CMMC Paused. The FAR CUI Rule Didn't.

On June 23, 2026, the FAR Council published a proposed rule that would extend controlled unclassified information (CUI) safeguards to every federal contractor that handles CUI, civilian agencies included, for the first time. Ten days later, on July 13, the Department of War (DoW, formerly DoD) suspended CMMC Phase 2. The two events ran in opposite directions, and much of the coverage ran them together as one story. They are not one story.

The CMMC suspension is a DoD-only event. It removed the third-party C3PAO assessment while leaving DFARS 252.204-7012 and the underlying NIST SP 800-171 Rev 2 obligations in force, and I have written about that side in the memo-not-a-rule post and the contractor-risk post. The FAR CUI rule is a different rulemaking on a different track. It is government-wide, it is still moving, and the pause does not touch it. McDermott’s headline states the dynamic plainly: “FAR Council speeds up CUI rules while DoW slows down.”

Two tracks, one standard

CUI obligations have been a DoD story since 2017, imposed through DFARS 252.204-7012. The government-wide track has been a gap for more than a decade. Executive Order 13556 created the CUI program in 2010, and NARA’s implementing rule followed in 2016 (81 FR 63324), but the FAR Council never finished the contracting side. Civilian agencies patched the hole with agency-specific requirements while defense contractors carried NIST SP 800-171 alone.

NIST moved first on the baseline. SP 800-171 Rev 3 was published May 14, 2024, and it reorganizes the 110 controls into 17 control families, up from 14. Then the FAR Council tried twice. In January 2025 it proposed a standalone CUI rule (FAR Case 2017-016, 90 FR 4278) built on Rev 2 with 8-hour incident reporting, and Holland & Knight covered that version for non-defense contractors. Rather than finalize it, the administration folded it into the “Revolutionary FAR Overhaul” started by Executive Order 14275 in April 2025. On June 23, 2026, the FAR Council published FAR Case 2026-001 (RIN 9000-AO86, 91 FR 37550, 85 pages), which supersedes the January 2025 proposal and relocates CUI safeguarding into a new, expanded FAR Part 40, “Information Security and Supply Chain Security”. Comments closed July 23, 2026, after a 30-day window.

What the proposed rule would do

The core obligation has three parts. Contractors whose systems handle CUI would have to meet NIST SP 800-171 Rev 3, report CUI incidents within 72 hours of discovery, and flow both obligations down to subcontractors that receive CUI. The rule applies to commercial product and commercial service contracts, with the only carve-out being contracts solely for commercially available off-the-shelf (COTS) items.

The obligations sit in three instruments: a solicitation provision (FAR 52.240-6), a contract clause (FAR 52.240-7), and a new standard form, referenced as SF XXX, that the procuring agency fills out to identify the CUI in play. Most of this is a burden reduction, and the form is the quiet part of it. For the first time, the government has to tell a contractor in the contract exactly what CUI it must protect, instead of leaving the contractor to infer scope the way DFARS 7012 has forced for years.

The baseline is Rev 3, not Rev 2. An offeror that cannot meet it at proposal must disclose the gaps and submit a plan of action and milestones. Agencies may layer NIST SP 800-172 controls on top for critical programs and high-value assets. Cloud services handling CUI must meet a FedRAMP Moderate-equivalent baseline. VDI endpoints configured so no CUI is processed, stored, or transmitted beyond keyboard, video, and mouse sit outside that scope.

The two-baseline fork

This is where the divergence matters most for a contractor that holds both defense and civilian work. DFARS 252.204-7012 is still anchored to NIST SP 800-171 Rev 2, confirmed as the interim baseline by the May 2, 2024 class deviation. The FAR proposal mandates Rev 3. Morrison Foerster notes it is “unclear when, if at all, the Department of War plans to revise the DFARS to match the FAR.” A dual-track contractor could face Rev 2 on its DoD contracts and Rev 3 on its civilian ones at the same time, with no announced plan to reconcile them.

Rev 3 is not a renumbering. It adds real implementation work, from software inventory to system use restrictions and tighter access control. The only official cost estimate traces to the January 2025 Rev 2 proposal, so treat it as a floor rather than a number. Hunton puts first-year costs around $148,200 for a small business and $543,400 for other-than-small, with recurring costs of roughly $98,800 and $494,000. A Rev 3 baseline will likely move those figures.

The temptation to read the CMMC pause as permission to slow down fails exactly here. Pausing spend because “CMMC is suspended” leaves the civilian-side Rev 3 obligation untouched. The pause removed third-party verification on the DoD track. It did nothing to the government-wide track. Sheppard Mullin puts it without hedging: “this action does nothing to the governmentwide CUI rule, now folded into the June 23, 2026, FAR Overhaul rulemaking.”

No assessor, no attestation

The two tracks share a shape. Both descend from NIST SP 800-171, both require incident reporting, and both flow down to subcontractors. They differ on what sits on top. CMMC adds a third-party C3PAO assessment, the layer the pause suspended, plus a self-attestation mechanism in the SPRS score and the annual affirmation. The FAR rule has neither. There is no third-party assessment and no affirmation requirement in the proposed rule. The rule asks for the outcome, systems that meet Rev 3, and, at the offer stage, a disclosure of any gaps with a plan of action and milestones. The POA&M is a disclosure, not an attestation of compliance.

That makes the FAR rule lighter on process than CMMC. The enforcement picture is thinner too. The proposed rule names no penalties. Mayer Brown cautions that a CUI incident or a misrepresented security posture can still expose a contractor to termination, suspension or debarment, or False Claims Act liability under DOJ’s Civil Cyber-Fraud Initiative. The exposure comes from misrepresenting what you did, not from a new attestation the rule creates.

The revised proposal also loosened several requirements from the January draft. Incident reporting moved from 8 hours to 72 hours, aligned with DFARS 7012 and CIRCIA. The “CUI incident” definition narrowed, dropping “suspected” incidents and carving out improper handling that does not result in disclosure, modification, destruction, or unauthorized access. Contractor-liability language came out, the one-size-fits-all training mandate became a flexible framework, and the 8-hour mismarking-report requirement was dropped. Subcontractors now report directly to the government rather than only up the chain, with civilian reports going to a CISA portal and DoD reports continuing to DIBnet.

What to do now, and the discipline that matters

Status discipline first. This is a proposed rule. There is no final rule and no effective date, and as of the 2026 Unified Agenda, RIN 9000-AO86 sits at the Proposed Rule Stage. One vendor has floated the idea that the rule will finalize before the end of 2026, but that is vendor reporting, not the rule itself. Mayer Brown is explicit that the proposal does not forecast a timeline for implementation.

That does not make it comfortable to wait. A few moves keep their value no matter how the final rule lands. Keep the control-implementation spend, because the Rev 2 to Rev 3 delta is no-regrets work whether or not the rule finalizes this year. Build the SF XXX intake and subcontract flow-down templates now, before the scoping has to happen under a proposal deadline. Align incident response to 72 hours, since that number already matches DFARS 7012 and CIRCIA. Disclose POA&Ms at the offer stage rather than after award, because a gap disclosed in the proposal is easier to defend than one found in a later review.

The research community is already pushing on scope, which is a signal about where the final rule may move. EDUCAUSE’s August comments ask the FAR Council to clarify the fundamental-research exclusion, to stop making contractors infer unmarked CUI, and to make sure POA&M disclosures do not become a competitive disadvantage. Those comments are the live fight over how much of this burden actually lands.

The CMMC pause got the headline. The FAR CUI rule kept moving, on a higher baseline, to a broader set of contractors. A defense contractor that reads the pause as permission to slow cybersecurity spend is misreading the calendar.

Sources

  1. Federal Register — Revolutionary FAR Overhaul, Parts 1, 2, 4, 33, 39, 40, and 53 (FAR Case 2026-001, 91 FR 37550) (June 23, 2026)
  2. Acquisition.GOV — FAR Federal Register Publications Requesting Comments
  3. NIST CSRC — SP 800-171 Rev. 3, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations
  4. Wiley — FAR Council Proposes Consolidated Part 40 Framework for Security and Supply Chain Compliance
  5. Wiley — FAR Council Proposes Revised CUI Framework as Part of Revolutionary FAR Overhaul
  6. Mayer Brown — FAR Council Proposes Revised CUI Safeguarding and Incident-Reporting Framework, While DoW Pauses CMMC Implementation (July 2026)
  7. Morrison Foerster — New Proposed Rule Would Implement Government-wide Safeguarding and Disclosure Requirements for CUI
  8. Holland & Knight — FAR Council Proposes Compliance with NIST SP 800-171 for Non-Defense Contractors (Feb 2025)
  9. Government Contracts Law (Sheppard Mullin) — DoD Suspends CMMC Phase 2: What Happened, What It Means, and What Nobody Is Telling You (July 2026)
  10. McDermott — FAR Council speeds up CUI Rules while DoW slows down
  11. Hunton — FAR Council Releases Updated CUI Proposed Rule as Part of the Revolutionary FAR Overhaul
  12. EDUCAUSE — EDUCAUSE Encourages Continued Improvement of FAR CUI Requirements (Aug 2026)
  13. Reginfo.gov — 2026 Unified Agenda, DOD/GSA/NASA (FAR) Agency Rule List
  14. Summit 7 (vendor) — The FAR CUI Rule: A Long-Awaited Milestone in Federal Cybersecurity (vendor source; conflates the superseded January 2025 proposal with the June 2026 revision)