A community resource for the acquisition workforce not a .gov website
part52.dev Federal Acquisition Clause Monitor
R-DFARS Provision

252.204-7008

Compliance with safeguarding covered defense information controls
Source deviation PDF →
Effective Date
February 1, 2026
Deviation
Versions
1

This text is not in eCFR or DITA. It is extracted from the Revolutionary FAR Overhaul deviation guide for FAR Part 40. The parsed text is a convenience layer; the Source PDF tab is authoritative. Always verify against the official deviation PDF.

As prescribed in 240.370-5(a). See the Prescription tab for the prescribing policy text.

COMPLIANCE WITH SAFEGUARDING COVERED DEFENSE INFORMATION CONTROLS (OCT 2016)

  1. (a) Definitions. As used in this provision— Controlled technical information, covered contractor information system, covered defense information, cyber incident, information system, and technical information are defined in clause 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting.
  2. (b) The security requirements required by contract clause 252.204-7012, shall be implemented for all covered defense information on all covered contractor information systems that support the performance of this contract.
  3. (c) For covered contractor information systems that are not part of an information technology service or system operated on behalf of the Government (see 252.204-7012(b)(2))—
    1. (1) By submission of this offer, the Offeror represents that it will implement the security requirements specified by National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171, “Protecting Controlled Unclassified Information in Nonfederal Information Systems and Organizations” (see http://dx.doi.org/10.6028/NIST.SP.800-171)that are in effect at the time the solicitation is issued or as authorized by the contracting officer, not later than December 31, 2017.
    2. (2)
      1. (i) If the Offeror proposes to vary from any of the security requirements specified by NIST SP 800-171 that are in effect at the time the solicitation is issued or as authorized by the Contracting Officer, the Offeror shall submit to the Contracting Officer, for consideration by the DoD Chief Information Officer (CIO), a written explanation of—
        1. (A) Why a particular security requirement is not applicable; or
        2. (B) How an alternative but equally effective, security measure is used to compensate for the inability to satisfy a particular requirement and achieve equivalent protection.
      2. (ii) An authorized representative of the DoD CIO will adjudicate offeror requests to vary from NIST SP 800-171 requirements in writing prior to contract award. Any accepted variance from NIST SP 800-171 shall be incorporated into the resulting contract.

Prescription: 240.370-5 Solicitation provisions and contract clauses

As prescribed in 240.370-5(a). Scope applicability here before applying the provision.

  1. (a) Insert the provision at 252.204-7008, Compliance with Safeguarding Covered Defense Information Controls, in all solicitations, including solicitations using FAR part 12 procedures for the acquisition of commercial products and commercial services, except for solicitations solely for the acquisition of commercially available off-the-shelf (COTS) items.

Version history

One version on record, first captured 2026-06-11 15:53:08, effective February 1, 2026.

Prescription: 240.370-5

Prescribing text cropped from the same deviation PDF.

Prescription for 252.204-7008

Provision text (pages 28–29)

Rendered from the deviation PDF. Open the full PDF.

Source page for 252.204-7008
Source page for 252.204-7008