Guide
FAR 52.204-21 in plain English: the 15 basic safeguarding requirements
If your contract includes FAR 52.204-21, it requires 15 basic safeguarding measures on any system that processes, stores or transmits federal contract information. Here's what each one means for a small shop.
When it applies
The clause covers any information system you own or operate that processes, stores, or transmits federal contract information (FCI).
FCI is information that isn't meant for public release and is provided by or generated for the government under a contract to develop or deliver a product or service. It doesn't include information the government has made public, like what's posted on public websites, or simple transactional information, like what's needed to process a payment.
In practice, a non-public drawing, site schedule or job contact list the government sends you may well be FCI. If it is, the systems it passes through, like laptops, email and cloud storage, are covered.
It also flows down. Contractors at every tier have to put the substance of the clause in subcontracts where the sub may have FCI on its systems, except subcontracts only for commercially available off-the-shelf items.
The 15 requirements
The right-hand column is examples, not a checklist. No single product or setting proves a requirement is met.
| # | What the clause says (short) | Examples of what that can look like |
|---|---|---|
| i | Limit access to authorized users, processes and devices | Everyone has their own named login, and shared user accounts are avoided. Access is removed when someone leaves. |
| ii | Limit access to the transactions and functions users are permitted to run | People get the access their job needs, not admin on everything. |
| iii | Verify and control connections to external systems | Know which outside systems and personal devices connect to yours or handle FCI, and decide which are allowed. |
| iv | Control information posted on publicly accessible systems | Someone reviews what goes on public systems, like your website and social accounts, before it's posted. |
| v | Identify users, processes and devices | Named accounts, and a way to tell which devices and programs are allowed on your system. |
| vi | Authenticate them before allowing access | Users, devices and programs prove who they are before they get in. Multi-factor wherever you can. |
| vii | Sanitize or destroy media with FCI before disposal or reuse | Wipe or shred drives, laptops and phones before you sell, toss or hand them down. |
| viii | Limit physical access to systems and equipment | Locked office and locked equipment areas. Only authorized people get in. |
| ix | Escort visitors, log physical access, control access devices | Visitors don't wander alone. Keep a sign-in log. Track keys and badges. |
| x | Monitor, control and protect communications at external and key internal boundaries | A firewall at the edge of your network, plus controls between key parts of the network inside. |
| xi | Separate public-facing systems from internal networks | Anything the public can reach sits on its own network segment, physical or logical, away from your business machines. |
| xii | Identify, report and correct flaws in a timely manner | Track known flaws and fix them on time. Install security updates. |
| xiii | Protect against malicious code at appropriate locations | Malware protection where it counts, which for most small shops means every computer. |
| xiv | Update that protection when new releases are available | Keep it current. Automatic updates make that easy. |
| xv | Run periodic scans, plus real-time scans of outside files | Scheduled scans, plus scanning files from outside sources when they're downloaded, opened or run. |
What it isn't
These 15 are the basic floor. The clause says plainly that it doesn't relieve you of other safeguarding requirements, including the rules for controlled unclassified information (CUI). If the work involves CUI, check your contract for the rules that apply. For many Defense Department contracts that's NIST SP 800-171, which is a much bigger lift.
Where CMMC Level 1 fits
This clause on its own doesn't require CMMC. CMMC applies when a Defense Department solicitation, contract or covered subcontract calls for it. When one calls for Level 1, it's built on these same 15 requirements.
Level 1 means a self-assessment every year, with the results entered in SPRS. A senior official of your company, called the Affirming Official, also has to enter an affirmation in SPRS every year. All 15 have to be fully in place. Level 1 doesn't allow a plan to fix gaps later.
The department, which now calls itself the Department of War, began putting CMMC requirements into solicitations on November 10, 2025. In July 2026 it suspended the next phase of the rollout for a program review, but Level 1 self-assessments stayed in place. This is moving, so check each new solicitation for whether it asks for CMMC and at what level.
Where to start this week
- Figure out where FCI actually lives: which email accounts, laptops, phones and cloud folders.
- Shrink that footprint. Fewer places means fewer things to protect.
- Walk the 15 rows above and write down, for each, what you do today. That's your starting record. It doesn't prove anything by itself, but it shows you where the gaps are.
This is a plain-English summary, not legal advice. The clause in your contract is what counts. Your local APEX Accelerator offers no-cost counseling and can point you to cybersecurity help.
Next step
How do you screen opportunities today?
Tell us how you find and screen federal work today. A few quick questions, and you get a free one-page plan back within 24 hours.