CMMC: FAR Compliance

If you are on a federal government contract, you are required to meet the Federal Acquisition Regulations (FAR) specified in your contract. If you are dealing with the Department of Defense, you are required to comply with FAR 52.204-21 as the prime contractor or as a sub-contractor to the prime.

When the CMMC Final Rule was published, the CMMC Level 1 compliance requirements were aligned to meet with the same 15 safeguards required in FAR 52.204-21.

Compliance Requirements

FAR Clause 52.204-21 defines the safeguarding requirements as:

The Contractor shall apply the following basic safeguarding requirements and procedures to protect covered contractor information systems. Requirements and procedures for basic safeguarding of covered contractor information systems shall include, at a minimum, the following security controls:

(i) Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems).

(ii) Limit information system access to the types of transactions and functions that authorized users are permitted to execute.

(iii) Verify and control/limit connections to and use of external information systems.

(iv) Control information posted or processed on publicly accessible information systems.

(v) Identify information system users, processes acting on behalf of users, or devices.

(vi) Authenticate (or verify) the identities of those users, processes, or devices, as a prerequisite to allowing access to organizational information systems.

(vii) Sanitize or destroy information system media containing Federal Contract Information before disposal or release for reuse.

(viii) Limit physical access to organizational information systems, equipment, and the respective operating environments to authorized individuals.

(ix) Escort visitors and monitor visitor activity; maintain audit logs of physical access; and control and manage physical access devices.

(x) Monitor, control, and protect organizational communications (i.e., information transmitted or received by organizational information systems) at the external boundaries and key internal boundaries of the information systems.

(xi) Implement subnetworks for publicly accessible system components that are physically or logically separated from internal networks.

(xii) Identify, report, and correct information and information system flaws in a timely manner.

(xiii) Provide protection from malicious code at appropriate locations within organizational information systems.

(xiv) Update malicious code protection mechanisms when new releases are available.

(xv) Perform periodic scans of the information system and real-time scans of files from external sources as files are downloaded, opened, or executed.

The Good News

If your contract requires compliance with the FAR, you are close to meeting CMMC Level 1 compliance. Once you have met the compliance requirements and have completed the self-attestation you may find that there are other DoD contracts available to you since the contracts will require compliance at the time of contract award.

What Next?

Ensuring you have all the necessary policies, procedures and documentation for compliance can be overwhelming and that is where Core Cyber can assist. We can examine you existing policies and procedures to make sure they cover the compliance requirements; help you collect the evidence of compliance and guide you through obtaining a CAGE (Commercial and Government Entity) code to register in the SPRS (Supplier Performance Risk System).

If you have questions about FAR Compliance, CMMC Compliance, or other cybersecurity related items, please contact the sales team at Core Cyber to learn more about how we can help your organization achieve your desired cybersecurity goals.

Kevin Hutchinson, CISSP, CMMC RPA
Core Cyber, LLC
Owner/Operator