What the requirement actually says · 1.2
Reading the clause that binds you
Reading the clause that binds you. What the requirement says, what it means in practice, and what an assessor will ask.
For an adjacent operational perspective, this guide explains the topic in a practical workplace context.
For an independent reference point, see CUI category list.
Start here
The clause is the requirement
Everything else on this site, and everything any vendor tells you, is commentary. What binds you is the text incorporated into your contract, and suppliers regularly plan a programme without having read it.
Find it. It will be in the contract itself, in a flow-down schedule from a prime, or incorporated by reference to a clause number, which means the text sits in the acquisition regulation and you have to go and get it.
What to establish
Six things the clause tells you
Which standard applies, by name and version.
What information it covers. The definitions section matters more than the obligations section, because it decides what is in scope.
What you must do: implement, self-assess, submit a score, be certified, or some combination.
By when. A date, or a condition such as at time of award.
What you must report, to whom, and how quickly.
What you must flow down to your own suppliers, which is an obligation on you rather than a suggestion.
Incorporated by reference
Two lines in a contract can carry twenty pages
Most defence contracts list clause numbers rather than reproducing text. The clause exists in full elsewhere, it changes over time, and the version incorporated into your contract is the one in force when the contract was formed unless the contract says otherwise.
Which means two contracts signed eighteen months apart can carry different obligations under the same clause number, and a supplier working to the newer text may be under-complying with the older one, or the reverse.
Reading it properly
Three passes
First for the definitions, marking every defined term. Second for the obligations, listing each as a separate line. Third for the dates and the conditions attached to them.
An hour, producing a page. That page is the specification for the entire programme and almost nobody has one.
The commonest errors
Four
Planning to the wrong level. In both directions, and the correction is free.
Missing the flow-down obligation. Discovered when a prime asks what you require of your own suppliers.
Assuming the reporting requirement is somebody else's. It attaches to you.
Treating a prime's security schedule as the whole requirement. It may be stricter, looser or simply different from the regulatory clause, and both apply.
When the clause is not there
Ask, in writing
Some suppliers discover they hold controlled information without a clause requiring anything, usually because it arrived informally. That is a real situation and it is worth resolving with the customer rather than assuming an absence of obligation.
An email asking what standard applies to the work costs nothing and produces a document.
Keep it
File the clause with the programme
Not in the contracts folder: with the compliance evidence, alongside the plan, so that anybody joining can see what the programme is for without a hunt through procurement records.
The safeguarding clause in the defence acquisition regulation supplement and the related certification clauses, whose texts are published in full.
Which clauses and which versions are in your contract is a fact about that contract.
Who should read it
Three people, separately
Whoever handles contracts, who will spot the incorporation mechanics and the flow-down. The compliance owner, who needs the specification. And whoever runs the systems, who will recognise which obligations touch what.
Reading it together as a meeting produces agreement; reading it separately and then comparing produces the questions.
Multiple contracts
Build one table
Customer, contract, clause, level, date, reporting requirement, flow-down obligation. One row per contract.
Suppliers with several defence customers frequently discover the obligations differ, and the programme has to satisfy the strictest of each column rather than an average.
Terms defined elsewhere
The definitions may not be in the clause
Several defined terms point at other documents: what counts as covered information, what counts as an information system, what counts as an incident. Each definition can change what is in scope substantially.
Follow them once, write down what each says, and keep that page with the clause. It is a morning and it prevents an argument later about whether something was covered.
Changes mid-contract
Modifications carry clauses too
A contract modification can introduce or update a clause, and the change arrives in a document that looks administrative.
Whoever reviews modifications should be checking for this. In most suppliers nobody is, and the obligation changes without anybody in the programme knowing.
If a prime will not share it
Ask for the obligation, not the contract
Where a prime declines to show you their prime contract, they can still state in writing what they require of you and under which standard. That statement is what your programme is built on and it is reasonable to insist on having it.
Also
Elsewhere in what the requirement actually says
- What the three levels are, and which appliesThe level is set by your contract, not by your size. Most suppliers handling controlled unclassified information are at the second.
- Which systems are in scopeWhich systems are in scope. What the requirement says, what it means in practice, and what an assessor will ask.
- Self-assessment, and why the scores driftedSelf-assessment, and why the scores drifted. What the requirement says, what it means in practice, and what an assessor will ask.
- Who assesses you, and how each kind worksWho assesses you, and how each kind works. What the requirement says, what it means in practice, and what an assessor will ask.
- What the standard does not requireWhat the standard does not require. What the requirement says, what it means in practice, and what an assessor will ask.
- Machines older than the requirementsA control written for a server, applied to a lathe with a shared login, a decade-old operating system and a USB port.
- Drawings, job packets and paperDrawings, job packets and paper. What the requirement says, what it means in practice, and what an assessor will ask.
- Removable media, and why bans failRemovable media, and why bans fail. What the requirement says, what it means in practice, and what an assessor will ask.
- Vendor remote accessVendor remote access. What the requirement says, what it means in practice, and what an assessor will ask.
- Technical data packages and what they containTechnical data packages and what they contain. What the requirement says, what it means in practice, and what an assessor will ask.
- Segmentation, and what it does not solveSegmentation, and what it does not solve. What the requirement says, what it means in practice, and what an assessor will ask.
- What insider risk actually coversWhat insider risk actually covers. What the requirement says, what it means in practice, and what an assessor will ask.
- What detection can and cannot establishWhat detection can and cannot establish. What the requirement says, what it means in practice, and what an assessor will ask.
- Monitoring, and where the law constrains itMonitoring, and where the law constrains it. What the requirement says, what it means in practice, and what an assessor will ask.
- The fortnight around a departureThe fortnight around a departure. What the requirement says, what it means in practice, and what an assessor will ask.
- Privileged access, and who reviews itPrivileged access, and who reviews it. What the requirement says, what it means in practice, and what an assessor will ask.
- False positives, and what they costFalse positives, and what they cost. What the requirement says, what it means in practice, and what an assessor will ask.
- The documents an assessor reads firstThe documents an assessor reads first. What the requirement says, what it means in practice, and what an assessor will ask.
- What counts as evidenceWhat counts as evidence. What the requirement says, what it means in practice, and what an assessor will ask.
- The findings that recurThe findings that recur. What the requirement says, what it means in practice, and what an assessor will ask.
- Plans of action, and their limitsPlans of action, and their limits. What the requirement says, what it means in practice, and what an assessor will ask.
- What the assessment week is likeWhat the assessment week is like. What the requirement says, what it means in practice, and what an assessor will ask.
- The certificate, and what it coversThe certificate, and what it covers. What the requirement says, what it means in practice, and what an assessor will ask.