Major rules for federal contractors handling sensitive data are nearing the finish line

Wait 5 sec.

Federal government contractors that handle sensitive information could soon face a “sea change” in rules about how they protect that information and report when it has been part of a breach.Pending federal regulations on the handling of “controlled unclassified information,” or CUI, a category of sensitive data that falls short of classified — including people’s personal information such as Social Security numbers, information that could expose vulnerabilities in critical infrastructure and more — could arrive as soon as the end of this year, but likely no later than the end of President Donald Trump’s term, attorneys who specialize in federal procurement rules said. The changes are part of a larger overhaul of federal contracting rules.As currently written, the proposed CUI rules mandate that unauthorized access of such data, including as a result of a cyberattack, would have to be reported to the federal government within 72 hours of discovery. The rules are a companion for most federal agencies to existing  Defense Department rules that cover the same subject. The 72-hour notice also is deliberately aligned with forthcoming rules from the Cybersecurity and Infrastructure Security Agency (CISA) for critical infrastructure owners and operators to report major cyber incidents under the Cybersecurity Incident Reporting for Critical Infrastructure Act (CIRCIA).The CUI rules require contractors to adhere to minimum electronic security standards for protecting that sensitive information. Experts said the rules could expose contractors who fail to comply with cybersecurity guidelines to penalties under the False Claims Act, a lever that the federal government has been using increasingly since 2022 to punish contractors over lackluster cyber safeguards.It’s “going to be a sea change for a lot of companies,” said Trayce Howard, a government contracts partner at Wiley Rein. “If it’s finalized in the form that it’s in now, it will be a fairly significant change for federal contractors,” said Ryan Burnette, a partner at Covington focused on government contracts and technology.Susan Cassidy, another partner at Covington who advises government contractors, said the proposed regulation is part of a journey that began as far back as an executive order in 2010, when officials realized they couldn’t have sufficient, consistent requirements for protecting CUI given that so many agencies used different terminology for it: “sensitive but unclassified,” “for official use only,” and more.The proposed rule is intended to “make it easier for contractors to comply with one set of standards, rather than many different types of standards” for the protection of CUI and the reporting on CUI incidents such as breaches, she said.One industry source who spoke on condition of anonymity was candid about the difficulties CUI poses.“CUI can be painful for many industry stakeholders because it’s not always clear what constitutes CUI,” the source said. “Many contractors will say they don’t necessarily know exactly what CUI is, despite their best efforts. Information from agencies isn’t always clearly marked as CUI.”The reporting requirementsAn earlier draft of the rule gave industry groups more heartburn: It had an 8-hour standard for reporting CUI incidents, rather than 72, and it required reporting of suspected incidents as well.Still, a number of industry groups objected to the 72-hour standard, despite it being part of a much-sought after attempt to align federal breach reporting notification standards under CIRCIA.The Aerospace Industries Association, for instance, said in filed comments that it “reiterates concerns with these compressed timelines which will be difficult and costly for industry to comply with,” in reference to the 72-hour standard. “AIA recommends extending these timelines to 30 calendar days to accommodate improved reporting while reducing compliance costs.”The industry source said that “72 hours is largely a policy decision, based on extensive public-private deliberation,” rather than one based on any study of what’s best.Another point of discussion about the reporting rule as written is where contractors report incidents.“While the 72-hour reporting window is a significant improvement over the 8-hour window in the January 2025 proposal, the June 2026 rulemaking still appears to require reporting to agency -specific points of contact … rather than to a single centralized hub,” the Chamber of Commerce wrote in its comments.Cassidy said “it will be interesting to see how centralized reporting into CISA, which is the other place where civilian agencies go, is handled, and whether there’s coordination with DOD or whether or not we still see two separate streams going through.”The standardsThe other major aspect of the proposed rule is that contractors handling CUI would have to abide by certain cybersecurity standards set by the National Institute of Standards and Technology known as SP 800-171, which Howard and her Wiley coauthors said would be imposed “on a broader group of contractors than ever before.” Some contractors might also have to meet other cybersecurity requirements, too.“Another thing that will affect contractors is they’re going to have to flow down these requirements to their subcontractors,” she said. “So they’re going to have to identify what CUI am I giving to my subcontractors, and do some sort of oversight to make sure that their subcontractors are appropriately handling CUI.”Howard and other experts predict that the rules could expand who might be subjected to False Claims Act punishments.“I do think that this creates some significant False Claims at risk for contractors,” she said. This is going to encompass a whole new universe of contractors that may not be quite ready for that… contractors that have been working for civilian agencies exclusively have not been subject to this before.”Final stepsThe next steps aren’t 100 percent clear. Howard said a final rule could arrive by the end of the year. Cassidy said either an interim rule could take effect soon, or a final rule could be issued. Burnette said a final rule might be farther away, though the Trump administration has made it clear it wants everything finalized before the end of its term.That means contractors need to get ready, he said.“I think contractors should really be looking at this, preparing for it in certain ways, at least by recognizing at a high level, where this is headed and the types of activities and steps they need to be doing internally,” Burnette said. “Some of the minutia and the details, those are still subject to ironing out. But generally speaking, if you look at this rule compared to the rule that we saw early last year, they are much more similar than they are different. So we are starting to see  some crystallization here of the requirements, and we’re starting to get an idea what might change and what is most likely baked at this point.”The Office of Management and Budget did not respond to requests for comment.The post Major rules for federal contractors handling sensitive data are nearing the finish line appeared first on CyberScoop.