Effective Date: 12/01/2026
HHSAR Text Baseline is 48 CFR Chapter 3 as of August 4, 2026.
Changes to baseline shown as [bolded, bracketed additions] and strikethrough deletions.
For HHSAR part 352, only the provisions and clauses associated with part 340 are shown.
HHSAR PART 340 – INFORMATION SECURITY AND SUPPLY CHAIN SECURITY [(RFO DEVIATION)]
[Subpart 340.3 – Safeguarding Information
340.370 Basic safeguarding of HHS information.
340.370-1 Definition.
340.370-2 General.
340.370-3 Contract clause.
Subpart 340.70 – Supply Chain Risk Assessments
340.7000 Scope of subpart.
340.7001 Definitions.
340.7002 Policy.
340.7003 SCRA requirements.
340.7004 SCRA determinations.
340.7005 Contract clause.]
[Subpart 340.3 – Safeguarding Information
340.370 Basic safeguarding of HHS information.
340.370-1 Definition.
As used in this section—
HHS information—
(1) Means information, in any form or format, that—
(i) Is provided by or on behalf of HHS to the contractor in connection with contract performance; or
(ii) Is collected, created, generated, received, maintained, managed, processed, or otherwise handled by the contractor on behalf of HHS in connection with contract performance.
(2) May include Federal contract information, HHS sensitive information, controlled unclassified information, protected health information, personally identifiable information, Privacy Act records, Federal records, and other information subject to specific protection or handling requirements when the information meets the applicable definition or criteria for that category.
340.370-2 General.
(a) HHS will identify in the contract—
(1) The safeguarding requirements and handling conditions applicable to HHS information, and
(2) When warranted by the nature of the information, the manner in which it is handled, or the circumstances of contract performance; any additional or more restrictive security, privacy, confidentiality, records management, access, use, disclosure, reporting, retention, preservation, disposition, or other requirements.
(b) Contractors must—
(1) Ensure that HHS information is, at a minimum—
(i) Protected against unauthorized access, use, disclosure, release, modification, loss, or destruction; and
(ii) Used, disclosed, released, or disseminated only as authorized by the contract; and
(2) Comply with the specified safeguarding requirements and handling conditions identified in the contract.
340.370-3 Contract clause.
Insert the clause at 352.240-71, Basic Safeguarding of HHS Information, in solicitations and contracts when contract performance may involve handling HHS information.
Subpart 340.70 – Supply Chain Risk Assessments
340.7000 Scope of subpart.
This subpart implements, in part, various statutes, executive orders and policies, including Executive Order 14017 of February 23, 2021, America’s Supply Chains; the HHS Enterprise Supply Chain Risk Management (E-SCRM) Program Policy; and the HHS Cyber Supply Chain Risk Management (C-SCRM) Policy requirement to conduct a supply chain risk assessment on mission-critical acquisitions.
340.7001 Definitions.
As used in this subpart—
Foreign person means as defined in 31 CFR 800.224.
Mission-critical acquisition means an acquisition of products, materials, information, or services that support or involve—
(1) Continuity of operations (COOP) mission essential functions;
(2) Critical infrastructure;
(3) Research and development;
(4) High-value information and communication-based technology (ICT);
(5) Use or sharing of HHS Intellectual property;
(6) Financial databases and services; or
(7) Other critical assets or services as identified by HHS Division leadership.
Supply chain risk means as defined in FAR 40.101.
Supply chain risk assessment (SCRA) means a systematic examination of supply chain threats, risks, or vulnerabilities, likelihoods of their occurrence, and potential impacts.
340.7002 Policy.
HHS will conduct SCRAs on mission-critical acquisitions when required by the E-SCRM and C-SCRM policies to protect the Department's internal supply chain as it relates to threats posed by the activities of foreign and other adversaries toward the acquisition lifecycle of mission-critical products, materials, information, and services.
340.7003 SCRA requirements.
(a) For mission-critical acquisitions, SCRAs—
(1) Will be conducted before award when required by the E-SCRM Program Policy and C-SCRM Policy, and
(2) May be conducted during contract performance when—
(i) There is an active supply chain risk mitigation in place;
(ii) Adverse information is identified during performance;
(iii) There are changes in reporting items in clause 352.240-70;
(iv) The contract is modified to acquire mission-critical products, materials, information, or services;
(v) The Government plans to exercise an option period; or
(vi) The contracting officer determines a SCRA is needed after consultation with the appropriate SCRM personnel.
(b) HHS will perform a SCRA using information submitted in response to the solicitation and other sources.
340.7004 SCRA determinations.
(a) Findings from the SCRA will be considered in connection with a determination of the—
(1) Offeror’s responsibility and eligibility for award, or
(2) Contractor’s eligibility to continue performance on the contract.
(b) Failure to furnish the required information in clause 352.240-70 or additional information as requested by the contracting officer may render the—
(1) Offeror non-responsible and ineligible for award, or
(2) Contractor ineligible to continue performance on the contract.
340.7005 Contract clause.
Insert the clause at 352.240-70, Supply Chain Risk Assessment, in solicitations and contracts for mission-critical acquisitions when required by the E-SCRM and C-SCRM policies.]
HHSAR PART 352 – SOLICITATION PROVISIONS AND CONTRACT CLAUSES [(RFO DEVIATION)]
Subpart 352.2 – Texts of Provisions and Clauses
[352.240-70 Supply Chain Risk Assessment.
352.240-71 Basic Safeguarding of HHS Information.]
Subpart 352.2 – Texts of Provisions and Clauses
[352.240-70 Supply Chain Risk Assessment.
As prescribed in 340.7005, insert the following clause:
SUPPLY CHAIN RISK ASSESSMENT (DEC 2026) (RFO DEVIATION)
(a) Definitions. As used in this clause—
Foreign person means as defined in 31 CFR 800.224.
Mission-critical acquisition means an acquisition of products, materials, information, or services that support or involve—
(1) Continuity of operations (COOP) mission essential functions;
(2) Critical infrastructure;
(3) Research and development;
(4) High-value information and communication-based technology (ICT);
(5) Use or sharing of HHS Intellectual property;
(6) Financial databases and services; or
(7) Other critical assets or services as identified by HHS Division leadership.
Supply chain risk means as defined in FAR 40.101.
Supply chain risk assessment (SCRA) means a systematic examination of supply chain threats, risks, or vulnerabilities, likelihoods of their occurrence, and potential impacts.
(b) Supply chain risk assessment. HHS, including individuals or entities working on behalf of HHS, may conduct a SCRA of the Offeror prior to the award of a contract and of the Contractor during contract performance. When conducting the SCRA, HHS may use and maintain information submitted under this clause and may consider public and non-public information relating to the Offeror’s/Contractor’s supply chain.
(c) Offeror/Contractor submission requirements.
(1) Prior to award. The Offeror must complete paragraphs (d) and (e) of this clause and submit the completed information with its proposal.
(2) During contract performance. At least annually, when requested by the Government, or whenever there are material changes to information previously submitted in paragraphs (d) or (e), the Contractor must submit the updated, completed version of this clause to the Contracting Officer.
(d) Required information submittal. The Offeror/Contractor must provide the following information for products, materials, information, or services provided under their proposal/contract:
(1) Description of the type of products, materials, information, or services provided.
(2) Offeror/Contractor information. Company name, including all “doing business name” aliases, Government Entity (CAGE) code, Unique Entity Identifier (UEI), address, and website.
(3) Subcontractor, supplier, and manufacturer information. For each subcontractor, supplier, or manufacturer associated with the award, provide the company name, CAGE code, UEI, address, and website. Please ensure this information is specific for the entity and location that is participating in the delivery of goods or services to HHS.
(4) Owner, joint venture, or merger information of the Offeror/Contractor. Provide the name, CAGE code, UEI, address, and website for each owner, joint venture partner, or merger.
(e) Representations. The Offeror/Contractor represents that—
(1) It [ ] does, [ ] does not have any foreign ownership (whether by a private entity, foreign investment company, state-owned entity, or foreign government). If yes, identify the foreign company, individual, or government involved; country of affiliation; the percentage of ownership; and the type of business involvement.
(2) It [ ] does, [ ] does not have any of the following business affiliations: technology development partnerships, strategic partnerships, joint ventures, foreign subsidiaries, or grants from a foreign entity. If yes, identify the legal name of the organization, its foreign address, and the nature of the relationship.
(3) Its leadership (C-Suite executives, Board members, etc.) [ ] does, [ ] does not have any connections to foreign countries, such as citizenship in a foreign country, prior work or residence in a foreign country, graduation from a foreign university, or financial investments in a foreign country. If yes, identify the individual, describe the specific type of connection, and the foreign country involved.
(4) It [ ] has, [ ] has not been prohibited from doing business with the government of the United States or any foreign governments or subdivisions thereof. If yes, enter the event, the date, and any remediation the company committed after the event.
(5) It [ ] has, [ ] has not had affiliations with any prohibited entities (see SAM.gov “exclusions” page for additional information regarding prohibited entities)? If yes, enter the name, date, and description of the affiliation.
(6) It [ ] has, [ ] has not implemented a formal cybersecurity framework or program aligned to a recognized standard (e.g., NIST CSF, ISO 27001, CMMC)? If yes, identify the applicable framework(s) and current certification or maturity level.
(7) It [ ] has, [ ] has not experienced a cybersecurity incident, data breach, or ransomware event in the last five (5) years? If yes, please briefly describe the nature of the incident and remediation steps taken.
(8) It [ ] has, [ ] has not incorporated open-source or foreign-origin Artificial Intelligence (AI) in the product or service being delivered? If yes, please describe the origin of the AI, if the system is incorporating HHS information to learn, and/or describe the data retention capabilities.
(9) It [ ] will, [ ] will not provide support as a cloud support provider (CSP). If so, please identify the FedRAMP sponsoring federal agency which issued its authority to operate (ATO), and the date of ATO expiration.
(f) Supply chain risk determination. Findings from the SCRA will be considered in connection with a determination of the Offeror’s responsibility and eligibility for award, or the Contractor’s eligibility to continue performance on the contract.
(1) Failure of the Offeror/Contractor to furnish the information required in this clause or provide additional information as requested by the Contracting Officer may render the Offeror non-responsible and ineligible for award, or the Contractor ineligible to continue performance on the contract.
(2) The Government reserves the right to limit the disclosure of information to the Offeror/Contractor regarding the risk in accordance with all applicable laws or regulations.
(g) Mitigation plans. Any mitigation plans and amendments determined necessary and to be implemented and sustained during contract performance will be incorporated into the contract.
(h) Subcontracts. The Offeror/Contractor must include the substance of this clause, including the information and representations at paragraphs (d) and (e), and including this paragraph (h), in subcontracts (at all tiers) proposed to be, or actually, used involving the development or delivery of any mission-critical products, materials, information, or services.
(1) The Offeror/Contractor must submit all potential and actually used subcontractor information and representations with its proposal and during performance of the contract, for any mission-critical products, materials, information, or services provided for in the proposal and performed during the contract period.
(End of clause)
352.240-71 Basic Safeguarding of HHS Information.
As prescribed in 340.370-3, insert the following clause:
BASIC SAFEGUARDING OF HHS INFORMATION (DEC 2026) (RFO DEVIATION)
(a) Definition. As used in this clause—
HHS information—
(1) Means information, in any form or format, that—
(i) Is provided by or on behalf of HHS to the Contractor in connection with contract performance; or
(ii) Is collected, created, generated, received, maintained, managed, processed, or otherwise handled by the Contractor on behalf of HHS in connection with contract performance.
(2) May include Federal contract information, HHS sensitive information, controlled unclassified information, protected health information, personally identifiable information, Privacy Act records, Federal records, and other information subject to specific protection or handling requirements when the information meets the applicable definition or criteria for that category.
(b) Baseline safeguarding requirements. The Contractor must—
(1) Protect the confidentiality, integrity, and availability of HHS information in accordance with the requirements of the contract;
(2) Protect HHS information against unauthorized access, use, disclosure, release, modification, loss, or destruction;
(3) Use HHS information only for purposes authorized by the contract and limit access to persons requiring access for authorized contract performance;
(4) Not disclose, release, disseminate, or otherwise make HHS information available except as authorized by the contract or otherwise authorized in writing by the Contracting Officer; and
(5) When uncertain whether an action is authorized by the contract, consult with the Contracting Officer before disclosing, releasing, disseminating, or otherwise making HHS information available.
(c) Additional safeguarding requirements. HHS information—based on the nature of the information, the manner in which it is handled, or the circumstances of contract performance—may be subject to additional or more restrictive requirements, including security, privacy, confidentiality, records management, access, use, disclosure, reporting, retention, preservation, disposition, or other requirements. When applicable, those requirements will be identified elsewhere in the contract. The Contractor must comply with those requirements in addition to this clause.
(d) Incidents and unauthorized handling. The Contractor must—
(1) Report any known or suspected unauthorized access, use, disclosure, release, modification, loss, destruction, or other compromise of HHS information in accordance with the notification procedures and timeframes identified in the contract; and
(2) Cooperate with HHS in any investigation, containment, mitigation, remediation, recovery, risk analysis, or other response activity required by the contract.
(e) Relationship to other contract requirements.
(1) The requirements of this clause are in addition to, and do not replace, limit, or modify, other applicable requirements governing HHS information identified elsewhere in the contract.
(2) When another contract requirement imposes additional or more restrictive obligations with respect to HHS information, the Contractor must comply with those obligations.
(f) Subcontracts. The Contractor must include the substance of this clause, including this paragraph (f), in subcontracts at any tier when the subcontractor will handle HHS information in connection with subcontract performance.
(End of clause)]