out where FCI actually lives: which email accounts, laptops, phones and cloud folders.
  2. Shrink that footprint. Fewer places means fewer things to protect.
  3. Walk the 15 rows above and write down, for each, what you do today. That's your starting record. It doesn't prove anything by itself, but it shows you where the gaps are.

This is a plain-English summary, not legal advice. The clause in your contract is what counts. Your local APEX Accelerator offers no-cost counseling and can point you to cybersecurity help.

Next step

How do you screen opportunities today?

Tell us how you find and screen federal work today. A few quick questions, and you get a free one-page plan back within 24 hours.

Answer five questions

Sources

← All guides