DFARS Part 239 — Acquisition of Information Technology

What this Part does

DFARS Part 239 overlays FAR Part 39 for DoD IT acquisitions, with four distinctive additions:

  1. Cloud computing services (239.76) — prescribes DFARS 252.239-7010 which mandates FedRAMP Moderate baseline (or DoD equivalent IL4/IL5/IL6 for sensitive data) for any cloud service provider handling DoD data.
  2. Telecommunications services (239.74) — anti-backdoor requirements for network equipment, implementing the Section 889 prohibition on Huawei/ZTE/Hytera/Dahua/Hikvision equipment (broader implementation is in FAR 52.204-25 and DFARS 252.225-7975).
  3. Supply chain risk management (239.73) — prescribes clauses requiring contractors to identify, assess, and mitigate supply chain risk in IT components.
  4. Acquisition of information technology and commercial satellite communications services (239.71, 239.72).

Because Part 239 is narrow in scope — it applies to information technology specifically — most DoD IT is actually procured under Part 12 (commercial items) and Part 15 (negotiation), with Part 239 adding specific clause requirements layered on top.

When you’d look here

  • Your client is a Cloud Service Provider proposing to host DoD data — DFARS 252.239-7010 FedRAMP compliance is the gate.
  • A client with non-cloud IT services needs to understand Section 889 flow-down and representations.
  • A solicitation includes DFARS 252.239-7018 (Supply Chain Risk) and the client needs to build an assessment process.
  • You’re advising on the overlap between DFARS 252.204-7012 (cyber safeguarding) and DFARS 252.239-7010 (cloud) — a cloud service handling CDI has to satisfy both.

Case study: FedRAMP-Moderate-equivalent for a growing startup

Celestial Cloud Services (hypothetical), a 90-person startup offering an enterprise SaaS for operations scheduling, received a purchase inquiry from a DoD program office. The program wanted to use Celestial for unclassified-but-sensitive program-schedule data. Under DFARS 252.239-7010, cloud services holding DoD data must be FedRAMP Moderate (or higher for sensitive data), with specific requirements for data sovereignty (U.S.-based), audit logging, and incident reporting.

Celestial’s existing commercial SaaS was hosted on AWS GovCloud (which IS FedRAMP High), but the Celestial-specific application layer had never been FedRAMP-assessed. The application inherited some FedRAMP controls from AWS GovCloud but not all; Celestial needed an Agency Authorization (sponsored by the DoD program) or a FedRAMP Joint Authorization Board (JAB) P-ATO before starting work.

The Agency Authorization path:

  • Sponsoring DoD program office issues an Agency ATO (Authorization to Operate) based on Celestial’s System Security Plan (SSP) and Continuous Monitoring package.
  • Celestial must be assessed by a 3PAO (Third-Party Assessment Organization — there are about 35 accredited).
  • Timeline: 6–9 months typically.
  • Cost: 1M for the 3PAO engagement plus internal effort.

The JAB P-ATO path:

  • Portable across agencies but much harder to obtain.
  • Timeline: 12–18 months.
  • Cost: similar to Agency ATO, but with stricter scrutiny.

Celestial chose Agency ATO. Timeline from contract engagement to authorization: 7 months. The DoD program sponsored the assessment and the ATO was issued.

Teaching points:

  1. FedRAMP isn’t automatic with IaaS. Hosting on AWS GovCloud or Azure Government gives inheritance of FedRAMP controls at the infrastructure layer, but the application layer still requires its own authorization.
  2. Agency ATO vs. JAB P-ATO is a strategic choice. Agency ATO is faster and cheaper for a single-customer start; JAB P-ATO is portable across the federal government and better for scale.
  3. Continuous Monitoring is the hidden cost. FedRAMP authorizations require ongoing compliance — monthly scans, annual assessments, significant-change reviews. Budget for the ongoing program, not just the initial authorization.

Case study: Section 889 flow-down and the supplier audit

Meridian Networks (hypothetical), an IT integrator, held a DoD contract providing campus network equipment (switches, routers, access points). The contract incorporated FAR 52.204-25 (Section 889 prohibition — no covered telecommunications equipment from Huawei, ZTE, Hytera, Dahua, or Hikvision) and required quarterly representations that the contractor’s supply chain was 889-compliant.

Meridian’s immediate suppliers were all U.S.-based integrators. But Meridian’s reseller agreements didn’t include 889 flow-down language in the older contracts. When Meridian audited its own supply chain (under pressure from the DoD 889 reporting obligation), it found that a specific video-conference camera model in 200 inventory units had been manufactured with a Hikvision OEM board. The camera vendor was not a 889-covered entity, but the Hikvision board inside was.

Meridian had to:

  • Halt deliveries of the affected model.
  • Replace inventory with a non-Hikvision alternative.
  • Update 889 representations to reflect the remediation.
  • Notify the CO of the prior non-compliant deliveries and propose a remediation plan.

The remediation was accepted. No termination; modest cost ($1.2M) absorbed. But the incident triggered a supplier-tier audit that identified two other covered-equipment risks in Meridian’s supply chain — an ongoing compliance program instead of one-time remediation.

Teaching points:

  1. Section 889 is an OEM-level requirement. The regulation reaches down to component-level manufacture, not just top-level brand. Hikvision-OEM cameras in non-Hikvision branded products are non-compliant.
  2. Flow-down language at contract execution matters. Older supplier agreements may not have 889 language. Plan amendments or new agreements with explicit flow-down.
  3. 889 representations are material. False 889 certifications are FCA-actionable. Audit before certifying.

Key sections

Key clauses

  • DFARS 252.239-7010Cloud Computing Services. Mandates FedRAMP Moderate baseline (higher for sensitive data) and U.S. data sovereignty.
  • DFARS 252.239-7016 — Telecommunications Security Equipment.
  • DFARS 252.239-7017 — Notice of Supply Chain Risk.
  • DFARS 252.239-7018 — Supply Chain Risk.
  • FAR 52.204-25 — Section 889 prohibition on covered telecommunications equipment. (Civilian FAR clause, not DFARS, but applied to DoD contracts.)
  • FAR Part 39 — Civilian IT Part; thinner than DFARS 239.
  • DFARS Part 204 — Cyber (where 252.204-7012 and CMMC live; interacts with 252.239-7010 for cloud services handling CDI).
  • DFARS Part 225 — Sourcing restrictions (rare-earth, semiconductors); supply chain overlap with 239.73.
  • Statutory authority:
    • 10 USC 2339a — Supply chain risk management authority.
    • 50 USC 4565 — CFIUS (for foreign-ownership of IT providers).
    • Section 889 of FY2019 NDAA — codified at 15 USC 1637 et al. scattered across USC.