DFARS compliance

    Can I use Encyro to store data subject to Defense Federal Acquisition Regulation Supplement (DFARS) compliance, or data security regulations subject to defense contracts, or related government data?

    The requirements of DFARS compliance vary depending on the security level required, which depends on the sensitivity of data being secured.

    If only encryption is needed (both for data at rest and for data in transit) Encyro Essentials membership (Free) provides that. However most DFARS compliance levels do require audit trails and so Encyro Pro is required.

    Even Encyro Pro does not meet all levels of DFARS compliance. For certain types of data, it must be stored in a data center used only for government data. Encyro can provide a custom quote for you if this need applies to you. We will need to verify that your organization qualifies for hosting in the government-specific data center. To get started, please contact us for a quote. Our price is very likely to be much lower than the alternatives.

    Resources

    Many organizations are subject to DFARS compliance because they handle Controlled Unclassified Information (CUI). For these situations, the NIST provides a Security Systems Plan (SSP) template and a Plan of Action and Milestones (POA&M) template. Preparing these two documents using the templates linked above will help you demonstrate your organization’s compliance with DFARS for handling CUI. In situations where the government agency or the defense contractor you are serving requires you to obtain third party certification of your compliance, these two documents will both prepare you for the requirements and speed up the certification related audits.

    Related articles

    • National Institue of Standards and technology (NIST) Special Publication 800-171 or NIST-SP800-171, specifies requirements for non-Federal computer systems...

    • Encyro Inc is based in the United States of America, and is subject to US laws and regulations.  Your data in your Encyro account is stored in our data cen...

    • Can I use Encyro for HIPAA compliance? Can I store and send patient information using Encyro? Encyro complies with Health Insurance Portability and Account...

    • (If your Encyro account is part of an organization, see organizational compliance settings.) To enable or edit compliance settings, go to your account Sett...

    • PCI-DSS requires safeguarding credit card data that you receive. Email is not a secure way to ask a customer to provide their credit card information to se...

    • IRS Publication 4557 provides seven checklists for tax preparers to help protect tax clients' tax data. The safeguards also protect your business from a da...

    • If you are being asked to login every time you visit your Encyro account, it is likely that you or your organization's compliance settings have enforced au...