FAR Council proposes civilian CUI rule after 15-year gap
The proposal replaces agency improvisation with a contract-marking regime, then gives industry 30 days to parse the buried rewrite.
TL;DR
Federal News Network reports the FAR Council has proposed a government-wide controlled unclassified information (CUI) rule for civilian agencies, built around a standard form and contracting officer directions for identifying and marking CUI. Contractors, primes and subs would get one baseline for scope and flowdown; Cybersecurity Maturity Model Certification (CMMC) third-party assessment organizations (C3PAOs) will have to track the NIST SP 800-171 Revision 3 split from CMMC’s Revision 2 work. The rule still arrives inside the larger FAR overhaul with 30 days for comment, and its effective date and existing-contract treatment remain unresolved.

Federal News Network’s interview with Haynes Boone partner Zach Prince describes a FAR Council proposal that would put a government-wide contract mechanism around civilian agency controlled unclassified information (CUI), a category agencies have handled unevenly since the 2010 rollout mandate. The operating change is the standard form. Contractors would safeguard CUI identified through that form, and contracting officers would have to say whether the contract contains CUI and how it must be marked.
That matters because the DoD model has often put the clause in the contract and left contractors to decide whether the data they touch is CUI. The FAR proposal would make a failure to designate CUI a contract problem, potentially requiring a modification, the applicable clause and an equitable adjustment. For contractors, that turns marking from a scavenger hunt into a document-control obligation. The document can still be wrong, but at least it exists.
The timing is less clean. Prince says the CUI rule drew industry pushback after the January 2025 proposal, went quiet, and then resurfaced as one small piece of the broader FAR overhaul with 30 days for comment. That is a short lane for a rule touching contract clauses, marking, training, incident reporting, subcontract flowdowns and NIST Special Publication 800-171 Revision 3.
Revision 3 is the practical fault line. DoD’s Cybersecurity Maturity Model Certification (CMMC) Level 2 work remains tied to Revision 2 for now, while the FAR Council proposal points civilian agencies at Revision 3. Contractors that sell to both sides can treat Revision 3 as the higher target, but they still need to map the extra requirements into controls, evidence and proposals. CMMC third-party assessment organizations (C3PAOs) will get pulled into that evidence conversation.
The unresolved questions are the ones counsel and contracting teams need before this becomes a clause-library exercise: when the rule takes effect, whether existing contracts get modified, and how agencies with their own implementations, Prince singled out Homeland Security, align with the FAR baseline. The proposal is cleaner than the current civilian patchwork. It still risks a messy rollout because the clock is short and the rule is easy to miss.
Published ·Deep Fathom