Proposed FAR CUI rule would extend NIST SP 800-171 Rev. 3 government-wide

On June 23, 2026, the Federal Acquisition Regulatory (FAR) Council published a proposed rule under FAR Case 2026-001 (91 FR 37550). Inside the broader Revolutionary FAR Overhaul package is a government-wide approach to Controlled Unclassified Information (CUI) for contractors.

The comment window closed on July 23, 2026. The proposal is not final yet, but the direction is clear: CUI safeguarding would no longer be mainly a defense-contract story.

What the proposal would require

For contractor (non-federal) systems that handle CUI, the draft clause at FAR 52.240-7 would require compliance with NIST SP 800-171 Revision 3, plus any organization-defined parameters the government identifies. Some contracts tied to critical programs or high-value assets could also pull in enhanced controls from NIST SP 800-172.

Other pieces that matter in practice:

  • A standardized form (SF XXX) to tell contractors what CUI is in play and how it must be marked and protected
  • Flow-down of safeguarding and reporting duties to subcontractors that receive CUI
  • A 72-hour window to report CUI incidents (and certain marking or compliance problems) to the contracting officer
  • Cloud services used to store, process, or transmit CUI would need to meet at least the FedRAMP Moderate baseline (or equivalent)
  • When contractors operate on federal systems, the proposal points to agency-identified NIST SP 800-53 requirements

Offerors that cannot meet every applicable requirement at proposal time would need to disclose gaps and include a plan of action and milestones.

How this relates to CMMC

DoD Cybersecurity Maturity Model Certification (CMMC) Level 2 still tracks NIST SP 800-171 Revision 2 for Phase 1 self-assessments while Phase 2 third-party assessments are paused. This FAR proposal would put Revision 3 into civilian (and broader FAR) contracts. Organizations that work both defense and civilian federal business may eventually need to track both baselines until the programs align.

What to do now

  1. Confirm whether your contracts (or upcoming bids) identify CUI. If they will, map your current controls to NIST SP 800-171 Rev. 3.
  2. Inventory cloud providers that touch CUI and check FedRAMP Moderate (or equivalent) status.
  3. Update incident-response playbooks for a 72-hour contracting-officer notice path, separate from any cyber insurance or customer SLAs.
  4. See the NIST SP 800-171 page for which revision your current contracts require and how assessments work.
  5. Follow NIST SP 800-171 on this site for the final rule and any transition language.

#program-changes#version-updates

← Back to news