Federal contractors handling sensitive information may soon face significant changes in cybersecurity regulations concerning controlled unclassified information (CUI). Proposed federal regulations, which could be finalized by the end of the year, mandate that contractors report unauthorized access to CUI within 72 hours of discovery, aligning with forthcoming rules from the Cybersecurity and Infrastructure Security Agency (CISA) for critical infrastructure owners.
The proposed rules aim to standardize the handling of CUI, which includes personal information and data that could expose vulnerabilities in critical infrastructure. This overhaul is part of a broader reform of federal contracting rules, as highlighted by legal experts specializing in federal procurement. The changes are expected to impose minimum electronic security standards on contractors, potentially exposing those who fail to comply to penalties under the False Claims Act.
New Reporting Requirements
Under the proposed regulations, contractors would be required to notify the federal government of any unauthorized access to CUI within 72 hours. This timeline is a significant improvement over an earlier draft that suggested an 8-hour reporting window. However, industry groups have expressed concerns about the feasibility of the 72-hour requirement, arguing that it may be difficult and costly to comply with such compressed timelines. The Aerospace Industries Association has recommended extending the reporting period to 30 days to better accommodate compliance efforts.
Additionally, the proposed rules stipulate that contractors must report incidents to specific agency points of contact rather than a centralized hub, which could complicate the reporting process. Experts are closely monitoring how these reporting requirements will be implemented and whether they will be coordinated with existing Department of Defense protocols.
Cybersecurity Standards and Compliance
Contractors handling CUI will also need to adhere to cybersecurity standards set by the National Institute of Standards and Technology (NIST), specifically SP 800-171. This requirement is expected to broaden the scope of contractors subject to these standards, including those who may not have previously dealt with CUI. Furthermore, contractors will be responsible for ensuring that their subcontractors also comply with these cybersecurity requirements, adding another layer of complexity to the compliance landscape.
Legal experts warn that the new regulations could increase the risk of penalties under the False Claims Act for contractors who fail to meet the required cybersecurity standards. This shift may affect a wider range of contractors, particularly those who have primarily worked with civilian agencies and have not faced such stringent requirements before.
Next Steps and Industry Preparedness
The timeline for finalizing these regulations remains uncertain, but experts anticipate that a final rule could be issued by the end of the year. Contractors are advised to begin preparing for these changes by assessing their current cybersecurity practices and understanding the implications of the proposed rules. As Trayce Howard, a government contracts partner at Wiley Rein, noted, “It’s going to be a sea change for a lot of companies.”
As the regulatory landscape evolves, contractors must stay informed and proactive in adapting to these new requirements to ensure compliance and protect sensitive information effectively. For further details on the proposed regulations, refer to CyberScoop.
For more insights into global cybersecurity developments, visit our Global cybersecurity coverage.


