Full Report
CMMC Phase 2 is paused, but the FAR CUI proposed rule pushes NIST 800-171 obligations past the defense industrial base. Here's what changed, what didn't, and the 32 requirements you can't defer.
Analysis Summary
# Regulation/Compliance: FAR CUI Proposed Rule & CMMC Phase 1
## Overview
While the Department of Defense (DoD) has issued a "strategic pause" on CMMC Phase 2 (third-party certifications), the Federal Acquisition Regulation (FAR) Council has introduced a proposed rule that expands Controlled Unclassified Information (CUI) safeguarding requirements (NIST 800-171) beyond the Defense Industrial Base (DIB) to all federal contractors. Simultaneously, CMMC Phase 1 remains in full effect, requiring self-assessments and senior-level affirmations of cybersecurity scores.
## Key Details
- **Issuing Authority:** FAR Council (including DoD, GSA, and NASA) and the DoD.
- **Effective Date:** CMMC Phase 1 is currently in effect (since Nov 2025). The FAR CUI Rule is currently in the proposed rulemaking stage (published June 2026).
- **Jurisdiction:** All federal contractors handling CUI (Civilian and Defense).
- **Status:** Proposed (FAR CUI Rule) / In Effect (CMMC Phase 1 Self-Assessments).
## Requirements
### Mandatory Requirements
1. **NIST 800-171 Rev 3 Compliance:** The FAR Council has moved the baseline to the newer, more stringent Revision 3 (expanded from Revision 2).
2. **Annual Affirmation:** Senior company officials must annually affirm the accuracy of their SPRS (Supplier Performance Risk System) scores.
3. **Incident Reporting:** Contractors must report cyber incidents involving CUI within 72 hours (DFARS 252.204-7012).
4. **SPRS Scoring:** Contractors must maintain and submit accurate self-assessment scores to the DoD.
### Recommended Practices
1. **Logical Separation:** Utilizing "Sensitive Data Mode" or similar configurations to isolate CUI without necessarily requiring full FedRAMP cloud authorization.
2. **Continuous Monitoring:** Implementing Managed SIEM and 24/7 security monitoring to meet detection requirements.
## Affected Organizations
- **Industries:** The entire Federal Industrial Base (FIB), including civilian agency contractors (e.g., NASA, DHS, GSA) and the Defense Industrial Base (DIB).
- **Organization Size:** All sizes; no exemptions for small businesses handling CUI.
- **Geographic Scope:** Any organization (domestic or international) holding FAR-based contracts involving CUI.
## Compliance Timeline
- **November 2025:** CMMC Phase 1 (Self-Assessments) went into effect.
- **June 23, 2026:** FAR Council published the proposed CUI rule.
- **Sept/Oct 2026:** CMMC Reform Task Force expected to release recommendations.
- **November 10, 2026:** Original target for CMMC Phase 2 (currently paused/under review).
## Implementation Guidance
### Assessment Phase
- **Score Verification:** Conduct an internal audit against NIST 800-171 Rev 3 to ensure the SPRS score is defensible.
- **CUI Identification:** Work with contracting officers to use new FAR forms to identify exactly what data is classified as CUI and where it resides.
### Implementation Phase
- **Gap Remediation:** Address the "32 requirements you can't defer" (as noted in NIST 800-171) to ensure a minimum passing score.
- **Update Standards:** Transition internal policies from NIST 800-171 Rev 2 to Rev 3.
### Validation Phase
- **Executive Sign-off:** Ensure a senior official reviews the assessment, as they now face personal legal liability under the False Claims Act.
## Technical Requirements
- **Access Control:** Strict management of who can view or process CUI.
- **Monitoring & Logging:** 24/7 visibility into system activity (SIEM).
- **Security Baseline:** Adoption of all controls outlined in NIST 800-171 Rev 3.
## Penalties & Enforcement
- **Fines:** Significant monetary penalties under the **False Claims Act (FCA)** for misrepresenting compliance scores.
- **Other Consequences:** Suspension or debarment from federal contracting; loss of existing contracts.
- **Enforcement:** The DoD’s assessment teams (DIBCAC) are now cooperating directly with the **Department of Justice (DOJ)** to prosecute fraud without requiring a whistleblower.
## Related Standards
- **NIST 800-171 Rev 3:** The primary technical framework for safeguarding CUI.
- **DFARS 252.204-7012/7021:** The specific defense clauses governing CUI and CMMC.
- **FedRAMP:** While related, the article notes that logical separation may allow for CMMC compliance without full FedRAMP authorization in certain cloud contexts.
## Resources
- **Official Documentation:** [acquisition.gov](https://www.acquisition.gov) (Defanged)
- **Guidance Documents:** NIST 800-171 Revision 3 Final Draft.
- **Tools:** SPRS (Supplier Performance Risk System) portal.
## Practical Recommendations
- **Do Not Wait for Phase 2:** The "pause" only affects third-party audits. Self-assessments and NIST obligations are active now.
- **Review Rev 3:** If you were built for Rev 2, audit the delta between the versions immediately.
- **Legal Review:** Treat the annual affirmation of the SPRS score as a legal filing, not just a technical check.