A defense contract is a legally binding agreement between a government entity and a private company to supply products, technology, or services related to national security and defense. In the United States these are issued largely by the Department of Defense, and they come with strings that pure commercial contracts do not: cybersecurity clauses that dictate how the contractor has to protect government information.
What is a defense contract?
At its core it is procurement: the government buys hardware, software, research, or support, and the contractor delivers under agreed specifications, schedule, and price. What sets a defense contract apart is the regulatory weight attached. The terms reference the Federal Acquisition Regulation (FAR) and its defense supplement (DFARS), and increasingly they require the contractor to prove it can safeguard sensitive data before the work even starts.
What cybersecurity requirements come with a defense contract?
Most of the security obligation traces back to one thing: Controlled Unclassified Information, or CUI, the sensitive-but-unclassified data a contractor handles on the DoD's behalf. Protecting it means meeting specific standards:
- NIST SP 800-171 defines 110 security requirements for protecting CUI in non-federal systems. DFARS clause 252.204-7012 has required compliance for years. See NIST SP 800-171.
- CMMC (Cybersecurity Maturity Model Certification) adds third-party verification on top. Under the CMMC 2.0 rule finalized in 2024, contractors handling CUI must reach Level 2 and, for many, pass an assessment by a C3PAO rather than self-attest. See CMMC.
- IEC 62443 governs industrial automation security and matters wherever a contract touches OT or manufacturing systems.
Why do defense contract security rules reach the OT network?
Because a growing share of defense work happens on a shop floor. Contractors machine parts, run assembly lines, and test systems on networks that mix IT with operational technology. CUI does not stay in email and file shares. It lands on the machines that cut the metal. When it does, those OT systems fall inside the compliance boundary, and the same access control, segmentation, and logging requirements apply to a CNC controller as to a laptop. That is why so many manufacturers discover, mid-CMMC-prep, that their plant network is in scope.
How is a defense contract different from a commercial contract?
A commercial contract is governed by ordinary contract law and whatever security terms the parties negotiate. A defense contract layers on federal acquisition regulation, mandatory security baselines, flow-down obligations that push requirements onto subcontractors, and audit or certification gates that can decide whether you are even eligible to bid. Security is not a nice-to-have clause. It is a condition of award.
Trout's focus is narrow but relevant here: when a defense contract puts CUI on your OT network, the access control and segmentation that CMMC and NIST SP 800-171 ask for is exactly what an agent-free Zero Trust overlay is built to deliver. See Defense and government contracting.

