Skip to main content

CMMC Pause: What DoW & Primes Still Require

  • blog
  • The FAR CUI Rule: What the June 2026 Proposed Rule Means for Federal Contractors

The FAR CUI Rule: What the June 2026 Proposed Rule Means for Federal Contractors

  • August 12, 2026
Author

Anna Fitzgerald

Senior Content Marketing Manager

Reviewer

Rob Gutierrez

Senior Cybersecurity and Compliance Manager, CISA, CCSK, CMMC RP

While most contractors are focused on the DoW’s next announcement about the CMMC phased rollout, they should also be focused on the Federal Acquisition Regulatory (FAR) Council’s next move with another landmark regulation.

First proposed in January 2025, the FAR CUI rule would extend requirements for safeguarding Controlled Unclassified Information (CUI) and incident reporting to nearly every federal contractor and subcontractor, not just defense ones. On June 23, 2026, it was re-proposed as part of the Revolutionary FAR Overhaul and public comments closed last month.

This rule marks a significant step toward standardizing how CUI is handled across the entire federal supply chain. Given this rule’s far-reaching impact, it’s important that you understand its requirements, history, and current timeline, all covered below.

Key takeaways about the FAR CUI Rule

  • First proposed in January 2025, the FAR CUI rule was re-proposed with changes on June 23, 2026 as part of the Revolutionary FAR Overhaul.
  • The 30-day comment period closed July 23, 2026 with 96 comments received, and the rule now awaits finalization.
  • The new proposal relocates all requirements to a consolidated and expanded FAR Part 40, and adds the new provision FAR 52.240-6, Notice of Controlled Unclassified Information Requirements (the solicitation provision) and new clause FAR 52.240-7, Controlled Unclassified Information.
  • It would establish the cybersecurity baseline as NIST SP 800-171 Revision 3 for civilian contracts involving CUI. DFARS 252.204-7012 and CMMC still reference Revision 2.
  • It would change the incident reporting timeline from 8 hours to 72 hours to align with existing DFARS requirements and all Part 40 security requirements.
  • It would require the procuring agency to complete a new Standard Form (SF XXX, Controlled Unclassified Information Requirements) to identify the CUI involved in a given contract.
  • The rule is still a proposal and can change before it is final, but contractors should use this time before finalization to prepare and enhance their cybersecurity program.
  • The CMMC Phase 2 pause did not impact the proposed FAR CUI rule or existing obligations for CUI handling and incident reporting for defense contractors.

What is the FAR CUI rule?

The FAR CUI Rule is a proposed regulation that establishes uniform requirements for the protection of CUI across all federal executive branch contracts.

Under the most recent proposed rule on June 23, 2026, contractors handling CUI would be required to:

  • Meet the security requirements of NIST SP 800-171 Revision 3
  • Report any CUI incidents within 72 hours of discovery
  • Flow down requirements to subcontractors that will receive CUI

Previously, only the DoW had mandated CUI safeguarding and reporting requirements for defense contractors via DFARS 252.204–7012. No similar uniform requirements existed across other federal agencies because the FAR does not presently cover CUI. Only federal contract information (FCI) is protected under FAR 52.204-21 (renumbered FAR 52.240-5 as part of the FAR overhaul), which requires contractors to apply 15 basic safeguarding requirements and procedures to protect covered contractor information systems.

In the absence of a government-wide rule, federal agencies have employed different policies to manage CUI on an ad hoc basis, resulting in agencies marking and handling information inconsistently and inefficiently and contractors not realizing that they are handling confidential information that requires safeguarding.

In response to increasingly sophisticated and frequent cyber attacks targeting the federal government and larger supply chain, the FAR Council has led the development of the proposed FAR CUI rule.

A note on naming: The Department is now commonly referred to by its official secondary title, the Department of War (DoW). Because existing CMMC rules, contract clauses, and source documents still read "Department of Defense (DoD)," we continue to use this statutory name or "the Department” as well as the secondary title.

What are the requirements of the FAR CUI rule?

The requirements of the most recent version of the FAR CUI rule proposed on June 23, 2026 are outlined below.

RequirementWhat it means
CUI identification via SF XXXThe contracting officer completes a Standard Form (SF XXX, Controlled Unclassified Information Requirements) that identifies whether CUI is involved, which categories apply, and where it will reside (federally controlled or non-federally controlled facilities). The contractor safeguards only what the form identifies.
NIST SP 800-171 Revision 3Contractor information systems that handle CUI must meet the Revision 3 security requirements, and apply the organization-defined parameters (ODPs) defined by the DoD for the applicable requirements.
NIST SP 800-172For contracts involving critical programs or high-value assets, agencies may add enhanced controls from NIST SP 800-172.
72-hour incident reportingReport CUI incidents within 72 hours of discovery, using a tiered approach: submit the data elements available at the time of the initial report, then supplemental reports as the investigation progresses. Reports go to DIBNet for DoD contracts and to CISA for non-DoD contracts, with a notification to the contracting officer. If a FedRAMP authorized cloud provider already reported the incident under FedRAMP procedures, no additional report is required.
Cloud servicesA cloud service provider handling CUI must meet security requirements equivalent to the FedRAMP Moderate baseline, plus the additional requirements specified in the clause.
Subcontractor flowdownThe prime includes the substance of the clause in subcontracts where the subcontractor handles CUI. Subcontractors report incidents directly to the government and notify the contracting officer and next higher-tier contractor.
TrainingEmployees who handle CUI complete the training identified on the SF XXX. The blanket, one-size-fits-all training mandate from the January 2025 version was removed.
Gap disclosure at proposalAn offeror that cannot meet all requirements when it submits a proposal must include a disclosure as part of their offer identifying the gaps and a plan of action and milestones (POA\&M) for remediating them.
Validation by self-attestationThe rule relies on “normal contract administration procedures for validating compliance,” i.e. the contractor implementing the requirements and effectively self-attesting to compliance by signing the contract.

Recommended reading

What Is Controlled Unclassified Information (CUI)?

What changed from the January 2025 proposal?

The most recent version of the FAR CUI rule was proposed on June 23, 2026 as part of the Revolutionary FAR Overhaul (FAR Case 2026-001, 91 FR 37550), the government-wide rewrite of the FAR directed by Executive Order 14275, "Restoring Common Sense to Federal Procurement."

This revision responds to public comments on the January 2025 rule and makes several substantive changes, outlined below.

ElementJanuary 2025 proposalJune 2026 revised proposal
Location in the FARPart 4Consolidated into Part 40
NIST 800-171 baselineRevision 2Revision 3, with ODPs applied
Incident reporting window8 hours72 hours
Provision and clauses52.204-WW (solicitation notice), 52.204-XX (CUI obligations), 52.204-YY (potentially CUI)52.240-6 (solicitation notice), 52.240-7 (CUI obligations); the 52.204-YY clause was deleted
"CUI incident" definitionBroader, including suspected eventsNarrowed to unauthorized disclosure, improper modification, improper destruction, or unauthorized system access. Unmarked or mismarked CUI alone is not an incident
Contractor liability for CUI incidentsExplicit language specifying liability for CUI incidentsRemoved
Cloud service requirementsFedRAMP Moderate AuthorizationFedRAMP Moderate equivalency
TrainingBlanket “one-size-fits all” training framework before handling CUIA more flexible, tailored program based on what’s specified per contract on the SF XXX
Government validation actionsCooperate if agency requests access to contractor’s SSP or its facilities, systems, and personnel to verify complianceRemoved

The deleted clause is worth a deeper explanation. FAR 52.204-YY would have imposed reporting obligations even on contracts where no CUI was identified. Removing it was a response to industry concerns about open-ended duties raised during the public comment period for the January 2025 version. A narrower obligation remains in the most recent proposed rule: contractors must notify the contracting officer of unmarked or mismarked CUI they encounter within 72 hours.

The takeaway: Most of these changes in the June 2026 FAR CUI update ease specific burdens (a longer reporting clock, fewer clauses, narrower training requirements), while one raises the bar (NIST 800-171 Revision 3). That means the new proposed rule is more achievable and more demanding at the same time.

Recommended reading

NIST 800-171 Compliance: How to Comply with the Latest Revision [+ Checklist]

What’s the history of the FAR CUI rule?

The FAR CUI Rule has been years in the making. Its origins can be traced back to Executive Order 13556.

2010

Issued in 2010, EO 13556 established a government-wide CUI program. The EO aimed to standardize how executive agencies handle sensitive unclassified information, addressing inconsistencies in protection and labeling.

However, the EO did not actually implement the CUI program so contractors continued to be uncertain what their obligations were, particularly when working with multiple agencies that had different safeguarding and reporting standards. This left contractors vulnerable to potential liability and the entire federal supply chain vulnerable to cybersecurity risk.

2015

In 2015, NIST 800-171 was introduced as a stop-gap measure. This framework provided baseline security requirements for protecting CUI in non-federal systems.

2016

In 2016, National Archives and Records Administration (NARA) published a final rule to implement the CUI requirements of EO 13556, but it still did not incorporate those requirements into the federal acquisition process.

This same year, the Department of Defense adopted the CUI requirements through DFARS 252.204-7012, which required defense contractors to implement NIST 800-171 Revision 2 and report cybersecurity incidents and went into effect on October 21, 2016. These CUI requirements did not extend to other federal contractors, however.

2017

Full implementation of NIST 800-171 was required under DFARS 7012 by December 31, 2017.

That same year, the DoD, GSA, and NASA first proposed to amend the FAR to ensure uniform implementation of the requirements of the CUI program of Executive Order 13556 in contracts across the government (FAR Case 2017-016).

2025

In January 2025, the FAR Council published the first proposed FAR CUI rule to make CUI protection mandatory across all federal contracts, and collected public comments.

2026

On June 23, 2026, it re-proposed the rule as part of the Revolutionary FAR Overhaul, reopening comment through July 23, 2026. This public comment period closed with 96 comments received.

When does the FAR CUI rule take effect?

The rule is not final, and there is no effective date yet. The FAR Council re-proposed it on June 23, 2026 and ran a 30-day comment period that closed July 23, 2026. Nearly 100 comments were received that will inform the final rule.

The Council has said it intends to finalize the Revolutionary FAR Overhaul rules, including the FAR CUI Rule requirements, before the end of 2026. While the turnaround would have to be fast, this timeline is still possible because the comment period was short and the rule does not set a phase-in period.

Once finalized, agencies will insert the new FAR Part 40 clauses into contracts, and contractors handling CUI will need to comply as soon as the clauses appear. That is why the smart move is to start identifying and closing gaps to the NIST 800-171 and incident reporting requirements now rather than waiting for the final publication.

Does the CMMC Phase 2 pause affect the FAR CUI rule timeline?

No. The CMMC Phase 2 pause does not technically affect the FAR CUI rule's timeline. They are separate regulations developed and enforced by different bodies for different types of contractors.

CMMC is an assessment framework for defense contractors that completed its own rulemaking processes and went into effect starting on November 10, 2026. On July 13, 2026, its rollout was paused and the program put under review by the DoW, with public comments accepted through a public Request for Information until August 14, 2026. During the pause, CMMC Level 1 and Level 2 self-assessment requirements remain in effect, which add an additional layer of verification through SPRS scores and annual affirmations that must be verified by DoW contracting officers and primes prior to award.

The FAR CUI rule is a proposed rule by the FAR Council in a later stage of its own rulemaking process, with its most recent comment period closed on July 23, 2026 and finalization targeted by the end of 2026.

While they are separate regulations with distinct rulemaking and implementation timelines, the FAR CUI Rule and CMMC are closely intertwined and moving closer to each other.

The ODP values for NIST 800-171 Rev 3 that the latest proposed FAR CUI rule points to were defined by the Department. While CMMC currently assesses against NIST 800-171 Revision 2 and Class Deviation 2024-O0013 aligns DFARS 7012 with Rev 2, both will eventually transition to Rev 3. That way, the same cybersecurity baseline will apply to all federal contractors handling CUI.

Set side by side, here’s how the two CUI frameworks for civilian and defense contractors track:

Civilian contracts (proposed FAR CUI rule)Defense contracts (CMMC)
Governing authorityFAR Part 40 (proposed)32 CFR Part 170, 48 CFR Part 204
NIST 800-171 baselineRevision 3 with DoW-specified ODP valuesRevision 2 for now
Incident reporting72 hours72 hours
VerificationSelf-attestation validated through normal contract administration (no third-party or government-led assessments)Self-assessment results, scores, and affirmations signed by named senior executive required in SPRS (third-party and DIBCAC assessment requirements currently on hold)
Current statusProposed and awaiting finalizationDFARS 7012 and CMMC Phase 1 self-assessment requirements in effect, but CMMC Phase 2 paused and program in review

Right now, both tracks run on self-attestation and self-assessment rather than third-party certification, which makes implementing the underlying cybersecurity standard the immediate priority.

The best way for contractors to prepare for what’s next is to focus on identifying and closing gaps in their NIST 800-171 implementation. For civilian contractors, that means Rev 3. For defense contractors, that means Rev 2 but use the DoW-defined ODP values for your NIST 800-171 Revision 2 configurations when possible. That will future-proof your program once DFARS 7012 and CMMC align with Rev 3.

Recommended reading

Who Needs CMMC? Defense Contractor Requirements in 2026

How to prepare for the FAR CUI rule now

The most useful thing any contractor can do is implement NIST SP 800-171, because it is the common denominator across the FAR CUI rule, DFARS 7012, and CMMC. Preparation does not depend on the final rule text. Start here:

  1. Run a gap analysis against NIST SP 800-171 Rev 3. Establish where your systems stand today against the requirements. This is the single most consequential step, and it applies no matter which revision your contracts ultimately reference.
  2. Build and maintain your System Security Plan (SSP). The rule ties disclosure at proposal to a POA&M, so an accurate SSP and a live POA&M are foundational.
  3. Scope where CUI lives, especially in the cloud. Identify every system that stores, processes, or transmits CUI, and confirm your cloud services meet the FedRAMP Moderate bar the rule sets.
  4. Stand up 72-hour incident reporting. Make sure you can detect, triage, and report a CUI incident within the window, with a tiered initial-plus-supplemental process.
  5. Prepare subcontractor flowdown. Map which subcontractors handle CUI and get the flowdown and notification path in place before it is contractually required.
  6. Plan for two NIST baselines if you serve both markets. Contractors with both defense and civilian customers may need to satisfy Revision 2 (through DFARS 7012 and CMMC) and Revision 3 (under the proposed FAR rule) at the same time. Map which systems and contracts fall under each, and build to the higher bar where they overlap.

NIST 800-171 Rev 2 vs Rev 3 Change Analysis Summary

We mapped all 17 control families across NIST 800-171 Rev 2 and Rev 3 to count up total requirements, significant changes, new ODPs, new and withdrawn requirements. Get this overview in a free downloadable spreadsheet.

Preparing for the future of federal contract compliance

Whether your contracts run through a civilian agency or the defense supply chain, the work is similar: protect CUI to the NIST SP 800-171 standard and keep the evidence and documentation current. That is what earns and keeps a contract and what protects the sensitive information behind it.

Secureframe Defense helps contractors reduce the cost and complexity of implementing and maintaining these requirements by:

  • Mapping your existing controls, policies, and procedures to either NIST 800-171 Rev 2 and Rev 3 to identify gaps
  • Generating remediation guidance to close those gaps with Comply AI
  • Isolating CUI in a secure cloud environment in either Microsoft GCC High or Google Workspace and accessing it through compliant devices only
  • Automatically generating and keeping your SSP and POA&M continuously up to date based on your actual posture.
  • Automatically calculating and updating your readiness percentage or SPRS score based on control implementation
  • Continuously collecting configuration evidence via automated tests
  • Monitoring drift and sending alerts to ensure you maintain a strong cybersecurity posture
  • Providing expert guidance from former federal auditors who understand the technical complexities of NIST 800-171 requirements

With Secureframe Defense, you can get and prove you’re capable of protecting sensitive unclassified government information and stay ready for any FAR, DFARS, or CMMC requirements that appear in your contracts.

Talk to an expert to see how we can help federal contractors reduce the cost and complexity of meeting and maintaining cybersecurity requirements for CUI.

This post was originally published in June 2025 and has been updated for accuracy and comprehensiveness.

Get secure. Stay compliant.

Talk to an expert

FAQs

Does the FAR CUI rule require NIST 800-171 Revision 2 or Revision 3?

The June 2026 proposed FAR CUI rule requires Revision 3 for contractor systems that handle CUI. This differs from DFARS 252.204-7012 and CMMC, which still reference Revision 2. Moving DoD's own requirements to Revision 3 would take a separate rulemaking.

What changed between the January 2025 and June 2026 versions?

The revised rule moved the requirements into a consolidated FAR Part 40, raised the baseline from Revision 2 to Revision 3, changed incident reporting from 8 hours to 72 hours, deleted the standalone clause for reporting potentially CUI (former FAR 52.204-YY), narrowed the definition of a CUI incident, and replaced the blanket training mandate with training specified on the SF XXX.

Is FedRAMP Moderate Authorization required for cloud providers under the FAR CUI rule?

Under the June 2026 proposed rule, cloud services that handle CUI must meet security requirements equivalent to the FedRAMP Moderate baseline, plus the additional requirements specified in the clause. The rule does not require a full FedRAMP Moderate authorization, so review the clause to confirm what "equivalent to" means for your contract.

Who does the FAR CUI rule apply to?

It is written to reach nearly all federal contractors and subcontractors, civilian and defense, whenever a contract identifies CUI on the SF XXX. Acquisitions solely for commercially available off-the-shelf (COTS) items are excluded.

Does the CMMC Phase 2 pause change the FAR CUI rule?

No. The CMMC pause is a Department of War action affecting defense certification. It does not touch the civilian FAR CUI rule, and it does not remove existing obligations under DFARS 252.204-7012 or NIST SP 800-171. For defense contractors, self-assessments, SPRS scores, annual affirmations, and prime flowdown all continue.

Do contractors have to meet both NIST 800-171 Revision 2 and Revision 3?

Possibly, if you serve both defense and civilian customers. DFARS 252.204-7012 and CMMC reference Revision 2, while the proposed FAR CUI rule references Revision 3. A contractor with both types of contracts could need to satisfy both until the frameworks align.

When were comments due, and when will the rule be final?

The latest comment period closed on July 23, 2026, with 96 comments received. The FAR Council intends to finalize the Revolutionary FAR Overhaul rules, including CUI, before the end of 2026. Given the short comment window, a relatively quick finalization is possible, though the timeline can still move.

Anna Fitzgerald

Senior Content Marketing Manager

Anna Fitzgerald is a digital and product marketing professional with nearly a decade of experience delivering high-quality content across highly regulated and technical industries, including healthcare, web development, and cybersecurity compliance. At Secureframe, she specializes in translating complex regulatory frameworks—such as CMMC, FedRAMP, NIST, and SOC 2—into practical resources that help organizations of all sizes and maturity levels meet evolving compliance requirements and improve their overall risk management strategy.

Rob Gutierrez

Senior Cybersecurity and Compliance Manager, CISA, CCSK, CMMC RP

Rob Gutierrez is an information security leader with nearly a decade of experience in GRC, IT audit, cybersecurity, FedRAMP, cloud, and supply chain assessments. As a former auditor and security consultant, Rob performed and managed CMMC, FedRAMP, FISMA, and other security and regulatory audits. At Secureframe, he’s helped hundreds of customers achieve compliance with federal and commercial frameworks, including NIST 800-171, NIST 800-53, FedRAMP, CMMC, SOC 2, and ISO 27001.