48 CFR § 1239.7000 - 1239.7000 Scope of subpart.
---
identifier: "/us/cfr/t48/s1239.7000"
source: "ecfr"
legal_status: "authoritative_unofficial"
title: "48 CFR § 1239.7000 - 1239.7000 Scope of subpart."
title_number: 48
title_name: "Federal Acquisition Regulations System"
section_number: "1239.7000"
section_name: "1239.7000 Scope of subpart."
chapter_number: 12
chapter_name: "DEPARTMENT OF TRANSPORTATION"
subchapter_number: "F"
subchapter_name: "SPECIAL CATEGORIES OF CONTRACTING"
part_number: "1239"
part_name: "ACQUISITION OF INFORMATION TECHNOLOGY"
positive_law: false
currency: "2026-03-24"
last_updated: "2026-03-24"
format_version: "1.1.0"
generator: "[email protected]"
authority: "5 U.S.C. 301; 41 U.S.C. 1121(c)(3); 41 U.S.C. 1702; and 48 CFR 1.301 through 1.304."
regulatory_source: "87 FR 61159, Oct. 7, 2022, unless otherwise noted."
cfr_part: "1239"
---
# 1239.7000 1239.7000 Scope of subpart.
(a) This subpart applies to contracts and subcontracts requiring contractors and subcontractors to safeguard DOT sensitive data that resides in or transits through covered contractor information systems by applying specified network security requirements. It also requires reporting of cyber incidents.
(b) This subpart does not abrogate any other requirements regarding contractor physical, personnel, information, technical, or general administrative security operations governing the protection of unclassified information, nor does it affect requirements of the National Industrial Security Program.