What the Rule Is
The federal government is standardizing how its contractors protect sensitive but unclassified government information. For years, obligations of this kind fell mainly on Department of Defense contractors through the Defense Federal Acquisition Regulation Supplement and the Cybersecurity Maturity Model Certification program. The proposed FAR Controlled Unclassified Information rule, published as part of the Revolutionary FAR Overhaul, extends comparable requirements across the federal government. The rule reaches broadly, but the operative trigger is whether a given solicitation or contract identifies CUI through a new standard form. Purchases of commercial off-the-shelf products remain outside its scope.
The clause that carries the obligations is FAR 52.240-7, Controlled Unclassified Information, accompanied by the solicitation provision at FAR 52.240-6 and the covered federal information clause at FAR 52.240-5. A contractor that handles CUI must protect it to a recognized federal standard, report incidents within 72 hours, ensure its people understand the applicable handling requirements, make its system security plan available on request, and pass the same obligations to subcontractors that handle the same information.
Readiness Becomes Part of the Bid
The most consequential change for leadership is not a single security control. It is where readiness has to exist. The solicitation provision at FAR 52.240-6 addresses the offeror directly, and it sets a low threshold with a firm obligation. If an offeror is not compliant with any requirement of the CUI clause, it must submit, as part of its offer, a disclosure that identifies every requirement it does not meet, together with a plan of action and milestones to meet them. Cyber readiness becomes part of the submission rather than a project that begins after award. A company that treats compliance as work for the implementation phase may find that it has disclosed a gap, in writing, at the moment it competed for the contract.
Noncompliance is disclosed in the offer. Under FAR 52.240-6, an offeror that does not meet any requirement of the CUI clause must submit, with its offer, the requirements it does not meet and a plan of action and milestones to reach them.
The threshold is low. Noncompliance with even one requirement produces a written disclosure inside the proposal itself.
Capture, contracts, and security now share the problem. Readiness moves upstream into proposal preparation, not the period after award.
External Service Providers and the Cloud
The rule requires that the system security plan identify any external service provider that handles CUI. For most organizations that single requirement reaches further than it first appears. Managed service providers, hosted email, cloud file storage, backup services, governance and compliance tooling, engineering and product lifecycle platforms, and remote support vendors can all fall within it. Each becomes a documented part of the security posture the government may ask to review.
Where a cloud service provider stores, processes, or transmits CUI identified in the contract, the rule does not leave the security bar to general judgment. It requires that the provider meet security requirements equivalent to the federal FedRAMP Moderate baseline. Cloud selection becomes a defined procurement filter rather than a broad impression of security. Organizations that already operate in compliant government cloud environments will recognize this requirement. Those relying on ordinary commercial productivity tools should examine the gap with care.
How This Relates to CMMC
For a defense contractor, much of this will feel familiar, because many suppliers already work toward the same security standard under existing defense rules and CMMC. One difference deserves attention. The defense certification program currently measures compliance against Revision 2 of NIST SP 800-171, while the proposed rule points to Revision 3, applied with government-set parameters, and adds adjacent paths to NIST SP 800-53 for federal systems and NIST SP 800-172 for designated critical programs or high value assets. A company that serves both defense and civilian customers could be asked to satisfy two editions of the same standard at the same time. This is a planning matter rather than an emergency, but it belongs on the radar of anyone responsible for both lines of business.
No third-party certification in the FAR rule. Unlike CMMC, the proposed FAR rule relies on disclosure in the offer and documentation provided on request, not a third-party certification.
Two editions of one standard. CMMC Level 2 is measured against NIST SP 800-171 Revision 2. The proposed FAR rule points to Revision 3.
Reporting aligns. Both regimes use a 72-hour incident reporting window.
What Management Should Do Now
A measured response begins with a few questions that do not require a consultant to answer. Determine whether your current or prospective contracts involve CUI. Coordinate security readiness with your capture and contracts teams before proposals go out, given that an offer may have to disclose gaps and a plan of action and milestones. Inventory where sensitive information lives in your systems today, and which outside providers touch it. Confirm that any cloud service handling CUI meets the FedRAMP Moderate equivalent bar. Bring your system security plan up to date so it reflects actual practice, including the external providers it must name. Assign clear internal ownership across information technology, contracts, and operations, because these obligations tend to fall through the gaps when no single person is accountable.
Status
This is a proposed rule, not final law. The clause language is part of the Revolutionary FAR Overhaul, a broad rewrite of the Federal Acquisition Regulation. The proposed rule was placed on public inspection on June 22, 2026 and is scheduled for publication in the Federal Register on June 23, 2026 as document 2026-12559, a single action running 439 pages. Publication opens a public comment period, and the text can change before any final rule takes effect. The reasonable posture is to treat this period as preparation time, and to comment where the proposed language would create practical difficulty.
Download the Full Brief
The full brief carries the plain language treatment through what the rule requires, the bid stage disclosure obligation, external service provider identification, cloud handling at the FedRAMP Moderate equivalent bar, the Revision 2 to Revision 3 planning question, an executive action list, and the cost picture, with sourced references to the proposed rule and the underlying NIST and FedRAMP authorities.
The CMMC Decision, Second Edition
Strategic guide for CEOs and senior executives of small and mid-sized defense contractors. Level determination, enforcement timelines, certification economics, and the governance questions executives cannot delegate to the IT organization.
Read More →