Security Information
SSA-222, Security and Privacy Awareness Training Contractor/Affiliate Personnel Security Certification
This is the certification referenced in the Agency-Specific clause, "Federal Information Security Management Act (FISMA) and Agency Privacy Management." Please refer to the language in the clause for information regarding the completion and retention of this document.
SSA Information Security and General Privacy Requirements (January 2026)
A collection of information security requirements to assist in the standardization of the language, used in the procurements of information technology (IT) products and services.
Agency Specific Clause 2352.204-1, Security and Suitability Requirements (March 2018)
SSA's Cybersecurity Supply Chain Risk Management (CSCRM) Program
Before awarding a contract, all third-party vendors, contractors, original equipment manufacturers (OEMs), and service providers must undergo a cybersecurity supply chain risk assessment (CSCRA) conducted by our agency. This process includes collecting relevant information from third parties through the CSCRA Questionnaire and performing due diligence using specialized tools, such as the agency's Third-Party Cyber Risk Monitoring platform. The assessment determines contractor eligibility and identifies any necessary mitigating controls.
After a contract is awarded, our CSCRM program continues to monitor and manage risks throughout the onboarding process, the duration of the contract, and at contract completion. All third-party relationships are reviewed and tracked using the agency's Third-Party Risk Management system
The CSCRA Questionnaire includes questions that cover the following high-level categories:
- Foreign Ownership, Control, and Influence
- Importing of Products/Parts
- Remote Service, Maintenance, or Support Location
- Non-US Labor
- Cybersecurity Incident History
- Cybersecurity Programs
- Counterfeit Incident History
- Current Economic Status/Business Reputation
- Executive Background