Government building columns

Home / Guides / FAR 52.204-21

FAR 52.204-21 in plain English: the 15 controls every contractor needs

The baseline safeguarding clause is in almost every federal contract and flows down to subcontractors. Here are all 15 required controls in plain language, what each means in practice, and how it relates to NIST 800-171 and CMMC.

FAR 52.204-21 requires 15 basic security controls on any system that handles Federal Contract Information (FCI). It's the floor for doing business with the US government, it flows down to subcontractors, and it maps directly to the 15 basic requirements of NIST SP 800-171 and to CMMC Level 1. Most of the 15 are things a competent IT setup already does — the work is proving it.

If you sell to the federal government — directly or as a subcontractor — this clause is almost certainly in your contract, and by signing you commit to it. The good news for a small business: it's genuinely a basic baseline, not the full weight of NIST 800-171. Here's the whole thing translated, from a firm that helps small businesses meet federal requirements without gold-plating. The clause below is quoted directly from the FAR.

First: what is FCI, and does this apply to you?

The clause protects Federal Contract Information — defined in the FAR as information "not intended for public release, that is provided by or generated for the Government under a contract to develop or deliver a product or service to the Government." It excludes information the government makes public, and simple transactional information like what's needed to process payments. Translation: if your work for a federal customer produces or touches non-public information — statements of work, deliverables, correspondence, plans — you handle FCI, and 52.204-21 applies to the systems that store, process, or transmit it. It also flows down: prime contractors must include the substance of the clause in subcontracts where the subcontractor will handle FCI, so a great deal of small-business exposure arrives second-hand from a prime.

The 15 required controls, in plain English

The FAR groups these as basic safeguarding requirements. Below, each is the plain-language version with the practical "what this means for you." The official wording lives in the clause itself (linked in Sources).

#The control (plain English)What it means in practice
1Limit system access to authorized users and devicesAccounts for real people; no shared logins; devices you don't recognize don't get on.
2Limit access to the transactions and functions users are permitted to doLeast privilege — staff can do their job and not more; not everyone is an admin.
3Verify and control connections to external systemsKnow and control what your systems connect to — cloud services, partner links, remote access.
4Control information posted on publicly accessible systemsSomeone approves what goes on your public website/portals; FCI never lands there by accident.
5Identify system users, processes, and devicesEvery user and device has a unique identity — the prerequisite for the next control.
6Authenticate users, processes, and devices before accessProve identity before entry — strong passwords and, in practice, MFA.
7Sanitize or destroy media before disposal or reuseWipe drives and devices before they leave; don't sell the old laptop with the data on it.
8Limit physical access to systems and environmentsServer closet locked; office access controlled; equipment isn't in the open lobby.
9Escort visitors; keep physical access logs; manage access devicesVisitors are accompanied, entry is logged, and badges/keys are tracked and recovered.
10Monitor and protect communications at external and key internal boundariesFirewalls at the edge and between important internal zones — watch and control the traffic.
11Separate publicly accessible components onto subnetworksAnything public-facing sits in its own segment (a DMZ), not on your internal network.
12Identify, report, and correct flaws in a timely mannerA real patch and vulnerability-remediation process — find issues, fix them, on a cadence.
13Provide protection from malicious code at appropriate locationsAnti-malware/EDR where it matters — endpoints, mail, gateways.
14Update malicious-code protection when new releases are availableKeep those defenses current — automatic updates, not "we'll get to it."
15Periodically scan systems, and scan files from external sources in real timeScheduled system scans plus real-time scanning of downloads and email attachments.

Read them together and a shape appears: access control (1, 2, 5, 6), boundary and network protection (3, 10, 11), physical security (7, 8, 9), and system integrity (4, 12, 13, 14, 15). It is, deliberately, ordinary good hygiene — much of it overlaps our general 20-point SMB security checklist. The federal difference is that here it's contractual, and you attest to it.

How this relates to NIST 800-171 and CMMC (the part that confuses everyone)

These three names travel together and get conflated constantly. Cleanly separated: FAR 52.204-21 is the contract clause requiring these 15 basic controls to protect FCI. NIST SP 800-171 is the fuller standard (many more requirements) for protecting the more sensitive Controlled Unclassified Information (CUI) — a higher tier than FCI. CMMC (Cybersecurity Maturity Model Certification) is the Defense Department's program for verifying contractors meet these requirements, with Level 1 corresponding to exactly these 15 FCI safeguards and higher levels aligning to NIST 800-171.

ProtectsRoughly how many controlsVerification
FAR 52.204-21FCI (basic)15Self-attestation, by signing the contract
CMMC Level 1FCI (basic)15 (same set)Annual self-assessment + affirmation
NIST SP 800-171 / CMMC L2CUI (sensitive)110 requirementsSelf- or third-party assessment (C3PAO)

The practical takeaway for most small businesses: if you only handle FCI, 52.204-21 / CMMC Level 1 is your world — the 15 controls above. You step up to NIST 800-171 and CMMC Level 2 only when a contract involves CUI. Don't let a vendor scare you into a 110-control project when your contracts only require 15.

Not sure whether you're handling FCI or CUI — or whether a subcontract just flowed 800-171 onto you? Send us the clause and we'll tell you which tier you're actually in.

A minimum-viable path to compliance

For a small business handling FCI, a realistic route: Step one, scope — identify which systems touch FCI; often you can keep it to a defined, smaller environment rather than "everything." Step two, gap-check the 15 controls against what you have; a competent modern setup often meets 10–12 already. Step three, close the gaps — usually physical-access logging, media sanitization procedure, network segmentation, and formalizing the patch process are the ones missing. Step four, document — because "we do this" and "we can show an assessor we do this" are different states, and CMMC Level 1 requires an annual self-assessment and a signed affirmation. The documentation is genuinely most of the work; the controls themselves are rarely exotic.

The compliance mistake that becomes a legal problem

By signing a contract with this clause — or affirming CMMC Level 1 — you represent that you meet these controls. Doing that when you don't isn't a paperwork gap; under the civil False Claims Act it can become a fraud exposure, and the government has pursued cybersecurity misrepresentations exactly this way. The safe posture is boring and cheap: meet the 15 controls, document them honestly, and if you're mid-remediation, know your contract's actual requirement before you affirm. We build to standards our clients can verify precisely so the attestation is true when signed — the same principle behind everything on our federal capabilities page.

A quick scoping example

Here's how "scope it small" works in practice. A 12-person engineering subcontractor wins a flow-down with 52.204-21 attached. Their instinct is panic — 15 controls across the whole company. But the FCI in question is a set of design documents delivered to one federal prime, and it lives in one shared drive folder and the laptops of the four engineers on that project. Scoped correctly, the "covered contractor information system" is that folder and those four laptops — not the marketing team's tools, not the whole M365 tenant. Now the 15 controls apply to a bounded environment: unique logins and MFA for those four (already have it), the folder's access limited to the project team (a five-minute change), the laptops encrypted and running EDR (already), a media-disposal procedure and a physical-access note for the office (write them down), the network boundary already firewalled. Suddenly a "compliance project" is an afternoon of tightening plus a page of documentation. Over-scoping is how small businesses turn a 15-control clause into an imagined 110-control ordeal — read what the contract actually names, then draw the smallest honest boundary around the FCI.

Frequently asked questions

Does FAR 52.204-21 apply to subcontractors?

Yes. The clause requires prime contractors to include its substance in subcontracts where the subcontractor will have FCI in or transiting its systems — including subcontracts for commercial products and services (other than commercially-available off-the-shelf items). Much small-business exposure arrives this way, flowed down from a prime.

Is FAR 52.204-21 the same as CMMC Level 1?

They cover the same 15 basic safeguarding controls for FCI. The difference is verification: 52.204-21 is met by signing the contract; CMMC Level 1 adds a required annual self-assessment and an affirmation of compliance. If you meet the 15 controls and document them, you're positioned for both.

Do we need NIST 800-171's 110 controls?

Only if you handle Controlled Unclassified Information (CUI), which is more sensitive than FCI. If your contracts involve only FCI, the 15 basic controls are your requirement. Check what your specific contract and any flow-down clauses actually name before scoping a larger project.

How much does meeting these 15 controls cost a small business?

Far less than the 800-171/CMMC-L2 path. Many small firms already satisfy most of the 15 through normal IT hygiene; typical spend is on the gaps (segmentation, physical-access logging, formalized patching) plus the documentation and annual self-assessment. It's a modest, well-bounded project — not an enterprise program.

What counts as Federal Contract Information exactly?

Per the FAR: information not intended for public release, provided by or generated for the government under a contract to deliver a product or service — excluding information the government releases publicly and simple transactional information like payment processing data. In practice: your non-public deliverables, SOWs, plans, and correspondence with a federal customer.

Check your federal requirements Our federal capabilities

Sources: FAR 52.204-21, Basic Safeguarding of Covered Contractor Information Systems (acquisition.gov) · NIST SP 800-171 Rev. 3 (csrc.nist.gov). This is general information, not legal advice — confirm your specific obligations against your contract and, where the stakes warrant, with counsel.