32 CFR 236.7
§ 236.7 DoD's DIB CS Program requirements.
United States · 32 CFR — National Defense · Status: effective
Cite this
- Citation
- 32 CFR 236.7, § 236.7 DoD's DIB CS Program requirements, United States, version 1 as recorded 2026-07-09, yourstate.us, https://yourstate.us/provision/146113
- Permanent ID
ys:prov:146113@1- SHA-256
ab365c764791645a77390035fc70dc083d8a9f50c183eefa8ea53ce54dc7c940
The hash is SHA-256 of this version's text, with every run of whitespace collapsed to a single space and the ends trimmed. The ID always leads back here, and checking it says whether the text you cited is still the current version.
Full text
(a) To participate in the DIB CS Program, a contractor must own or operate a covered contractor information system and shall execute the standardized FA with the Government (available during the application process), which implements the requirements set forth in §§ 236.5 and 236.6.
(b) In order for DIB CS Program participants to receive classified cyber threat information electronically, the company must be a cleared defense contractor and must:
(1) Have an existing active facility clearance level (FCL) to at least the Secret level in accordance with 32 CFR part 117;
(2) Have or acquire a Communication Security (COMSEC) account in accordance with 32 CFR part 117, which provides procedures and requirements for COMSEC activities;
(3) Have or acquire approved safeguarding for at least Secret information, and continue to qualify under 32 CFR part 117 for retention of its FCL and approved safeguarding; and
(4) Obtain access to DoD's secure voice and data transmission systems supporting the voluntary DIB CS Program.
Legislative history
This is a federal regulation, adopted through agency rulemaking under the Administrative Procedure Act — not enacted by a recorded vote of Congress.