Skip to main content
Greypike's CMMC Knowledge Base

Welcome to the CMMC Knowledgebase. Search for CMMC, resources, tools, sources, sites, and platforms using the search box below.
We add more to the database weekly, check back often.

If you cannot find an answer then contact us or click the chat button on the lower right..

< All Topics
Print

FAR 52.204-21 and FCI: The 15 Basic Safeguarding Requirements

FAR 52.204-21 is the clause most contractors assume doesn’t apply to them, and most of them are wrong. It applies to nearly every company holding a federal contract, it predates CMMC, and it is the floor everything else is built on. For how it fits with the DFARS clauses, see DFARS and FAR Cybersecurity Clauses: What Each One Actually Requires.

Here is the part worth knowing up front: none of the fifteen requirements demand a government cloud, an enclave, an assessor, or a consultant. Most companies with competent IT already meet ten or twelve of them. This is the cheapest compliance obligation in the federal space, and treating it like the expensive one is a common and costly mistake.

What triggers it: Federal Contract Information

The clause attaches to systems that process, store, or transmit Federal Contract Information — information provided by or generated for the government under a contract, that is not intended for public release.

That definition is broader than people expect. FCI includes:

  • Statements of work and delivery schedules
  • Correspondence with your contracting officer
  • Contract line items, pricing, and performance data
  • Drawings and specifications that aren’t controlled but aren’t public either
  • Almost any working document generated in performance of the contract

It excludes information the government has made public, and it excludes simple transactional information like invoices or payment data.

The practical test: if you hold a federal contract and exchange email with the government about performing it, you have FCI. Very few contractors genuinely don’t.

FCI versus CUI, and why the difference costs money

This is the distinction that determines whether your compliance obligation is small or large.

FCICUI
ClauseFAR 52.204-21DFARS 252.204-7012
Requirements15 basic practices110 requirements, 320 objectives
CMMC levelLevel 1Level 2
AssessmentSelf-assessmentSelf or third-party, depending on designation
Government cloudNot requiredFedRAMP Moderate or equivalent
SPRS scoreNot requiredRequired under 7019

Contractors get hurt in both directions. Some assume they only have FCI when they’re actually handling controlled technical information — a machine shop working from an engineering drawing is the classic case, and it’s covered in who is exempt from CMMC and DFARS cybersecurity clauses.

Others assume the worst and buy GCC High for a business that only ever touches FCI. That is a five-figure annual mistake driven by a scoping question nobody answered.

The fifteen requirements, in plain language

The clause lists fifteen basic safeguarding requirements. Grouped by what they actually ask you to do:

Who can get in (access control)

  1. Limit system access to authorized users — named accounts, no shared logins for the office.
  2. Limit access to the types of transactions and functions authorized users are permitted to execute — the accounting clerk doesn’t need domain admin.
  3. Verify and control connections to external systems — know what’s connecting to your network and from where.
  4. Control information posted on publicly accessible systems — someone reviews what goes on the website before it goes there.

Proving who someone is (identification and authentication)

  1. Identify system users and devices — unique identifiers, not a generic “office” account.
  2. Authenticate identities before granting access — passwords at minimum; multifactor is not required by this clause but is the obvious answer.

Handling media

  1. Sanitize or destroy media containing FCI before disposal or reuse — the retired laptop, the returned copier, the USB drive in a drawer.

Physical access

  1. Limit physical access to systems and equipment — a locked server closet counts.
  2. Escort visitors and monitor visitor activity
  3. Maintain audit logs of physical access — a visitor book is a valid control.
  4. Control and manage physical access devices — keys, badges, and a list of who has them.

Network protection

  1. Monitor, control, and protect communications at external boundaries and key internal boundaries — a properly configured firewall.
  2. Implement subnetworks for publicly accessible components — the guest wifi is not on the same network as accounting.

Keeping systems clean

  1. Identify, report, and correct system flaws in a timely manner — a patching process, and evidence it runs.
  2. Provide protection from malicious code, update mechanisms when new releases are available, and perform periodic and real-time scans — endpoint protection, current, on everything.

What “we already do most of this” actually means

The gap for most companies isn’t the controls. It’s the evidence.

You probably do patch. Can you show a patch report from last month? You probably do escort visitors. Is there a log? You probably do sanitize media. Is there a documented procedure and a record of the last device you disposed of?

FAR 52.204-21 is a self-assessment obligation, so nobody is coming to check on a normal Tuesday. But the moment a prime sends a security questionnaire, or a contract moves you into CUI territory, or someone asks you to affirm Level 1 — the questions become evidence questions, not control questions.

The cheapest hour you can spend on this is writing down what you already do. Not implementing anything new. Documenting the fifteen things, one paragraph each, with a pointer to where the evidence lives.

Flowdown

FAR 52.204-21 flows down to subcontractors at all tiers where the subcontractor will have FCI on its systems. Same logic as the DFARS clauses — the trigger is the data, not the supplier relationship.

In practice this means most of your suppliers who do actual work on federal contracts need this clause, which is a much wider net than the CUI clauses cast. See Flowdown: which clauses you must pass to your subcontractors for how to separate the two populations, and vendor and partner selection for what to do when a supplier can’t meet it.

Where this goes next

Two directions, depending on your contracts.

If you only ever handle FCI, you are largely done. Maintain the fifteen, document them, and revisit when your contract mix changes — a new award or a new prime relationship is a trigger event that should prompt a re-check.

If any contract brings CUI into your environment, the obligation changes shape entirely and what DFARS 252.204-7012 requires becomes the relevant page. The fifteen basic requirements don’t disappear — they’re a subset of the 110 — but they stop being the whole job.

If you’re selling to civilian agencies rather than DoD, watch the FAR CUI rule, which extends CUI handling requirements government-wide on a separate track.

Common questions about FAR 52.204-21

What is FAR 52.204-21?

A Federal Acquisition Regulation clause requiring 15 basic safeguarding controls on any information system that processes, stores, or transmits Federal Contract Information. It applies government-wide, not only to DoD contracts, and maps closely to CMMC Level 1.

What is Federal Contract Information?

Information provided by or generated for the government under a contract that is not intended for public release. It includes statements of work, delivery schedules, contract correspondence, and most working documents produced in performance. It excludes information the government has made public and simple transactional data such as invoices.

Does FAR 52.204-21 require a government cloud like GCC High?

No. None of the 15 requirements demand a government cloud, an enclave, or a third-party assessment. Commercial Microsoft 365 or Google Workspace with sensible configuration can meet all fifteen. A government cloud becomes relevant only when Controlled Unclassified Information enters the picture under DFARS 252.204-7012.

Is FAR 52.204-21 the same as CMMC Level 1?

They map closely. CMMC Level 1 consists of the same 15 practices drawn from FAR 52.204-21, assessed annually through self-assessment with an affirmation. The clause creates the contractual obligation; CMMC Level 1 is the framework used to demonstrate it.

Do I have to flow FAR 52.204-21 down to subcontractors?

Yes, at all tiers, where the subcontractor will have Federal Contract Information on its own systems. Because FCI is broad, this typically covers far more suppliers than the CUI clauses do.


Next step: If you’re not certain whether you hold FCI, CUI, or both, that’s the question to settle before spending anything. The Security & Compliance Posture Scorecard takes eighteen questions and returns a ranked list of your gaps. Free, no email required.

Last reviewed: August 2026. Verify current requirements against official sources before acting.

Table of Contents