CUI compliance used to be a defense-contractor problem. In 2026 it stopped being one. A federal contract cybersecurity case closed in June 2026 with a $507,144 False Claims Act settlement tied to unmet safeguarding requirements, and two parallel regulatory moves now push controlled unclassified information obligations toward nearly every federal contractor and subcontractor. If your organization touches federal data of any kind, the question is no longer whether CUI compliance applies to you, but how soon you have to prove it.
This article explains what changed in 2026, what agencies are now required to pass down to you in contracts, and the concrete steps that separate a defensible CUI program from a paper one.
Why CUI Compliance Changed in 2026
For most of the last decade, controlled unclassified information lived in a strange gap. The government created the category in 2010, wrote the rules for agencies, and told defense contractors to protect it through a single Defense Federal Acquisition Regulation Supplement clause. Civilian-agency contractors had no equivalent obligation. That gap is closing on two fronts at once.
The Agency Side: ISOO Notice 2026-07
On September 2, 2026, the Information Security Oversight Office issued ISOO Notice 2026-07, refreshing how every federal agency must run its CUI program. The notice consolidates and updates the required elements agencies must implement, from designation and marking through decontrol, misuse reporting, and annual self-inspection. It rescinds older guidance, including the 2020 notice that governed program implementation deadlines.
The part that matters to you sits in the notice’s contract requirements. Agencies entering any contract that requires access to controlled unclassified information must, at a minimum, give the prime contractor specific guidance on a defined list of items. That list is effectively a preview of what will land in your contracts, and it is worth reading as a checklist rather than as background.
The Contractor Side: The FAR CUI Rule
The second front is the Federal Acquisition Regulation itself. The FAR CUI rule, formally FAR Case 2017-016, was first proposed in January 2025 and re-proposed on June 23, 2026 as part of the Revolutionary FAR Overhaul. The comment period closed on July 23, 2026 with 96 comments, and the rule now awaits finalization. Industry observers expect it to begin appearing in contracts before the end of 2026, though as a proposed rule its terms can still change.
The rule would extend CUI safeguarding and incident reporting to nearly every federal contractor and subcontractor, not just defense suppliers. It relocates these obligations into the expanded FAR Part 40 and introduces a standard form the agency completes to identify the CUI in a given contract.
The Cost of Getting It Wrong
Enforcement is not theoretical. In June 2026, a contractor resolved False Claims Act allegations involving Navy contract cybersecurity requirements for $507,144, in a matter that reportedly involved a Defense Contract Management Agency assessment score of negative 170 after alleged noncompliance with required controls. The False Claims Act exposure attaches to the representations a contractor makes about its security posture, which means a weak or inaccurate CUI program is not only an operational risk but a financial and legal one.
What the FAR CUI Rule Requires
The proposed rule builds a single, uniform mechanism for communicating and enforcing CUI obligations across federal contracts. The table below summarizes the core requirements as proposed in the June 2026 version.
| Requirement | What it means for you | Source mechanism |
|---|---|---|
| NIST SP 800-171 Rev 3 | Meet the current revision of the security requirements for CUI in nonfederal systems | FAR 52.240-7 clause |
| 72-hour incident reporting | Report a suspected or confirmed CUI incident within 72 hours of discovery | FAR 52.240-7 clause |
| Subcontractor flowdown | Pass safeguarding and reporting requirements to subs that will receive CUI | FAR 52.240-7 clause |
| CUI identification | Receive an agency-completed Standard Form identifying the CUI in the contract | SF XXX, CUI Requirements |
| Records preservation | Preserve information related to a CUI incident for a defined retention period | FAR 52.240-7 clause |
The single most consequential line in that table is the move to NIST SP 800-171 Revision 3. Defense contractors have operated under Revision 2 through the existing DFARS clause, so the shift to Revision 3 is a real delta in control expectations, not a rename. For civilian-agency contractors who have never lived under a cybersecurity clause at all, the entire framework is new. Either way, the practical work is the same: your information systems that store, process, or transmit CUI have to meet a named control set, and you have to be able to show it.
The 72-Hour Clock
The June 2026 version proposes a 72-hour window to report a suspected or confirmed CUI incident, a change from the 8-hour requirement in the January 2025 version. Seventy-two hours sounds generous until you consider what has to happen inside it: detection, triage, a preliminary determination that CUI was involved, and a report that contains the required data elements. Organizations that have never run this drill discover during a real incident that the clock starts at discovery, not at the moment they finish investigating.
Flowdown Is Now Your Responsibility
The rule requires prime contractors to flow safeguarding and incident-notification requirements down to subcontractors that will receive CUI. This is where many programs break. A prime can hold an excellent internal posture and still carry unmanaged risk through a sub that never received, acknowledged, or implemented the requirements. The obligations that primes and subs must meet to secure CUI are not a clause you paste once; they are a supplier-management process you have to be able to evidence.
What Agencies Must Pass Down in Contracts
ISOO Notice 2026-07 lists the specific guidance an agency must provide to a prime contractor for any contract requiring CUI access. Read this as the map of what your next CUI-bearing contract will ask of you.
| Contract element | What you will need to operate |
|---|---|
| Identification and marking | A way to recognize government-furnished CUI and mark contractor-developed CUI correctly |
| Safeguarding and access | Controls limiting CUI to authorized holders, at rest and in transit |
| Training | Documented CUI training for every person who handles it |
| Decontrol and disposition | Procedures to release or destroy CUI when protection is no longer required |
| Reporting and misuse | A process to report incidents and misuse of CUI |
| Self-inspection | Internal oversight that confirms the program actually runs |
The pattern across every row is the same: the requirement is not the hard part, the evidence is. An assessor or contracting officer cannot grade intent. They can only grade what you produce, on request, within the window an assessment allows. A structured CMMC compliance checklist for managing CUI scoping is the fastest way to turn that list into evidence you can actually show.
What an Assessor Actually Checks
For a control like CUI marking, the requirement is that CUI is designated and marked consistently across every format, from documents to emails to metadata. What an assessor looks for is proof that marking happens in practice: marked samples, a marking procedure, and evidence that people were trained on it. What organizations commonly produce instead is a policy that says CUI will be marked, with no artifacts showing that it is. What good looks like is a marking process that runs by default, with training records and spot-check evidence behind it. A useful self-test: pull five recent documents that should carry CUI markings and time how long it takes to confirm they are marked and to name the person responsible. If that takes more than a few minutes, the gap will surface during an assessment, not before it.
Decontrol and Disposition
The notice requires agencies to identify a decontrol date or event for CUI and to establish disposition procedures. For contractors, this translates into a lifecycle obligation many programs skip: CUI does not protect itself forever, and holding it past its useful life expands both your scope and your risk. A program that ingests CUI but never decontrols or disposes of it accumulates liability quietly, one contract at a time.
How CUI Compliance Connects to CMMC and FedRAMP
CUI compliance does not sit alone. It intersects two programs your organization may already be navigating, and understanding the relationship prevents duplicated effort and scoping mistakes.
The Cybersecurity Maturity Model Certification program is the Department of War’s mechanism for verifying that defense contractors protect CUI to the NIST 800-171 standard. The recent pause of CMMC Phase 2 third-party assessment did not remove the underlying obligation, and it did not touch the FAR CUI rule or existing CUI handling and incident-reporting duties for defense contractors. Self-assessment against the control set remains the live requirement, and the False Claims Act exposure remains fully in force.
When CUI lives in a cloud environment, a second standard attaches. The cloud’s operative benchmark is FedRAMP Moderate equivalency, measured against the FedRAMP Moderate baseline. That equivalency is separate from your own obligation on your own systems, and the two stack rather than substitute. Getting this boundary right is a scoping decision with real cost consequences, which is why defining where CUI lives is the foundation of any credible program.
Elevate helps defense and regulated-industry organizations build CUI programs that hold up under assessment, connect cleanly to CMMC and FedRAMP obligations, and produce the evidence an assessor asks for. To pressure-test where your program stands before a contract or assessment window opens, book a readiness call with an Elevate advisor.
Conclusion
CUI compliance in 2026 is defined by convergence. The agency-side refresh in ISOO Notice 2026-07 and the contractor-side expansion in the FAR CUI rule are two halves of the same movement, and together they push controlled unclassified information obligations across the entire federal supply chain. The organizations that treat this as a documentation and evidence problem, not a policy-writing exercise, are the ones that will pass.
The window to prepare is the gap between now and the moment the FAR CUI rule enters your contracts. That gap is closing. A program built deliberately during it costs far less than one assembled under the pressure of a live incident or an active assessment.
Elevate works with contractors to map CUI boundaries, align controls to the current NIST standard, and build the self-inspection discipline that keeps documentation and operational reality pointing at the same thing. Book a readiness call to start.
Key Takeaways
- CUI compliance now reaches civilian contractors, not just defense. The proposed FAR CUI rule would extend safeguarding and incident-reporting obligations to nearly every federal contractor and subcontractor, closing a decade-old gap between defense and civilian acquisition.
- The standard is rising to NIST SP 800-171 Revision 3. Contractors accustomed to Revision 2 under DFARS face a real change in control expectations, and civilian contractors face the framework for the first time.
- Evidence beats policy every time. Agencies and assessors grade what you can produce on request, not what your policy promises, so marking, training, and self-inspection artifacts matter more than the documents that describe them.
- Flowdown is a process, not a clause. Prime contractors must pass CUI requirements to subs that receive CUI and be able to show that the requirements were received, acknowledged, and implemented.
- The enforcement risk is financial and legal. A June 2026 False Claims Act settlement of $507,144 tied to contract cybersecurity requirements shows that inaccurate security representations carry liability well beyond a failed audit.
FAQs
What is CUI compliance?
CUI compliance is the set of obligations a federal contractor must meet to protect controlled unclassified information, sensitive but unclassified government data such as procurement-sensitive information or controlled technical information. It covers identifying and marking CUI, safeguarding it in your information systems, training the people who handle it, reporting incidents, and disposing of the information when protection is no longer required. In 2026, these obligations are being standardized across federal contracts through the proposed FAR CUI rule.
Does the FAR CUI rule apply to all federal contractors?
As proposed in June 2026, the FAR CUI rule would extend CUI safeguarding and incident-reporting requirements to nearly every federal contractor and subcontractor whose contracts involve CUI, not only defense contractors. It remains a proposed rule and can change before it is final, but industry expectation is that it will begin appearing in contracts before the end of 2026. Contractors who have never operated under a cybersecurity clause should use the time before finalization to prepare.
What security standard does CUI compliance require?
The proposed FAR CUI rule references the security requirements of NIST SP 800-171 Revision 3 for contractor information systems that handle CUI. Defense contractors have historically met Revision 2 through the DFARS 252.204-7012 clause, so Revision 3 represents a meaningful change in control expectations rather than a simple update. Organizations should assess their systems against the current revision and document how each requirement is met.
How quickly must a CUI incident be reported?
The June 2026 version of the FAR CUI rule proposes reporting a suspected or confirmed CUI incident within 72 hours of discovery, a change from the 8-hour window in the earlier 2025 version. The clock starts at discovery, not at the completion of an investigation, which means organizations need a detection and triage process that can produce a report with the required data elements inside that window.
How does CUI compliance relate to CMMC?
CMMC is the Department of War’s mechanism for verifying that defense contractors protect CUI to the NIST 800-171 standard. The two are closely linked because CUI protection is the object CMMC assesses. The recent pause of CMMC Phase 2 third-party assessment did not remove the underlying CUI obligation, and it did not affect the FAR CUI rule or existing incident-reporting duties, so self-assessment and safeguarding remain live requirements.