On September 2, the National Archives’ Information Security Oversight Office — the government-wide executive agent for the CUI program — issued ISOO Notice 2026-07. It directs agencies to give contractors “clear guidance … regarding all facets” of CUI handling, and it spells out what that guidance must cover in twelve specific categories.
The list is unusually concrete: identification of the government-furnished information designated as CUI; the process for deciding whether contractor-developed information is CUI; a process for challenging markings; training requirements; access; marking; safeguarding; decontrol and disposition, with specific dates or triggering events; reporting; self-inspection; reporting misuse; and penalties for misuse.
For years, the honest complaint from the defense industrial base has been that nobody could say with confidence what was CUI and what was not — over-marking in one program, under-marking in the next. That problem came up again and again in the feedback that drove the current CMMC review. This notice is the government’s structural answer, and it lines up with the FAR Council’s proposed CUI rule, which would add a standard form itemizing the CUI expected in each contract.
Now think through what happens once that answer arrives in your contract file. When the contract itself names the information, the marking rules, the safeguarding standard, the self-inspection expectation, and the penalties, there is no longer any room to argue about scope after the fact. Ambiguity has quietly served as a defense for a lot of organizations. Written specificity takes it away. A companion notice issued the same day, ISOO Notice 2026-08, tightens the same screw from the other side: agency waivers are now limited to three narrow types, so an informal “don’t worry about that” from a program office will not count as a waiver.
The FAR rewrite reached subcontracting on Friday, and a 30-day clock started
After clearing OMB on August 28, the second batch of the Revolutionary FAR Overhaul finally published in the Federal Register on September 18. It is four proposed rules covering sixteen FAR parts, and comments are due October 19.
For CUI holders, the rule to read is the one covering Parts 8, 12, 13, 15, 38, 44, and 51. Part 12 governs commercial acquisitions and Part 44 governs subcontracting, and the FAR Council states that it re-examined which clauses flow down to commercial subcontracts. Flow-down tables are the plumbing that decides whether a safeguarding obligation reaches your supplier’s supplier. The basic safeguarding clause — formerly FAR 52.204-21, now 52.240-93 under the overhaul deviations — and the DFARS CUI clauses already travel through that plumbing. The details are worth checking against your own subcontract templates while the text is still a proposal.
Two things have not moved this week. The Reform Task Force’s recommendations are still not public, and the government-wide FAR Part 40 CUI rule from batch one still has no final version. As Professional Services Council president Stephanie Kostro put it on September 15: “This is not the death knell of CMMC. In no way, shape or form does this class deviation say CMMC is dead.” The rules are being rewritten around the requirement. They are not being written out of existence.
Where things stand, and what is next:
- Sep 18, 2026FAR Overhaul batch two publishes — four proposed rules, sixteen parts, including commercial acquisition (Part 12) and subcontracting (Part 44).
- Sep 29, 2026Cyber AB town hall — the first scheduled forum since the review window closed.
- Late Sep – early Oct 2026Task Force recommendations — still the most recently signaled window, with nothing released so far.
- Oct 19, 2026Comments due on all four batch-two proposed rules, via regulations.gov.
- Oct 29, 2026Free NIST webinar on assessing CUI requirements under SP 800-171A Rev. 3 — see the next section.
NIST just published the assessor’s playbook in 14 pages
On September 16, NIST released Special Publication 1352, a small business primer on SP 800-171A Revision 3 — the document that defines how compliance with the CUI requirements is actually assessed. It is written for the business leader or employee “tasked with managing the implementation of SP 800-171r3, including conducting self-assessments or preparing to work with external assessors.”
Its value is that it lays out, in plain language, how anyone checking your work will do it. That applies whether the checker is a C3PAO, a government assessment team, your prime, or an investigator reviewing your SPRS score. Every requirement has a determination statement. Every determination is reached through three methods. And every finding comes back one of two ways: “satisfied” or “other than satisfied.” There is no partial credit for intent.
| Method | What the assessor does | Where self-assessments tend to fall short |
|---|---|---|
| Examine | Reviews specifications: policies, procedures, plans, and the System Security Plan. | Documents describe an environment that has since changed. |
| Interview | Talks with the people who are supposed to carry out each control. | The people named in the SSP cannot describe the process they own. |
| Test | Exercises mechanisms and activities to see whether the control actually works. | The setting was configured once and never re-verified. |
The primer also walks through a four-step plan — prepare, develop the plan, conduct, document — and puts the hardest question first: where, specifically, is CUI stored, processed, or transmitted? That is the same question this week’s ISOO notice pushes onto the contract, and it is the one every assessment starts from.
Note the revision number, too. The primer covers Rev. 3, the baseline the FAR Council’s proposed CUI rule adopts and the one DoD has signaled it will move to. NIST’s co-author of SP 800-171, Victoria Pillitteri, will walk through it in a free webinar on October 29.
What to do this week
The theme this issue: the definitions are getting sharper. Sharper definitions reward the organizations that are already measuring themselves honestly.
- Request written CUI guidance on every active CUI contract. Use ISOO Notice 2026-07’s twelve categories as your checklist, and file whatever comes back with the contract.
- Reconcile the contract’s CUI list against your actual boundary. Every item named in the contract should map to a system that protects it. Anything that does not is your top remediation item.
- Replace informal accommodations with written ones. If you are relying on a verbal “that’s fine” from a program office, get it documented, or treat it as not granted.
- Re-test your riskiest controls the NIST way. Examine, interview, and test — then update SPRS if the honest answer changed.
- Review your subcontract templates before October 19. Know which safeguarding and CUI clauses you flow down today, and decide whether the batch-two proposals warrant a comment.
Quick hits
- Sep 2, 2026Waivers just got narrower.ISOO Notice 2026-08 limits agency CUI waivers to three types: limited internal marking waivers, limited legacy-material marking waivers, and exigent circumstances. If a relaxed handling arrangement on one of your programs does not fit one of those three, assume it will not hold up.
- Aug 25, 2026The Cyber AB’s CEO on runway.Matthew Travis cautioned that contractors “might be out of runway,” pointing to implementation timelines of “nine months, 12 months, even up to 18 months.” Count forward from today and you land well past the Task Force’s recommendations and into whatever rules follow them.
- Sep 15, 2026Industry is splitting into two camps.Per the Professional Services Council, some contractors treat Level 2 certification as a competitive advantage and are pressing ahead, while others have paused assessments pending clarity. When the requirement returns, the first group will already be through the door.
- Oct 29, 2026Free NIST webinar on assessing CUI requirements.2:00–3:00 p.m. ET, virtual, with SP 800-171 co-author Victoria Pillitteri and NIST small business lead Daniel Eliot. Worth putting whoever owns your SSP in the seat.
Not sure where your organization stands?
CUI Vault gives you a live, always-audit-ready picture of your CUI environment and NIST 800-171 posture — so headlines like today’s are a footnote, not a fire drill. Reach out to your NtelSec team to talk through your current gaps.
