If you cannot find information about a compliance topic, please contact us for free support.
-
Policies & Procedures
- How to Submit Your SPRS Score: PIEE Step-by-Step Guide [2026 Update]
- CMMC Policies and Procedures: What Documentation You Need
- How to Write a System Security Plan: The Owner's Guide to the One Document That Gates Everything
- Creating a Plan of Action and Milestones for CMMC
- Documenting Evidence for CMMC Assessment
-
SPRS & Self-Assessment
-
CMMC Fundamentals
-
Contract Clauses & Flowdown
- DFARS and FAR Cybersecurity Clauses: What Each One Actually Requires
- What DFARS 252.204-7012 Requires, in Plain English
- DFARS 252.204-7019 vs 7020 vs 7021: What Each Clause Triggers
- FAR 52.204-21 and FCI: The 15 Basic Safeguarding Requirements
- DFARS flowdown requirements: Which Clauses You Must Pass to Your Subcontractors
- Flowdown: Which Clauses You Must Pass to Your Subcontractors
- Who Is Exempt from CMMC, and Why "We Only Make Parts" Usually Isn't
- What to Do When a DFARS Clause Appears in a Contract You Already Signed
- FAR 52.204-21 and FCI: The 15 Basic Safeguarding Requirements
-
Trigger Events & Urgent Situations
- Cybersecurity Questionnaire From Your Prime? Do This
- CUI Marked Drawings You Were Not Expecting? Do This
- Expired SPRS Score and a Bid Due? Fix It This Week
- Dropped Without CMMC? What a Prime Can Actually Do
- 90 Days to CMMC Compliance: What Is Really Possible
- DFARS 7021 Clause Found After Award? Read This First
- CMMC Compliant MSP? How to Verify What Yours Claims
- CUI in Commercial Microsoft 365: What to Do Now
- CMMC Level 2 Certification an RFP Wants? Bid Anyway
- CMMC Trigger Events: A Triage Guide for Contractors
-
CMMC Levels & Requirements
-
The 14 Control Families
- Access Control (AC)
- Awareness and Training (AT)
- Audit and Accountability (AU)
- Configuration Management (CM)
- Identification and Authentication (IA)
- CMMC Incident Response (IR)
- Maintenance (MA)
- Media Protection (MP)
- Personnel Security (PS)
- Physical Protection (PE)
- Risk Assessment (RA)
- Security Assessment (CA)
- System and Communications Protection (SC)
- System and Information Integrity (SI)
-
Implementation Roadmaps
-
Industry-Specific Guides
-
CMMC Documentation & Evidence
-
CMMC Costs & Budgeting
-
Technology & Tools
-
CMMC Training & Awareness
-
Supply Chain & Third-Party Risk
-
Incident Response & Breach Reporting
-
Common Mistakes & Failures
-
Advanced Topics & Level 2
-
Updates & Regulatory Changes
-
Artificial Intelligence (AI)
-
Comparisons & Alternatives
- GCC High vs GCC vs Commercial Microsoft 365 for CUI
- CMMC Compliance Options: Enclave, Environment or Service
- Enclave vs Full Remediation: Which CMMC Path Fits
- PreVeil vs GCC High for Small Defense Contractors
- CMMC Platform vs Consultant vs Doing It In House
- RPO vs C3PAO vs Consultant: Who Does What in CMMC
- CMMC Compliance Software for Small Manufacturers
- Azure Government vs AWS GovCloud for CUI Workloads
- Virtual Desktop Enclave vs Managed Laptops for CUI
- Free NIST 800-171 Tools vs Paid Platforms: The Gaps
- Build vs Buy Enclave: What In House Actually Costs
FAR 52.204-21 and FCI: The 15 Basic Safeguarding Requirements
FAR 52.204-21 is the clause most contractors assume doesn’t apply to them, and most of them are wrong. It applies to nearly every company holding a federal contract, it predates CMMC, and it is the floor everything else is built on. For how it fits with the DFARS clauses, see DFARS and FAR Cybersecurity Clauses: What Each One Actually Requires.
Here is the part worth knowing up front: none of the fifteen requirements demand a government cloud, an enclave, an assessor, or a consultant. Most companies with competent IT already meet ten or twelve of them. This is the cheapest compliance obligation in the federal space, and treating it like the expensive one is a common and costly mistake.
What triggers it: Federal Contract Information
The clause attaches to systems that process, store, or transmit Federal Contract Information — information provided by or generated for the government under a contract, that is not intended for public release.
That definition is broader than people expect. FCI includes:
- Statements of work and delivery schedules
- Correspondence with your contracting officer
- Contract line items, pricing, and performance data
- Drawings and specifications that aren’t controlled but aren’t public either
- Almost any working document generated in performance of the contract
It excludes information the government has made public, and it excludes simple transactional information like invoices or payment data.
The practical test: if you hold a federal contract and exchange email with the government about performing it, you have FCI. Very few contractors genuinely don’t.
FCI versus CUI, and why the difference costs money
This is the distinction that determines whether your compliance obligation is small or large.
| FCI | CUI | |
|---|---|---|
| Clause | FAR 52.204-21 | DFARS 252.204-7012 |
| Requirements | 15 basic practices | 110 requirements, 320 objectives |
| CMMC level | Level 1 | Level 2 |
| Assessment | Self-assessment | Self or third-party, depending on designation |
| Government cloud | Not required | FedRAMP Moderate or equivalent |
| SPRS score | Not required | Required under 7019 |
Contractors get hurt in both directions. Some assume they only have FCI when they’re actually handling controlled technical information — a machine shop working from an engineering drawing is the classic case, and it’s covered in who is exempt from CMMC and DFARS cybersecurity clauses.
Others assume the worst and buy GCC High for a business that only ever touches FCI. That is a five-figure annual mistake driven by a scoping question nobody answered.
The fifteen requirements, in plain language
The clause lists fifteen basic safeguarding requirements. Grouped by what they actually ask you to do:
Who can get in (access control)
- Limit system access to authorized users — named accounts, no shared logins for the office.
- Limit access to the types of transactions and functions authorized users are permitted to execute — the accounting clerk doesn’t need domain admin.
- Verify and control connections to external systems — know what’s connecting to your network and from where.
- Control information posted on publicly accessible systems — someone reviews what goes on the website before it goes there.
Proving who someone is (identification and authentication)
- Identify system users and devices — unique identifiers, not a generic “office” account.
- Authenticate identities before granting access — passwords at minimum; multifactor is not required by this clause but is the obvious answer.
Handling media
- Sanitize or destroy media containing FCI before disposal or reuse — the retired laptop, the returned copier, the USB drive in a drawer.
Physical access
- Limit physical access to systems and equipment — a locked server closet counts.
- Escort visitors and monitor visitor activity
- Maintain audit logs of physical access — a visitor book is a valid control.
- Control and manage physical access devices — keys, badges, and a list of who has them.
Network protection
- Monitor, control, and protect communications at external boundaries and key internal boundaries — a properly configured firewall.
- Implement subnetworks for publicly accessible components — the guest wifi is not on the same network as accounting.
Keeping systems clean
- Identify, report, and correct system flaws in a timely manner — a patching process, and evidence it runs.
- Provide protection from malicious code, update mechanisms when new releases are available, and perform periodic and real-time scans — endpoint protection, current, on everything.
What “we already do most of this” actually means
The gap for most companies isn’t the controls. It’s the evidence.
You probably do patch. Can you show a patch report from last month? You probably do escort visitors. Is there a log? You probably do sanitize media. Is there a documented procedure and a record of the last device you disposed of?
FAR 52.204-21 is a self-assessment obligation, so nobody is coming to check on a normal Tuesday. But the moment a prime sends a security questionnaire, or a contract moves you into CUI territory, or someone asks you to affirm Level 1 — the questions become evidence questions, not control questions.
The cheapest hour you can spend on this is writing down what you already do. Not implementing anything new. Documenting the fifteen things, one paragraph each, with a pointer to where the evidence lives.
Flowdown
FAR 52.204-21 flows down to subcontractors at all tiers where the subcontractor will have FCI on its systems. Same logic as the DFARS clauses — the trigger is the data, not the supplier relationship.
In practice this means most of your suppliers who do actual work on federal contracts need this clause, which is a much wider net than the CUI clauses cast. See Flowdown: which clauses you must pass to your subcontractors for how to separate the two populations, and vendor and partner selection for what to do when a supplier can’t meet it.
Where this goes next
Two directions, depending on your contracts.
If you only ever handle FCI, you are largely done. Maintain the fifteen, document them, and revisit when your contract mix changes — a new award or a new prime relationship is a trigger event that should prompt a re-check.
If any contract brings CUI into your environment, the obligation changes shape entirely and what DFARS 252.204-7012 requires becomes the relevant page. The fifteen basic requirements don’t disappear — they’re a subset of the 110 — but they stop being the whole job.
If you’re selling to civilian agencies rather than DoD, watch the FAR CUI rule, which extends CUI handling requirements government-wide on a separate track.
Frequently asked
Questions about this topic
What is FAR 52.204-21?
What is Federal Contract Information?
Does FAR 52.204-21 require a government cloud like GCC High?
Is FAR 52.204-21 the same as CMMC Level 1?
Do I have to flow FAR 52.204-21 down to subcontractors?
Keep reading
More in Contract Clauses & Flowdown
- DFARS 252.204-7019 vs 7020 vs 7021: What Each Clause Triggers →
- DFARS and FAR Cybersecurity Clauses: What Each One Actually Requires →
- DFARS flowdown requirements: Which Clauses You Must Pass to Your Subcontractors →
- FAR 52.204-21 and FCI: The 15 Basic Safeguarding Requirements →
- Flowdown: Which Clauses You Must Pass to Your Subcontractors →
- What DFARS 252.204-7012 Requires, in Plain English →
- What to Do When a DFARS Clause Appears in a Contract You Already Signed →
- Who Is Exempt from CMMC, and Why “We Only Make Parts” Usually Isn’t →
Free tools
Get to an honest number faster
You will run this more than once: after any material change to your environment, and again before every annual affirmation. Both are free, and both are yours to keep.
Neither is a certified assessment, and neither pretends to be.
The audit is gone. The liability isn't.
Greypike runs the environment your CUI lives in and owns the compliance outcome that proves it's protected. If you are not certain your environment supports the score sitting in SPRS next to your CAGE code, that is the conversation to have.
Talk to Greypike about SPRS Attestation AssuranceGreypike Inc.
SBA-certified Veteran-Owned Small Business
Cyber AB Registered Practitioner (RP) and Registered Practitioner Advanced (RPA) on staff
CAGE 9WVS6 · UEI N6CJNGDARFM5