Proposed FAR CUI rule would extend NIST SP 800-171 Rev. 3 government-wide
On June 23, 2026, the Federal Acquisition Regulatory (FAR) Council published a proposed rule under FAR Case 2026-001 (91 FR 37550). Inside the broader Revolutionary FAR Overhaul package is a government-wide approach to Controlled Unclassified Information (CUI) for contractors.
The comment window closed on July 23, 2026. The proposal is not final yet, but the direction is clear: CUI safeguarding would no longer be mainly a defense-contract story.
What the proposal would require
For contractor (non-federal) systems that handle CUI, the draft clause at FAR 52.240-7 would require compliance with NIST SP 800-171 Revision 3, plus any organization-defined parameters the government identifies. Some contracts tied to critical programs or high-value assets could also pull in enhanced controls from NIST SP 800-172.
Other pieces that matter in practice:
- A standardized form (SF XXX) to tell contractors what CUI is in play and how it must be marked and protected
- Flow-down of safeguarding and reporting duties to subcontractors that receive CUI
- A 72-hour window to report CUI incidents (and certain marking or compliance problems) to the contracting officer
- Cloud services used to store, process, or transmit CUI would need to meet at least the FedRAMP Moderate baseline (or equivalent)
- When contractors operate on federal systems, the proposal points to agency-identified NIST SP 800-53 requirements
Offerors that cannot meet every applicable requirement at proposal time would need to disclose gaps and include a plan of action and milestones.
How this relates to CMMC
DoD Cybersecurity Maturity Model Certification (CMMC) Level 2 still tracks NIST SP 800-171 Revision 2 for Phase 1 self-assessments while Phase 2 third-party assessments are paused. This FAR proposal would put Revision 3 into civilian (and broader FAR) contracts. Organizations that work both defense and civilian federal business may eventually need to track both baselines until the programs align.
What to do now
- Confirm whether your contracts (or upcoming bids) identify CUI. If they will, map your current controls to NIST SP 800-171 Rev. 3.
- Inventory cloud providers that touch CUI and check FedRAMP Moderate (or equivalent) status.
- Update incident-response playbooks for a 72-hour contracting-officer notice path, separate from any cyber insurance or customer SLAs.
- See the NIST SP 800-171 page for which revision your current contracts require and how assessments work.
- Follow NIST SP 800-171 on this site for the final rule and any transition language.
Sources
- FAR Case 2026-001 proposed rule (91 FR 37550) (June 23, 2026)