
FAR 52.204-21 in plain English: the 15 controls every contractor needs
The baseline safeguarding clause is in almost every federal contract and flows down to subcontractors. Here are all 15 required controls in plain language, what each means in practice, and how it relates to NIST 800-171 and CMMC.
FAR 52.204-21 requires 15 basic security controls on any system that handles Federal Contract Information (FCI). It's the floor for doing business with the US government, it flows down to subcontractors, and it maps directly to the 15 basic requirements of NIST SP 800-171 and to CMMC Level 1. Most of the 15 are things a competent IT setup already does — the work is proving it.
If you sell to the federal government — directly or as a subcontractor — this clause is almost certainly in your contract, and by signing you commit to it. The good news for a small business: it's genuinely a basic baseline, not the full weight of NIST 800-171. Here's the whole thing translated, from a firm that helps small businesses meet federal requirements without gold-plating. The clause below is quoted directly from the FAR.
First: what is FCI, and does this apply to you?
The clause protects Federal Contract Information — defined in the FAR as information "not intended for public release, that is provided by or generated for the Government under a contract to develop or deliver a product or service to the Government." It excludes information the government makes public, and simple transactional information like what's needed to process payments. Translation: if your work for a federal customer produces or touches non-public information — statements of work, deliverables, correspondence, plans — you handle FCI, and 52.204-21 applies to the systems that store, process, or transmit it. It also flows down: prime contractors must include the substance of the clause in subcontracts where the subcontractor will handle FCI, so a great deal of small-business exposure arrives second-hand from a prime.
The 15 required controls, in plain English
The FAR groups these as basic safeguarding requirements. Below, each is the plain-language version with the practical "what this means for you." The official wording lives in the clause itself (linked in Sources).
| # | The control (plain English) | What it means in practice |
|---|---|---|
| 1 | Limit system access to authorized users and devices | Accounts for real people; no shared logins; devices you don't recognize don't get on. |
| 2 | Limit access to the transactions and functions users are permitted to do | Least privilege — staff can do their job and not more; not everyone is an admin. |
| 3 | Verify and control connections to external systems | Know and control what your systems connect to — cloud services, partner links, remote access. |
| 4 | Control information posted on publicly accessible systems | Someone approves what goes on your public website/portals; FCI never lands there by accident. |
| 5 | Identify system users, processes, and devices | Every user and device has a unique identity — the prerequisite for the next control. |
| 6 | Authenticate users, processes, and devices before access | Prove identity before entry — strong passwords and, in practice, MFA. |
| 7 | Sanitize or destroy media before disposal or reuse | Wipe drives and devices before they leave; don't sell the old laptop with the data on it. |
| 8 | Limit physical access to systems and environments | Server closet locked; office access controlled; equipment isn't in the open lobby. |
| 9 | Escort visitors; keep physical access logs; manage access devices | Visitors are accompanied, entry is logged, and badges/keys are tracked and recovered. |
| 10 | Monitor and protect communications at external and key internal boundaries | Firewalls at the edge and between important internal zones — watch and control the traffic. |
| 11 | Separate publicly accessible components onto subnetworks | Anything public-facing sits in its own segment (a DMZ), not on your internal network. |
| 12 | Identify, report, and correct flaws in a timely manner | A real patch and vulnerability-remediation process — find issues, fix them, on a cadence. |
| 13 | Provide protection from malicious code at appropriate locations | Anti-malware/EDR where it matters — endpoints, mail, gateways. |
| 14 | Update malicious-code protection when new releases are available | Keep those defenses current — automatic updates, not "we'll get to it." |
| 15 | Periodically scan systems, and scan files from external sources in real time | Scheduled system scans plus real-time scanning of downloads and email attachments. |
Read them together and a shape appears: access control (1, 2, 5, 6), boundary and network protection (3, 10, 11), physical security (7, 8, 9), and system integrity (4, 12, 13, 14, 15). It is, deliberately, ordinary good hygiene — much of it overlaps our general 20-point SMB security checklist. The federal difference is that here it's contractual, and you attest to it.
How this relates to NIST 800-171 and CMMC (the part that confuses everyone)
These three names travel together and get conflated constantly. Cleanly separated: FAR 52.204-21 is the contract clause requiring these 15 basic controls to protect FCI. NIST SP 800-171 is the fuller standard (many more requirements) for protecting the more sensitive Controlled Unclassified Information (CUI) — a higher tier than FCI. CMMC (Cybersecurity Maturity Model Certification) is the Defense Department's program for verifying contractors meet these requirements, with Level 1 corresponding to exactly these 15 FCI safeguards and higher levels aligning to NIST 800-171.
| Protects | Roughly how many controls | Verification | |
|---|---|---|---|
| FAR 52.204-21 | FCI (basic) | 15 | Self-attestation, by signing the contract |
| CMMC Level 1 | FCI (basic) | 15 (same set) | Annual self-assessment + affirmation |
| NIST SP 800-171 / CMMC L2 | CUI (sensitive) | 110 requirements | Self- or third-party assessment (C3PAO) |
The practical takeaway for most small businesses: if you only handle FCI, 52.204-21 / CMMC Level 1 is your world — the 15 controls above. You step up to NIST 800-171 and CMMC Level 2 only when a contract involves CUI. Don't let a vendor scare you into a 110-control project when your contracts only require 15.
A minimum-viable path to compliance
For a small business handling FCI, a realistic route: Step one, scope — identify which systems touch FCI; often you can keep it to a defined, smaller environment rather than "everything." Step two, gap-check the 15 controls against what you have; a competent modern setup often meets 10–12 already. Step three, close the gaps — usually physical-access logging, media sanitization procedure, network segmentation, and formalizing the patch process are the ones missing. Step four, document — because "we do this" and "we can show an assessor we do this" are different states, and CMMC Level 1 requires an annual self-assessment and a signed affirmation. The documentation is genuinely most of the work; the controls themselves are rarely exotic.
The compliance mistake that becomes a legal problem
By signing a contract with this clause — or affirming CMMC Level 1 — you represent that you meet these controls. Doing that when you don't isn't a paperwork gap; under the civil False Claims Act it can become a fraud exposure, and the government has pursued cybersecurity misrepresentations exactly this way. The safe posture is boring and cheap: meet the 15 controls, document them honestly, and if you're mid-remediation, know your contract's actual requirement before you affirm. We build to standards our clients can verify precisely so the attestation is true when signed — the same principle behind everything on our federal capabilities page.
A quick scoping example
Here's how "scope it small" works in practice. A 12-person engineering subcontractor wins a flow-down with 52.204-21 attached. Their instinct is panic — 15 controls across the whole company. But the FCI in question is a set of design documents delivered to one federal prime, and it lives in one shared drive folder and the laptops of the four engineers on that project. Scoped correctly, the "covered contractor information system" is that folder and those four laptops — not the marketing team's tools, not the whole M365 tenant. Now the 15 controls apply to a bounded environment: unique logins and MFA for those four (already have it), the folder's access limited to the project team (a five-minute change), the laptops encrypted and running EDR (already), a media-disposal procedure and a physical-access note for the office (write them down), the network boundary already firewalled. Suddenly a "compliance project" is an afternoon of tightening plus a page of documentation. Over-scoping is how small businesses turn a 15-control clause into an imagined 110-control ordeal — read what the contract actually names, then draw the smallest honest boundary around the FCI.
Frequently asked questions
Does FAR 52.204-21 apply to subcontractors?
Yes. The clause requires prime contractors to include its substance in subcontracts where the subcontractor will have FCI in or transiting its systems — including subcontracts for commercial products and services (other than commercially-available off-the-shelf items). Much small-business exposure arrives this way, flowed down from a prime.
Is FAR 52.204-21 the same as CMMC Level 1?
They cover the same 15 basic safeguarding controls for FCI. The difference is verification: 52.204-21 is met by signing the contract; CMMC Level 1 adds a required annual self-assessment and an affirmation of compliance. If you meet the 15 controls and document them, you're positioned for both.
Do we need NIST 800-171's 110 controls?
Only if you handle Controlled Unclassified Information (CUI), which is more sensitive than FCI. If your contracts involve only FCI, the 15 basic controls are your requirement. Check what your specific contract and any flow-down clauses actually name before scoping a larger project.
How much does meeting these 15 controls cost a small business?
Far less than the 800-171/CMMC-L2 path. Many small firms already satisfy most of the 15 through normal IT hygiene; typical spend is on the gaps (segmentation, physical-access logging, formalized patching) plus the documentation and annual self-assessment. It's a modest, well-bounded project — not an enterprise program.
What counts as Federal Contract Information exactly?
Per the FAR: information not intended for public release, provided by or generated for the government under a contract to deliver a product or service — excluding information the government releases publicly and simple transactional information like payment processing data. In practice: your non-public deliverables, SOWs, plans, and correspondence with a federal customer.
Check your federal requirements Our federal capabilities
Sources: FAR 52.204-21, Basic Safeguarding of Covered Contractor Information Systems (acquisition.gov) · NIST SP 800-171 Rev. 3 (csrc.nist.gov). This is general information, not legal advice — confirm your specific obligations against your contract and, where the stakes warrant, with counsel.