What the requirement actually says · 1.2

Reading the clause that binds you

Reading the clause that binds you. What the requirement says, what it means in practice, and what an assessor will ask.

For an independent reference point, see CUI category list.

Start here

The clause is the requirement

Everything else on this site, and everything any vendor tells you, is commentary. What binds you is the text incorporated into your contract, and suppliers regularly plan a programme without having read it.

Find it. It will be in the contract itself, in a flow-down schedule from a prime, or incorporated by reference to a clause number, which means the text sits in the acquisition regulation and you have to go and get it.

What to establish

Six things the clause tells you

Which standard applies, by name and version.

What information it covers. The definitions section matters more than the obligations section, because it decides what is in scope.

What you must do: implement, self-assess, submit a score, be certified, or some combination.

By when. A date, or a condition such as at time of award.

What you must report, to whom, and how quickly.

What you must flow down to your own suppliers, which is an obligation on you rather than a suggestion.

Incorporated by reference

Two lines in a contract can carry twenty pages

Most defence contracts list clause numbers rather than reproducing text. The clause exists in full elsewhere, it changes over time, and the version incorporated into your contract is the one in force when the contract was formed unless the contract says otherwise.

Which means two contracts signed eighteen months apart can carry different obligations under the same clause number, and a supplier working to the newer text may be under-complying with the older one, or the reverse.

Reading it properly

Three passes

First for the definitions, marking every defined term. Second for the obligations, listing each as a separate line. Third for the dates and the conditions attached to them.

An hour, producing a page. That page is the specification for the entire programme and almost nobody has one.

The commonest errors

Four

Planning to the wrong level. In both directions, and the correction is free.

Missing the flow-down obligation. Discovered when a prime asks what you require of your own suppliers.

Assuming the reporting requirement is somebody else's. It attaches to you.

Treating a prime's security schedule as the whole requirement. It may be stricter, looser or simply different from the regulatory clause, and both apply.

When the clause is not there

Ask, in writing

Some suppliers discover they hold controlled information without a clause requiring anything, usually because it arrived informally. That is a real situation and it is worth resolving with the customer rather than assuming an absence of obligation.

An email asking what standard applies to the work costs nothing and produces a document.

Keep it

File the clause with the programme

Not in the contracts folder: with the compliance evidence, alongside the plan, so that anybody joining can see what the programme is for without a hunt through procurement records.

Rests on

The safeguarding clause in the defence acquisition regulation supplement and the related certification clauses, whose texts are published in full.

Which clauses and which versions are in your contract is a fact about that contract.

Who should read it

Three people, separately

Whoever handles contracts, who will spot the incorporation mechanics and the flow-down. The compliance owner, who needs the specification. And whoever runs the systems, who will recognise which obligations touch what.

Reading it together as a meeting produces agreement; reading it separately and then comparing produces the questions.

Multiple contracts

Build one table

Customer, contract, clause, level, date, reporting requirement, flow-down obligation. One row per contract.

Suppliers with several defence customers frequently discover the obligations differ, and the programme has to satisfy the strictest of each column rather than an average.

Terms defined elsewhere

The definitions may not be in the clause

Several defined terms point at other documents: what counts as covered information, what counts as an information system, what counts as an incident. Each definition can change what is in scope substantially.

Follow them once, write down what each says, and keep that page with the clause. It is a morning and it prevents an argument later about whether something was covered.

Changes mid-contract

Modifications carry clauses too

A contract modification can introduce or update a clause, and the change arrives in a document that looks administrative.

Whoever reviews modifications should be checking for this. In most suppliers nobody is, and the obligation changes without anybody in the programme knowing.

If a prime will not share it

Ask for the obligation, not the contract

Where a prime declines to show you their prime contract, they can still state in writing what they require of you and under which standard. That statement is what your programme is built on and it is reasonable to insist on having it.

Also

Elsewhere in what the requirement actually says