PFTN Buyer's Guide

Federal Contractor Insurance: FAR 52.228 Clauses and CMMC Cyber Coverage Explained

What the FAR insurance clauses actually require, why CMMC is not cyber insurance, and what every federal prime and sub should ask before the next contract award.

By Ryan Mefford · President & Risk Advisor · Peoples First Tennessee

What's in this guide

  1. Why federal contractor insurance is different
  2. The FAR 52.228 series, clause by clause
  3. DFARS modifications for DoD contractors
  4. CMMC compliance is not cyber insurance
  5. The CMMC flow-down liability problem
  6. Why federal COIs keep getting rejected
  7. DCAA timekeeping audits — insurable and not
  8. Price-Anderson and nuclear-adjacent work
  9. The SBOM mandate and software-supplier exposure
  10. Questions every federal contractor should ask
  11. Frequently asked questions

Why federal contractor insurance is different

Federal contractor insurance is its own discipline and most commercial brokers don't have it.

The reason is that federal contracts are built on top of the Federal Acquisition Regulation (FAR), with agency-specific supplements (DFARS for DoD, DEAR for DOE, FAR Supplement for the General Services Administration). The insurance requirements are written into the contract by reference to specific FAR clauses, and the clauses have specific language, specific limits, and specific compliance expectations that don't match the standard commercial COI form.

A general commercial broker can place a federal contractor's GL and workers comp. Where the trouble starts is the specific FAR clause language, the additional-insured requirements unique to federal contracting officers, the certificate-holder wording the contracting officer expects, and the per-contract variations that make a one-size renewal almost impossible.

The result is a federal-contractor insurance market that runs on specialists. This guide is for federal prime and sub owners who need to evaluate whether their current broker actually understands the work, and what to ask if they don't.

The FAR 52.228 series, clause by clause

FAR 52.228 is the section of the Federal Acquisition Regulation that addresses insurance requirements. The clauses most likely to appear in a federal contract are:

FAR 52.228-3 — Workers Compensation Insurance (Defense Base Act)

Required for work performed outside the United States. Provides workers compensation and war hazard coverage under the Defense Base Act for employees working overseas on federal contracts. Standard domestic workers comp does not extend to DBA exposure; a separate policy or endorsement is required.

FAR 52.228-4 — Workers Compensation and War-Hazard Insurance Overseas

Similar to 52.228-3 but with broader applicability to non-US work. Often invoked alongside 52.228-3 to ensure both DBA and war-hazard coverage are in place.

FAR 52.228-5 — Insurance — Work on a Government Installation

Required when the contractor performs work on government property. Specifies minimum limits for workers comp, employer's liability, general liability, automobile liability, and aircraft liability where applicable. The minimums under 52.228-5 are floors, not ceilings — the contracting officer can require more, and routinely does.

FAR 52.228-7 — Insurance — Liability to Third Persons

Used in cost-reimbursement contracts. Requires the contractor to maintain GL coverage with limits set in the contract, name the United States government as additional insured where applicable, and carry the contracting officer's required wording on the certificate.

FAR 52.228-15 — Performance and Payment Bonds — Construction

Requires performance and payment bonds on federal construction contracts above the Simplified Acquisition Threshold. Bond limits and the surety qualification requirements (Treasury Listing) are specified.

FAR 52.228-12 — Prospective Subcontractor Requests for Bonds

Allows subcontractors to request bond information from primes. Often invoked alongside Miller Act bond requirements on federal construction.

Other clauses in the 52.228 series cover specific contract types: ship repair, transportation of supplies, etc. The point is that the clause-by-clause specificity is the work — getting the COI wording right requires reading the actual clause invoked in the contract, not the generic FAR summary.

DFARS modifications for DoD contractors

The Defense Federal Acquisition Regulation Supplement (DFARS) modifies and adds to the base FAR for DoD-specific contracts. The most commonly invoked DFARS insurance clauses include:

The cybersecurity DFARS clauses (especially 252.204-7012) are where most DoD primes are exposed in 2026. The clause requires safeguarding CUI to NIST SP 800-171 standards and reporting cyber incidents within 72 hours. Failure to safeguard or report creates contract default exposure that no insurance policy directly cures — but the related fraud and False Claims Act exposure is what cyber and D&O policies need to address.

CMMC compliance is not cyber insurance

The single largest misunderstanding we see across federal contractors is the assumption that CMMC certification covers what cyber liability insurance covers. It doesn't.

CMMC (Cybersecurity Maturity Model Certification) governs the federal contractor's data-handling posture pre-incident. It's a compliance framework requiring documented controls, third-party assessment, and ongoing maintenance. Achieving CMMC Level 2 says: "this contractor handles CUI according to the prescribed standards."

Cyber liability insurance funds the response post-incident. When a breach happens, cyber insurance pays for the forensic investigation, the legal counsel, the notification of affected parties, the credit monitoring, the regulatory defense, the ransom payment if applicable, and the business interruption losses while systems are down. CMMC does not pay any of this.

Defense primes that assume their CMMC certification is their cyber insurance discover the gap when the first ransomware demand or data-exfiltration notification arrives. We covered this dynamic in detail in CMMC compliance is not cyber insurance.

CMMC certification is what the auditor checks. Cyber insurance is what funds the response when the auditor's controls don't hold.

The CMMC flow-down liability problem

The 2026 DoD prime contractor is now in the chain of liability for subcontractor CMMC failures.

When a prime flows down CUI-handling work to a subcontractor, the prime is contractually responsible for the sub's compliance posture. If the sub fails CMMC and a CUI exposure event occurs, the prime can be in the False Claims Act chain — the prime represented to the government that its supply chain met CMMC standards, and the failure is a misrepresentation.

The defensive posture for primes is:

  1. Audit subcontractor CMMC posture before flow-down, not at the year-end checkbox
  2. Include CMMC-related representations and warranties in subcontract terms
  3. Require subs to carry their own cyber liability coverage with limits proportional to data exposure
  4. Document the audit and warranty trail so the prime can defend reasonable reliance if a sub fails

Primes that don't do this work are absorbing exposure they may not realize they carry. We covered the prime-contractor posture in CMMC flow-down is now a prime contractor liability problem.

Why federal COIs keep getting rejected

Roughly 45-55% of certificates of insurance submitted to federal contracting officers are rejected on first submission.

The rejection reasons are almost never the COI form itself. They're the underlying contract requirements being missed:

The fix is auditing the contract before the COI gets issued — reading every insurance requirement against the actual policy form and endorsement list before the COI hits the contracting officer's desk. The broker that does this work proactively avoids the rejection cycle. The broker that doesn't is what makes the 45-55% rejection rate possible. We covered this in the 45% rejection rate no one talks about.

DCAA timekeeping audits — insurable and not

DCAA (Defense Contract Audit Agency) timekeeping audits are intensifying in 2026 and the insurance question is more nuanced than most contractors realize.

Insurance generally does not cover: cost disallowance, contract price reductions, withheld payments resulting from documented timekeeping violations. Those are commercial disputes between the contractor and the government, not insurable losses.

Insurance may cover: fraud allegations arising from timekeeping discrepancies, False Claims Act exposure if the government alleges intentional misrepresentation, defense costs of regulatory investigations even when no fraud is ultimately found, and individual director or officer exposure if the allegations reach personal conduct.

The line between "audit finding" and "fraud allegation" is where the insurance question turns. A documented control failure that produces an audit finding is typically a commercial matter. A pattern of falsified timecards is potentially criminal. The middle ground — where the government alleges deliberate misclassification — is where the policy form's wording on fraud, intentional acts, and regulatory defense matters most.

We covered the audit pattern in the DCAA timekeeping audit that started last quarter.

Price-Anderson and nuclear-adjacent work

The Price-Anderson Act provides federal indemnification and a liability cap for nuclear incidents at licensed nuclear facilities. For contractors operating at DOE sites — the Oak Ridge complex, Hanford, Savannah River, INL — Price-Anderson is a foundational piece of the risk environment.

What Price-Anderson covers: nuclear-incident liability for the operator and contractors covered under the operator's program, up to the statutory cap.

What Price-Anderson does not cover: standard workplace injuries, environmental claims unrelated to a nuclear incident, contract disputes, intellectual property matters, and most third-party liability claims that don't involve a defined nuclear incident.

The practical result for a contractor at a DOE nuclear site is that Price-Anderson is one layer of a multi-layered program, not the whole program. The contractor's own GL, professional liability, pollution liability, and workers comp programs have to fill the gaps. We covered the layering in the three layers of nuclear liability no one explains and what Price-Anderson doesn't cover.

The SBOM mandate and software-supplier exposure

OMB memoranda M-22-18 (September 2022) and M-23-16 (June 2023) require federal software suppliers to attest to secure software development practices, including providing Software Bill of Materials (SBOM) documentation. The attestation requirement applies broadly across federal software procurement.

The SBOM mandate doesn't directly require new insurance policies. What it creates is a new False Claims Act exposure: a software supplier that attests to secure development practices that the supplier doesn't actually follow has potentially made a false claim. The downstream insurance question is whether the supplier's D&O, cyber, and government-contractor E&O programs cover defense of the False Claims Act exposure.

Most policy forms do — but the wording matters. Standard D&O exclusions for "intentional acts" can block coverage when the government alleges deliberate misrepresentation. Cyber policies often have specific government-investigation language that has to be triggered correctly.

Software suppliers should align their attestation posture, their internal development practices, and their insurance forms in a coherent way. We covered the framework in the software bill of materials mandate is here.

Questions every federal contractor should ask

Whether your broker is PFTN or someone else, these are the questions worth raising at the start of every renewal cycle and before every major new contract award:

  1. Will you read every active prime contract and flow-down package for FAR 52.228 clauses, DFARS clauses, and agency-specific insurance requirements?
  2. How are we structuring cyber liability to address the gap between CMMC compliance and breach response?
  3. What's our subcontractor compliance posture, and do our contracts include CMMC representations and warranties?
  4. What's our COI first-submission acceptance rate, and where are we getting rejected?
  5. How is DCAA exposure addressed in our D&O and government-contractor E&O forms?
  6. If we work on DOE sites, how are we layering with Price-Anderson?
  7. If we are a software supplier, how is our SBOM attestation posture aligned with our D&O and cyber forms?
  8. Are we carrying Defense Base Act coverage if we have any overseas employees?

A broker who can answer all eight cleanly is running a federal-specialist model. A broker who can't is running a commercial model and is missing the FAR-specific work that determines whether the COIs clear and whether the claims pay.

CMMC governs the data posture pre-incident. Cyber insurance funds the response post-incident. Both are required. Neither is the other.

Frequently asked questions

What insurance is required by FAR 52.228?

FAR 52.228 is a series of insurance-related clauses in the Federal Acquisition Regulation. The most commonly invoked are 52.228-3 (workers compensation and war hazard insurance for overseas work), 52.228-4 (vehicle liability insurance for government-owned vehicles), 52.228-5 (insurance required for work on government property), 52.228-7 (insurance for liability to third persons), and 52.228-15 (insurance for performance and payment bonds). Specific limits and forms depend on contract type, agency, and project scope.

Does CMMC certification replace cyber liability insurance?

No. CMMC (Cybersecurity Maturity Model Certification) is a compliance framework that governs the data-handling posture of defense contractors pre-incident. Cyber liability insurance funds the response post-incident. The two serve different functions.

What is the CMMC flow-down problem?

DoD primes are now contractually responsible for CMMC compliance of their subcontractors that handle Controlled Unclassified Information (CUI). When a sub fails CMMC compliance and a CUI exposure event occurs, the prime is in the chain of liability.

Why are federal certificates of insurance getting rejected?

Roughly 45-55% of certificates of insurance submitted to federal contracting officers are rejected on first submission. The rejection reasons are usually not the COI form itself but the underlying contract requirements — additional insured wording, primary-and-noncontributory language, waiver-of-subrogation depth, certificate-holder language.

What does Price-Anderson cover and not cover?

The Price-Anderson Act provides federal indemnification and a liability cap for nuclear incidents at licensed nuclear facilities, primarily for the operator. Contractors working on DOE nuclear sites are sometimes indemnified under the operator's Price-Anderson coverage, but the scope is narrower than many contractors assume.

Is DCAA timekeeping audit covered by insurance?

Insurance generally does not cover DCAA cost disallowance or contract price reductions resulting from timekeeping violations. However, related fraud allegations, False Claims Act exposure, and defense costs of regulatory investigations may be covered depending on policy wording.

What is the SBOM mandate?

Office of Management and Budget memoranda M-22-18 and M-23-16 require federal software suppliers to attest to secure software development practices, including providing Software Bill of Materials documentation. The mandate creates False Claims Act exposure for false or incomplete attestations.

How do I find a good federal contractor insurance broker?

Look for a broker who reads the actual FAR clauses in your contracts, understands the CMMC-vs-cyber distinction, has placed at least one program with Price-Anderson considerations if you do nuclear-adjacent work, and runs a year-round calendar that includes quarterly COI audit and contract flow-down review.

Ryan Mefford, President & Risk Advisor

Want a thirty-minute conversation about your federal contracting program?

No proposal, no submission, no quoting. Strategic Discovery starts with a conversation about your prime contracts, the FAR clauses inside them, and what the program is supposed to be doing.

865-363-2498 RMefford@PeoplesFirstInsurance.com LinkedIn