Quick answer
DFARS is the DoD-specific supplement to the FAR that adds defense-unique acquisition rules, clauses, and cybersecurity requirements for all defense contracts.
The Defense Federal Acquisition Regulation Supplement (DFARS) is the Department of Defense's mandatory supplement to the Federal Acquisition Regulation, adding defense-specific rules, contract clauses, and requirements that apply to all DoD contracts and subcontracts.
What is DFARS?
DFARS implements and supplements the FAR specifically for DoD procurement. While the FAR applies to all federal agencies, DFARS contains provisions unique to defense contracting, covering areas such as cybersecurity, supply chain security, foreign acquisition restrictions, and specialty metals requirements.
Key DFARS provisions that contractors must know include:
- DFARS 252.204-7012: requires safeguarding of covered defense information and cyber incident reporting, tied directly to NIST SP 800-171 compliance
- DFARS 252.225: Buy American and specialty metals clauses restricting the origin of materials in defense items
- DFARS 252.246: quality assurance requirements for defense contracts
- DFARS 252.239: cloud computing requirements including FedRAMP authorization
DFARS is published in Title 48, Chapter 2 of the Code of Federal Regulations and is updated frequently. DoD also issues DFARS Procedures, Guidance, and Information (PGI) as companion guidance. Any company pursuing DoD work, whether as a prime or subcontractor, must understand which DFARS clauses flow down to their level of performance.
Why DFARS matters for government contractors
DFARS compliance is non-negotiable for DoD work. The cybersecurity clause (252.204-7012) has become one of the most scrutinized requirements in defense contracting, requiring contractors to implement 110 security controls from NIST SP 800-171 and report cyber incidents within 72 hours. Failure to comply can result in contract termination, False Claims Act liability, and debarment. DFARS also imposes supply chain restrictions, such as prohibiting certain Chinese telecommunications equipment under Section 889, that affect purchasing decisions throughout the supply chain.
Example
A mid-size IT firm wins a $4M Army software development contract. The contract incorporates DFARS 252.204-7012, requiring the firm to implement NIST 800-171 controls across all systems that handle Controlled Unclassified Information. The firm must also report any cyber incident to DoD within 72 hours and preserve images of compromised systems for 90 days. These requirements flow down to any subcontractors who handle covered defense information.
Frequently Asked Questions
Does DFARS apply to subcontractors?
Yes. Prime contractors are required to flow down applicable DFARS clauses to subcontractors, particularly cybersecurity requirements under 252.204-7012. Subcontractors handling covered defense information are subject to the same obligations as the prime.
How is DFARS different from the FAR?
The FAR applies to all federal civilian and defense procurement. DFARS supplements the FAR with defense-specific requirements. When DFARS and FAR conflict, DFARS takes precedence for DoD contracts. Many FAR parts have a corresponding DFARS subpart numbered in the 200s.
Where can I find DFARS clauses?
DFARS is publicly available at acquisition.gov and dfars.mil. Individual contract solicitations will list which DFARS clauses are incorporated, either in full text or by reference in Section I of the solicitation.
What is the difference between DFARS and a DFARS deviation?
A DFARS deviation allows a DoD component (such as the Army or Navy) to depart from standard DFARS requirements for a specific acquisition. Deviations must be approved and can be class deviations (applying broadly) or individual deviations (for a single contract).
How Bidovate helps
Bidovate puts Defense Federal Acquisition Regulation Supplement (DFARS) to work inside your capture and proposal workflow.
Federal contractingSee Bidovate in action
Book a demo and we will show you the platform using your actual contract data.
Related terms
Federal Acquisition Regulation (FAR)
The primary rulebook governing how U.S. federal executive agencies buy goods and services.
ViewCybersecurity Maturity Model Certification (CMMC)
CMMC is the DoD's mandatory cybersecurity certification framework requiring defense contractors to demonstrate compliance with NIST security controls before receiving contracts.
ViewControlled Unclassified Information (CUI)
Controlled Unclassified Information is government-designated sensitive information that is not classified but requires safeguarding controls and access restrictions by contractors.
ViewDefense Contract Audit Agency (DCAA)
DCAA is the DoD agency that audits contractor accounting systems, incurred costs, and financial representations to protect the government against overpricing and unallowable cost claims.
View