FAR 52.204-21 in plain English

What FAR 52.204-21 is

FAR 52.204-21 is the contract clause that lists 15 basic safeguarding requirements for company computer systems that handle Federal Contract Information. If your DoD contract or subcontract includes this clause, those 15 requirements are the foundation of CMMC Level 1.

The clause is called Basic Safeguarding of Covered Contractor Information Systems. It has been part of federal contracts since 2016. A proposed update to the Federal Acquisition Regulation would renumber it as 52.240-5. Until that change is final, use the clause number that appears in your contract.

How it connects to CMMC Level 1. CMMC Level 1 uses these same 15 requirements. Each year, your company assesses itself against all 15, enters the results in SPRS (the Supplier Performance Risk System), and a senior company official affirms that the results are accurate. At Level 1, you must meet every requirement; there's no partial credit or plan-to-fix-later option.

Who it applies to. The clause applies when a contract or subcontract says you may receive or create Federal Contract Information on your systems. Prime contractors must flow it down to subcontractors in the same situation, so a small shop can be covered even without a direct government contract. Check your purchase orders and subcontracts, or ask your prime contractor, if you're not sure.

Two terms to know

Federal Contract Information (FCI) is information the government provides or creates under a contract that isn't meant for public release. Think drawings, specifications, delivery schedules, and contract details for a part you make. It doesn't include information the government has made public, or simple transaction details like payment processing.

Covered contractor information system means any computer system your company owns or runs that stores, processes, or sends FCI. In a small shop, that usually includes office PCs and laptops, email, file storage like SharePoint or Google Drive, and any shop floor computer that holds customer drawings.

If FCI never touches a system, that system is outside the scope of these requirements. Many small shops keep their assessment manageable by keeping FCI in a few well-understood places.

The 15 requirements

Each requirement below shows the exact clause text, what it means in plain English, what it usually looks like in a small shop, and examples of evidence you might keep. Your setup may look different, and that's fine, as long as you can show how you meet each one.

1. Only authorized people and devices get in

(i) Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems).

In plain English: Only people you've approved, and devices you know about, can use systems that hold FCI.

In a small shop: Everyone has their own login. Accounts for people who've left are turned off promptly. You know which computers and phones connect to company email and files.

Evidence you might keep: A list of user accounts and who approved each one, a list of company devices, and your process for removing access when someone leaves.

2. People can only do what their job requires

(ii) Limit information system access to the types of transactions and functions that authorized users are permitted to execute.

In plain English: Being allowed in isn't the same as being allowed to do everything. People get the access their role needs, and no more.

In a small shop: Everyday users don't have administrator rights on their computers. Only the people who need them can open certain folders, like customer drawings or the finance share.

Evidence you might keep: A list of who has admin rights, and folder or group permissions showing who can reach FCI.

3. Control connections to outside systems

(iii) Verify and control/limit connections to and use of external information systems.

In plain English: Decide which outside systems can touch your company's FCI, like personal devices, personal email, or someone else's cloud storage, and stick to it.

In a small shop: Company files stay in company accounts. People don't forward customer drawings to personal email or save them to personal cloud storage. If personal phones get company email, you've set rules for that.

Evidence you might keep: A short written policy on personal devices and outside services, plus any settings that enforce it.

4. Control what goes on public websites

(iv) Control information posted or processed on publicly accessible information systems.

In plain English: Make sure FCI never ends up somewhere the public can see it, like your website or social media.

In a small shop: One or two named people can post to the company website and social accounts, and they know not to post customer project details, drawings, or photos showing controlled parts.

Evidence you might keep: A list of who can publish public content, and a short note on reviewing posts before they go up.

5. Know who every user and device is

(v) Identify information system users, processes acting on behalf of users, or devices.

In plain English: Every account belongs to a specific, identifiable person or device. No mystery accounts.

In a small shop: No shared logins like "shop@" or "frontdesk" used by several people to reach FCI. Each device has a name you can match to a person or location.

Evidence you might keep: Your user and device lists, showing each account tied to a named person or device.

6. Prove who someone is before letting them in

(vi) Authenticate (or verify) the identities of those users, processes, or devices, as a prerequisite to allowing access to organizational information systems.

In plain English: Before anyone gets in, the system checks they are who they say they are, usually with a password.

In a small shop: Every account needs a password to sign in. Default passwords on new equipment and software get changed. Many shops also turn on multi-factor sign-in for email and file storage, which is a strong way to meet this requirement even though the clause doesn't name it.

Evidence you might keep: Your password rules and any sign-in settings, such as multi-factor authentication being turned on.

7. Wipe or destroy old drives before they leave

(vii) Sanitize or destroy information system media containing Federal Contract Information before disposal or release for reuse.

In plain English: Before an old computer, hard drive, USB stick, or copier leaves your control, make sure no FCI can be recovered from it.

In a small shop: Old drives are wiped with a proper tool or physically destroyed. Leased copiers and printers with hard drives are wiped before they’re returned. Paper with FCI gets shredded.

Evidence you might keep: A log of wiped or destroyed equipment, or certificates from a disposal vendor.

8. Only authorized people get physical access

(viii) Limit physical access to organizational information systems, equipment, and the respective operating environments to authorized individuals.

In plain English: Keep unauthorized people away from the computers, network equipment, and areas where FCI is handled.

In a small shop: Lock the office after hours. Lock the server or network closet. Computers holding FCI aren't in open areas where visitors wander unattended.

Evidence you might keep: A list of who has keys or access badges, and notes on which areas are locked.

9. Escort visitors and track physical access

(ix) Escort visitors and monitor visitor activity; maintain audit logs of physical access; and control and manage physical access devices.

In plain English: Visitors are accompanied, you keep a record of who came in, and you keep track of keys, badges, and door codes.

In a small shop: Visitors sign in at the front and are escorted in areas with FCI. Someone knows who holds every key and badge, and door codes change when someone leaves.

Evidence you might keep: A visitor log (paper is fine), and a key or badge list with how you handle lost keys and departures.

10. Protect the edge of your network

(x) Monitor, control, and protect organizational communications (i.e., information transmitted or received by organizational information systems) at the external boundaries and key internal boundaries of the information systems.

In plain English: Control what traffic comes in and goes out of your network, so outsiders can't reach your systems freely.

In a small shop: A business firewall sits between your network and the internet, and it's configured to block unwanted incoming traffic. The guest Wi-Fi is separate from the company network.

Evidence you might keep: A simple network diagram, your firewall make and model, and a note on how it’s configured and who manages it.

11. Keep public-facing systems separate

(xi) Implement subnetworks for publicly accessible system components that are physically or logically separated from internal networks.

In plain English: Anything the public can reach from the internet should be kept apart from your internal network, so a problem there can’t spread inward.

In a small shop: Most small shops don’t host public systems themselves. If an outside provider hosts your website, it’s already separate. If you do run something public-facing in the building, it sits on its own network segment. Guest Wi-Fi on its own network also helps.

Evidence you might keep: A note on where your website and any public-facing systems are hosted, and your network diagram showing any separate segments.

12. Fix security flaws promptly

(xii) Identify, report, and correct information and information system flaws in a timely manner.

In plain English: Keep software updated, and fix known security problems without long delays.

In a small shop: Windows and Mac updates install automatically or on a regular schedule. Browsers, Office, and other key software stay current. Replace or remove computers that can't receive updates anymore.

Evidence you might keep: Your update settings or schedule, a recent update report, and a list of any older systems and how you handle them.

13. Use antivirus protection

(xiii) Provide protection from malicious code at appropriate locations within organizational information systems.

In plain English: Computers that handle FCI run protection against viruses and other malicious software. Email filtering helps too.

In a small shop: Every company computer has antivirus or endpoint protection turned on, such as Microsoft Defender or a business security product. Company email has spam and malware filtering.

Evidence you might keep: A list of computers showing protection is installed and active, and the email filtering you use.

14. Keep that protection up to date

(xiv) Update malicious code protection mechanisms when new releases are available.

In plain English: Antivirus is only useful if it’s current. It should automatically pick up new updates.

In a small shop: Turn on automatic updates for your antivirus, and check now and then that it's actually updating.

Evidence you might keep: A screenshot or report showing automatic updates are on and definitions are current.

15. Scan regularly, and scan downloads as they arrive

(xv) Perform periodic scans of the information system and real-time scans of files from external sources as files are downloaded, opened, or executed.

In plain English: Your antivirus runs scheduled scans, and it checks files the moment they’re downloaded, opened, or run.

In a small shop: Real-time protection is on, and scheduled scans run regularly, such as weekly. Most modern antivirus products, including Microsoft Defender, do both once they’re turned on.

Evidence you might keep: Your antivirus settings showing real-time protection and a scan schedule.

After you've worked through all 15

Once you've reviewed each requirement and recorded where your evidence lives, your company completes its annual self-assessment, enters the results in SPRS, and a senior company official makes the affirmation. The affirmation is your company's own statement that the results are accurate, and it's renewed every year.

AffirmReady walks you through each requirement, keeps an evidence register that points to where your documents live in your own systems, and reminds you before your affirmation is due. Next year, you pick up where you left off.

What this guide covers, and what it doesn't. This page covers the 15 basic safeguarding requirements for Federal Contract Information, which are the basis of CMMC Level 1. It doesn't cover Controlled Unclassified Information (CUI) or CMMC Level 2. If your contracts involve CUI, you likely need Level 2, and the Cyber AB Marketplace lists organizations that can help.

This guide is general information to help you prepare. It isn't legal advice, and following it doesn't guarantee any assessment outcome or contract award. Your contract terms and the current regulations govern your obligations. AffirmReady is not affiliated with or endorsed by the Department of Defense, The Cyber AB, or any government body.

Questions? Email support@affirmready.com. We answer Monday through Friday, 8 AM to 5 PM Eastern.