FeaturesFrameworks
Compliance
Contract ComplianceProposal CompliancePricing⚡ Updates
Sign InGet Started
FEDERAL CONTRACT COMPLIANCE

Federal contract requirements — and a gap report on your document

FAR, CMMC 2.0, NIST 800-171, DFARS 252.204-7012, Section 508, and ITAR — what each one requires and who it applies to. Then upload your contract and get a severity-ranked gap report showing exactly where it falls short — across 180+ frameworks, in under 90 seconds.

Winning federal work means proving your document meets a moving target of clauses and controls. The requirements below are the ones contractors ask about most. Each section explains the framework in plain language and its key requirements — then GovCheck AI reads your actual contract or statement of work and returns a severity-ranked gap report showing exactly where it falls short.

Applies to virtually all federal contractors

FAR — Federal Acquisition Regulation

The FAR is the primary rulebook for how the U.S. government buys goods and services. Individual solicitations incorporate specific FAR clauses your offer and performance must satisfy — by full text or by reference.

Who it applies to: Any company selling to a federal agency, prime or subcontractor.

Key requirements
  • Confirm every clause the solicitation incorporates by reference is actually addressed in your document
  • Basic safeguarding of contractor information systems (FAR 52.204-21)
  • Contractor code of business ethics and conduct (FAR 52.203-13)
  • Commercial products/services terms rolled up under FAR 52.212-5
  • Small-business and subcontracting representations (FAR 52.219 series) where applicable
  • Labor, wage, and equal-opportunity clauses (FAR 52.222 series) where applicable
  • Complete and accurate representations & certifications (SAM.gov reps)
DoD contractors handling FCI or CUI

CMMC 2.0 — Cybersecurity Maturity Model Certification

CMMC 2.0 verifies that Defense contractors protect government information at a level matched to what they handle. Level 1 protects Federal Contract Information (FCI); Level 2 protects Controlled Unclassified Information (CUI) and maps to NIST 800-171; Level 3 covers the highest-priority programs.

Who it applies to: Companies in the Defense industrial base whose contracts involve FCI or CUI.

Key requirements
  • Determine your required level from the contract: Level 1 (FCI) vs Level 2 (CUI)
  • Level 1 — implement the 17 basic safeguarding practices; complete the annual self-assessment
  • Level 2 — implement all 110 NIST 800-171 controls; self-assessment or C3PAO assessment per contract
  • Maintain a current System Security Plan (SSP) and POA&M
  • Affirm your status and keep supporting evidence on file
  • Note: program phasing and assessment requirements are evolving — verify against the current solicitation
110 controls across 14 families

NIST SP 800-171 — Protecting CUI

NIST 800-171 defines how nonfederal organizations must protect Controlled Unclassified Information. It is the technical backbone of CMMC Level 2 and is made contractually binding by DFARS 252.204-7012.

Who it applies to: Contractors and subcontractors that store, process, or transmit CUI.

Key requirements
  • Implement all 110 controls across the 14 control families (access control, audit, IR, etc.)
  • Write and maintain a System Security Plan (SSP) describing how each control is met
  • Track unmet controls in a Plan of Action & Milestones (POA&M)
  • Calculate and post your assessment score to SPRS
  • Multi-factor authentication, FIPS-validated encryption, and incident response are common gaps
  • Flow the requirement to subcontractors who will handle CUI
The clause that makes 800-171 mandatory

DFARS 252.204-7012 — Safeguarding Covered Defense Information

This DFARS clause requires "adequate security" for Covered Defense Information — defined as implementing NIST 800-171 — plus rapid reporting of cyber incidents and flow-down to subcontractors.

Who it applies to: DoD contractors whose work involves Covered Defense Information (CDI).

Key requirements
  • Implement NIST SP 800-171 as your "adequate security" baseline
  • Report cyber incidents to the Department within 72 hours of discovery
  • Preserve and protect affected media and images per the clause
  • Flow 252.204-7012 down to subcontractors handling CDI
  • Confirm cloud service providers meet the required security equivalency
Accessible technology for federal agencies

Section 508 — ICT Accessibility

Section 508 requires information and communication technology supplied to federal agencies to be accessible to people with disabilities, following the WCAG 2.0/2.1 Level AA criteria adopted in the 508 Refresh.

Who it applies to: Contractors delivering software, websites, documents, or other ICT to federal agencies.

Key requirements
  • Meet WCAG 2.0/2.1 Level AA for web and electronic content
  • Produce an Accessibility Conformance Report (ACR), commonly on the VPAT template
  • Ensure keyboard operability, sufficient contrast, and screen-reader support
  • Provide accessible documentation and support materials
  • Address the specific 508 requirements cited in the solicitation
Defense articles and technical data

ITAR — International Traffic in Arms Regulations

ITAR controls the export of defense articles and services on the U.S. Munitions List, including technical data. Non-compliance carries some of the steepest penalties in federal contracting.

Who it applies to: Contractors that manufacture, export, or furnish USML defense articles or services.

Key requirements
  • Register with the Directorate of Defense Trade Controls (DDTC) if you manufacture or export USML items
  • Obtain the correct licenses or agreements before any export
  • Restrict access to controlled technical data to authorized U.S. persons
  • Maintain export-control recordkeeping and a compliance program
  • Screen parties against denied/restricted lists

Turn every gap into a checklist your team can work from

Every gap report comes with a Fix List: each finding ranked worst first, with the recommended fix and the clauses it cites. Export it as a PDF with clickable checkboxes, or share a link your team can check off together.

govcheckai.com — Compliance Fix List (illustrative sample)
Add basic safeguarding of contractor information systems (FAR 52.204-21)
Recommended fix included · Owner ______ Date ______
Critical
Document the 72-hour cyber incident reporting process (DFARS 252.204-7012)
Recommended fix included · Owner ______ Date ______
High
✓
Attach an Accessibility Conformance Report (Section 508)
Checked off in the app — shows who and when
Done

Contract compliance FAQ

What is a FAR compliance checklist?
A FAR compliance checklist is the set of Federal Acquisition Regulation clauses and representations a contractor must satisfy for a given federal contract — things like basic safeguarding of contractor information systems (52.204-21), business ethics and conduct (52.203-13), and the commercial-item terms rolled up under 52.212-5. Because required clauses change with the contract type, agency, and dollar thresholds, the practical checklist is "which clauses does this specific solicitation incorporate, and does my document address each one."
What is the difference between CMMC Level 1 and Level 2?
CMMC Level 1 covers basic safeguarding of Federal Contract Information (FCI) — 17 practices, met by an annual self-assessment. Level 2 covers Controlled Unclassified Information (CUI) and maps to the 110 controls of NIST SP 800-171; depending on the contract it is met either by self-assessment or by a third-party (C3PAO) assessment. Level 3 adds expert-level requirements for the highest-priority programs.
Do I need NIST 800-171 if I am a small business?
Size does not exempt you. If your DoD contract involves Controlled Unclassified Information, DFARS 252.204-7012 requires you to implement the 110 controls of NIST SP 800-171 regardless of company size, maintain a System Security Plan (SSP) and Plan of Action & Milestones (POA&M), and post a score to SPRS.
What does DFARS 252.204-7012 require?
The clause requires contractors handling Covered Defense Information to provide "adequate security" by implementing NIST SP 800-171, to report cyber incidents to the Department within 72 hours of discovery, and to flow the requirement down to relevant subcontractors. It is the clause that makes NIST 800-171 contractually binding on most DoD work.
What is a Section 508 compliance checklist?
Section 508 requires information and communication technology (ICT) delivered to federal agencies to be accessible to people with disabilities, using the WCAG 2.0/2.1 Level AA success criteria adopted by the 508 Refresh. Contractors typically document conformance in an Accessibility Conformance Report (ACR), often produced on the VPAT template.
Who has to comply with ITAR?
Contractors that manufacture, export, or furnish defense articles or defense services on the U.S. Munitions List are subject to ITAR. That generally means registering with the Directorate of Defense Trade Controls (DDTC), obtaining licenses for exports, and restricting access to controlled technical data to authorized U.S. persons.
What is the Fix List?
The Fix List is a checklist built from your gap report. Every finding is ranked worst first (Critical to Low) with the recommended fix and the clauses it cites, plus an Owner and Date line. Export it as a PDF with clickable checkboxes, or share a link so your team can check items off together. Items already checked off in GovCheck appear pre-ticked with who completed them and when.
How long does an automated contract compliance check take?
GovCheck AI analyzes a contract or statement of work against your selected frameworks and returns a severity-ranked gap report in under 90 seconds. It is designed to surface gaps and missing clauses before submission or award — it does not certify compliance or guarantee a passing score.

Find the gaps before the government does

Upload a contract or statement of work and get a severity-ranked gap report against FAR, DFARS, CMMC 2.0, NIST 800-171, and 180+ more frameworks — in under 90 seconds.

Get your gap report

GovCheck AI surfaces potential compliance gaps to support your review. It does not certify compliance, guarantee a score, or constitute legal advice. Always confirm requirements against your specific solicitation and qualified counsel.