1. Far and Dfars: the Regulatory Starting Point
Every defense contract incorporates Federal Acquisition Regulation (FAR) clauses and, for DoD work, Defense Federal Acquisition Regulation Supplement (DFARS) requirements. These two frameworks govern pricing, ethics, data protection, and subcontractor responsibilities. Subcontractors receive the same obligations through flowdown clauses.
| Framework | Authority | Key areas |
| FAR | All federal agencies | Ethics, cost principles, contract administration |
| DFARS | Department of Defense | Cybersecurity, technical data, specialty materials |
| ITAR / EAR | DDTC / BIS | Export control, controlled technology |
| CAS | CASB | Cost measurement, allocation, consistency |
Core Far Obligations
FAR sets baseline requirements for contractor ethics, cost accounting, and contract administration. FAR 52.203-13 requires contractors on qualifying contracts to maintain a written code of conduct, a formal compliance program, and an internal mechanism for reporting violations.
What Dfars Adds
DFARS adds defense specific requirements on top of FAR: counterfeit part avoidance under DFARS 252.246-7007 and contractor business system standards under DFARS 252.242-7005. Identified deficiencies in a covered business system can trigger payment withholds until the contracting officer confirms adequate corrective action.
2. Cybersecurity Obligations
Defense contractors that handle Controlled Unclassified Information (CUI) face two overlapping cybersecurity requirements: DFARS 252.204-7012 and the Cybersecurity Maturity Model Certification (CMMC) program. Both are contract eligibility thresholds, not just audit considerations.
Nist Sp 800-171 and Dfars 252.204-7012
Contractors must implement all 110 security controls in NIST SP 800-171, document their posture in a System Security Plan, and report cyber incidents to the DoD within 72 hours of discovery. After a reportable incident, contractors must preserve forensic images and submit a report through the DIBNet portal. Cybersecurity compliance failures carry direct consequences for contract eligibility, not just audit findings.
Cmmc Assessments
CMMC requires independent or government assessment before contract award for procurements involving sensitive information. Contractors at Level 2 must fully implement NIST SP 800-171. A contractor that cannot demonstrate the required CMMC level is ineligible for award regardless of technical qualifications.
3. Export Control: Itar and Ear
Aerospace defense contractors regularly handle hardware, software, and technical data subject to the International Traffic in Arms Regulations (ITAR) and the Export Administration Regulations (EAR). ITAR and EAR obligations apply before any controlled item or data moves, not only when crossing a border.
Classification and Screening
ITAR covers defense articles on the United States Munitions List; EAR covers dual use items on the Commerce Control List. Misclassification is one of the most common enforcement triggers. Before sharing controlled technology with any employee, partner, or foreign national, contractors must screen against the Consolidated Screening List.
Penalties and Voluntary Disclosure
ITAR civil penalties reach up to $1,000,000 per violation; criminal penalties can reach 20 years imprisonment. Voluntary disclosure to DDTC or BIS can reduce exposure when it is timely and paired with genuine remediation steps. Contractors that discover a potential violation should consult legal counsel before making any disclosure.
4. Cost Accounting and Dcaa Audits
Defense contracts above the thresholds in FAR 9903.201-1 require compliance with Cost Accounting Standards (CAS), which regulate how contractors measure and allocate costs. The Defense Contract Audit Agency (DCAA) audits cost representations and business systems against those standards.
Cas Obligations
Contractors subject to full CAS coverage must file a Disclosure Statement describing their accounting practices before award and obtain government approval before changing any of those practices. Undisclosed changes can trigger retroactive cost adjustments.
Audit Readiness
DCAA audits cover incurred costs, labor charges, indirect cost pools, and forward pricing proposals. Findings can result in payment demands or fraud referrals. Contractors should maintain documentation sufficient to defend every cost claim.
5. Building a Compliance Program
A written policy is not a compliance program. Effective government contract compliance in the defense sector requires designated personnel, regular audits, trained staff, and documented procedures that are actually followed.
Program Essentials
- Designated compliance personnel with direct reporting lines to senior management
- Periodic internal audits covering billing, cybersecurity controls, and export classifications
- Written procedures for identifying and remediating deficiencies before government review
- Annual training for all personnel involved in contract performance or export activities
- Records retention schedule aligned with FAR 4.703 and any agency specific requirements
Contractors who discover a potential violation should consult legal counsel before any disclosure. Voluntary disclosure can reduce liability, but timing and scope require careful judgment.
6. Enforcement Exposure
The False Claims Act reaches contractors that submit false payment claims or falsely certify compliance with contract requirements. Qui tam provisions allow employees to file suit on the government's behalf, so internal compliance failures rarely stay internal.
False Claims Act Liability
FCA liability includes treble damages and civil penalties per false claim. Cost mischarging, false certifications at award, and cybersecurity compliance failures are the most frequent FCA enforcement theories in defense contracting.
Suspension and Debarment
A suspended or debarred contractor cannot receive new government contracts during the exclusion period and may lose performance rights on existing awards. Suspension and debarment proceedings often follow FCA investigations or DCAA audit referrals.
7. Frequently Asked Questions
What is the difference between FAR and DFARS?
FAR applies to all federal procurements and sets baseline requirements. DFARS is a DoD-specific supplement that adds cybersecurity, technical data, and other defense obligations on top of FAR.
What cybersecurity standards apply to DoD contractors?
Contractors handling CUI must implement NIST SP 800-171 under DFARS 252.204-7012. CMMC adds an independent assessment requirement before award for many DoD contracts.
What happens when a contractor violates ITAR?
DDTC can impose civil penalties up to $1,000,000 per violation, suspend export privileges, and refer the matter for criminal prosecution. Contract termination and loss of future eligibility are also possible.
Does CAS apply to every defense contract?
No. The exemptions in FAR 9903.201-1 exclude many smaller contracts. Each award requires its own evaluation of whether full or modified CAS coverage applies.
22 Apr, 2026

