The FAR Overhaul’s CUI Rule Heads to Formal Rulemaking: What Contractors Should Watch

Posted on June 23, 2026

Article by: Steffanie Lee

On Tuesday, June 23, the Federal Acquisition Regulatory Council published the first tranche of proposed FAR rules in the Federal Register, formally opening public comment on the first wave of its Revolutionary FAR Overhaul. This first set spans roughly 17 FAR Parts, with additional batches expected in the coming months. After more than a year of operating through agency deviations, the Council is now moving these changes into formal notice-and-comment rulemaking.

For contractors, updates to one rule (FAR Case 2017-016) deserves a close read: it carries the long-awaited governmentwide framework for handling Controlled Unclassified Information (“CUI”).

A uniform process for CUI

CUI has been an unfinished project for the better part of a decade. The underlying program traces back to Executive Order 13556 in 2010 and NARA’s implementing requirements at 32 CFR Part 2002, but the FAR has never provided a consistent, governmentwide framework for telling contractors what CUI they must protect and how. The result has created a patchwork: DoD built its own clause-based regime with DFARS 252.204-7012 and the CMMC program, while civilian agencies have adopted ad hoc approaches.

This proposed rule aims to close that gap. It creates a common mechanism using a new Standard Form (SF XXX, Controlled Unclassified Information Requirements) to enable a uniform process for communicating the information contractors must manage and safeguard, identifying where a CUI incident must be reported, and flagging when incident-reporting requirements differ from or add to those in the core clause at FAR 52.240-7. The rule pairs the form with updated FAR clauses 52.240-6 and 52.240-7. Contracting Officers must complete the SF XXX to identify whether a contractor is expected to handle CUI, which categories are involved, where it will reside, and the applicable safeguarding and reporting obligations.

One structural change from the earlier version of the proposed rule is that the CUI requirements will now sit within a consolidated FAR Part 40, Information and Supply Chain Security, which merges security prohibitions, exclusions, and safeguarding requirements that were previously scattered across FAR Parts 4, 25, and 40. The original January 2025 proposal had placed the CUI provisions in FAR Part 4. This change emphasizes the FAR Overhaul’s intent to build out Part 40 as a dedicated home for the government’s national security-flavored contracting controls.

Now that CUI lives next to the other Part 40 security prohibitions, the Overhaul was able to standardize several requirements across the whole group—most visibly the 72-hour reporting timeline, which now applies consistently to both security-prohibition reports and CUI incident reports.

Cloud Requirements: at least FedRAMP Moderate or equivalent

For contractors that rely on cloud services (which is to say, nearly everyone), the rule sets a clear floor. If a contractor uses a cloud service provider to store, process, or transmit any CUI identified in the SF XXX, that provider must meet security requirements equivalent to those the Government has established for the FedRAMP Moderate baseline.

The new language matters. The January 2025 version of the rule required cloud providers to be FedRAMP Moderate authorized, with no allowance for an equivalency determination. This was a notably stricter posture than even DoD’s. The current proposal reframes the requirement as meeting security requirements “equivalent to” the FedRAMP Moderate baseline, which the Council describes as providing more flexibility to the contractor while still ensuring the underlying controls are implemented. Contractors should still expect to inventory their cloud services and confirm coverage, but the equivalency framing is a meaningful shift.

What changed since the January 2025 Proposal

As this is a revised version of the rule first proposed in January 2025, the most useful lens for contractors is what the Council changed in response to public comments. Below are some key revisions:

  • Incident reporting harmonization: The incident reporting clock moved from 8 hours to 72 hours. The original proposal drew significant industry pushback for requiring contractors to report suspected or confirmed CUI security incidents within 8 hours of discovery—far faster than DoD’s 72-hour “rapid report” standard. The revised rule extends the reporting window to 72 hours from discovery, aligning it with DFARS 252.204-7012 and the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA). This harmonization gives contractors time to confirm whether an event actually qualifies as a CUI incident and provide accurate information.
  • Narrowed definition for “CUI Incident”: The Council revised the definition of a “CUI Incident” to only reach unauthorized disclosure, improper modification or destruction of CUI, or unauthorized access to the information system on which CUI resides. The January 2025 rule defined a CUI incident broadly and included “suspected or confirmed” incidents, attaching reporting obligations to mere suspicion, not just confirmed events. Combined with the 8-hour reporting clock, this created a very fast, low-threshold trigger. The new rule also clarifies that improper handling of CUI, such as unmarked or mismarked CUI, is not itself a CUI incident unless it results in one of the above outcomes. This is probably the most consequential narrowing as marking errors are common and largely administrative. Treating every such marking slip as a potential “incident” would have generated significant reporting noise over events where nothing was compromised.
  • Carve-outs for cloud incidents: Contractors need not file duplicate report where a FedRAMP authorized cloud provider reports a CUI incident under FedRAMP Incident Communication Procedures. This avoids redundant reporting of the same event through two channels.
  • Contractor liability language removed: The rule’s earlier proposal included an express financial-liability hook, noting that contractors “may be financially liable” for the Government’s response costs if the contractor is found to be at fault for a CUI incident. The update removed this language completely. While this change does not foreclose the Government’s other, independent enforcement tools, it puts contractors in a somewhat better defensive position because the Government would have to rely on generally available remedies, each with its own burden of proof—for example, an FCA case would still require proof of materiality and scienter.
  • One-size-fits-all training mandate is gone: The new rule removes the prescriptive training requirement in favor of a flexibility-based approach to ensuring employee compliance. The updated approach is meant to mirror other similar FAR requirements regarding how contractors ensure employees will have the knowledge, skills, and ability to comply with CUI requirements.

These changes reflect the Council’s focus on predictability, easing administrative burdens, and reducing over-reporting: a tighter definition with determinable triggers, more time to investigate, and removing clerical markings errors means contractors can distinguish genuine security incidents from administrative hiccups and report with more confidence about what qualifies.

How long industry has to comment

Public comment opens Tuesday, June 23 and closes July 23—only a 30-day window. Given this is the formal rulemaking step, it is the contracting community’s clearest opportunity to shape the final clause language before it lands in solicitations and contracts. Any contractor whose work touches CUI should read the revised FAR 52.240-7 and the SF XXX closely and consider weighing in.

The Federal Register notice is available at: https://www.federalregister.gov/public-inspection/2026-12559/federal-acquisition-regulation-revolutionary-overhaul