Common questions
Contract compliance FAQ
What is a FAR compliance checklist?
A FAR compliance checklist is the set of Federal Acquisition Regulation clauses and representations a contractor must satisfy for a given federal contract — things like basic safeguarding of contractor information systems (52.204-21), business ethics and conduct (52.203-13), and the commercial-item terms rolled up under 52.212-5. Because required clauses change with the contract type, agency, and dollar thresholds, the practical checklist is "which clauses does this specific solicitation incorporate, and does my document address each one."
What is the difference between CMMC Level 1 and Level 2?
CMMC Level 1 covers basic safeguarding of Federal Contract Information (FCI) — 17 practices, met by an annual self-assessment. Level 2 covers Controlled Unclassified Information (CUI) and maps to the 110 controls of NIST SP 800-171; depending on the contract it is met either by self-assessment or by a third-party (C3PAO) assessment. Level 3 adds expert-level requirements for the highest-priority programs.
Do I need NIST 800-171 if I am a small business?
Size does not exempt you. If your DoD contract involves Controlled Unclassified Information, DFARS 252.204-7012 requires you to implement the 110 controls of NIST SP 800-171 regardless of company size, maintain a System Security Plan (SSP) and Plan of Action & Milestones (POA&M), and post a score to SPRS.
What does DFARS 252.204-7012 require?
The clause requires contractors handling Covered Defense Information to provide "adequate security" by implementing NIST SP 800-171, to report cyber incidents to the Department within 72 hours of discovery, and to flow the requirement down to relevant subcontractors. It is the clause that makes NIST 800-171 contractually binding on most DoD work.
What is a Section 508 compliance checklist?
Section 508 requires information and communication technology (ICT) delivered to federal agencies to be accessible to people with disabilities, using the WCAG 2.0/2.1 Level AA success criteria adopted by the 508 Refresh. Contractors typically document conformance in an Accessibility Conformance Report (ACR), often produced on the VPAT template.
Who has to comply with ITAR?
Contractors that manufacture, export, or furnish defense articles or defense services on the U.S. Munitions List are subject to ITAR. That generally means registering with the Directorate of Defense Trade Controls (DDTC), obtaining licenses for exports, and restricting access to controlled technical data to authorized U.S. persons.
What is the Fix List?
The Fix List is a checklist built from your gap report. Every finding is ranked worst first (Critical to Low) with the recommended fix and the clauses it cites, plus an Owner and Date line. Export it as a PDF with clickable checkboxes, or share a link so your team can check items off together. Items already checked off in GovCheck appear pre-ticked with who completed them and when.
How long does an automated contract compliance check take?
GovCheck AI analyzes a contract or statement of work against your selected frameworks and returns a severity-ranked gap report in under 90 seconds. It is designed to surface gaps and missing clauses before submission or award — it does not certify compliance or guarantee a passing score.