DFARS Part 239 — Acquisition of Information Technology
What this Part does
DFARS Part 239 overlays FAR Part 39 for DoD IT acquisitions, with four distinctive additions:
- Cloud computing services (239.76) — prescribes DFARS 252.239-7010 which mandates FedRAMP Moderate baseline (or DoD equivalent IL4/IL5/IL6 for sensitive data) for any cloud service provider handling DoD data.
- Telecommunications services (239.74) — anti-backdoor requirements for network equipment, implementing the Section 889 prohibition on Huawei/ZTE/Hytera/Dahua/Hikvision equipment (broader implementation is in FAR 52.204-25 and DFARS 252.225-7975).
- Supply chain risk management (239.73) — prescribes clauses requiring contractors to identify, assess, and mitigate supply chain risk in IT components.
- Acquisition of information technology and commercial satellite communications services (239.71, 239.72).
Because Part 239 is narrow in scope — it applies to information technology specifically — most DoD IT is actually procured under Part 12 (commercial items) and Part 15 (negotiation), with Part 239 adding specific clause requirements layered on top.
When you’d look here
- Your client is a Cloud Service Provider proposing to host DoD data — DFARS 252.239-7010 FedRAMP compliance is the gate.
- A client with non-cloud IT services needs to understand Section 889 flow-down and representations.
- A solicitation includes DFARS 252.239-7018 (Supply Chain Risk) and the client needs to build an assessment process.
- You’re advising on the overlap between DFARS 252.204-7012 (cyber safeguarding) and DFARS 252.239-7010 (cloud) — a cloud service handling CDI has to satisfy both.
Case study: FedRAMP-Moderate-equivalent for a growing startup
Celestial Cloud Services (hypothetical), a 90-person startup offering an enterprise SaaS for operations scheduling, received a purchase inquiry from a DoD program office. The program wanted to use Celestial for unclassified-but-sensitive program-schedule data. Under DFARS 252.239-7010, cloud services holding DoD data must be FedRAMP Moderate (or higher for sensitive data), with specific requirements for data sovereignty (U.S.-based), audit logging, and incident reporting.
Celestial’s existing commercial SaaS was hosted on AWS GovCloud (which IS FedRAMP High), but the Celestial-specific application layer had never been FedRAMP-assessed. The application inherited some FedRAMP controls from AWS GovCloud but not all; Celestial needed an Agency Authorization (sponsored by the DoD program) or a FedRAMP Joint Authorization Board (JAB) P-ATO before starting work.
The Agency Authorization path:
- Sponsoring DoD program office issues an Agency ATO (Authorization to Operate) based on Celestial’s System Security Plan (SSP) and Continuous Monitoring package.
- Celestial must be assessed by a 3PAO (Third-Party Assessment Organization — there are about 35 accredited).
- Timeline: 6–9 months typically.
- Cost: 1M for the 3PAO engagement plus internal effort.
The JAB P-ATO path:
- Portable across agencies but much harder to obtain.
- Timeline: 12–18 months.
- Cost: similar to Agency ATO, but with stricter scrutiny.
Celestial chose Agency ATO. Timeline from contract engagement to authorization: 7 months. The DoD program sponsored the assessment and the ATO was issued.
Teaching points:
- FedRAMP isn’t automatic with IaaS. Hosting on AWS GovCloud or Azure Government gives inheritance of FedRAMP controls at the infrastructure layer, but the application layer still requires its own authorization.
- Agency ATO vs. JAB P-ATO is a strategic choice. Agency ATO is faster and cheaper for a single-customer start; JAB P-ATO is portable across the federal government and better for scale.
- Continuous Monitoring is the hidden cost. FedRAMP authorizations require ongoing compliance — monthly scans, annual assessments, significant-change reviews. Budget for the ongoing program, not just the initial authorization.
Case study: Section 889 flow-down and the supplier audit
Meridian Networks (hypothetical), an IT integrator, held a DoD contract providing campus network equipment (switches, routers, access points). The contract incorporated FAR 52.204-25 (Section 889 prohibition — no covered telecommunications equipment from Huawei, ZTE, Hytera, Dahua, or Hikvision) and required quarterly representations that the contractor’s supply chain was 889-compliant.
Meridian’s immediate suppliers were all U.S.-based integrators. But Meridian’s reseller agreements didn’t include 889 flow-down language in the older contracts. When Meridian audited its own supply chain (under pressure from the DoD 889 reporting obligation), it found that a specific video-conference camera model in 200 inventory units had been manufactured with a Hikvision OEM board. The camera vendor was not a 889-covered entity, but the Hikvision board inside was.
Meridian had to:
- Halt deliveries of the affected model.
- Replace inventory with a non-Hikvision alternative.
- Update 889 representations to reflect the remediation.
- Notify the CO of the prior non-compliant deliveries and propose a remediation plan.
The remediation was accepted. No termination; modest cost ($1.2M) absorbed. But the incident triggered a supplier-tier audit that identified two other covered-equipment risks in Meridian’s supply chain — an ongoing compliance program instead of one-time remediation.
Teaching points:
- Section 889 is an OEM-level requirement. The regulation reaches down to component-level manufacture, not just top-level brand. Hikvision-OEM cameras in non-Hikvision branded products are non-compliant.
- Flow-down language at contract execution matters. Older supplier agreements may not have 889 language. Plan amendments or new agreements with explicit flow-down.
- 889 representations are material. False 889 certifications are FCA-actionable. Audit before certifying.
Key sections
- DFARS 239.71 — Policy for acquisition of commercial IT.
- DFARS 239.72 — Acquisition of commercial satellite services.
- DFARS 239.73 (Subpart) — Requirements for information relating to supply chain risk (implements 10 USC 2339a).
- DFARS 239.74 (Subpart) — Telecommunications.
- DFARS 239.75 (Subpart) — Section 508 accessibility.
- DFARS 239.76 (Subpart) — Cloud Computing Services.
- DFARS 239.7602 — Policy.
- DFARS 239.7603 — Requirements.
Key clauses
- DFARS 252.239-7010 — Cloud Computing Services. Mandates FedRAMP Moderate baseline (higher for sensitive data) and U.S. data sovereignty.
- DFARS 252.239-7016 — Telecommunications Security Equipment.
- DFARS 252.239-7017 — Notice of Supply Chain Risk.
- DFARS 252.239-7018 — Supply Chain Risk.
- FAR 52.204-25 — Section 889 prohibition on covered telecommunications equipment. (Civilian FAR clause, not DFARS, but applied to DoD contracts.)
Related
- FAR Part 39 — Civilian IT Part; thinner than DFARS 239.
- DFARS Part 204 — Cyber (where 252.204-7012 and CMMC live; interacts with 252.239-7010 for cloud services handling CDI).
- DFARS Part 225 — Sourcing restrictions (rare-earth, semiconductors); supply chain overlap with 239.73.
- Statutory authority:
- 10 USC 2339a — Supply chain risk management authority.
- 50 USC 4565 — CFIUS (for foreign-ownership of IT providers).
- Section 889 of FY2019 NDAA — codified at 15 USC 1637 et al. scattered across USC.