Federal government contractors handling sensitive information are poised for significant new regulations concerning data protection and breach reporting. These forthcoming rules, which define "controlled unclassified information" (CUI) as a category of sensitive data below classified status—including personal information like Social Security numbers and critical infrastructure vulnerabilities—could be finalized by the end of the year, or at the latest, by the end of the current presidential term.
The proposed CUI regulations mandate that contractors report unauthorized access to such data, including cyberattacks, within 72 hours of discovery. This 72-hour timeframe aligns with upcoming rules from the Cybersecurity and Infrastructure Security Agency (CISA) for critical infrastructure owners and operators under the Cybersecurity Incident Reporting for Critical Infrastructure Act (CIRCIA), and mirrors existing Department of Defense (DOD) rules for its contractors. An earlier draft of the rule had proposed an 8-hour reporting window for suspected incidents, which drew significant industry concern.
Beyond reporting, the rules require contractors to adhere to minimum electronic security standards, specifically those outlined in the National Institute of Standards and Technology (NIST) Special Publication 800-171. This standard is expected to apply to a broader range of contractors than ever before, including those working exclusively with civilian agencies. Contractors will also be responsible for flowing down these cybersecurity requirements to their subcontractors, necessitating oversight to ensure proper CUI handling.
Non-compliance with these cybersecurity guidelines could expose contractors to penalties under the False Claims Act, a mechanism the federal government has increasingly utilized since 2022 to address inadequate cyber safeguards. Experts anticipate that these new regulations will significantly expand the universe of contractors facing such risks.
Industry groups have raised concerns about the compressed reporting timelines, with the Aerospace Industries Association (AIA) recommending an extension to 30 calendar days to improve reporting accuracy and reduce compliance costs. While the 72-hour window is a policy decision resulting from public-private deliberation, some industry stakeholders still find it challenging.
Another point of discussion revolves around the reporting mechanism. The June 2026 rulemaking draft appears to require reporting to agency-specific points of contact rather than a single centralized hub. This raises questions about coordination with CISA and DOD, and whether two separate reporting streams will persist.
The concept of CUI itself has presented difficulties for industry, with some contractors expressing uncertainty about what precisely constitutes CUI, despite their best efforts, and noting that information from agencies is not always clearly marked. The proposed rule aims to streamline compliance by establishing a single set of standards for CUI protection and incident reporting, replacing the varied terminology and requirements previously used across different agencies.
While some details are still being ironed out, the core requirements of the rule are becoming clearer. Contractors are advised to begin preparing by understanding the general direction of these changes and identifying internal steps they need to take. A final rule could be issued soon, potentially as an interim rule, or a definitive final rule before the end of the current administration.






