Quick answer
The HSAR is the Department of Homeland Security's FAR supplement that establishes DHS-specific acquisition policies, clauses, and requirements for contractors working with DHS.
The Homeland Security Acquisition Regulation (HSAR) is the Department of Homeland Security's supplement to the Federal Acquisition Regulation (FAR) that establishes DHS-specific contracting policies, procedures, and contract clauses applicable to acquisitions by DHS and its component agencies.
What is the HSAR?
Like DFARS for DoD and HHSAR for HHS, the HSAR implements DHS-unique acquisition policies within the broader FAR framework. It addresses DHS-specific areas including safeguarding of sensitive information, background investigation requirements for contractor personnel, cybersecurity requirements aligned with DHS's mission, and procurement preferences tied to DHS programs. HSAR clauses are incorporated into DHS contracts by reference and must be reviewed carefully during proposal preparation because they impose obligations beyond standard FAR requirements. Contractors working with DHS components, including Customs and Border Protection (CBP), Immigration and Customs Enforcement (ICE), Transportation Security Administration (TSA), FEMA, the Coast Guard, and CISA, are subject to HSAR provisions. The HSAR is codified at 48 CFR Chapter 30 and is maintained by the DHS Chief Procurement Officer. As DHS has expanded its cybersecurity and critical infrastructure responsibilities, HSAR has increasingly incorporated cyber-specific clauses that reflect DHS's unique role in protecting national digital infrastructure.
Why HSAR matters for government contractors
Contractors working with any DHS component must be familiar with HSAR requirements beyond the standard FAR. Failure to identify and comply with HSAR clauses, particularly those related to background investigations and sensitive information handling, can result in contract non-compliance findings. DHS proposal teams should build HSAR review into their compliance matrix process from the outset.
Example
A technology company responds to a TSA solicitation for IT support services. The proposal team reviews all HSAR clauses incorporated by reference and identifies a requirement for contractor employees to hold Transportation Worker Identification Credentials (TWIC) before accessing certain TSA facilities. The proposal's management volume addresses how the firm will ensure TWIC compliance during onboarding, satisfying a DHS/HSAR-specific requirement that would not appear in a standard civilian agency contract.
Frequently Asked Questions
Where can I find the full text of the HSAR?
The HSAR is published at 48 CFR Chapter 30 and is available on the Electronic Code of Federal Regulations (eCFR) at ecfr.gov. DHS also publishes the HSAR on its procurement website along with guidance documents for contractors.
Does the HSAR apply to all DHS component agencies?
Yes. The HSAR applies to acquisitions by DHS and all its component agencies, including CBP, ICE, TSA, FEMA, the Secret Service, the Coast Guard, and CISA. Component agencies may issue additional supplemental guidance or local clauses, but all are bound by the HSAR.
What kinds of sensitive information requirements does the HSAR impose?
HSAR includes clauses requiring contractors to safeguard Controlled Unclassified Information (CUI) and DHS-sensitive data, report cybersecurity incidents within specified timeframes, and restrict access to sensitive information to personnel with appropriate background investigations. These requirements are similar to but distinct from DFARS cyber clauses in the defense context.
Are there HSAR-specific small business requirements?
The HSAR incorporates and supplements FAR small business provisions, but DHS also has its own small business program priorities that align with DHS mission areas, particularly in cybersecurity, emergency management, and border security technology. DHS contracting officers may apply additional small business evaluation criteria beyond what FAR requires.
How Bidovate helps
Bidovate puts Homeland Security Acquisition Regulation (HSAR) to work inside your capture and proposal workflow.
Proposal checklistsSee Bidovate in action
Book a demo and we will show you the platform using your actual contract data.
Related terms
Federal Acquisition Regulation (FAR)
The primary rulebook governing how U.S. federal executive agencies buy goods and services.
ViewCompliance Matrix
A tool that maps every solicitation requirement to a place in your proposal so no requirement is missed.
ViewSystem Security Plan (SSP)
A System Security Plan is a formal document that describes the security controls implemented in a federal information system and how they satisfy NIST requirements for authorization.
ViewNAICS Code
The North American Industry Classification System code that classifies a business by industry for federal contracting.
View