Wiley.Law FAR Council Proposes Major Overhaul of CUI Regulations for Contractors
Article Content
- •FAR Council's proposed rule clarifies CUI obligations for contractors.
- •Contractors must use a new Standard Form to identify CUI in contracts.
- •Public comments on the proposed rule are due by July 23, 2026.
On June 23, 2026, the FAR Council proposed a rule to clarify contractor obligations regarding Controlled Unclassified Information (CUI) as part of a broader FAR overhaul. This rule mandates that contractors identify CUI in contracts using a new Standard Form and comply with NIST SP 800-171 cybersecurity requirements. The proposed changes aim to enhance clarity and guidance for contractors handling CUI, affecting a wide range of government contractors and their subcontractors. The public comment period for the proposed rule ends on July 23, 2026. Additionally, the FAR Council has removed certain obligations from a previous proposal, easing compliance for contractors. These changes are part of a government-wide effort to strengthen cybersecurity and supply chain security. The implications for contractors include potential loss of contract eligibility and exposure to False Claims Act liability for noncompliance.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (5)
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Mandates Urgent Patching of Five Critical Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch five critical vulnerabilities by October 11, 2026, following exploitation by the China-linked hacking group Flax Typhoon. The vulnerabilities, added to CISA's Known Exploited Vulnerabilities (KEV) catalog, include…