The FAR Part 40 CUI rule, explained for everyone who thought this didn't apply to them.
For a decade, the safeguarding of Controlled Unclassified Information has been treated as a defense contractor's burden. If you sold to the Department of War, DFARS 252.204-7012 put NIST SP 800-171 in your contracts, SPRS scores in your future, and eventually CMMC on your calendar. If you sold to HHS, DOT, Education, GSA, or any other civilian agency, you mostly watched from the sidelines, subject at worst to a patchwork of agency-specific clauses that were inconsistently written and even more inconsistently enforced.
That era is ending. On June 23, 2026, the FAR Council published a proposed rule, as part of the broader Revolutionary FAR Overhaul implementing Executive Order 14275, that would establish a single government-wide framework for safeguarding CUI and reporting CUI incidents. The comment period closed July 23, 2026. The rule is not final, and rules of this size take time. But the direction is unambiguous, and the substance is worth understanding now, because the organizations that will feel it most are the ones that have never had to think about any of this.
The proposal folds CUI requirements into an expanded FAR Part 40, Information Security and Supply Chain Security. This is a revision of the January 2025 proposed CUI rule, which placed these requirements in FAR Part 4. The mechanics arrive through three instruments:
A solicitation provision, FAR 52.240-6 (Notice of Controlled Unclassified Information Requirements), that tells offerors CUI is in play.
A contract clause, FAR 52.240-7 (Controlled Unclassified Information), that carries the substantive obligations.
A standard form, currently designated SF XXX, that the contracting agency must complete for each solicitation and contract, identifying whether CUI is involved, which CUI categories apply, where the CUI will reside, and what safeguarding and reporting requirements attach. The form is the cornerstone of the design: contractors safeguard the CUI the government identifies in the contract, rather than guessing at scope.
The teeth are in paragraph (d) of the clause: contractor information systems that handle CUI must meet the security requirements of NIST SP 800-171 Revision 3, plus any additional requirements identified in the contract. For contracts involving critical programs or high-value assets, agencies can layer on selected controls from NIST SP 800-53.
And the clause flows down: prime contractors must insert its substance, unaltered, into any subcontract where the subcontractor will handle CUI.
Incident reporting gets standardized too. CUI incidents would generally be reportable within 72 hours, with DoW-related incidents going to the DIBnet portal and all other CUI incidents going to CISA, plus notification to the contracting officer. Subcontractors report directly to the government and notify both the contracting officer and the next-higher-tier contractor. For the thousands of civilian-agency contractors that have never had a federal incident-reporting obligation, this alone is a new operational capability they will need to build: someone has to detect the incident, characterize it, and file within three days.
One piece of genuine relief compared to the January 2025 version: the FAR Council deleted the clause that would have required contractors on contracts with no CUI to identify and report potentially mismarked CUI. If your contract involves no CUI, this framework largely leaves you alone.
The population that should be paying attention is precisely the population that is not. Defense contractors have spent years building SSPs, calculating SPRS scores, and arguing about enclaves. The organizations facing the steepest climb are:
For these organizations, the hardest work is not the controls. It is the step before the controls: figuring out what CUI they actually hold, where it lives, and which systems are therefore in scope. Defense contractors learned over a painful decade that CUI identification and system scoping determine the entire cost of compliance. Civilian contractors get to learn the same lesson, hopefully faster.
Here is the detail that will cause the most practical confusion: the FAR rule points to NIST SP 800-171 Revision 3, while the entire DoW ecosystem, including CMMC and current DFARS assessments, still runs on Revision 2.
Revision 3, finalized in May 2024, is not a light edit. It restructures the framework to align with the NIST SP 800-53 Revision 5 moderate baseline: 97 requirements across 17 families, up from 14 families, with Planning, System and Services Acquisition, and Supply Chain Risk Management added. Thirty-three Revision 2 requirements were withdrawn or absorbed into others. The distinction between basic and derived requirements is gone. And Revision 3 introduces 88 organization-defined parameters across 49 requirements: values that must be explicitly set before the requirements are even assessable. Anyone tempted to read the drop from 110 requirements to 97 as a lighter lift should note that the companion assessment guide, 800-171A Revision 3, contains 422 determination statements, roughly a third more than its predecessor. The bar moved up, not down.
The result, if the rule finalizes in anything like its current form, is a dual-revision world: DoW contracts on Revision 2 until the Department transitions, civilian contracts on Revision 3 from the start. Contractors serving both markets will need to understand the delta between the revisions at the control level, not just in the abstract. That crosswalk work is unglamorous and it is exactly where compliance programs will succeed or fail.
Ten days before the comment period closed, on July 13, 2026, the Department of War suspended implementation of the CMMC program pending a review. Some contractors read the pause as a reprieve. Read together with the FAR proposal, it is closer to the opposite.
What paused is an enforcement mechanism: third-party certification of a subset of defense contractors. What the FAR rule proposes is an expansion of the underlying obligation to the entire federal contracting base. The safeguarding requirement itself, NIST 800-171 in one revision or another, is not in retreat anywhere. Self-assessment requirements continue to appear in DoW solicitations during the pause, SPRS obligations remain, and the False Claims Act does not care whether a third party checked your work before you attested to it.
Organizations that treat the pause as a reason to stop preparing are optimizing for the one variable that was never really in question.
Nothing in this rule requires action today, and forecasting final-rule timing is a mug's game; a rulemaking of this scale plausibly takes a year or more to finalize, and provisions may change. But the preparation this rule implies is almost entirely revision-proof and rule-proof, because it is the same preparation every version of federal CUI policy has pointed toward for a decade:
The comment period is closed and the rulemaking machinery is turning. Whatever emerges, the trajectory of federal CUI policy has been consistent through every administration and every reorganization: broader scope, tighter timelines, more explicit requirements. The contractors who do well under regimes like this are never the ones who moved fastest after the final rule. They are the ones who were unhurried because they started early.
Sources: Proposed rule, Federal Register, June 23, 2026 (Revolutionary FAR Overhaul, FAR Case 2026-001, FAR Part 40); NIST SP 800-171 Revision 3 and SP 800-171A Revision 3 (May 2024); Department of War CMMC program announcement, July 13, 2026.
Take our 3-minute Readiness Check and get an instant gap summary based on your environment.
Start Readiness Check →An independent firm focused exclusively on CMMC compliance for defense contractors and the DIB.