48 CFR 40.000
40.000 Scope of part.
United States · 48 CFR — Federal Acquisition Regulations System · Status: effective
Cite this
- Citation
- 48 CFR 40.000, 40.000 Scope of part, United States, version 1 as recorded 2026-07-09, yourstate.us, https://yourstate.us/provision/241302
- Permanent ID
ys:prov:241302@1- SHA-256
63518069b8416469937b63b5aac6491f61f557da54d7b2cd35695a9a227e3789
The hash is SHA-256 of this version's text, with every run of whitespace collapsed to a single space and the ends trimmed. The ID always leads back here, and checking it says whether the text you cited is still the current version.
Full text
(a) This part addresses broad security requirements that apply to acquisitions of products and services. It prescribes policies and procedures for managing information security and supply chain security when acquiring products and services that include, but are not limited to, information and communications technology (ICT).
(b) See part 39 for security-related policies and procedures that only apply to ICT.
(c) See parts 4, 24, and 46 for additional policies and procedures related to managing information security and supply chain security.
(d) Information and supply chain policies and procedures that are unrelated to security are covered in other parts of the FAR (e.g., part 22 for labor and human trafficking risks and part 23 for climate-related risks).
Legislative history
This is a federal regulation, adopted through agency rulemaking under the Administrative Procedure Act — not enacted by a recorded vote of Congress.