CLIENT ALERT
FAR Council speeds up CUI Rules while DoW slows down
July 28, 2026
Read time: 14 min
Federal contractors are facing divergent developments in cybersecurity compliance. First, the Federal Acquisition Regulatory (FAR) Council proposed sweeping changes to the FAR that would extend Controlled Unclassified Information (CUI) safeguarding and incident-reporting obligations to virtually all federal contractors and subcontractors. Then, the US Department of War (DoW) suspended Phase 2 of the Cybersecurity Maturity Model Certification (CMMC) Program, pausing the introduction of third-party certification requirements for defense contractors handling CUI. Both changes require Federal contractors to pay close attention to their cybersecurity compliance posture.
On July 13, 2026, the DoW announced the immediate suspension of Phase 2 of the CMMC Program, which had been scheduled to begin on November 10, 2026. DoW also placed all other pending and future CMMC implementation milestones on hold while a newly established task force conducts a 60-day review of the program.
The suspension does not eliminate CMMC or relieve defense contractors of their existing cybersecurity obligations. CMMC remains in Phase 1, under which applicable solicitations and contracts may require CMMC Level 1 or Level 2 self-assessments. Contractors that handle CUI also remain subject to the cybersecurity requirements in Defense Federal Acquisition Regulation Supplement (DFARS) 252.204-7012, including compliance with National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171 Revision 2.
Federal contractors preparing for a CMMC certification assessment now have some breathing room, but the suspension should not be viewed as a reason to abandon CMMC efforts. DoW has paused independent certification requirements, not the underlying requirements those certifications were intended to verify. Subcontractors also remain subject to Prime contractor requirements, many of which already include CMMC Level 2 certification requirements.
How we got here
DoW’s final CMMC Program rule became effective on December 16, 2024, establishing the substantive requirements for the CMMC Program in 32 C.F.R. Part 170. The companion DFARS contracting rule became effective on November 10, 2025, allowing DoW to incorporate CMMC requirements into solicitations and contracts and begin Phase 1 of the program’s four-phase implementation schedule.
During Phase 1, DoW intended to require CMMC Level 1 self-assessments for applicable contractors handling Federal Contract Information (FCI) and CMMC Level 2 self-assessments for applicable contractors handling CUI. The Rule also gave DoW discretion to require a Level 2 assessment performed by a CMMC Third-Party Assessment Organization (C3PAO) during Phase 1.
Phase 2 was scheduled to begin one calendar year later, on November 10, 2026. Under the original schedule, Phase 2 would incorporate Level 2 C3PAO certification requirements. DoW also would have been permitted to begin imposing Level 3 assessments performed by the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC).
That transition is now on hold.
Why DoW hit the brakes
DoW attributed the suspension to concerns that the existing CMMC structure imposes prohibitive compliance costs and administrative burdens, particularly on small businesses, nontraditional contractors, and new entrants to the defense industrial base. DoW also cited shortages in third-party assessment capacity and complex implementation timelines as impediments to expanding the industrial base and rapidly acquiring commercial technologies.
The announcement reflects a significant change in DoW’s framing of the CMMC Program. When adopting the final acquisition rule in 2025, DoW emphasized that independent verification was necessary to address malicious cyber activity targeting defense information and intellectual property. The July 2026 memorandum, by contrast, directs DoW to consider replacing what it characterizes as “prohibitive, third-party compliance models” with more scalable security measures.
The suspension goes beyond delaying the November deadline
Although DoW’s announcement focuses on the November 2026 Phase 2 transition, its implementation guidance goes further. During the suspension, program managers may designate only:
- CMMC Level 1 (Self) assessments; or
- CMMC Level 2 (Self) assessments.
They may not designate Level 2 C3PAO or Level 3 DIBCAC assessments. Thus, the guidance not only postpones the broader use of third-party assessments contemplated for Phase 2, but also temporarily eliminates DoW’s discretion to impose those assessments during Phase 1.
DoW has also directed program managers to initiate amendments to active solicitations that include Level 2 C3PAO or Level 3 DIBCAC requirements. Contracting officers and agreements officers must issue corresponding amendments removing such requirements “as soon as practicable.” For existing contracts and agreements containing those requirements, the guidance directs contracting officers to remove them through a modification before the next option period is exercised or during the next scheduled administrative modification. A revised class deviation implementing the suspension similarly directs contracting officers to work with requiring activities to remove or revise CMMC requirements in new and existing solicitations and contracts.
Contractors should not assume, however, that an existing contract changed automatically when DoW issued its internal guidance. Until a contracting officer issues the modification, the contract’s existing language remains applicable. Contractors with Level 2 C3PAO or Level 3 requirements in an existing contract should therefore coordinate with the contracting officer and confirm the effect and timing of any modification in writing.
What remains in effect
The suspension is not a repeal of the CMMC Program rule or the DFARS Contracting rule. Both remain in the Code of Federal Regulations. DoW has emphasized that all Phase 1 self-assessment requirements remain in place. Contractors will still be required to:
- Conduct CMMC Level 1 or Level 2 self-assessments;
- Report assessment results in the Supplier Performance Risk System (SPRS);
- Maintain the required CMMC status for covered information systems; and
- Complete applicable affirmations of continuous compliance.
DoW will also continue enforcing compliance with NIST SP 800-171 Revision 2 through self-assessments and selected government-led assessments. DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting, remains in effect, as do the other contractual cybersecurity clauses contained in individual contracts.
The 60-day review and request for information
DoW has established a cross-department CMMC Review and Reform Task Force to conduct a “top-to-bottom” review of the certification program. The task force is charged with recommending a revised cybersecurity and operational-resilience framework that:
- Prioritizes speed to capability;
- Reduces barriers for small, medium-sized and nontraditional businesses;
- Supports expansion of the defense industrial base; and
- Replaces unnecessarily burdensome compliance processes with scalable and realistic security measures.
The task force is expected to provide its recommendations to DoW chief information officer within 60 days. DoW has also issued a public Request for Information titled “Reforming CMMC and Reducing Compliance Burden for the Defense Industrial Base.” Responses are due by noon eastern on August 14, 2026. DoW has also planned listening sessions across the country.
On June 23, 2026, the Office of Federal Procurement Policy within the Office of Management and Budget, together with the Department of Defense, General Services Administration (GSA), and National Aeronautics and Space Administration (collectively, the Federal Acquisition Regulatory Council, or FAR Council), jointly issued four proposed rules in the Federal Register1 amending the Federal Acquisition Regulation (FAR). The four proposed rules are part of the “revolutionary FAR overhaul” implementing Executive Order 14275, Restoring Common Sense to Federal Procurement.
As part of that overhaul, the proposed rule addressing FAR Parts 1, 2, 4, 33, 39, 40, and 53 would affect Federal implementation of the Federal CUI program established by the National Archives and Records Administration (NARA). The rule proposes a common mechanism, “Standard Form XX, CUI Requirements,” to create a uniform process for identifying the CUI contractors must manage and safeguard under a given contract, and incorporates safeguards and incident reporting requirements similar to existing requirements under DFARS.
Background: The 2025 CUI proposed rule
On January 15, 2025, the FAR Council issued FAR Case 2017-016, Controlled Unclassified Information. That proposed rule, with minor adjustments, makes up the majority of the changes to the federal CUI program included in the FAR overhaul, including Standard Form XX, CUI incident-reporting requirements, and applicability to subcontractors, but the overhaul proposes a number of structural changes to the 2025 proposed rule.
A new home in FAR Part 40
The proposed rule reflects the FAR overhaul’s broader structural philosophy in how it treats CUI. Rather than retaining the CUI provisions in FAR Part 4, where the 2025 proposed rule had placed them, the new proposal relocates them to a consolidated and expanded FAR Part 40, Information and Supply Chain Security. Part 40 would now house security-related requirements previously dispersed across several FAR parts. These include three subparts: (1) Processing Supply Chain Risk Information, (2) Security Prohibitions and Exclusions, and (3) Safeguarding Information. The CUI requirements sit within “Safeguarding Information,” alongside other national-security-oriented procurement controls the FAR Council has incorporated into Part 40. Consistent with that consolidation, the proposed CUI clauses have been renumbered: the core obligations would now appear at FAR 52.240-7, Controlled Unclassified Information, with the accompanying solicitation provision at FAR 52.240-6 and the covered federal information clause at FAR 52.240-5.
Alignment with existing requirements
The proposed rule would require contractors to comply with both the security requirements of NIST SP 800-171 Revision 3 and any requirements from NIST SP 800-172 identified by the contracting agency. This tracks recent cybersecurity guidance published by GSA, which cites NIST SP 800-171 Revision 3, and similarly allows for agencies to consider additional requirements. The FAR proposal and GSA guidance do not neatly align with the existing DFARS/CMMC framework, which is based on NIST SP 800-171 Revision 2. Contractors whose customers include both DoD and civilian agencies could be required to comply with both versions under the proposed rule.
Two key changes from the 2025 proposal
The proposed rule makes two substantive changes to the 2025 proposal that contractors should note. First, it deletes the previously proposed clause FAR 52.204-YY, Identifying and Reporting Information That Is Potentially Controlled Unclassified Information, which had applied requirements even to contracts where no CUI was expected. Second, and more significantly, the rule extends the CUI incident-reporting timeline from the eight hours proposed in January 2025 to 72 hours from discovery. The FAR Council made this change in part to standardize the reporting timeline across all Part 40 security requirements, so the same 72-hour window applies both to CUI incident reports and to other reporting obligations now housed in Part 40. The 72-hour timeframe also aligns with existing DFARS reporting requirements.
Cloud security and subcontractor flow-down
For contractors that rely on cloud service providers to store, process, or transmit CUI identified on the Standard Form XX, the proposed rule sets a floor: The provider must meet security requirements equivalent to the FedRAMP Moderate baseline. The proposed rule also retains the requirement that prime contractors flow down applicable CUI safeguarding and reporting obligations to subcontractors that handle the same information. As under the January 2025 proposal, the requirements would apply to contracts and subcontracts regardless of dollar value and to commercial products and services, with an exception for acquisitions solely for commercially available off-the-shelf (COTS) items.
What’s next
If finalized, the rule would create a common mechanism, through use of the Standard Form XX, for identifying and communicating the information contractors must manage and safeguard, determining when a CUI incident must be reported, and flagging which incident-reporting requirements differ from those in the existing clause at FAR 52.240-7. The proposed rule had a 30-day comment period, which closed on July 23, 2026. The rule does not specify a date for the new clauses, if finalized, to appear in solicitations and contracts, but given the short comment period, a comparatively quick finalization and implementation process is anticipated.
Continue complying with existing cybersecurity requirements. Contractors handling CUI should continue implementing and maintaining the NIST SP 800-171 Revision 2 requirements incorporated through DFARS 252.204-7012. Contractors should also continue completing any applicable CMMC self-assessments, SPRS submissions and affirmations. The suspension of third-party assessments does not suspend those requirements.
Review pending DoW solicitations. Offerors should identify solicitations containing Level 2 C3PAO or Level 3 DIBCAC requirements and monitor them for amendments. Where an amendment has not yet been issued, offerors may wish to seek clarification from the contracting officer rather than assume that the requirement no longer applies.
Review existing contracts and upcoming options. Contractors should identify contracts containing independent-assessment requirements and determine whether an option period or administrative modification is approaching. Any removal of the requirement should be documented through a formal contract modification.
Reevaluate – but do not necessarily abandon – C3PAO preparations. Contractors with scheduled assessments should evaluate cancellation and postponement rights, sunk costs, customer expectations and the possibility that independent assessments will remain part of the revised program. Subcontractors with CMMC Level 2 C3PAO assessment requirements should continue to pursue that certification. Even without Prime requirements, documentation developed for a C3PAO assessment may be valuable for self-assessments and demonstrating compliance with existing contractual requirements.
Consider responding to the CMMC RFI. Companies experiencing assessment-capacity constraints, disproportionate compliance costs, uncertainty regarding scoping or difficulties flowing requirements through the supply chain have an opportunity to provide DoW with specific examples and potential alternatives.
Assess exposure beyond DoD. Contractors that have never held defense contracts, but do business with civilian agencies, should evaluate whether they handle CUI and prepare for safeguarding and reporting obligations comparable to those long familiar to the defense industrial base.
Prepare for two NIST baselines. Contractors serving both DoD and civilian customers should evaluate whether, and how, they will need to satisfy both NIST SP 800-171 Revision 2 (as incorporated through DFARS 252.204-7012 and referenced by CMMC) and NIST SP 800-171 Revision 3 plus applicable SP 800-172 controls under the proposed FAR rule.
Once again, no. After years of rulemaking and the start of contractual implementation, DoW has paused CMMC before its most consequential phase and reopened fundamental questions about the program’s design. At the same time, the FAR Council has proposed extending CUI safeguarding and reporting obligations well beyond the defense sector, to nearly every federal contractor and subcontractor. Taken together, these developments only underscore the importance of cybersecurity compliance programs in Federal contracting.
For now, CMMC remains in Phase 1, DFARS 252.204-7012 remains in effect, and the proposed FAR CUI rule is only that: proposed. Contractors, whether they hold defense contracts, civilian contracts, or both, should continue strengthening and documenting their cybersecurity programs, closely track DoW’s 60-day CMMC review, and watch for the FAR Council’s next move on the CUI overhaul.
1 Federal Register :: Federal Acquisition Regulation: Revolutionary Federal Acquisition Regulation Overhaul Parts 1, 2, 4, 33, 39, 40, and 53
Federal Register :: Federal Acquisition Regulation: Revolutionary Federal Acquisition Regulation Overhaul Parts 6, 7, 10, 18, 26, 37, and 41
Federal Register :: Federal Acquisition Regulation: Revolutionary Federal Acquisition Regulation Overhaul Parts 5, 24, and 29
Federal Register :: Federal Acquisition Regulation: Revolutionary Federal Acquisition Regulation Overhaul Parts 3 and 49