The FAR Council has moved its long-pending Controlled Unclassified Information (CUI) safeguarding rule into formal notice-and-comment rulemaking, folding it into the "Revolutionary FAR Overhaul" and extending cybersecurity obligations that once sat almost entirely inside the Defense Department to the entire federal contracting base. The proposed rule, published in the Federal Register on June 23, 2026, revises FAR Parts 1, 2, 4, 33, 39, 40, and 53 and consolidates supply-chain, prohibition, and CUI-safeguarding requirements under a new FAR Part 40 security construct. Comments are due July 23, 2026.

Background

Federal agencies have handled CUI unevenly for years. The Defense Department built out a detailed regime through DFARS 252.204-7012, NIST SP 800-171, and the Cybersecurity Maturity Model Certification program, but civilian agencies never had an equivalent government-wide clause. A CUI rule to close that gap was first proposed in January 2025, then stalled. The FAR Overhaul revives it as a "second opportunity to comment," reopening the public comment period rather than advancing the earlier proposal unchanged — and the revised text differs from the 2025 version in several important respects.

The rule sits inside a broader restructuring. On June 23 the FAR Council initiated formal rulemaking for the Revolutionary FAR Overhaul, the procurement rewrite launched by Executive Order 14275, "Restoring Common Sense to Federal Procurement," which is rewriting large sections of the FAR. The CUI package is the security-focused piece: it builds the new Part 40 to house supply-chain risk management, source prohibitions, and information-safeguarding requirements in one place, giving civilian agencies a standardized cybersecurity clause for the first time.

Key Details

The proposed rule requires contractors that handle CUI on non-federal systems to implement the security controls in NIST SP 800-171, and the revised text points to Revision 3 of that standard — a newer control set than the Revision 2 baseline the Defense Department currently applies through a class deviation. The rule also clarifies that organizationally defined parameters (ODPs) supplied by DoD would apply where relevant, giving contractors a concrete set of expectations rather than open-ended discretion.

The most closely watched change is to incident reporting. The original 2025 proposal would have required contractors to report suspected or confirmed CUI incidents within eight hours of discovery — an aggressive window that drew industry objections. The revised rule extends that timeline to 72 hours from discovery, aligning it with the reporting cadence contractors already know from DFARS 252.204-7012 and the Cyber Incident Reporting for Critical Infrastructure Act of 2022. Incidents involving cloud environments authorized through FedRAMP would follow separate FedRAMP reporting procedures rather than the new clause.

The revised rule also drops an obligation that appeared in the earlier version. The Council removed the requirement that contractors notify the government when information appears to be unmarked or mismarked CUI, deleting the associated clause. That change lifts a classification-judgment burden the 2025 proposal would have pushed onto contractors, though the Council has signaled it may revisit the question through comments.

The scope is the headline. Unlike DFARS 252.204-7012, which reaches only Defense contracts, the proposed CUI requirements apply government-wide, across every federal agency, to both prime contractors and subcontractors. The rule also introduces a new Standard Form to identify CUI at the solicitation stage, giving contracting officers a consistent way to flag which awards carry safeguarding obligations. Rather than finalizing every mechanic, the Council is expressly seeking industry input on several open questions — including how safeguarding and reporting obligations should flow down to subcontractors, how cloud-service and telecommunications providers should be treated, and whether enhanced controls drawn from NIST SP 800-172 should apply to higher-risk information.

What It Means for Contractors

For companies that already operate under DFARS 7012 and are preparing for CMMC, much of this will feel familiar; the NIST 800-171 control set and the incident-reporting mechanics track the Defense model closely. The larger disruption falls on civilian-only contractors — firms serving agencies that have never faced a standardized CUI clause. Those companies would need to stand up NIST 800-171 compliance programs, evaluate whether the newer Revision 3 controls require changes to their current posture, and build an incident-response process capable of detecting and reporting a CUI incident within 72 hours of discovery.

The move from an eight-hour to a 72-hour reporting window is a meaningful softening from the 2025 draft, and it lowers the pressure toward around-the-clock reporting staff that the original timeline implied. But 72 hours is still a firm clock that starts at discovery, so contractors need monitoring and alerting capable of surfacing an incident quickly, plus a pre-built reporting workflow and designated staff who know exactly where and how to file. The alignment with existing DFARS and CIRCIA timelines means firms that already report on those cadences have a head start.

The open questions around subcontractor flow-down are worth close attention. Because the Council is still soliciting views on how obligations should reach lower-tier suppliers, primes cannot yet assume a settled structure, and they will want to weigh in on flowdown language and coordination processes before the mechanics harden in a final rule. The same is true for cloud and telecommunications providers: contractors that rely on commercial cloud environments to store or process CUI should track how the Council resolves the provider-security question, since that outcome will shape which vendors clear the bar.

The comment window is the immediate action item. Because this is a second opportunity to comment, contractors and industry groups that objected to the January 2025 version — over the original eight-hour timeline, the unmarked-CUI obligation, subcontractor reporting, or the cloud requirements — have a fresh chance to weigh in before July 23. Firms should also inventory now which of their contracts and pipeline opportunities involve CUI, since the new Standard Form means the requirement will surface at solicitation and leave little room to negotiate it away after award.

The proposal remains subject to change through the rulemaking process, and the FAR Council could revise the reporting timeline, scope, or cloud requirements in response to comments. But the direction is clear: the government is standardizing CUI protection across all agencies and importing the Defense Department's core requirements into the civilian marketplace.

Sources