The Federal Acquisition Regulatory (FAR) Council has published a proposed rule (FAR Case 2026-001) which, if adopted, would require all federal contractors to implement the cybersecurity requirements contained in the National Institute of Technology and Standards Special Publication 800-171 (NIST 800-171), Revision 3 for any systems that contain Controlled Unclassified Information (CUI).
The deadline for comments is July 23, 2026.
The proposed rule is part of the Revolutionary Federal Acquisition Regulation Overhaul (RFO) and is intended to align FAR requirements with the National Archives and Records Administration (NARA) CUI program and the NIST cybersecurity standards.
Applicability of the Rule
- Very Broad Coverage Across Federal Contracts
The proposed rule would apply to federal contracts and subcontracts involving CUI, regardless of contract value, including many commercial-item acquisitions. Contracts solely for commercially available off-the-shelf (COTS) products generally would remain exempt, but many service and support contracts would be covered if CUI is involved. This broad application could cause significant costs and compliance risks to several contractors and subcontractors that have not yet been subjected to these requirements.
- Government-Wide Definition of CUI
The rule adopts a standardized definition of CUI as information that the Government creates or possesses, or that an entity creates or possesses for or on behalf of the Government, which requires safeguarding or dissemination controls pursuant to law, regulation, or government-wide policy. The definition excludes classified information and information that is otherwise publicly available or outside the scope of the CUI program.
- Use of a New Contract-Specific Form
Agencies would identify applicable CUI and any special handling requirements through a new Standard Form. This form would communicate the CUI requirements for each contract, such as contractor marking responsibilities.
Contractors’ CUI Obligations: Implementation of NIST SP 800-171
Under the proposed rule, contractors would be required to adopt security standards from NIST SP 800-171 Revision 3. Agencies could also impose additional safeguards for a “critical program or high-value asset” through contract requirements and the new Standard Form.
- Potential CMMC Compliance Implications
The proposed rule’s adoption of NIST SP 800-171 Rev. 3 is significant because the current Cybersecurity Maturity Model Certification (CMMC) Program related to Department of Defense contracts utilizes security standards from Revision 2 of NIST SP 800-171. Defense contractors subject to CMMC requirements should pay close attention to the differences between Revisions 2 and 3 for NIST SP 800-171, as compliance under one may not lead to compliance under the other. Revision 3 places a stronger emphasis on supply chain risk management, continuous monitoring, multi-factor authentication and identity assurance, and consolidation of controls categories. Revision 3 has 95 controls, while Revision 2 has 110; however, contractors should not assume that Rev. 3 is easier to comply with or has more relaxed requirements.
- Cloud Service Provider Requirements
Any cloud environments used to process, store, or transmit CUI must meet FedRAMP Moderate baseline requirements and any additional requirements under NIST SP 800-171’s Enhanced Security Requirements for Protecting CUI.
- Marking and Safeguarding CUI, and Employee Training
In addition to safeguarding marked CUI, if a contractor encounters information that appears to be CUI but lacks proper markings, the contractor would still be expected to protect the information and notify the contracting officer within 72 hours. The proposal also contemplates contractors training employees so they can identify and appropriately safeguard CUI during contract performance.
Incident Response Obligations
- Mandatory Reporting of CUI Incidents within 72 Hours.
Contractors would be required to report a CUI incident within 72 hours of discovery. The rule broadly defines reportable incidents to include unauthorized access, disclosure, modification, or destruction of CUI, as well as compromises affecting information systems containing CUI. Subcontractors who experience a CUI incident would have to report directly to the contracting office and to the next-higher tier contractor as well.
- Documentation, Preservation, and Supplemental Reporting.
After a CUI incident, contractors would be expected to determine the CUI involved in the incident and how it was accessed, while also constructing a timeline of user activity. Contractors would be required to preserve system images and monitoring and packet capture data until the government declines interest in such data or until at least 90 days from the date of the report. Initial reports may be supplemented as additional facts become known.
- Incident Occurrence Does Not Automatically Establish Noncompliance.
Compliance determinations would depend on the facts and circumstances revealed in a subsequent investigation—the report of a CUI incident would not, by itself, mean that a prime or subcontractor failed to adequately safeguard CUI.
Key Takeaways
- Comments to the Proposed Rule Must Be Submitted by July 23, 2026.
Similar to other RFO publications, the proposed rule has a quick comment period. All comments must be submitted by July 23, 2026. Federal contractors and subcontractors would be wise to review closely the proposed rule and to submit any comments before the expiration date.
- Be Prepared to Comply with NIST SP 800-171 Rev. 3 Controls.
The proposal seeks to replace inconsistent agency-specific approaches with a uniform FAR framework rooted in NARA’s CUI program and NIST cybersecurity standards from NIST SP 800-171 Rev. 3. Contractors who may also have defense contracts should carefully map out the differences between Rev. 2 and Rev. 3 to identify overlaps and gaps in compliance.
- The New Clauses and Standard Form Will Be Critical.
Contractors should pay close attention to the proposed FAR clauses (FAR 52.240-6 and FAR 52.240-7) and the new SF XXX form, as those provisions will define the specific CUI subject to protection and any additional requirements.
- Incident Response Plans Should Be Reviewed Now.
Organizations handling CUI should assess whether current procedures can support the proposed 72-hour reporting deadline and associated evidence-preservation obligations.
- Subcontractor Compliance Will Remain a Key Focus.
Prime contractors should evaluate subcontract management processes to ensure appropriate CUI requirements are flowed down and that subcontractors understand their independent compliance and reporting responsibilities.
Conclusion
The FAR Council’s proposed rule would create a comprehensive regime governing the protection of CUI by federal contractors and subcontractors that would greatly expand existing requirements. By incorporating NIST SP 800-171 Rev. 3 requirements, establishing uniform reporting obligations, and introducing new contract clauses and the Standard Form, the proposal would significantly expand CUI compliance obligations across the federal marketplace. Contractors should review the proposed requirements carefully, evaluate existing cybersecurity practices and incident-response programs, and prepare for significant implementation efforts if the rule is finalized.
Womble Bond Dickinson’s Government Contracting and Privacy and Security teams have highly talented lawyers who have extensive experience assisting federal contractors with their cyber security compliance and reporting needs, including the analysis of applicable regulations, handling cyber security incidents, addressing voluntary and mandatory disclosures, and government contracts disputes. If you have any questions about this client alert or federal contract cybersecurity requirements, please contact Matt Delfino, Josh Mullen, Tyler Bridegan, or your regular Womble Bond Dickinson attorney.
Also, click here to read “FAR Council Launches “Revolutionary” Overhaul: What Contractors Should Watch”.