We've learned in the past few years that cybersecurity scams are on the rise, and they aren't as simple as the infamous gift cards for your boss gimmick. Bad actors have become more skilled in their phishing and hacking, making it more important than ever to have a strong cybersecurity posture. As a government contractor, you inevitably deal with sensitive government information, data, and software, so there are certain government regulations you have to follow to defend against compromising your network.
Keeping compliant with the Federal Acquisition Regulation (FAR) and related requirements will mitigate the risk of cyberattacks and prevent leakage of sensitive government information. Here are the top cybersecurity requirements you should keep in mind as a federal government contractor.
In recent years, several federal agencies including the Department of Defense (DoD) have issued acquisition regulations that impose new cybersecurity requirements on contractors. The top requirements that your organization should be familiar with are listed below:
Given the highly technical nature of each one of these regulations, policies, and emerging trends, it’s important to review each one of these in detail.
If you are a contractor in the federal marketplace, you should be especially familiar with FAR 52.204-21, which is the Basic Safeguarding of Covered Contractor Information Systems. At a minimum, GSA Schedule contractors are required to meet 15 basic security controls outlined in FAR 52.204-21 and the procedures to protect their covered contractor information systems.
These requirements and procedures shall include, at a minimum, the following security controls:
The Federal Information Security Modernization (FISMA) Act of 2014 was created to establish a framework for the federal government’s cybersecurity practices, especially as it relates to the Executive Branch. FISMA applies to all federal agenices and government contractors if they operate federal systems, like providing a cloud-based platform. The main goal of FISMA is to:
Contractors can maintain compliance with FISMA in-house following the Assessment Procedures defined in the National Institute of Standards and Technology (NIST) section 800-53, or they can work with a third party Managed Security Services Provider (MSSP).
DFARS clause 252.204.7012 is emerging as a very relevant form of cybersecurity requirement for federal contractors. Established under Executive Order 13556, DFARS 252.204-7012 requires contractors and subcontractors to:
NIST SP 800-171 refers to National Institute of Standards and Technology Special Publication 800-171, which governs Controlled Unclassified Information (CUI) in Non-Federal Information Systems and Organizations. NIST 800-171 requires contractors to protect controlled unclassified information in nonfederal systems and organizations. For more information on NIST 800-171, please visit the latest revision on the NIST website.
It's important to note that the current NIST SP 800-171 framework was used to create the building blocks for the Cybersecurity Maturity Model Certification (CMMC) program. CMMC was created as a way to verify contractors in the Defense Industrial Base (DIB) are meeting NIST guidelines for protecting Federal Classified Information (FCI) and CUI.
Depending on the nature of the business your organization may be seeking, agencies or Contracting Officers may require a certain level of CMMC prior to awarding a contract. Right now, CMMC applies to businesses in the Defense Industrial Base (DIB), but agencies may start requiring it in future contract vehicles or solicitations.
The CMMC Final Rule was published in October 2024 and is will be in effect on December 16, 2024. The DoD has also implemented a draft rule on how CMMC will be implemented in future solicitations.
Following cybersecurity requirements is just the beginning to successfully managing your GSA Schedule. GSA Schedule maintenance can be a lot to keep up with from sales reporting, to modifications, and Contractor Assessment Visits (CAVs), but it’s rewarding to be a part of such a booming marketplace. Need help with your contract? If you would like to learn more about staying on top of your GSA Schedule or need help identifying ways you can optimize your offerings, Winvale is here to help!