★ ANNUAL REVIEW 2027 SPONSORSHIPS NOW OPEN   Learn more →

Log In  |  Become a Member  |  Sponsor  |  ⌕ Search

News/FAR Council Publishes Long-Awaited CUI Rule
Pub K

FAR Council Publishes Long-Awaited CUI Rule

On January 15, 2025, the FAR Council issued its long-awaited “CUI Rule” on the handling of  Controlled Unclassified Information (CUI).  CUI is defined as Information that the government creates or possesses, or that an entity creates or possesses for or on behalf of the government, that a law, regulation, or governmentwide policy requires or permits an agency to handle using safeguarding or dissemination controls.

CUI in the Federal Government encompasses a variety of sensitive but unclassified information categories. Here are some examples:

  1. Personally Identifiable Information (PII): This includes any data that could potentially identify a specific individual, such as Social Security numbers or dates of birth.
  2. Sensitive Personally Identifiable Information (SPII): Highly sensitive personal information that requires additional protection.
  3. Proprietary Business Information (PBI): Also known as Confidential Business Information (CBI), this includes trade secrets or confidential commercial or financial data.
  4. Unclassified Controlled Technical Information (UCTI): Technical data that is unclassified but requires safeguarding, such as procurement-sensitive drafts, budgets, plans or proposals, reports, software and code.
  5. For Official Use Only (FOUO): Unclassified information intended for limited public release.

The new FAR clause will require contractors to follow any unique safeguarding directives detailed in a new Standard Form (SF) to be provided with each contract.

  • Contractors using their own information systems will comply with NIST 800-171 Revision
  • Contractors relying on federal information systems must adhere to agency-specified requirements from the latest NIST SP 800-53
  • Contractors must report any suspected or confirmed CUI incident on non-federal information systems within eight hours of discovery to a designated agency official. If found at fault, they may be liable for government costs incurred in response.
  • Contractors must also notify the contracting officer within eight hours if they discover information believed to be CUI that’s not identified in the SF or improperly marked.

Contractors must include this clause in all subcontracts and agreements involving CUI, and may extend the clause requirements to all parties with access to CUI, not just direct subcontractors.

In anticipation of a solicitation and ultimate award of a contract with CUI requirements, ensure your systems and procedures align with NIST requirements. Train staff and subcontractors on new safeguarding and reporting obligations. As a new requirement and standard, maintain open dialogue with contracting officers to clarify uncertainties about CUI identification and handling. While these changes introduce extra responsibilities, they also present a unique opportunity to strengthen our information security practices and build deeper trust with USAID and other federal clients.

Read the full post at Blank Rome

Not ready to join? Take the free Pub K Weekly digest.One email. Free. Top industry articles, the community calendar, and the latest job postings.