Вход на сайт

Просмотр новости

Найдите то, что Вас интересует

GSA Joins the CUI Compliance Movement: What Non-Defense Contractors Need to Know

Дата публикации: 09-02-2026 15:50:22

Key point: Historically, civilian‑agency contractors who handled Controlled Unclassified Information (CUI) enjoyed an informal compliance environment, with a requirement to adhere to NIST SP 800‑171 often framed as self‑attestation. That world is now decisively over, with the GSA following a path similar, but not identical, to the DoD’s CMMC requirements. What Changed? The GSA’s IT...

Основное содержимое страницы с новостью.

Key point: Historically, civilian‑agency contractors who handled Controlled Unclassified Information (CUI) enjoyed an informal compliance environment, with a requirement to adhere to NIST SP 800‑171 often framed as self‑attestation. That world is now decisively over, with the GSA following a path similar, but not identical, to the DoD’s CMMC requirements.

What Changed?

The GSA’s IT security procedural guide (“GSA Guide”) describes the new procedures and processes to protect CUI on nonfederal systems, through select requirements in NIST SP 800-172 Revision 3 and NIST SP 800-53, Revision 5. As a result, a much larger portion of the federal contractor population must demonstrate compliance with NIST cybersecurity requirements.

GSA vs. CMMC: Which Version of NIST SP 800-171 Applies?

The GSA Guide applies whenever CUI resides on a nonfederal information system, unless the contractor operates that system on behalf of a federal agency, incorporates requirements in NIST SP 800-171 Revision 3, and selected privacy controls from NIST SP 800-53, Revision 5.

The GSA Guide states that a contractor can be authorized to receive CUI, even if it has not yet satisfied every cybersecurity and privacy control. However, the GSA Guide Appendix C lists nine “Showstopper Security Requirements” from NIST SP 800-171 Revision 3 that must be satisfied to gain approval.

In contrast, the DOD’s CMMC program requires all contractors handling CUI to be 100% compliant with NIST SP 800-171 Revision 2. Where the DOD requires defense contractors to notify their agency counterpart within 72 hours of a cyber incident, the GSA Guide requires notification within one hour of a suspected or actual incident affecting the confidentiality, integrity, or availability of those CUI systems.

This divergence between material and complete compliance, combined with the application of different versions of the same NIST publication introduce a new layer of complexity for contractors who may be subject to both DOD and GSA requirements.

Who Can Approve? Assessors and Potential Bottlenecks

GSA will be allowing assessments by either a FedRAMP-accredited third-party assessment organization (3PAO) or a GSA-approved independent assessor for approval of the system. However, the current guide does not specify who these GSA-approved assessors are, whether there will be any reciprocity for CMMC assessors, or how an organization can obtain GSA approval. This ambiguity could lead to similar bottlenecks as the C3PAO process, especially as demand for qualified assessors increases.

Next Steps

The GSA Guide is not a regulation and appears to have gone into effect when it was published on January 5, 2026. As federal agencies like the GSA adopt and expand NIST SP 800-171 requirements, the responsibility for safeguarding CUI is no longer limited to traditional defense contractors. All federal contractors need to be prepared for evolving standards and potentially confusing compliance obligations. Proactively reviewing your security controls and seeking expert guidance will be key to maintaining your competitive edge and eligibility for future federal contracts.

Схожие новости

#Наименование новостиТональностьИнформативностьДата публикации
1The Defense Department’s Cybersecurity Requirements Go Live08.811-09-2025
2OIRA Completes its Review of the DFARS CMMC Proposed Rule: Is Your Company CMMC Certified, or Will It be Excluded from Future Awards?08.1502-09-2025
3Department of War Suspends CMMC Phase II: What Defense Contractors Need to Know010.9814-07-2026
4Navigating Cyber Disclosures in 2026: A Limited Renewal of CISA 2015, and “Take Two” on Finalizing CIRCIA’s Reporting Regulations011.7426-02-2026
5CISA 2015: Congress Faces Fast-Approaching Deadline to Reauthorize a Critical Cybersecurity Law012.9714-08-2025
6CISA Announces Rescheduled Virtual Town Hall Meetings for CIRCIA Rulemaking06.7401-06-2026
7Points Well Taken: The Privacy Side of Loyalty Programs and Promotions06.6902-03-2026
8Website Compliance Must-Dos for 2026: What Legal and Business Teams Should Revisit Now013.9117-02-2026
9Report finds wasteful travel expenses for California High-Speed Rail consultants09.3415-09-2026
10American CEO accused of alarming scheme to sneak Russians into Secret Service contract06.8825-09-2026

Классификация: Пресс-релизы. Схожих патентов: 0. Схожих новостей: 10. Тональность: 0. Информативность: 8.9. Источник: www.lexblog.com.