PARTNERSHIPCUI Vault and Trout Software partner to extend the CUI boundary to the machine.CUI Vault partners with Trout Software.Read the announcement

Agencies are now required to tell you exactly what your CUI is

A new National Archives notice orders federal agencies to hand contractors specific, written CUI instructions on every CUI-related contract. Clarity is good news for the well-prepared. For everyone else, it removes the last excuse.

On September 2, the National Archives’ Information Security Oversight Office — the government-wide executive agent for the CUI program — issued ISOO Notice 2026-07. It directs agencies to give contractors “clear guidance … regarding all facets” of CUI handling, and it spells out what that guidance must cover in twelve specific categories.

The list is unusually concrete: identification of the government-furnished information designated as CUI; the process for deciding whether contractor-developed information is CUI; a process for challenging markings; training requirements; access; marking; safeguarding; decontrol and disposition, with specific dates or triggering events; reporting; self-inspection; reporting misuse; and penalties for misuse.

For years, the honest complaint from the defense industrial base has been that nobody could say with confidence what was CUI and what was not — over-marking in one program, under-marking in the next. That problem came up again and again in the feedback that drove the current CMMC review. This notice is the government’s structural answer, and it lines up with the FAR Council’s proposed CUI rule, which would add a standard form itemizing the CUI expected in each contract.

Now think through what happens once that answer arrives in your contract file. When the contract itself names the information, the marking rules, the safeguarding standard, the self-inspection expectation, and the penalties, there is no longer any room to argue about scope after the fact. Ambiguity has quietly served as a defense for a lot of organizations. Written specificity takes it away. A companion notice issued the same day, ISOO Notice 2026-08, tightens the same screw from the other side: agency waivers are now limited to three narrow types, so an informal “don’t worry about that” from a program office will not count as a waiver.

So what: once your contract spells out exactly what your CUI is, that list becomes the yardstick every assessor, prime, and investigator measures you against. Two moves this month. First, request the twelve-category guidance in writing from the contracting officer — or from your prime — on every active CUI contract, as outside counsel is already advising. Second, compare what comes back against where that information actually lives in your environment today. Any gap between what the contract says is CUI and what your boundary protects is now documented, and it is yours to own.

The FAR rewrite reached subcontracting on Friday, and a 30-day clock started

After clearing OMB on August 28, the second batch of the Revolutionary FAR Overhaul finally published in the Federal Register on September 18. It is four proposed rules covering sixteen FAR parts, and comments are due October 19.

For CUI holders, the rule to read is the one covering Parts 8, 12, 13, 15, 38, 44, and 51. Part 12 governs commercial acquisitions and Part 44 governs subcontracting, and the FAR Council states that it re-examined which clauses flow down to commercial subcontracts. Flow-down tables are the plumbing that decides whether a safeguarding obligation reaches your supplier’s supplier. The basic safeguarding clause — formerly FAR 52.204-21, now 52.240-93 under the overhaul deviations — and the DFARS CUI clauses already travel through that plumbing. The details are worth checking against your own subcontract templates while the text is still a proposal.

Two things have not moved this week. The Reform Task Force’s recommendations are still not public, and the government-wide FAR Part 40 CUI rule from batch one still has no final version. As Professional Services Council president Stephanie Kostro put it on September 15: “This is not the death knell of CMMC. In no way, shape or form does this class deviation say CMMC is dead.” The rules are being rewritten around the requirement. They are not being written out of existence.

Where things stand, and what is next:

  • Sep 18, 2026
    FAR Overhaul batch two publishes — four proposed rules, sixteen parts, including commercial acquisition (Part 12) and subcontracting (Part 44).
  • Sep 29, 2026
    Cyber AB town hall — the first scheduled forum since the review window closed.
  • Late Sep – early Oct 2026
    Task Force recommendations — still the most recently signaled window, with nothing released so far.
  • Oct 19, 2026
    Comments due on all four batch-two proposed rules, via regulations.gov.
  • Oct 29, 2026
    Free NIST webinar on assessing CUI requirements under SP 800-171A Rev. 3 — see the next section.
So what: if you buy from subcontractors, or sell commercial products into the defense supply chain, the flow-down rules are being rewritten right now and you have until October 19 to say something. Pull your standard subcontract terms this week and confirm which cyber and CUI clauses they already carry. Your comment will be sharper, and you will know what to update when the final text lands.

NIST just published the assessor’s playbook in 14 pages

On September 16, NIST released Special Publication 1352, a small business primer on SP 800-171A Revision 3 — the document that defines how compliance with the CUI requirements is actually assessed. It is written for the business leader or employee “tasked with managing the implementation of SP 800-171r3, including conducting self-assessments or preparing to work with external assessors.”

Its value is that it lays out, in plain language, how anyone checking your work will do it. That applies whether the checker is a C3PAO, a government assessment team, your prime, or an investigator reviewing your SPRS score. Every requirement has a determination statement. Every determination is reached through three methods. And every finding comes back one of two ways: “satisfied” or “other than satisfied.” There is no partial credit for intent.

MethodWhat the assessor doesWhere self-assessments tend to fall short
ExamineReviews specifications: policies, procedures, plans, and the System Security Plan.Documents describe an environment that has since changed.
InterviewTalks with the people who are supposed to carry out each control.The people named in the SSP cannot describe the process they own.
TestExercises mechanisms and activities to see whether the control actually works.The setting was configured once and never re-verified.

The primer also walks through a four-step plan — prepare, develop the plan, conduct, document — and puts the hardest question first: where, specifically, is CUI stored, processed, or transmitted? That is the same question this week’s ISOO notice pushes onto the contract, and it is the one every assessment starts from.

Note the revision number, too. The primer covers Rev. 3, the baseline the FAR Council’s proposed CUI rule adopts and the one DoD has signaled it will move to. NIST’s co-author of SP 800-171, Victoria Pillitteri, will walk through it in a free webinar on October 29.

So what: your SPRS score is only as good as the method behind it. If your last self-assessment was a checklist completed from memory, re-run your ten highest-risk requirements the NIST way — examine the document, interview the owner, and test the control. Record “satisfied” only where all three hold up. The score may drop. That is far cheaper to find yourself than to have an assessor or an investigator find it for you.

What to do this week

The theme this issue: the definitions are getting sharper. Sharper definitions reward the organizations that are already measuring themselves honestly.

  • Request written CUI guidance on every active CUI contract. Use ISOO Notice 2026-07’s twelve categories as your checklist, and file whatever comes back with the contract.
  • Reconcile the contract’s CUI list against your actual boundary. Every item named in the contract should map to a system that protects it. Anything that does not is your top remediation item.
  • Replace informal accommodations with written ones. If you are relying on a verbal “that’s fine” from a program office, get it documented, or treat it as not granted.
  • Re-test your riskiest controls the NIST way. Examine, interview, and test — then update SPRS if the honest answer changed.
  • Review your subcontract templates before October 19. Know which safeguarding and CUI clauses you flow down today, and decide whether the batch-two proposals warrant a comment.

Quick hits

  • Sep 2, 2026
    Waivers just got narrower.
    ISOO Notice 2026-08 limits agency CUI waivers to three types: limited internal marking waivers, limited legacy-material marking waivers, and exigent circumstances. If a relaxed handling arrangement on one of your programs does not fit one of those three, assume it will not hold up.
  • Aug 25, 2026
    The Cyber AB’s CEO on runway.
    Matthew Travis cautioned that contractors “might be out of runway,” pointing to implementation timelines of “nine months, 12 months, even up to 18 months.” Count forward from today and you land well past the Task Force’s recommendations and into whatever rules follow them.
  • Sep 15, 2026
    Industry is splitting into two camps.
    Per the Professional Services Council, some contractors treat Level 2 certification as a competitive advantage and are pressing ahead, while others have paused assessments pending clarity. When the requirement returns, the first group will already be through the door.
  • Oct 29, 2026
    Free NIST webinar on assessing CUI requirements.
    2:00–3:00 p.m. ET, virtual, with SP 800-171 co-author Victoria Pillitteri and NIST small business lead Daniel Eliot. Worth putting whoever owns your SSP in the seat.

Not sure where your organization stands?

CUI Vault gives you a live, always-audit-ready picture of your CUI environment and NIST 800-171 posture — so headlines like today’s are a footnote, not a fire drill. Reach out to your NtelSec team to talk through your current gaps.

This briefing is a general-information summary of publicly reported CMMC and CUI developments. It is not legal advice; consult your compliance counsel before making contractual or certification decisions.
Talk to us about CUI Vault All issues