CUI Requirements Are Changing: Is Your Team Ready?

CUI requirements are changing faster than many federal construction teams can track. In 2026, civilian agencies, GSA, and the Department of Defense are no longer running on the same playbook for Controlled Unclassified Information. If your people still treat CUI as “the IT team’s problem,” you are already behind.

Drawings, specifications, facility layouts, access lists, and project correspondence can all qualify as CUI. That data now lives on job-site tablets, shared drives, email threads, and subcontractor portals. The standard that protects it is shifting from NIST SP 800-171 Revision 2 toward Revision 3, and the FAR Council is building a government-wide contract clause around that change.

This guide explains what CUI is, what changed, why construction teams are in scope, and how to get your people ready before the next solicitation makes it a bid killer.

What is Controlled Unclassified Information (CUI)?

Controlled Unclassified Information is government-created or government-held unclassified information that still requires safeguarding or dissemination controls under law, regulation, or government-wide policy. It is not classified. It is also not ordinary business data you can share freely with anyone on the job.

The program was created by Executive Order 13556. The National Archives and Records Administration (NARA) is the Executive Agent, and 32 CFR Part 2002 sets the rules for designating, marking, safeguarding, sharing, and decontrolling CUI. NARA maintains the official CUI program and the CUI Registry, which lists the categories agencies may use.

On a federal construction project, CUI often shows up as:

  • Facility security information and physical security details
  • Critical infrastructure data tied to federal buildings, utilities, or water systems
  • Sensitive drawings, as-builts, and system layouts
  • Procurement and acquisition information the government has marked for control
  • Personally identifiable information collected under a covered contract
  • Vulnerability information about systems, sites, or operations

If the government created it, required you to create it, or marked it as CUI, treat it as CUI until a contracting officer or the originating agency says otherwise.

Why CUI requirements are changing now

CUI requirements are changing because the federal government is trying to replace a patchwork of “For Official Use Only” labels with one safeguarding standard, then push that standard into contracts. Three moves are driving the 2026 shift.

1. NIST SP 800-171 Revision 3 is the new technical baseline

NIST published the final SP 800-171 Revision 3 in May 2024. It tells nonfederal organizations how to protect CUI on their own systems. Rev. 3 reorganizes the old 14 families into 17, drops the basic versus derived split used in Rev. 2, and adds organization-defined parameters. Those parameters force you to set and defend specific values for items such as lockout, password, and session timeout.

Rev. 3 also raises the bar on software inventory, use restrictions, and access control. A contractor that scored well against Rev. 2 is not automatically compliant with Rev. 3. The mapping work is real, and it belongs to more than the cybersecurity lead.

2. The FAR Council is writing CUI into civilian contracts

In 2026 the FAR Council updated its proposed CUI rule as part of the broader FAR overhaul. The draft framework uses a standard form (often called SF XXX) so solicitations can state, up front, whether CUI is in play, which categories apply, how it may be stored, and how incidents must be reported.

Two proposed clauses sit at the center of that change:

  • FAR 52.240-6, Notice of CUI Requirements, tells offerors that CUI is part of the work.
  • FAR 52.240-7, CUI, sets safeguarding and incident-reporting duties when CUI is involved.

The proposed baseline for contractor systems that handle CUI is NIST SP 800-171 Rev. 3. Some critical programs or high-value assets may also pull in enhanced controls from NIST SP 800-172. Draft language has pointed to 72-hour incident reporting after discovery, mandatory flow-down to subcontractors who receive CUI, and a requirement to disclose gaps plus a plan of action and milestones if you are not fully compliant at proposal time.

Industry reporting in 2026 has described a target of finalizing the rule by year end, with little or no phase-in once a clause hits a contract. Until the rule is final, treat it as direction of travel, not as a clause you can ignore. Contracting officers are already using similar language in some civilian awards.

3. GSA moved first. DoD did not move in lockstep.

GSA began applying NIST SP 800-171 Rev. 3 to contractors and other nonfederal entities that handle CUI, with a January 5, 2026 effective date for its updated IT security guidance. Independent assessments and tighter documentation are part of that approach. Prior CMMC work based on Rev. 2 does not automatically satisfy GSA’s Rev. 3 bar.

DoD CMMC is on a different clock. Phase I self-assessments remain in place. In July 2026 the Department paused Phase II third-party assessment rollout and opened a program review. For most Defense Industrial Base contractors, DFARS 252.204-7012 and NIST SP 800-171 Rev. 2 are still the operative CUI safeguarding standard, with scores and affirmations tracked in SPRS. A separate rulemaking track is expected to set how and when CMMC transitions to Rev. 3. Until that rule publishes, do not abandon Rev. 2 evidence. Build a map to Rev. 3 in parallel.

NIST has also finalized SP 800-172 Revision 3, the enhanced requirements for protecting CUI against advanced threats on high-value or critical programs. Those controls are not a blanket CMMC Level 2 duty today. Agencies can still write them into agreements for sensitive work.

What this means for federal construction teams

Federal construction teams feel CUI requirements in the field, not only in a server room. USACE, NAVFAC, GSA, Department of State, and other agency projects routinely produce drawings and data that identify how a facility is built, powered, accessed, or secured. That is exactly the kind of information the CUI Registry is designed to protect.

The risk is operational. A superintendent emails an unmarked drawing to a sub. A QC manager stores inspection photos of a restricted mechanical room in a personal cloud folder. A scheduler posts a file with controlled metadata to an unvetted collaboration tool. None of those people set out to break a federal rule. The contract still treats it as a safeguarding failure.

Flow-down makes this a team problem. Prime contractors who receive CUI must pass marking, handling, and incident-reporting duties to every subcontractor and vendor who will see that information. If your Division 1 package, onboarding packet, or site access process does not mention CUI, the flow-down is incomplete.

False or careless certifications remain a False Claims Act risk. Saying you protect CUI when your field process does not is not a paperwork issue. It is a legal one.

CUI requirements your team must be able to execute

CUI requirements only work if people in the trailer, the home office, and the supply chain can execute them without a lawyer standing nearby. Train to these six duties.

Identify CUI before you store or share it

Do not wait for a banner marking to appear after the file is already in five inboxes. At kickoff, ask the contracting officer which CUI categories apply, whether an SF-style CUI notice is in the solicitation, and which files, systems, and locations are in scope. Keep a simple inventory: what it is, where it lives, who can access it, and which subs receive it.

Mark it the same way every time

CUI marking must be consistent across documents, emails, drawings, and metadata. Banner markings go on the document. Portion markings go at the start of the applicable text. If a file leaves your system without a marking, the next holder cannot protect it. ISOO guidance in 2026 restated the need for accurate designation and marking in every format, not only PDFs produced by the home office.

Limit access to people with a lawful government purpose

CUI is not “anyone on the project can see it.” Access belongs to people who need it to perform the contract. That includes field staff, but it does not include every trade on site, every vendor in the billing chain, or personal devices that are convenient after hours.

Safeguard it at rest and in transit

Safeguarding covers physical copies, laptops, mobile devices, email, and cloud tools. NIST SP 800-171 is the technical floor for contractor systems that process, store, or transmit CUI. Construction firms often fail here because project tools were chosen for speed, not for CUI. If the platform cannot enforce access control, logging, and encryption that match the required NIST baseline, it is the wrong platform for that file.

Report incidents on the clock the contract sets

DFARS 252.204-7012 still requires rapid cyber incident reporting on covered DoD contracts. The proposed FAR CUI clause has pointed to a 72-hour clock after discovery for CUI incidents. Your team needs a one-page “what to do if” card: who they call, what they must not do (do not wipe the device, do not post about it), and how fast the report must move. A PM who finds a lost tablet on Friday afternoon cannot wait until Monday.

Train, refresh, and prove it

32 CFR 2002.30 requires CUI training for personnel who handle CUI, with initial and refresher training. ISOO Notice 2026-07 pressed agencies to designate a CUI Senior Agency Official and Program Manager, run annual self-inspections, and keep training current. Contractors should mirror that discipline. If you cannot show who was trained, on what, and when, you are not ready for an assessment or a protest fight.

Is your team ready? A CUI readiness checklist

Use this checklist with project managers, QC managers, superintendents, schedulers, and IT. If any line is a no, you have a gap to close before the next federal bid.

  1. We can name the CUI categories that appear on our current federal jobs, using the NARA CUI Registry rather than guesswork.
  2. Every solicitation is reviewed for CUI notices, DFARS 252.204-7012, FAR CUI language, and GSA IT security clauses before we price the work.
  3. We know whether the job is measured against NIST SP 800-171 Rev. 2, Rev. 3, or both, and we have a documented mapping if we are transitioning.
  4. CUI files are stored only in approved systems. Personal email, consumer cloud, and unmanaged phones are out of scope.
  5. Drawings, specs, and RFIs that contain CUI leave the office with the correct banner and portion markings.
  6. Subcontractors who receive CUI have written flow-down, training, and a named point of contact.
  7. New field staff receive CUI handling rules during onboarding, not after they have already been on the network.
  8. We have an incident script with a clock, an owner, and a backup owner.
  9. SPRS scores, self-assessments, and annual affirmations (where required) are current and match how we actually work.
  10. Leadership can explain our CUI process in plain language. If only one IT person understands it, the team is not ready.

Where construction teams usually fall short

Most CUI failures on construction jobs are process failures, not exotic hacks. Watch these patterns.

Unmarked files in the wild. A controlled drawing is exported, printed, photographed, or dropped into a transmittal without the banner. Once that happens, every downstream copy is uncontrolled.

Tool sprawl. Scheduling, RFIs, photos, and pay apps sit in four platforms with four permission models. CUI cannot be protected if you cannot say which system is authoritative.

Subcontractor blind spots. Specialty trades get the files they need to build. They rarely get the handling rules that came with those files. Flow-down that lives only in a prime’s policy binder does not protect the government.

Rev. 2 comfort. Teams that invested heavily in CMMC Level 2 against Rev. 2 assume they are done. GSA work and the coming FAR clause do not share that assumption. Start the Rev. 3 gap analysis now, even if DoD assessments still score Rev. 2.

No owner in the trailer. Cybersecurity staff sit at headquarters. CUI decisions happen at 6 a.m. on site. Appoint a project-level CUI contact who can say yes, no, or “ask the CO” without a two-day delay.

How to get your team ready without freezing the job

Readiness is a project controls problem as much as a security problem. Treat it like any other Division 1 requirement: assign it, schedule it, and inspect it.

Start with the contract, not the software. Pull every active federal agreement. List the CUI, DFARS, FAR, and GSA clauses. Note the NIST revision cited. That inventory tells you which jobs are already on Rev. 3 and which are still on Rev. 2.

Build a one-page handling standard. Marking, storage locations, approved apps, printing rules, visitor rules, and the incident number. Put it in the project startup packet next to safety and quality. If it takes a 40-page policy to send an email, nobody will follow it.

Train by role. Executives need the bid and False Claims Act picture. PMs need inventory and flow-down. Superintendents and QC need marking, photos, and device rules. IT needs the NIST control set and logging. One generic slide deck will not change behavior.

Run a tabletop. Lose a laptop. Mis-send a drawing. Find CUI in a sub’s unprotected Dropbox. Time the response. Fix the script before a real incident writes it for you.

Align staffing and access. People who do not need CUI should not have it. That is easier when field staffing, badging, and network access are coordinated. ACE’s federal construction and security staffing work exists for this reason: the right people, with the right access, on jobs that cannot tolerate sloppy handling.

If CMMC is in your pipeline, pair this CUI work with your certification path. ACE’s overview of CMMC compliance and our guide to navigating federal contract requirements sit alongside this article for teams that need the broader clause picture, not only the CUI slice.

CUI requirements are changing. Waiting is the expensive option.

CUI requirements are no longer a single DoD checklist you can file and forget. GSA is already on NIST SP 800-171 Rev. 3. The FAR Council is building a civilian clause set around the same baseline. DoD still scores much of CMMC against Rev. 2 while it reviews Phase II. Your team has to operate in that split without mixing the rules.

The contractors who stay eligible will be the ones who can identify CUI, mark it, limit it, report incidents, and prove training. That is a people system. Software helps. Trained PMs, QC managers, and field staff decide whether the system holds.

ACE Consulting Company is a Service-Disabled Veteran-Owned Small Business that has spent nearly two decades helping contractors execute federal construction work with integrity and urgency. If your next bid depends on CUI handling you cannot yet demonstrate, get the team ready before the clause shows up in the RFP.

Talk with ACE about federal compliance support, project controls, and field staffing that can operate inside today’s CUI rules: ace-consulting.net.

Frequently asked questions about CUI requirements

What does CUI stand for?

CUI stands for Controlled Unclassified Information. It is unclassified information that still requires safeguarding or dissemination controls under law, regulation, or government-wide policy. NARA runs the government-wide CUI program under Executive Order 13556 and 32 CFR Part 2002.

Are CUI requirements the same as classified information rules?

No. Classified information is governed by a separate national security system. CUI is unclassified. You still must mark it, limit who sees it, and protect the systems that store it. Mixing the two programs, or treating CUI as if it had no controls, both create compliance failures.

Do construction subcontractors have to follow CUI requirements?

Yes, when they receive CUI in order to perform the work. Primes must flow down safeguarding, marking, and incident-reporting duties. A sub who gets controlled drawings without handling rules is a gap in the prime’s program, not a free pass for the sub.

Is NIST SP 800-171 Rev. 3 required on every federal job in 2026?

No. GSA has moved contractors that handle CUI toward Rev. 3. The proposed FAR CUI rule also uses Rev. 3 as the civilian baseline. Many DoD CMMC Level 2 assessments still measure NIST SP 800-171 Rev. 2 until a transition rule publishes. Read the clause in your contract. Do not assume one revision covers every agency.

Does the CMMC Phase II pause mean we can ignore CUI?

No. DFARS 252.204-7012, CUI marking rules, and Phase I self-assessments remain in effect. The pause changed how some third-party CMMC assessments roll out. It did not cancel the duty to protect CUI or to avoid false SPRS scores.

How fast must a CUI incident be reported?

Follow the clause in the contract. Covered DoD contracts under DFARS 252.204-7012 have a rapid cyber incident reporting duty. The proposed FAR CUI framework has pointed to reporting within 72 hours after discovery. Build an internal clock that can meet the strictest clause you hold, then confirm the exact hours with the contracting officer.

Where can I find official CUI categories and NIST requirements?

Use the NARA CUI Registry category list for categories and the NIST SP 800-171 Revision 3 publication for the current nonfederal safeguarding baseline. Agency supplements, GSA guides, and DFARS clauses can add duties on top of those sources.

Key takeaways

  • CUI is unclassified information that still requires controls. Construction drawings and facility data are frequently in scope.
  • NIST SP 800-171 Rev. 3 is the emerging government-wide technical baseline. Rev. 2 remains operative for much of DoD CMMC in 2026.
  • GSA and the proposed FAR CUI clauses are moving faster than DoD’s CMMC transition.
  • Readiness is a team skill: identify, mark, limit access, safeguard systems, report incidents, and train by role.
  • Flow-down to subcontractors and field devices is where most construction programs break.
Fill Out the Form Below to Access the Webinar Download!

Fill Out the Form Below to Access the Webinar Download!

Name
Name
First Name
Last Name

Contact the ACE Help Desk Today!

Contact Help Desk
Please describe your help desk enquiry

Talk with an ACE Professional Today!