Skip to content

40.304 Controlled Unclassified Information

FAR Part 40 Status

Proposed

On June 23, 2026, the FAR Part 40 amendment was published into the Federal Register, including a section on CUI which would create a unified standard across federal agencies.

Status since
Last reviewed by ISI
Next milestone
EstimatedFinal Rule Publication,
Primary source
Federal RegisterFAR Council

Who this applies to

All government contractors and subcontractors who store, process, transmit, or generate CUI.

What we know

The proposed rule essentially absorbed the previous FAR CUI rule. The public comments were included in the new FAR Part 40 rule, which ended its public comment period on July 23, 2026. While most of the DoW’s CUI handling requirements may remain in place, FAR Part 40 requires adherence to NIST 800-171 Rev 3, unlike CMMC which is using Rev 2.

What we don't know yet

The government must now adjudicate all public comments and incorporate any reasonable changes into the final rule. There is no set time table for this. However, using CMMC rulemaking as a reference, we can expect the final rule to be published into the Federal Register roughly nine months after the public comment period ends.

What to do now

  • If in the defense space, begin mapping your NIST 800-171 Rev 2 controls to Rev 3 to ensure a smooth transition.
  • If not in the defense space, begin familiarizing your company with NIST 800-171 Rev 3 and conduct a gap analysis to identify your company’s current compliance posture.

ISI's read

The FAR Part 40 Rule could impact existing DFARS clauses (7012 and 7997) as well as 32 CFR Part 170 (the CMMC programmatic rule). However, FAR Part 40 leaves cybersecurity assessments to each agency’s discretion, meaning CMMC could be used as a tool to support FAR Part 40 in the future.

Our expert read is opinion, not fact.

Learn more about the Rev 2 to Rev 3 transition

Read more

Status history

Every change ISI has logged for FAR Part 40, newest first. Dates are when the event happened, not when it was recorded.

  1. Public comment period closes for Revolutionary Federal Acquisition Regulation Overhaul Parts 1, 2, 4, 33, 39, 40, and 53.

    Why it matters

    The public comment period was not limited to FAR Part 40. That said, the rule only received 90 public comments. This could be indicative of a lack of awareness of looming contractual requirements facing non-defense contractors. There is not timetable for the government to adjudicate these comments and publish a final rule.

    Source: Federal Register Federal Register

  2. Proposed CUI inclusion in FAR Part 40, part of the Revolutionary FAR Overhaul initiative.

    Status set to Proposed

    What changed

    In the proposed amendment to FAR Part 40, it includes a section dedicated to CUI handling and accounts for the DoW. In essence, the proposed amendment to the FAR Part 40 rule absorbed the previous FAR CUI rule, incorporating feedback from the original public comment period. Additionally, the FAR Part 40 rule sets the standard for contractors as NIST 800-171 Rev 3, breaking away from the 800-171 Revision 2 standard DoW is currently utilizing. Last, a key takeaway from this rule is that it leaves compliance assessments/validation up to agency discretion. Meaning each individual agency will determine how they will validate contractor compliance to NIST 800-171 Rev 3.

    Why it matters

    This move aligns with the Trump’s administration’s goal of reducing and streamlining regulations across the federal government. The amendment of FAR Part 40, as well as it’s inclusion of the DoW, could indicate that defense-specific clauses for protecting CUI could be redirecting to FAR Part 40 in the near future. Additionally, the CMMC program may not need its 48 CFR rule any longer. Last, if clauses like DFARS 252.204-7012 eventually point back to FAR Part 40, 32 CFR Part 170, the CMMC programmatic rule, will have to go through rulemaking to align with its new regulatory framework and adopt a scoring methodology and Plan of Action & Milestones (POA&M) guidance that reflect NIST 800-171 Revision 3 standards.

    Source: Federal Register Federal Register

  3. Public comment period for FAR CUI rule closes.

    Why it matters

    The rule received less than 100 comments, potentially indicative of a general lack of awareness as these requirements were being extended beyond the defense industrial base.

    Source: Regulations.gov, FAR-2017-0016 Federal Register

  4. Proposed FAR CUI rule published into Federal Register.

    What changed

    The proposed rule was established to standardize CUI safeguarding requirements across government agencies. This original proposed rule followed in the DoW’s footsteps by aligning with NIST 800-171 Revision 2.

    Why it matters

    It was the first sign that a CUI safeguarding framework would extend outside the defense industrial base. It also included proposed SF XXX that would list the types of CUI being included in the execution of the contract.

    Source: Federal Register Federal Register

Questions contractors are asking

Is FAR Part 40 replacing CMMC?

No. However, it may replace or alter DFARS 7012 which is currently the DoW’s underlying CUI safeguarding requirement. CMMC is a mechanism for verifying compliance to NIST 800-171 Rev 2, but it does not commit companies to being contractually required to safeguard CUI.

Will CMMC compliance still be mandatory when FAR Part 40 revisions go into effect?

Yes. As long as the CMMC 32 & 48 CFR rules are active and DFARS 7012, 7021, and 7025 are listed in contracts, CMMC compliance will be required for companies working on contracts with these clauses present. Additionally, it is likely the DoW keeps or amends these existing rules once FAR Part 40 is in effect to better align with this framework than DFARS 7012.

Does FAR Part 40 require third-party assessments like CMMC?

Short answer, no. However, unlike CMMC that was limited to one department, FAR Part 40 extends across most civilian and defense agencies. Therefore, the proposed language states that each individual agency will decide how it plans to best validate contractor compliance.