Cybersecurity requirements for contractors have been a patchwork — DoD had CMMC, GSA rolled out its own framework, and agencies improvised. Now the government is trying to set one standard for everyone. On June 23, 2026, the FAR Council proposed a rule — part of the Revolutionary FAR Overhaul — establishing governmentwide obligations for handling Controlled Unclassified Information (CUI) and reporting CUI incidents (Akin, 2026; Wiley, 2026).
What the rule does
The proposed rule moves CUI requirements into the new FAR Part 40 framework, implemented through a new provision (FAR 52.240-6, Notice of CUI Requirements) and clause (FAR 52.240-7, Controlled Unclassified Information) (Government Contracts Navigator, 2026). For contractors, two obligations stand out: your information systems that handle CUI must meet the NIST security standard, and you must report any CUI incident within 72 hours of discovery (Wiley, 2026).
Why this reaches almost everyone
CUI isn’t just defense secrets. It includes personally identifiable information, procurement-sensitive and source-selection data, and proprietary information held on the government’s behalf — categories that touch a huge share of federal contracts. Standardizing the rule across the FAR strengthens the government’s ability to enforce it, in an area the Department of Justice is already pursuing: DOJ has recovered more than $80 million in cybersecurity-related False Claims Act settlements since October 2021 (Akin, 2026). Getting CUI wrong isn’t just a security problem — it’s a false-claims exposure.
What to do now
- Know where your CUI lives. Map which systems store, process, or transmit CUI — you can’t protect what you can’t see.
- Align to the NIST standard now, not when a solicitation forces it; the same baseline underpins CMMC and the GSA framework.
- Build a 72-hour incident-reporting process — who detects, who decides, who reports — before you ever need it.
- Keep your representations accurate. With DOJ active, an inaccurate security attestation is a real liability.
The direction is unmistakable: one CUI standard, enforced harder. The firms that build the muscle now won’t scramble when the clause lands in their next award. Brick by brick.
FAQ
Is this the same thing as CMMC?
Related but not identical. CMMC is DoD’s verification mechanism (currently on pause at Phase 2); this FAR rule sets governmentwide CUI handling and reporting obligations. Both build on the same NIST standard (Government Contracts Navigator, 2026).
Is the rule final?
No — it’s a proposed rule with a public comment period that closed July 23, 2026. Expect a final rule to follow, so preparing now is prudent (Akin, 2026).
Sources
Akin Gump Strauss Hauer & Feld LLP. (2026, June 25). Proposed rule on CUI and CUI incident reporting would create new requirements and risks for contractors.
Government Contracts Navigator. (2026, July 21). CUI, FOCI, quantum, and CMMC: The federal government issues a wave of proposed rules.
Wiley Rein LLP. (2026, July). FAR Council proposes revised CUI framework as part of Revolutionary FAR Overhaul.
Need help mapping your CUI and building a reporting process? That’s the kind of readiness we help with. Explore GovCon iSource.