Beyond CMMC: The Rule DOD Contractors Are Missing

June 23, 2026

Executive Summary

Most DOD contractors have been focused on CMMC — and that focus is warranted. But a parallel federal requirement is moving toward finalization at the same time, and it applies to a broader set of contractors than CMMC does. The FAR CUI rule would formalize how Controlled Unclassified Information is handled across all federal contracts, with mandatory security standards, cloud requirements, and incident reporting obligations. The public comment window closes July 23, 2026. The preparation window is now.

Why It Matters

CUI stands for Controlled Unclassified Information. It covers the kind of data that flows through almost every federal contract: technical drawings, export-controlled research, procurement-sensitive information, and more. If your company holds a federal contract — or supplies goods or services to a company that does — CUI almost certainly touches your business, even if no one has ever used that term in your facility.

CMMC gets most of the attention because it comes with an explicit certification requirement and third-party assessments. But CMMC applies specifically to Department of Defense contracts. The FAR CUI rule applies across all federal agencies. A company that makes office furniture for a federal building, or provides logistics services to a civilian agency, could fall under this rule with no CMMC obligation at all.

The FAR CUI rule has been in development for years. A recent overhaul of the broader FAR process has cleared the path toward finalization faster than most observers expected. Analysts now believe a final rule could arrive before the end of 2026. Contractors who have been treating this as a distant regulatory footnote are running out of runway.

Business Impact

Here is what the proposed FAR CUI rule would require of contractors once finalized:

Incident reporting. Contractors must report CUI incidents — meaning any unauthorized access, loss, or compromise of covered information — in a timely manner. The rule creates a formal obligation where one was previously implied.

NIST SP 800-171 Revision 3 (and 800-172 where applicable). This is the updated security framework contractors must implement. Revision 3 tightens and clarifies the controls from the previous version. The government's own Regulatory Impact Analysis estimates the cost to implement 800-171r3 at roughly $175,000 per contractor — a significant number for businesses without a dedicated IT security team.

Cloud services at FedRAMP Moderate or equivalent. If you store or process CUI in the cloud, your cloud environment must meet at least FedRAMP Moderate authorization standards. This would be a contract requirement, not a suggestion.

Third-party assessments at agency discretion. Unlike CMMC, which mandates third-party assessments for certain contract types, the FAR CUI rule leaves the decision about third-party validation to the awarding agency. That may sound like flexibility, but it also means different agencies could impose different requirements on the same contractor.

A standard GSA form identifying CUI in the contract. A standardized form will identify what CUI is present in a given contract. The rule also clarifies that contractors are not responsible for handling CUI that is unmarked or mismarked — unless the contract specifically includes that obligation. That is a meaningful liability distinction.

This rule does not exist in isolation. It sits alongside CIRCIA (the federal cyber incident reporting law), FedRAMP 20x (the modernization effort for cloud authorization), and CMMC 3.0. Each framework has overlapping intent but different mechanics, and managing compliance across all of them requires a coherent strategy, not just a checklist.

What Companies Can Do

The public comment period closes July 23, 2026. If your company has concerns about specific requirements — cost burdens, implementation timelines, scope of applicability — this is the formal channel to raise them. Industry associations representing government contractors are likely to submit comments; your legal counsel or trade group can help you weigh in.

Beyond the comment period, the immediate practical steps are:

  • Inventory your CUI. Know where sensitive federal information lives in your systems, who has access, and how it is stored or transmitted.
  • Assess your cloud environment. If you use standard commercial cloud storage for anything that touches a federal contract, find out now whether it meets FedRAMP Moderate requirements.
  • Review your incident response plan. The reporting requirement involves your people, your processes, and your contracts — not just technology.
  • Map your subcontractor relationships. CUI obligations flow down the supply chain. Prime contractors may have responsibility for ensuring their subs are compliant as well.

For more on why getting ahead of audits matters, see The Compliance Audit Is Coming.

How an MSP Helps

Most defense contractors and subcontractors are not cybersecurity firms. Their expertise is in manufacturing, engineering, logistics, or research — not in interpreting NIST control families or managing FedRAMP-authorized cloud migrations.

An MSP with federal compliance experience can close that gap without requiring a contractor to build a full internal security team. Specifically, an MSP can help with:

  • Conducting a gap assessment against NIST SP 800-171 Revision 3 controls
  • Configuring and managing a cloud environment that meets FedRAMP Moderate equivalency
  • Building and testing an incident detection and response capability
  • Documenting controls and maintaining evidence for assessments
  • Advising on how FAR CUI requirements interact with CMMC obligations you may already be tracking

The goal is not to hand off responsibility — prime contractors remain accountable. The goal is to make sure the technical and operational work is handled by people who do this every day.

Best Practices

Whether or not the final rule lands this year, these practices are worth building now:

  1. Treat CUI as a known category, not a vague concept. Define it, label it, and train your team to recognize it.
  2. Don't wait for contract language. If you handle federal information, build compliant habits before a specific contract forces them.
  3. Align CMMC and FAR CUI work wherever possible. Many of the NIST 800-171 controls apply to both. Double-dipping on preparation saves time and cost.
  4. Document everything. Assessors and contracting officers want evidence that controls are in place and operating — not just assurances.
  5. Build your incident response process now. Reporting requirements are only as useful as the detection capability behind them. If you cannot identify an incident, you cannot report it.

FAQ

What is CUI and does it apply to my business?

CUI — Controlled Unclassified Information — is a government-wide category for sensitive information that does not rise to the level of classified but still requires protection. It covers things like technical data, export-controlled research, procurement information, and personally identifiable information in federal systems. If your company holds a federal contract, or provides products or services to a company that does, CUI likely touches your business.

What is the difference between FAR CUI and CMMC?

CMMC (Cybersecurity Maturity Model Certification) applies specifically to contracts involving the Department of Defense. It requires contractors to achieve and certify a defined level of cybersecurity maturity, with third-party assessments required for many contract types. The FAR CUI rule applies across all federal agencies — not just DoD — and focuses on how CUI is handled, reported, and protected in any federal contract. The two frameworks share a common foundation in NIST SP 800-171, but they are separate requirements with separate compliance paths.

Does my cloud storage need to be FedRAMP Moderate?

Under the proposed FAR CUI rule, yes — if you are storing or processing CUI in a cloud environment, that environment must meet at least FedRAMP Moderate authorization standards. Standard commercial cloud services, even from major providers like Microsoft or Google, may not qualify unless they are using the specific authorized configurations for federal use. This is an area where many contractors will need to make changes.

What happens if we don't comply by the deadline?

Once a final rule is published, compliance becomes a contract requirement. Non-compliance can mean contract termination, suspension from federal contracting, and potential False Claims Act exposure if a contractor certifies compliance they have not achieved. The deadlines and enforcement mechanisms will be clearer once the rule is finalized, but waiting until then to start preparing is not a viable strategy.

For more on how MSPs help defend against the security threats that put CUI at risk, see 5 Solutions MSPs Use to Combat Common Breaches in the Triangle Business Journal.

The FAR CUI rule is moving toward finalization, and the window to prepare — before it lands in your next contract — is now. Core Managed works with defense contractors and subcontractors to build practical, audit-ready compliance programs that address CMMC, NIST 800-171, and the evolving FAR requirements. Call us at 888-890-2673 or contact us here to schedule a conversation.