"It's going to be a sea change for a lot of companies," said Trayce Howard, a government contracts partner at Wiley Rein, summing up the stakes for federal contractors as new rules for handling controlled unclassified information (CUI) move toward finalization.
72‑hour reporting requirement and alignment with CIRCIA
The proposed rule would require federal contractors handling CUI to report unauthorized access — including access resulting from cyberattacks — to the government within 72 hours of discovery. The 72‑hour timeline is deliberately aligned with forthcoming rules from the Cybersecurity and Infrastructure Security Agency (CISA) under the Cybersecurity Incident Reporting for Critical Infrastructure Act (CIRCIA) that will require critical‑infrastructure owners and operators to report major cyber incidents.
Earlier drafts of the regulation proposed an 8‑hour reporting standard and required reporting of suspected incidents; industry objections prompted revision to the 72‑hour window. Still, several industry groups said even 72 hours is difficult to meet: the Aerospace Industries Association urged extending timelines to 30 calendar days, calling compressed timelines “difficult and costly for industry to comply with.” The Chamber of Commerce flagged that the June 2026 rulemaking appears to require reporting to agency‑specific points of contact rather than a single centralized hub.
NIST SP 800‑171 controls and subcontractor flow‑downs
The rule would impose minimum electronic security standards on contractors handling CUI based on the National Institute of Standards and Technology’s SP 800‑171. Attorneys quoted in the reporting said those standards would be applied “on a broader group of contractors than ever before.”
Contractors will likely need to identify CUI they provide to subcontractors and ensure flow‑down of requirements and oversight of subcontractor compliance. As Trayce Howard put it, prime contractors “are going to have to identify what CUI am I giving to my subcontractors, and do some sort of oversight to make sure that their subcontractors are appropriately handling CUI.”

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleFalse Claims Act exposure and enforcement dynamics
Experts warned the proposed rule could expand the universe of contractors exposed to False Claims Act (FCA) liability. The reporting notes that the federal government has used the FCA “increasingly since 2022 to punish contractors over lackluster cyber safeguards.” Several commentators said the new rule’s certification and compliance expectations may create significant FCA risk for contractors who have worked exclusively with civilian agencies and were not previously subject to similar regimes.
That risk could cascade through supply chains if primes are required to attest to subcontractor practices and later face enforcement for failures to secure CUI or to report incidents within prescribed windows.
How contractors, subcontractors, and CISA/DOD are positioned
- Contractors and procurement leaders: Need to inventory what constitutes CUI, prepare to implement NIST SP 800‑171 controls, and establish oversight for subcontractors; the proposal’s timing means many firms should begin preparations now rather than waiting for final text, attorneys advised.
- Subcontractors: May face new flow‑down obligations and scrutiny from primes; firms that historically served civilian agencies could find themselves newly subject to these standards and to enforcement risk under the False Claims Act.
- CISA, DOD and civilian agencies: The rule is intended as a companion to existing Defense Department rules covering CUI and to align civilian reporting with CISA’s forthcoming CIRCIA requirements; observers noted uncertainty about whether reporting will be centralized into CISA or continue as agency‑specific streams.
Timing, open questions, and next steps for contractors
The timetable for a final rule is unsettled but compressed. One attorney said a final rule could arrive “by the end of the year,” while another allowed that an interim rule could take effect soon or that a final rule might still be issued. A third observer cautioned a final rule could be farther away but noted the administration has signaled a desire to finalize everything before the end of its term. The Office of Management and Budget did not respond to requests for comment.
Contractors should therefore take the reporting and security expectations seriously: the proposal both broadens the set of firms covered and ties reporting timelines to CISA’s incident‑reporting regime. Questions remain about centralized versus agency‑specific reporting and how the government will administer flow‑downs in complex supply chains — issues that will shape compliance burdens and enforcement risk if the rule is finalized in its current form.
Read the original story: https://cyberscoop.com/federal-contractors-cui-cybersecurity-rules/




