FAR CUI Rule vs. CMMC: What Government Contractors Need to Know
by Jordan Dean on Sep 21, 2026

Government contractors have another CUI requirement to watch.
The FAR CUI Rule vs. CMMC comparison starts with an important distinction.
Both address Controlled Unclassified Information (CUI), but they serve different purposes and cover different parts of government contracting.
As of August 2026, the FAR CUI rule remains a proposal. The revised version was published June 23, 2026. It would establish governmentwide CUI requirements through FAR 52.240-6, FAR 52.240-7, and a standardized CUI form.
Cybersecurity Maturity Model Certification (CMMC) is in a different position. Phase II was suspended on July 13, 2026, before its planned November 10 start. Phase I self-assessment requirements remain active. Existing Defense Federal Acquisition Regulation Supplement (DFARS) requirements also remain in place.
So, contractors should keep moving on current obligations while watching what changes next.
Read RADICL’s update on the CMMC Phase II pause.
Key Takeaways
- Scope: The proposed FAR CUI rule could affect contractors handling CUI across government agencies. CMMC applies through defense contracts.
- Requirements: The proposed FAR rule uses National Institute of Standards and Technology Special Publication (NIST SP) 800-171 Revision 3. Current CMMC Level 2 requirements use Revision 2.
- Current action: Contractors should protect CUI, maintain evidence, review contract clauses, and complete applicable self-assessments while both programs evolve.
What Is the Proposed FAR CUI Rule?
The proposed FAR CUI rule would give government agencies a more consistent way to identify CUI requirements in contracts.
Today, contractors may encounter different instructions depending on the agency, contract, or information involved. The proposal gives agencies and contractors a common mechanism for communicating those requirements.
A key piece is the proposed Standard Form XXX, Controlled Unclassified Information Requirements. Agencies would use the form to identify the CUI involved in a contract and the applicable controls. Contractors whose work does not involve CUI would not receive the form or fall under the proposed CUI provisions.
The proposal includes several requirements government contractors should understand:
- FAR 52.240-6, Notice of Controlled Unclassified Information Requirements: This provision would communicate CUI requirements before award.
- FAR 52.240-7, Controlled Unclassified Information: This clause would establish contractor responsibilities for handling CUI.
- Standard Form XXX: The form would identify the CUI categories involved and applicable safeguarding requirements.
- NIST SP 800-171 Revision 3: Contractors operating nonfederal systems that handle covered CUI would follow Revision 3 requirements.
- Selected NIST SP 800-172 requirements: Agencies could add enhanced requirements for critical programs or high-value assets.
- Cloud security requirements: Cloud providers storing, processing, or transmitting CUI would need security equivalent to the Federal Risk and Authorization Management Program (FedRAMP) Moderate baseline.
- Incident reporting: Contractors would generally have 72 hours to report a CUI incident in a nonfederally controlled facility.
- Subcontractor flowdown: Requirements would extend to applicable subcontractors that can access contract CUI.
- Plan of Action and Milestones disclosures: An offeror that cannot meet a FAR 52.240-7 requirement would identify the gap and submit a Plan of Action and Milestones (POA&M) with its offer.
The proposed requirements generally apply when CUI is involved in contract performance. Solicitations and contracts solely for Commercially Available Off-the-Shelf (COTS) items would receive a limited exception.
The public comment period closed July 23, 2026. A final rule and effective date have not yet been announced.
Tip: For more background, see RADICL’s guides to NIST SP 800-171 and NIST 800-171 compliance.
What Is CMMC, and How Does It Apply to CUI?
CMMC takes a different approach. It is a defense contracting program that assesses whether contractors meet required cybersecurity practices.
A practical CMMC CUI definition starts with the governmentwide definition. CUI is government-created or government-related information that law, regulation, or governmentwide policy requires safeguarding or dissemination controls for.
CMMC organizes requirements into three levels.
- CMMC Level 1 focuses on Federal Contract Information (FCI). It uses 15 safeguarding requirements aligned with FAR 52.204-21.
- CMMC Level 2 focuses on CUI. It currently uses all 110 security requirements from NIST SP 800-171 Revision 2.
- CMMC Level 3 adds 24 selected NIST SP 800-172 requirements to the Level 2 baseline for higher-priority programs facing more advanced threats.
That last level is where searches around CMMC Level 3 CUI often create confusion. Level 3 does not introduce a new type of CUI. It adds enhanced security requirements for certain environments that already need to protect CUI.
CMMC also defines how organizations demonstrate their status.
Level 1 uses annual self-assessments. Under the current Phase I program, applicable Level 2 organizations may also complete self-assessments. CMMC originally planned to expand Certified Third-Party Assessment Organization (C3PAO) assessments under Phase II beginning November 10, 2026.
That expansion is now suspended while the Department reviews the program. Current Phase I self-assessment requirements remain active.
The pause also does not remove existing DFARS requirements. Contractors covered by DFARS 252.204-7012 must continue to protect applicable information and comply with their contract requirements. That clause also retains its 72-hour cyber incident reporting requirement.
Tip: For a deeper explanation, read The Complete Guide to CMMC, explore RADICL CMMC compliance support, or review DFARS 252.204-7012.
FAR CUI Rule vs. CMMC: Key Differences
The biggest difference is what each program is designed to do.
The CUI FAR clause proposal would standardize how government contracts identify, safeguard, and report CUI. CMMC establishes cybersecurity assessment requirements for defense contractors.
|
Comparison Point |
Proposed FAR CUI Rule |
CMMC |
|
Current status |
Proposed rule with no final effective date |
Phase I active; Phase II suspended for review |
|
Primary scope |
Government contractors and subcontractors handling CUI across agencies |
Contractors and subcontractors covered by defense contract requirements |
|
Main purpose |
Establish consistent contract requirements for identifying, safeguarding, and reporting CUI |
Assess and record a contractor’s cybersecurity status |
|
Security baseline |
Proposed NIST SP 800-171 Revision 3 |
Currently NIST SP 800-171 Revision 2 at Level 2 |
|
Higher requirements |
Agencies may add selected NIST SP 800-172 requirements |
Level 3 adds 24 selected NIST SP 800-172 requirements |
|
Contract mechanism |
Proposed FAR 52.240-6, FAR 52.240-7, and Standard Form XXX |
DFARS CMMC provisions, clauses, and CMMC status records |
|
Assessment approach |
Contract compliance, disclosures, documentation, and agency validation through normal contract administration |
Self-assessment, third-party assessment, or government assessment based on level and program phase |
|
POA&M treatment |
Offerors would disclose unmet requirements and provide a POA&M |
Conditional CMMC status permits limited POA&M use under defined rules |
|
Incident reporting |
Proposed 72-hour reporting for applicable CUI incidents |
DFARS 252.204-7012 requires 72-hour cyber incident reporting |
|
Cloud services |
Equivalent to FedRAMP Moderate when cloud providers handle covered CUI |
Requirements depend on applicable DFARS clauses and the provider’s role |
|
Subcontractors |
Proposed flowdown when subcontractors can access CUI |
CMMC and DFARS requirements may flow down based on the information and contract |
The FAR proposal would give agencies a common governmentwide mechanism for contract-level CUI requirements. CMMC adds a defined cybersecurity assessment and status model for defense procurement.
Work completed for one may help with the other. Contractors should still avoid assuming that one automatically satisfies the other.
For example, a current CMMC assessment can provide useful evidence about NIST SP 800-171 implementation. It does not automatically address every Revision 3 change or future FAR contract requirement.
Tip: Defense contractors can also review how Supplier Performance Risk System scores relate to cybersecurity requirements.
Where the FAR CUI Rule and CMMC Overlap
Although the programs differ, they share much of the same operational foundation.
Both require contractors to know where CUI exists and which systems interact with it. That includes email, collaboration platforms, file sharing, cloud environments, engineering applications, user devices, and third-party services.
Both also depend heavily on accurate documentation.
A System Security Plan (SSP) should describe the real environment. POA&Ms should accurately document eligible gaps and planned work. Evidence should support what the organization says it has implemented.
The relationship between CUI CMMC preparation and the proposed FAR requirements is especially important for current Level 2 contractors.
Existing Revision 2 work can provide a strong starting point. Asset inventories, system boundaries, policies, access controls, security logs, and assessment evidence do not lose their value because another rule references Revision 3.
However, Revision 3 is not simply a renamed version of Revision 2.
Organizations would need to evaluate changed requirements and new organizationally defined parameters. They would also need to review Standard Form XXX, agency-specific CUI requirements, cloud providers, and subcontractor responsibilities.
The proposed FAR language can also require selected NIST SP 800-172 controls for critical programs or high-value assets.
For organizations trying to narrow the number of systems involved, a CMMC enclave can help define a controlled subsection of the business where CUI is handled.
How Contractors Can Prepare for Both Requirements
Contractors do not need to predict exactly how every rule will change. They do need a clear picture of their current environment.
Review Contracts and Identify Applicable Clauses
Start with what is enforceable today.
Inventory prime contracts, subcontracts, active solicitations, and flowdown requirements. Confirm which contracts involve FCI, CUI, or both.
Separate existing DFARS and CMMC obligations from proposed FAR requirements. That keeps teams from treating future requirements as current contract terms.
It also helps identify where a finalized FAR rule could create new work.
Map Where CUI Is Handled
Document the full CUI lifecycle. Where is CUI created? Where is it stored? Which users can access it? How does it move between your team, the government, prime contractors, and subcontractors? Include:
- Endpoints
- Identity systems
- Cloud services
- File-sharing applications
- Engineering tools
- Backups
- External providers
- Remote access
- Physical records where applicable
This mapping helps define the compliance boundary and exposes systems that may otherwise be overlooked.
Compare Revision 2 and Revision 3 Requirements
Current CMMC Level 2 work remains important.
Organizations should continue meeting their existing Revision 2 obligations. At the same time, they can compare those requirements with Revision 3.
Focus on what changes operationally. Identify new documentation needs, revised control expectations, organizationally defined parameters, and systems that may need additional review.
This creates a transition plan without disrupting current CMMC work.
Review CUI Transfer and Protection Tools
Tools deserve review, but product labels do not determine compliance.
When evaluating CMMC-compliant CUI transfer tools, confirm they meet your contract and environment requirements. Relevant capabilities can include:
- Access controls
- Encryption
- Audit logging
- Data retention
- User authentication
- Support for the defined CUI boundary
- Provider documentation
- Evidence needed for assessments
The same principle applies when teams compare CUI protection tools for CMMC Level 2 compliance.
A secure file-sharing platform may solve one part of the problem. It cannot replace identity controls, endpoint protections, logging, policies, training, or assessment evidence.
The proposed FAR rule also makes cloud-provider requirements important. Cloud services that store, process, or transmit covered CUI would need security equivalent to FedRAMP Moderate.
Maintain Evidence and Incident-Response Readiness
Strong evidence makes it easier to understand your current position and prepare for future changes. Keep documentation current, including:
- System Security Plans
- Applicable POA&Ms
- Access records
- Configuration evidence
- Security logs
- Supplier documentation
- Incident-response procedures
- Evidence supporting self-assessment statements
Evidence should reflect the systems and controls operating today.
RADICL’s Managed Compliance Adherence gives growing businesses access to compliance consultants throughout that process. Consultants can answer specific questions, review evidence, and validate submissions for assessment readiness.
RADICL provides guidance on compliant implementation. Your team or Managed Service Provider (MSP) completes the hands-on implementation work.
Other services can support the security operations behind that evidence.
Managed Log Analytics provides ongoing visibility into security data, while the CMMC Readiness Calculator helps you understand where you stand in preparation.
Keep CUI Protection Moving as Requirements Evolve
The proposed FAR CUI rule and CMMC are moving on different timelines, but contractors do not need two completely separate compliance programs.
The FAR proposal could create a consistent governmentwide approach to CUI in contracts. CMMC remains focused on cybersecurity assessments for defense procurement.
Current obligations still come first. Follow your existing contract clauses, protect CUI, complete required self-assessments, and maintain reliable evidence.
From there, prepare for changes. Review Revision 3, understand supplier dependencies, and track updates to both the FAR proposal and CMMC.
RADICL compliance consultants can help you work through organization-specific questions, review evidence, and validate submissions before an assessment.
Speak with RADICL about your current CUI requirements and assessment readiness.
FAQs
Is the FAR CUI rule final?
No. The revised FAR language published June 23, 2026, remains proposed. The public comment period closed July 23, 2026. As of August 2026, the FAR Council has not published a final rule or effective date. Continue following the clauses in your active contracts while monitoring the rule-making process.
Does CMMC compliance satisfy the proposed FAR CUI rule?
You should not assume automatic reciprocity.
The programs overlap substantially, especially around CUI protection and NIST SP 800-171. However, current CMMC Level 2 uses Revision 2. The proposed FAR CUI rule would require Revision 3 for applicable nonfederal systems.
The FAR proposal also introduces Standard Form XXX and other contract-specific requirements that CMMC does not replace.
Did the CMMC Phase II suspension remove CUI requirements?
No. The July 13, 2026, suspension stopped the planned move to CMMC Phase II while the program undergoes review. Phase I self-assessment requirements remain active.
Existing DFARS safeguarding requirements also continue. Contractors covered by DFARS 252.204-7012 should continue to protect covered information and maintain evidence that supports their cybersecurity requirements.
Which NIST SP 800-171 revision should contractors follow?
Follow the version required by your current contract. Current CMMC Level 2 requirements use the 110 security requirements in NIST SP 800-171 Revision 2.
If finalized as proposed, the proposed FAR CUI rule would require Revision 3 for applicable contractor-operated nonfederal systems. Do not move away from current Revision 2 obligations simply because a proposed rule references Revision 3.
- DIB Innovators (133)
- Podcast (133)
- Industry Analysis (109)
- Threat Hunting and Intelligence (32)
- Regulatory Compliance (25)
- CMMC (16)
- Attack Surface and Vulnerability Management (15)
- Signal & Noise (11)
- Zero Gravity Summit (11)
- General (7)
- Security Operations & vSOC (6)
- Testimonials (6)
- Company (5)
- Founder (4)
- Incident Response (3)
- Managed Security Operations (3)
- Operational Resilience (2)
- Threat Management (2)
- The RAID Party (1)
- Webinar (1)
You May Also Like
These Related Stories

EP 21 - AWS's Travis Goldbach on Cloud Security and Zero Trust for Defense Contractors

CMMC Compliance Deadline 2026: Key Dates That Affect Your DoD Contract
%20(1).png)
No Comments Yet
Let us know what you think