Current: Phase II suspended July 13, 2026. Phase I self-assessment requirements remain.Read the update →
CONTRACT CLAUSE

FAR 52.204-21 Quick Reference: The 15 Basic Safeguarding Requirements Behind CMMC Level 1

A fast, checklist-style reference to the 15 basic safeguarding requirements in FAR 52.204-21 — the rule set CMMC Level 1 self-assessment is built on.

FAR 52.204-21 is broader than DFARS and CMMC — it applies to federal contracts generally (not only DoD) whenever a contractor's information system processes, stores, or transmits Federal Contract Information (FCI), unless the contract is exempt under commercial-off-the-shelf rules.

It sets 15 basic safeguarding requirements, grouped informally around access control, identification and authentication, media protection, physical protection, system and communications protection, and system and information integrity.

CMMC Level 1 self-assessment tracks these same 15 requirements. A contractor that can honestly check off all 15 against FAR 52.204-21 has, in effect, done the substance of a Level 1 self-assessment — the CMMC layer adds the annual affirmation and status record on top.

What this contract clause actually requires

  • Limit information-system access to authorized users, processes, and devices.
  • Limit access to the types of transactions and functions authorized users are permitted to execute.
  • Verify and control/limit connections to external information systems.
  • Control information posted or processed on publicly accessible systems.
  • Identify system users, processes, and devices before allowing access.
  • Authenticate (or verify) identities before allowing access.
  • Sanitize or destroy media containing FCI before disposal, release, or reuse.
  • Limit physical access to information systems, equipment, and operating environments to authorized individuals.
  • Escort visitors and monitor visitor activity; maintain audit logs of physical access; control and manage physical access devices.
  • Monitor, control, and protect communications at external boundaries and key internal boundaries.
  • Implement subnetworks for publicly accessible system components that are physically or logically separated from internal networks.
  • Identify, report, and correct information and system flaws in a timely manner.
  • Provide protection from malicious code at appropriate locations.
  • Update malicious-code protection when new releases are available.
  • Perform periodic scans of the information system and real-time scans of files from external sources as files are downloaded, opened, or executed.
COMMON MISTAKES

Where small contractors get this wrong

  • Assuming FAR 52.204-21 only matters for DoD work — it applies whenever FCI is on the system, across federal agencies, unless a COTS exemption applies.
  • Treating the 15 requirements as a one-time IT project instead of a maintained baseline (patching, malicious-code updates, media sanitization records).
  • Skipping written evidence — a self-assessment with no record of how each requirement is met is hard to defend later even if the practices are real.
  • Confusing FCI-only Level 1 scope with CUI-driven Level 2 obligations, which pull in the much larger NIST SP 800-171 requirement set.

Common questions

Does FAR 52.204-21 require a written system security plan?

The clause itself does not require an SSP the way NIST SP 800-171 does for Level 2. In practice, keeping a short written record of how each of the 15 requirements is met makes a Level 1 self-assessment and affirmation defensible.

Is FAR 52.204-21 the same 15 requirements as CMMC Level 1?

Yes — CMMC Level 1 self-assessment is built directly on these 15 FAR 52.204-21 basic safeguarding requirements for systems handling Federal Contract Information.

Official sources used for this page

Open the primary source before making a contract-specific decision. Regulations and program implementation can change.