Federal contractors may soon face new cybersecurity rules for handling controlled unclassified information

Published:

Federal contractors handling sensitive information may soon face significant changes in cybersecurity regulations concerning controlled unclassified information (CUI). Proposed federal regulations, which could be finalized by the end of the year, mandate that contractors report unauthorized access to CUI within 72 hours of discovery, aligning with forthcoming rules from the Cybersecurity and Infrastructure Security Agency (CISA) for critical infrastructure owners.

The proposed rules aim to standardize the handling of CUI, which includes personal information and data that could expose vulnerabilities in critical infrastructure. This overhaul is part of a broader reform of federal contracting rules, as highlighted by legal experts specializing in federal procurement. The changes are expected to impose minimum electronic security standards on contractors, potentially exposing those who fail to comply to penalties under the False Claims Act.

New Reporting Requirements

Under the proposed regulations, contractors would be required to notify the federal government of any unauthorized access to CUI within 72 hours. This timeline is a significant improvement over an earlier draft that suggested an 8-hour reporting window. However, industry groups have expressed concerns about the feasibility of the 72-hour requirement, arguing that it may be difficult and costly to comply with such compressed timelines. The Aerospace Industries Association has recommended extending the reporting period to 30 days to better accommodate compliance efforts.

Additionally, the proposed rules stipulate that contractors must report incidents to specific agency points of contact rather than a centralized hub, which could complicate the reporting process. Experts are closely monitoring how these reporting requirements will be implemented and whether they will be coordinated with existing Department of Defense protocols.

Cybersecurity Standards and Compliance

Contractors handling CUI will also need to adhere to cybersecurity standards set by the National Institute of Standards and Technology (NIST), specifically SP 800-171. This requirement is expected to broaden the scope of contractors subject to these standards, including those who may not have previously dealt with CUI. Furthermore, contractors will be responsible for ensuring that their subcontractors also comply with these cybersecurity requirements, adding another layer of complexity to the compliance landscape.

Legal experts warn that the new regulations could increase the risk of penalties under the False Claims Act for contractors who fail to meet the required cybersecurity standards. This shift may affect a wider range of contractors, particularly those who have primarily worked with civilian agencies and have not faced such stringent requirements before.

Next Steps and Industry Preparedness

The timeline for finalizing these regulations remains uncertain, but experts anticipate that a final rule could be issued by the end of the year. Contractors are advised to begin preparing for these changes by assessing their current cybersecurity practices and understanding the implications of the proposed rules. As Trayce Howard, a government contracts partner at Wiley Rein, noted, “It’s going to be a sea change for a lot of companies.”

As the regulatory landscape evolves, contractors must stay informed and proactive in adapting to these new requirements to ensure compliance and protect sensitive information effectively. For further details on the proposed regulations, refer to CyberScoop.

For more insights into global cybersecurity developments, visit our Global cybersecurity coverage.

CHAPTER X // CYBER AWARENESS CAMPAIGN
BEYOND THE BALLROOM
[C://ME] // CHAPTER X

REQUEST THE MEDIA KIT

Tell us where to send the Beyond the Ballroom media deck. Every field is required.

We will use these details to respond to your media-kit request. Privacy Policy

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

HPE security advisory AV26-1011 warns of vulnerabilities in AOS-S and CPPM products

Hewlett Packard Enterprise (HPE) has issued a security advisory (AV26-1011) regarding vulnerabilities affecting its AOS-Switch and ClearPass Policy Manager (CPPM) products. As of October...

Alleged Ploutus malware creator Anibal Canelon Aguirre appears in Nebraska court

The alleged mastermind behind the Ploutus malware, Anibal Alexander Canelon Aguirre, made his first court appearance in Nebraska after being apprehended by federal authorities....

AI-enabled threat actor JadePuffer automates destructive actions in cloud environments using Azure service principals

Recent research from Check Point has revealed that the AI-enabled threat actor known as JadePuffer, tracked as Storm-3168, is leveraging compromised Azure service principals...

FBI reports surge in AI-related online scams costing Alabamians over $6 million

The FBI has reported a significant rise in online scams fueled by artificial intelligence, marking the first time the bureau has tracked AI-related complaints...