Skip to main content
Clark Schaefer Consulting home
Share this
How Does the FAR CUI Rule Affect Federal Contractors?

How Does the FAR CUI Rule Affect Federal Contractors?

CMMC CRITICAL UPDATE

Phase II third-party certification requirements have been suspended as of July 13, 2026 pending a 60-day DoW review; Phase I self-assessments and DFARS 252.204-7012 data-protection obligations remain fully in effect.

DOW RELEASE
CMMC CRITICAL UPDATE

What is the FAR CUI Rule?

The FAR CUI rule, initially published as a draft on January 14, 2025, and substantially revised in June 2026 under the Revolutionary FAR Overhaul (RFO), is a governmentwide contract clause requiring the implementation of NIST SP 800-171 Revision 3 to protect Controlled Unclassified Information (CUI). It outlines the specific requirements for how contractors and subcontractors are expected to handle CUI. The FAR CUI rule intends to improve the government’s ongoing efforts to identify, detect, respond to, and protect against malicious threat actors.

We’ve identified six key takeaways that every contractor needs to know to navigate the complexities of the FAR CUI rule.

Standard Form (SF) XXX

The FAR CUI rule creates a standard form (SF) for identifying if CUI will be incorporated into the contract, what category of CUI it is, and the corresponding safeguarding requirements for the protection of said CUI.

“The SF XXX, Controlled Unclassified Information, which is incorporated into this contract identifies what controlled unclassified information (CUI) is involved in the contract. The Contractor is required to safeguard only the CUI that is identified in the SF XXX.”

Clear Definition of CUI

There is a clear definition of what CUI is and is not. As defined in the rule, CUI is “information that the Government creates or possesses, or that an entity creates or possesses for or on behalf of the Government, that a law, regulation, or Governmentwide policy requires or permits an agency to handle using safeguarding or dissemination controls.”

CUI is NOT:

  • Classified information.

  • Covered Federal information.

  • Information a Contractor holds or maintains within its own systems that was neither obtained from, created by, nor possessed on behalf of an executive branch agency or an entity acting on behalf of such an agency.

  • Federally funded basic and applied research in science, technology, and engineering at colleges, universities, and laboratories.

Handling Unmarked Data

Contractors must secure any information they believe is CUI, even if that information isn’t identified in the SF XXX or is not marked or properly marked as required in the SF XXX. The information must be safeguarded until the Contracting Officer can make a final determination on the proper marking of the information.

Standardized Incident Reporting Timeline

Contractors must now report any suspected or confirmed CUI incidents to their Contracting Officer within 72 hours. This aligns the FAR CUI rule with standard defense timelines (like DFARS 252.204-7012), removing the heavily criticized 8-hour reporting window proposed in the early 2025 draft.

Cloud Service Provider Requirements

If a Contractor uses cloud services to store, process, or transmit any CUI identified in SF XXX, then the cloud service provider must meet the FedRAMP Moderate baseline requirements. While the early draft eliminated FedRAMP equivalency, updated guidance continues to clarify how contractors can achieve acceptable compliance baselines or equivalents under modern federal cloud security standardizations.

Compliance Cost Estimates

The government’s official cost estimates for implementing NIST SP 800-171 Revision 3 have been highly scrutinized. Below is a breakdown of the anticipated compliance costs as adjusted for the more stringent Revision 3 baseline rules:

Small Businesses

  • Total Implementation Cost: Varies based on Revision 3 readiness (Initial 2025 baseline estimates calculated 1,560 hours at $95/hr for a total of $148,200 under older Rev 2 guidelines, but current Revision 3 requirements add additional control overhead).

  • Recurring Annual Labor Cost:Expected to exceed the original estimate of $98,800 due to new continuous monitoring mandates.

Other than Small Businesses

  • Total Implementation Cost: Varies (Initial 2025 baseline estimates projected 5,720 hours at $95/hr for a total of $543,400 under Rev 2 rules).

  • Recurring Annual Labor Cost: Expected to exceed the original baseline estimate of $494,000.

The estimates above don’t consider the cost of the specific software or hardware that may need to be implemented, the number of users, the complexity of the network, and more. For those, revised frameworks indicate that infrastructure costs will likely outpace the government's legacy estimates of $27,500 initially / $5,000 annually for small businesses, and $140,000 initially / $80,000 annually for larger organizations.

Source

Federal Register. (2026, June 23). Federal Acquisition Regulation: Revolutionary Federal Acquisition Regulation Overhaul. FAR Case 2026-001. Available at Federal Register Online.

Expert Contributors

Carly Devlin

Shareholder, Chief Information Security Officer
We're always excited to address challenges for our clients and to bring the best solutions for their situation to the table.
You may also like

Contact Us