Department of Veterans
Affairs Acquisition Regulation (VAAR)—Information Security and
Privacy Contract Clauses
Revision of a currently approved collection
No
Regular
03/25/2026
Requested
Previously Approved
36 Months From Approved
03/31/2026
15,384
15,384
4,815
4,815
0
0
VA uses three Department of Veterans
Affairs Acquisition Regulation (VAAR) contract clauses to ensure
security when a contractor has access to VA information or
information systems, as follows: • Clause 852.239-70, Security
Requirements for Information Technology Resources, is required in
all solicitations, contracts and orders exceeding the
micro-purchase threshold that include information technology
services. This clause requires the contractor to be responsible for
information technology security for all systems connected to a VA
network or operated by the contractor for VA, regardless of
location. • Clause 852.239-72, Information System Design and
Development, is required in all solicitations, contracts, orders
and agreements where services to perform information system design
and development are required. • Clause 852.239-73, Information
System Hosting, Operation, Maintenance, or Use, is required in all
solicitations, contracts, orders and agreements where services to
perform information system hosting, operation, or maintenance are
required. Clauses 852.239-72 and 852.239-73 are intended to protect
VA sensitive information and information technology by requiring
contractor and subcontractor personnel to be subject to the same
Federal laws, regulations, standards, and VA directives and
handbooks as VA and VA personnel regarding information and
information system security. This revision changes the title from
“Department of Veterans Affairs Acquisition Regulation Clause
852.239-70, VA Information and Information System Security and
Privacy” to “Department of Veterans Affairs Acquisition Regulation
(VAAR)—Information Security and Privacy Contract Clauses”. The
previous title implied that this OMB Control Number covered a
single clause instead of multiple clauses. The title change is the
only revision to the currently approved collection.
PL:
Pub.L. 113 - 283 2521 Name of Law: Federal Information Security
Modernization Act of 2014
On behalf of this Federal agency, I certify that
the collection of information encompassed by this request complies
with 5 CFR 1320.9 and the related provisions of 5 CFR
1320.8(b)(3).
The following is a summary of the topics, regarding
the proposed collection of information, that the certification
covers:
(i) Why the information is being collected;
(ii) Use of information;
(iii) Burden estimate;
(iv) Nature of response (voluntary, required for a
benefit, or mandatory);
(v) Nature and extent of confidentiality; and
(vi) Need to display currently valid OMB control
number;
If you are unable to certify compliance with any of
these provisions, identify the item by leaving the box unchecked
and explain the reason in the Supporting Statement.
03/25/2026
Something went wrong when
downloading this file. If you have any questions, please send an
email to risc@gsa.gov.