Abstract
In late June 2026, the Federal Acquisition Regulatory (FAR) Council released a series of proposed regulations to implement the “Revolutionary Federal Acquisition Regulation (FAR) Overhaul” project called for in the Trump administration’s Executive Order 14275, “Restoring Common Sense to Federal Procurement.” One of the rulemaking notices addressed federal contracting provisions regarding cybersecurity requirements for controlled unclassified information (CUI) that responded positively to EDUCAUSE comments on a prior “FAR CUI” rulemaking in 2025. However, EDUCAUSE provided comments on the 2026 rulemaking to encourage the FAR Council to clarify further key elements of the proposed regulations. Key points include the need for the council to:
- Provide in the final regulations objective indicators of what constitutes “clear evidence” that information is likely to be unmarked/mismarked CUI,
- Modify the standard form for sharing the details about the CUI a proposed project entails to state that covered entities are not required to infer that information may be unmarked/mismarked CUI and should not try to mark possible CUI themselves,
- Add a provision to the final regulations establishing that the version of NIST SP 800-171 with which a contractor or subcontractor must comply in relation to a given award is set for that award at the time of contract, and
- Incorporate requirements into the final regulations that minimize the possibility that including a plan of action and milestones (POA&M) in a contract proposal would negatively impact the competitiveness of the proposal.