Guide5 min read
FAR 52.204-21 and CMMC basics
The fifteen basic safeguarding requirements for federal contract information, how they relate to CMMC Level 1, and what a small business can do now to be ready.
By ONE VIEW Team

If your business will handle information from a federal contract, you will meet cybersecurity requirements in the contract itself. For most small businesses the starting point is one clause in the Federal Acquisition Regulation, FAR 52.204-21, and, for Department of Defense work, the Cybersecurity Maturity Model Certification (CMMC) program built on top of it. This guide explains both in plain terms. It is an orientation, not legal advice; the clause text and the official program pages are the authority.
What FAR 52.204-21 covers
FAR 52.204-21, Basic Safeguarding of Covered Contractor Information Systems, applies when a contractor's information system processes, stores or transmits Federal Contract Information (FCI).
FCI is information that is not intended for public release, that is provided by or generated for the government under a contract to develop or deliver a product or service. It does not include information the government provides to the public, such as on public websites, or simple transactional information such as that needed to process payments. In practice, a great deal of ordinary contract correspondence, schedules and deliverables is FCI.
A covered contractor information system is one you own or operate that handles FCI. For a small business that often means your laptops, email, file storage and phones.
The fifteen requirements
The clause lists fifteen basic safeguarding requirements. In summary, you must:
- Limit system access to authorized users, processes acting on behalf of authorized users, and devices.
- Limit access to the types of transactions and functions that authorized users are permitted to execute.
- Verify and control or limit connections to and use of external information systems.
- Control information posted or processed on publicly accessible information systems.
- Identify system users, processes acting on behalf of users, and devices.
- Authenticate, or verify, the identities of those users, processes and devices before allowing access.
- Sanitize or destroy media containing FCI before disposal or release for reuse.
- Limit physical access to systems, equipment and operating environments to authorized individuals.
- Escort visitors and monitor visitor activity, maintain audit logs of physical access, and control and manage physical access devices.
- Monitor, control and protect communications at the external boundaries and key internal boundaries of your systems.
- Implement subnetworks for publicly accessible system components that are physically or logically separated from internal networks.
- Identify, report and correct information and system flaws in a timely manner.
- Provide protection from malicious code at appropriate locations.
- Update malicious code protection when new releases are available.
- Perform periodic scans of the system and real-time scans of files from external sources as they are downloaded, opened or executed.
These are basic hygiene. Many small businesses already do most of them without having written them down.
What that looks like in a small business
- Accounts. Every person has their own account; nobody shares logins. Remove access the day someone leaves. Staff use standard accounts for daily work, with administrator rights only where needed.
- Authentication. Require strong passwords, and turn on multi-factor authentication for email and cloud storage. Multi-factor authentication is not one of the fifteen FAR requirements, but it is one of the most effective ways to meet the intent of the identification and authentication items.
- Devices and networks. Keep an inventory of the laptops, phones and services that touch contract information. Use a firewall at the boundary of your office network, and keep your public website separate from internal systems.
- Updates and malware protection. Turn on automatic updates for operating systems and applications. Use endpoint protection that updates itself and scans downloads.
- Physical security. Lock offices and equipment, keep track of who has keys or badges, and escort visitors where contract work happens.
- Media. Wipe or destroy drives and devices before they are disposed of or reused.
- Public information. Decide who is allowed to post on your website and social channels, and make sure FCI is never published.
Write down what you do for each requirement. A short document that names the control, the tool or process that meets it, and the person responsible is the foundation for everything that follows.
CMMC in brief
The Cybersecurity Maturity Model Certification program is the Department of Defense's way of verifying that contractors protect the information they handle. The program rule is codified at 32 CFR part 170 and took effect on December 16, 2024. The corresponding acquisition rule in the Defense Federal Acquisition Regulation Supplement began a phased introduction of CMMC requirements into DoD solicitations and contracts on November 10, 2025. The phase-in runs over several years, so check the DoD CIO's CMMC pages for which requirements apply to new contracts today.
CMMC has three levels:
- Level 1 (Foundational) applies where a contractor handles FCI only. Its requirements are the fifteen in FAR 52.204-21. Contractors perform an annual self-assessment and a senior company official affirms compliance in the Supplier Performance Risk System (SPRS).
- Level 2 (Advanced) applies where a contractor handles Controlled Unclassified Information (CUI). It aligns with the 110 security requirements of NIST SP 800-171. Depending on the contract, compliance is shown by a self-assessment or by a certification assessment from an authorized third-party assessment organization.
- Level 3 (Expert) applies to a smaller set of contracts involving the most sensitive CUI, adds selected requirements from NIST SP 800-172, and is assessed by the government.
The level a contract requires is stated in the solicitation. If you are new to defense work and will only handle FCI, Level 1 is where you start, and it is the same work as FAR 52.204-21.
A practical plan
- Find where FCI lives. List the systems, services and devices that will touch contract information. Keeping that footprint small makes everything else easier.
- Walk the fifteen requirements. For each, note how you meet it today and what is missing.
- Close the gaps. Most gaps are settings and habits: account hygiene, updates, multi-factor authentication, a visitor log.
- Write it down. Keep a short description of each control and who owns it, plus evidence such as screenshots of settings and a copy of your asset inventory.
- Review annually. CMMC Level 1 affirmations are annual. Put the date on the calendar.
How ONE VIEW Launchpad helps
The Cyber Readiness category walks you through a structured self-assessment aligned to these requirements and keeps your written controls and evidence in the document vault, with review dates. Your readiness score shows how much of that work is recorded. It describes your readiness; it is not a CMMC assessment, an SPRS affirmation or any official government qualification, and it never replaces reading the clause in your contract.
Official sources
- FAR 52.204-21 on Acquisition.gov (opens in a new tab): the clause text.
- DoD CIO: CMMC (opens in a new tab): the official program pages, documents and current implementation status.
- NIST SP 800-171 (opens in a new tab): the requirements behind CMMC Level 2.
- CISA: Cyber Essentials (opens in a new tab): practical guidance for small organizations.
- APEX Accelerators (opens in a new tab): free counseling, including cybersecurity readiness for defense contracting.
Guidance here is general information, not legal or regulatory advice. Official sources are the authority.