---
title: Proposed FAR Changes Loaded with More Contractor Requirements for Cyber Security
description: A new proposed FAR Rule addresses information sharing and a shorter reporting time for cyber incidents for Government contractors.
image: https://info.redstonegci.com/hubfs/RGCI%20-%20Proposed%20FAR%20Changes%20Loaded%20with%20More%20Contractor%20Requirements%20for%20Cyber%20Security.png
---

[ PAY INVOICE](https://redstonegci.com/invoice-payment/) [Call Us Today 256-704-9800](tel:2567049800) [info@redstonegci.com](Mailto:info@redstonegci.com)

<http://www.facebook.com/redstonegci> <http://www.twitter.com/RedstoneGCI> <http://www.linkedin.com/company/redstone-government-consulting-inc-> <https://www.youtube.com/channel/UCQv3eAwiPTTQAnoy7hnUwgg>

[![Redstone_Logo](https://info.redstonegci.com/hubfs/redstone%20logo%20version%201%20-%20rgb-1.png)](https://www.redstonegci.com/)

# Proposed FAR Changes Loaded with More Contractor Requirements for Cyber Security

[Posted by Lynne Nalley, CPA on Mon, Oct 23, 2023 @ 11:10 AM](https://info.redstonegci.com/blog/author/lynne-nalley)

- [Tweet](https://twitter.com/share)

![RGCI - Proposed FAR Changes Loaded with More Contractor Requirements for Cyber Security](https://info.redstonegci.com/hs-fs/hubfs/RGCI%20-%20Proposed%20FAR%20Changes%20Loaded%20with%20More%20Contractor%20Requirements%20for%20Cyber%20Security.png?width=1000&name=RGCI%20-%20Proposed%20FAR%20Changes%20Loaded%20with%20More%20Contractor%20Requirements%20for%20Cyber%20Security.png)

The FAR Council submitted a [proposed rule](https://www.govinfo.gov/content/pkg/FR-2023-10-03/pdf/2023-21328.pdf) amending FAR subparts, provisions, and clauses on October 3, 2023, to implement an Executive order on cyber threats, incident reporting, and information sharing for Federal contracts. This revision is being made to strengthen and standardize contractual requirements for cybersecurity across Federal agencies. The proposed rule also implements [OMB Memorandum M-21-07 Completing the Transition to internet Protocol Version 6 (IPv6),](https://www.whitehouse.gov/wp-content/uploads/2020/11/M-21-07.pdf) dated November 19, 2020.

## Major Changes in the Proposed Rule

The [FAR 2.101](https://www.acquisition.gov/far/2.101) definition for “Information and communication technology (ICT)” has been updated to include additional examples such as telecommunications services, electronic media, Internet of Things (IoT), and operational technology, as well as revising the term “software” to “computer software.”

A new provision, [FAR 52.239-AA Security Incident Reporting Representation,](https://www.acquisition.gov/far/52.239-1) is proposed. This provision will require offerors to certify that they have submitted all security incident reports in a current, accurate, and complete manner.

A new clause, [FAR 52.239-ZZ Incident and Threat Reporting and Incident Response Requirements for Products or Services Containing Information and Communications Technology](https://www.acquisition.gov/far/52.239-1) is proposed. Additionally, [FAR 52.244-6 Subcontracts for Commercial Products and Services](https://www.acquisition.gov/far/52.244-6) has a proposed update to require higher-tier contractors to flow this clause down in commercial subcontracts. Subcontractors will be required to notify the prime Contractor/higher tier subcontractor within 8 hours of discovering a security incident.

In addition to the proposed provisions/clauses above, the proposed rule includes the following contractor requirements:

- Develop and maintain a software bill of materials (SBOM) for any software used in the performance of the contract.
- Cooperate by providing access to the Cybersecurity and Infrastructure Security Agency (CISA) engagement services as needed for threat hunting and incident response.
- Provide full access to applicable contractor information systems and personnel to CISA, the Federal Bureau of Investigation (FBI), and the contracting agency in response to a security incident reported by the contractor or identified by the Government.
- Report security incidents and take actions to support incident response. Contractors operating in certain foreign countries may be subject to laws and regulations of those countries impacting the type of information or access that can be provided to the U.S. Government.
- Immediately investigate the security incident and submit information via the CISA incident reporting portal within 8 hours of discovery, with updates every 72 hours until investigation or remediation activities are complete.

While some of the requirements in the proposed rule will have to be performed whether you have a cyber incident or not (e.g., certification, flow down to subcontractors, develop SBOM, etc.), contractors should ensure they have controls in place to prevent cyber incidents so they don’t have all the other reporting and access requirements.

## Government Contractor Takeaways

Redstone recommends contractors begin developing a software bill of materials for any software used in performing contracts. In addition, contractors should ensure they have controls in place to prevent cyber-attacks. Redstone recommends companies assess their current information systems to ensure there are threat detection controls in place, such as multi-factor authentication including passwords, fingerprints, facial or voice recognition, employee access is limited on information systems, software, and operating systems are up to date, and a backup process is implemented in the event of a cyber-attack.

Contractors should develop and maintain an incident response plan, define roles, and include steps to resolve, document, and communicate a cyber incident efficiently and properly. Small businesses that don’t have information technology (IT) staff may need to obtain outside assistance to meet the requirements. 8 hours is not much time.

Comments to the proposed rule are due by December 4, 2023. The proposed rule includes questions that DoD, GSA, and NASA are requesting contractor input on (e.g., how should SBOMs be collected from contractors, challenges by contractors in developing SBOMs, concerns with providing CISA, FBI, or contracting agency full access to information, situations where a company cannot comply with the incident reporting due to foreign country laws, etc.). Redstone recommends contractors read the proposed rule and submit comments. It is rare that the FAR council requests input to specific areas vs. comments in general.

Redstone GCI can provide our clients with more information and guidance in working with established industry-leading partners who can assist in fulfilling numerous cybersecurity compliance requirements, including but not limited to penetration testing, incident response, security assessments, and POA&M revolving around the information technology infrastructure as well as develop software bills of material (SBOMs). Redstone GCI, along with our trusted partners, can bring you a full solution by ensuring cyber security policy and flow-down requirements revolving around all aspects are accomplished, including but not limited to purchasing policy requirements.

[![Contact Us for a Consultation](https://no-cache.hubspot.com/cta/default/203971/interactive-173774226074.png) ](https://info.redstonegci.com/hs/cta/wi/redirect?encryptedPayload=AVxigLKIsUW5FolUFdssMC3tlH4438vZeOLvVVDeCOiM8au%2BUvxkNgj%2BJnKTJDnmeXNqtB2MA1H7CY3SMHnXvDUKWfOUlhWie8e8bnyvPoWoeW6Qu7lfQyOFWdkvEZBtVPbad0Y7mIlqNOHr2xXpaW%2BFisCrCNDUCKEXTfPUAzvVmX5aGrma&webInteractiveContentId=173774226074&portalId=203971)

### Written by [Lynne Nalley, CPA](https://info.redstonegci.com/blog/author/lynne-nalley)

![Lynne Nalley, CPA](https://info.redstonegci.com/hubfs/images/Staff_/Lynne-Nalley.png) Lynne is a Director with Redstone Government Consulting, Inc. providing government contract consulting services to our clients primarily related to Commercial Item Determinations and support, Cost Accounting Standards, DFARS Business System Audits, Proposals, and Incurred Cost. Prior to joining Redstone Government Consulting, Lynne served in several capacities with DCAA and DCMA for over 35 years. Professional Experience Lynne began her career working with DCAA in the Honeywell Resident Office, Clearwater, FL in 1984. Lynne’s experience included various positions which involved conducting or reviewing forward proposals or rate audits, financial capability audits, progress payments, accounting and estimating systems, cost accounting standards, claims and disclosure statement reviews. She is an expert in FAR, DFARS, CAS and testified as an expert witness. Lynne assisted in drafting the commercial item guidance for DCAA Headquarters. Lynne was assigned as a Regional Technical Specialist where she provided guidance to 20 field offices on highly complex or technical issues relative to forward pricing, financial capability or progress payment issues. As an Assistant for Quality, she was involved in reviewing and ensuring audit reports were in compliance with policy and GAGAS as well as made NASBA certified presentations to the staff including but not limited to billing reviews, CAS, unallowable cost and progress payments. To enhance her experience in government contracting, Lynne accepted a position with DCMA in 2015 as part of the newly organized DCMA Cadre of Experts in the Commercial Item Group. This included performing reviews of prime contractor’s assertions and/or commercial item determinations as well as performing price analyses. Lynne was a project lead and later became a lead analyst where she engaged with the buying commands on requests and reviewed price analysis reviews performed by a team of 5 analysts. She also assisted the DCMA CPSR team relative to commercial items and co-instructed the Commercial Item Training presented to DCMA. Education Lynne earned a Bachelor of Science Degree in Accounting from the University of Central Florida. Certifications State of Florida Certified Public Accountant State of Alabama Certified Public Accountant Defense Acquisition Workforce Improvement Act (DAWIA) Level III- Auditing DAWIA Level III – Contracting

## About Redstone GCI

Redstone GCI is a consulting firm focused on fulfilling the needs of government contractors in all areas of compliance. With a singular mission to help contractors through the multiple layers of “red tape,” we allow contractors to focus on what they do best – support their mission with the U.S. Government. We are home to a group of consultants made up of GovCon industry professionals, CPAs, attorneys, and retired government audit and acquisition professionals.

Our focus and knowledge of audit and compliance functions administered by DCAA and DCMA will always be at the heart of what we do. However, for the past decade, we’ve strategically grown to support other areas of the government contractor back-office with that same level of focus and expertise. We’ve added expertise in contracts management, subcontract administration, proposal pricing, various software systems, HR and employment law, property administration, manufacturing, data analytics/reporting, Grant specialists, M&A, and many other areas. When we see a trend in the needs of contractors, we act to ensure we can provide the best expertise in the market to fulfill those needs.

One thing our clients can be certain of is that with the Redstone GCI Team in your corner, there is no problem too big and no issue too technical for our team to tackle.

 Topics: [DFARS Business Systems](https://info.redstonegci.com/blog/topic/dfars-business-systems), [Contractor Purchasing System Review (CPSR)](https://info.redstonegci.com/blog/topic/contractor-purchasing-system-review-cpsr), [Government Regulations](https://info.redstonegci.com/blog/topic/government-regulations), [Federal Acquisition Regulation (FAR)](https://info.redstonegci.com/blog/topic/federal-acquisition-regulation-far), [Cybersecurity](https://info.redstonegci.com/blog/topic/cybersecurity)

### Search Posts

This is a search field with an auto-suggest feature attached.

- There are no suggestions because the search field is empty.

### Subscribe via E-mail

### Latest Posts

### Posts by category

- [Accounting System Compliance (282)](https://info.redstonegci.com/blog/topic/accounting-system-compliance)
- [Commercial Determination (34)](https://info.redstonegci.com/blog/topic/commercial-determination)
- [Contractor Purchasing System Review (CPSR) (85)](https://info.redstonegci.com/blog/topic/contractor-purchasing-system-review-cpsr)
- [Contracts & Subcontracts Administration (300)](https://info.redstonegci.com/blog/topic/contracts-subcontracts-administration)
- [Cost Accounting Standards (CAS) (60)](https://info.redstonegci.com/blog/topic/cost-accounting-standards-cas)
- [COVID-19 (23)](https://info.redstonegci.com/blog/topic/covid-19)
- [Customer Success Story (2)](https://info.redstonegci.com/blog/topic/customer-success-story)
- [Cybersecurity (28)](https://info.redstonegci.com/blog/topic/cybersecurity)
- [DCAA Audit Support (249)](https://info.redstonegci.com/blog/topic/dcaa-audit-support)
- [Defense Procurement & Acquisition Policy (DPAP) (7)](https://info.redstonegci.com/blog/topic/defense-procurement-acquisition-policy-dpap)
- [Deltek Costpoint (54)](https://info.redstonegci.com/blog/topic/deltek-costpoint)
- [DFARS Business Systems (179)](https://info.redstonegci.com/blog/topic/dfars-business-systems)
- [DOD IG (10)](https://info.redstonegci.com/blog/topic/dod-ig)
- [Employee & Contractor Compensation (22)](https://info.redstonegci.com/blog/topic/employee-contractor-compensation)
- [Employers & Unions (8)](https://info.redstonegci.com/blog/topic/employers-unions)
- [Estimating System Compliance (18)](https://info.redstonegci.com/blog/topic/estimating-system-compliance)
- [Export & Import (19)](https://info.redstonegci.com/blog/topic/export-import)
- [Federal Acquisition Regulation (FAR) (187)](https://info.redstonegci.com/blog/topic/federal-acquisition-regulation-far)
- [Federal Construction Contracting (4)](https://info.redstonegci.com/blog/topic/federal-construction-contracting)
- [Government Compliance Training (59)](https://info.redstonegci.com/blog/topic/government-compliance-training)
- [Government Property Management (18)](https://info.redstonegci.com/blog/topic/government-property-management)
- [Government Regulations (265)](https://info.redstonegci.com/blog/topic/government-regulations)
- [Government Shutdown (9)](https://info.redstonegci.com/blog/topic/government-shutdown)
- [Grants & Cooperative Agreements (2 CFR 200) (32)](https://info.redstonegci.com/blog/topic/grants-cooperative-agreements-2-cfr-200)
- [Human Resources (118)](https://info.redstonegci.com/blog/topic/human-resources)
- [Incurred Cost Proposal Submission (ICP/ICE) (83)](https://info.redstonegci.com/blog/topic/incurred-cost-proposal-submission-icp-ice)
- [Litigation Consulting Support (17)](https://info.redstonegci.com/blog/topic/litigation-consulting-support)
- [Manufacturing Operations Consulting (26)](https://info.redstonegci.com/blog/topic/manufacturing-operations-consulting)
- [Material Management & Accounting System (MMAS) (23)](https://info.redstonegci.com/blog/topic/material-management-accounting-system-mmas)
- [Non-US Government Contractor (3)](https://info.redstonegci.com/blog/topic/non-us-government-contractor)
- [Office of Federal Contract Compliance Programs (31)](https://info.redstonegci.com/blog/topic/office-of-federal-contract-compliance-programs)
- [Organizational Change Management Consulting (17)](https://info.redstonegci.com/blog/topic/organizational-change-management-consulting)
- [Paycheck Protection Program (PPP) Loans (8)](https://info.redstonegci.com/blog/topic/paycheck-protection-program-ppp-loans)
- [Program Management & Project Cost Control (2)](https://info.redstonegci.com/blog/topic/program-management-project-cost-control)
- [Proposal Cost Volume Development & Pricing (79)](https://info.redstonegci.com/blog/topic/proposal-cost-volume-development-pricing)
- [Quickbooks (21)](https://info.redstonegci.com/blog/topic/quickbooks)
- [REAs, Claims & Terminations (10)](https://info.redstonegci.com/blog/topic/reas-claims-terminations)
- [Redstone GCI (50)](https://info.redstonegci.com/blog/topic/redstone-gci)
- [Sequestration (4)](https://info.redstonegci.com/blog/topic/sequestration)
- [Service Contract Act (14)](https://info.redstonegci.com/blog/topic/service-contract-act)
- [Small Business Compliance (121)](https://info.redstonegci.com/blog/topic/small-business-compliance)
- [System Award Management (SAM) (9)](https://info.redstonegci.com/blog/topic/system-award-management-sam)
- [UKG Ready HR Software Consulting (7)](https://info.redstonegci.com/blog/topic/ukg-ready-hr-software-consulting)
- [Unanet (35)](https://info.redstonegci.com/blog/topic/unanet)
- [Vlog (41)](https://info.redstonegci.com/blog/topic/vlog)

### Disclaimer

```
Data published on our website, such as our white papers, blogs and other government contracting commentary reflect our interpretations and opinions of current events and regulations, at the time such data is published, and the perspectives/opinions of other professionals in our industry may vary from our own.  Further, our commentary and perspectives do not reflect legal analyses, since we are not attorneys, but rather government contracts and accounting advisors.  We therefore make no representation that the use of our published information will insulate a company from government challenges, nor otherwise ensure a successful defense on any government procurement adverse action.  Readers agree that articles or blog commentary presented within our website shall not be replicated or re-published without requesting before publication in another medium, and our expressed written consent to do so.
```

**Redstone Government Consulting**  
501 Madison Street SE, Suite 100  
Huntsville, AL 35801

**Phone: ** [256.704.9800](tel:2567049800)  
**Email Us**[ info@redstonegci.com](mailto:info@redstonegci.com)

**[PAY INVOICE](https://redstonegci.com/invoice-payment/)**  
[PCI DSS compliance documentation](https://redstonegci.com/wp-content/uploads/2016/10/pci_dss_self_assessment_certificate.pdf)

<http://www.facebook.com/redstonegci> <http://www.twitter.com/RedstoneGCI> <http://www.linkedin.com/company/redstone-government-consulting-inc-> <https://www.youtube.com/channel/UCQv3eAwiPTTQAnoy7hnUwgg>

© 2026 Redstone Government Consulting | All Rights Reserved | [Privacy Policy](https://redstonegci.com/privacy-policy/) | [Event Refund / Cancellation Policy](https://redstonegci.com/event-refund-cancellation-policy/)