# FAR Council Proposes CUI Safeguards

A proposed Federal Acquisition Regulation (FAR) rule would standardize cybersecurity and breach-reporting requirements for federal contractors handling controlled unclassified information (CUI). If finalized, the rule would require reporting covered incidents within 72 hours, apply NIST SP 800-171 safeguards, extend protections to subcontractors through flow-down requirements, and potentially expose contractors to greater False Claims Act risk. The proposal is still pending, so these requirements are not described as effective obligations yet.

- Contractors can assess where they handle or share CUI and review incident-response processes against the proposed 72-hour reporting timeframe and NIST SP 800-171 safeguards.
- Prime contractors may need to identify CUI provided to subcontractors and strengthen oversight of how subcontractors protect and report incidents involving it.
- A single federal standard could reduce variation across agency requirements, while broader coverage and potential False Claims Act exposure make accurate implementation and oversight consequential for contractors.

**Jurisdictions:** federal
**Industries:** Information Technology, Defense & Military
**Topics:** Cybersecurity, Regulatory Compliance
**Published:** October 07, 2026

### Government Entities
- Federal Acquisition Regulatory Council (FAR Council)
- Cybersecurity and Infrastructure Security Agency (CISA)
- Department of Defense (DoD)
- National Institute of Standards and Technology (NIST)

### Key Quotes
> I think contractors should really be looking at this, preparing for it in certain ways, at least by recognizing at a high level, where this is headed and the types of activities and steps they need to be doing internally.
> — Ryan Burnette, Partner

> The proposed rule is intended to “make it easier for contractors to comply with one set of standards, rather than many different types of standards” for the protection of CUI and the reporting on CUI incidents such as breaches
> — Susan Cassidy, Partner

> So they’re going to have to identify what CUI am I giving to my subcontractors, and do some sort of oversight to make sure that their subcontractors are appropriately handling CUI.
> — Trayce Howard, Government Contracts Partner

### Sources
- [Major rules for federal contractors handling sensitive data are nearing the finish line | CyberScoop](https://cyberscoop.com/federal-contractors-cui-cybersecurity-rules) - CyberScoop