Summary
What does FAR Part 39 require for IT acquisitions? FAR Part 39 sets acquisition policy for IT and ICT, including security, privacy, accessibility, market research, and several technology prohibitions.
FAR Part 39 sets acquisition policy for IT and ICT, including security, privacy, accessibility, market research, and several technology prohibitions.
Summary
What does FAR Part 39 require for IT acquisitions? FAR Part 39 sets acquisition policy for IT and ICT, including security, privacy, accessibility, market research, and several technology prohibitions.
Part 39 of the FAR covers acquisition policy for information technology and information and communication technology. FAR 39.000 states that the part prescribes policies and procedures for acquiring IT, including financial management systems, and ICT. FAR 39.101 then tells agencies to identify IT requirements with attention to security of resources, privacy, national security and emergency preparedness, accessibility for individuals with disabilities, energy efficiency, sustainable products and services, power management, and energy-efficient management of servers and Federal data centers. The policy also directs contracting officers to use market research and technology refreshment techniques when developing an acquisition strategy. For financial management systems, agencies must follow OMB Circular A-127 and may acquire only core financial management software certified by the Joint Financial Management Improvement Program. The same section adds specific requirements for IT security policies, IP compliance, and consultation with the requiring official, and it lists several prohibited technologies and services.
Use FAR 39.000 to confirm that the acquisition involves information technology or information and communication technology.
Apply FAR 39.101 to capture security, privacy, accessibility, energy efficiency, sustainable products and services, and server and data center best practices.
Use market research and technology refreshment techniques when developing the strategy, as directed in FAR 39.101.
Apply the financial management system rules, IT security requirements, IP compliance requirements, and the listed technology prohibitions before proceeding.
FAR 39.101 names several specific prohibitions, including Kaspersky Lab hardware, software, and services; covered telecommunications equipment or services; the covered application TikTok; FASCSA-covered articles; and prohibited unmanned aircraft systems.