SecurityNot yet confirmed elsewhere1 publisher2 min readPublished
Pending federal CUI rule would give contractors 72 hours to report breaches
Proposed federal rules would require contractors holding controlled unclassified information to report breaches within 72 hours of discovery. Procurement attorneys say the rules could arrive as soon as the end of this year, and likely no later than the end of President Trump's term.
The Watch · Security desk

What happened
- For most federal agencies, the rules are a companion to existing Defense Department rules covering the same subject.
- The reporting window was deliberately set to match CISA's forthcoming CIRCIA rules for critical infrastructure operators reporting major cyber incidents.
- An earlier draft, the January 2025 proposal, gave contractors 8 hours to report and also required reporting of suspected incidents.
- Contractors would also have to meet minimum electronic security standards for protecting the data.
Why it matters
- cost Contractors pay for triage that can confirm an intrusion and file within three days, a pace the Aerospace Industries Association called difficult and costly to meet.
- exposure Falling short of the security floor could open a contractor to False Claims Act penalties, a lever the government has used increasingly since 2022 over weak cyber safeguards.
- constraint Incident triage would have to settle whether accessed files were CUI inside the 72-hour window, even when the agency never marked the data it handed over.
- decision A contractor holding CUI for several civilian agencies would need a separate reporting contact for each in its playbook if agency-specific routing survives.
The clock starts at discovery. The trigger is unauthorized access to CUI, including access gained through a cyberattack [3]. The window is nine times the one in the January 2025 draft [19]. It is also one-tenth of what the Aerospace Industries Association asked for in filed comments: 30 calendar days, "to accommodate improved reporting while reducing compliance costs" [12], or 720 hours [20]. An industry source who spoke to CyberScoop on condition of anonymity said "72 hours is largely a policy decision, based on extensive public-private deliberation" [13].
The alignment covers timing. Susan Cassidy, a Covington partner who advises government contractors, said the proposed rule is meant to "make it easier for contractors to comply with one set of standards, rather than many different types of standards" [8]. She traced the effort back to a 2010 executive order, issued when officials found agencies using different labels for the same data, among them "sensitive but unclassified" and "for official use only" [15]. On where reports go, the Chamber of Commerce wrote that the June 2026 rulemaking still appears to send them to agency-specific points of contact "rather than to a single centralized hub" [14]. The CIRCIA rules the window is matched to are themselves still forthcoming [5].
The text is still a proposal [3]. "If it's finalized in the form that it's in now, it will be a fairly significant change for federal contractors," said Ryan Burnette, a Covington partner focused on government contracts and technology [16]. Trayce Howard, a government contracts partner at Wiley Rein, said it is "going to be a sea change for a lot of companies" [17]. The CUI rules are one piece of a larger overhaul of federal contracting rules [2].
For a response team, the clock depends on knowing which holdings are CUI in the first place. The category covers data such as Social Security numbers and information that could expose vulnerabilities in critical infrastructure [18]. "Many contractors will say they don't necessarily know exactly what CUI is, despite their best efforts," the anonymous industry source said [9]. "Information from agencies isn't always clearly marked as CUI" [9].
What to watch
- Whether the final text holds at 72 hours or moves toward the 30 calendar days the Aerospace Industries Association requested.
- Whether the final rule names one central reporting hub, as the Chamber of Commerce wants, or keeps agency-specific points of contact.
- CISA's final CIRCIA rule, since the CUI reporting window was set to match it.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence58
- Adoption
- Insufficient
- Hype gap+10
- Incentives62
- Confidence55
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Pending federal regulations on controlled unclassified information could arrive as soon as the end of this year, but likely no later than the end of President Donald Trump's term, according to attorneys who specialize in federal procurement rules.
- [2]
The CUI changes are part of a larger overhaul of federal contracting rules.
- [3]
As currently written, the proposed CUI rules mandate that unauthorized access of CUI, including as a result of a cyberattack, be reported to the federal government within 72 hours of discovery.
- [4]
The CUI rules are a companion for most federal agencies to existing Defense Department rules that cover the same subject.
- [5]
The 72-hour notice is deliberately aligned with forthcoming CISA rules under CIRCIA for critical infrastructure owners and operators to report major cyber incidents.
- [6]
The CUI rules require contractors to adhere to minimum electronic security standards for protecting that information.
- [7]
Experts said the rules could expose contractors who fail to comply with cybersecurity guidelines to penalties under the False Claims Act, a lever the federal government has used increasingly since 2022 to punish contractors over lackluster cyber safeguards.
- [8]
make it easier for contractors to comply with one set of standards, rather than many different types of standards
- [9]
"Many contractors will say they don't necessarily know exactly what CUI is, despite their best efforts. Information from agencies isn't always clearly marked as CUI."
- [10]
An earlier draft of the rule had an 8-hour standard for reporting CUI incidents and required reporting of suspected incidents as well.
- [11]
The Aerospace Industries Association "reiterates concerns with these compressed timelines which will be difficult and costly for industry to comply with," in reference to the 72-hour standard.
- [12]
"AIA recommends extending these timelines to 30 calendar days to accommodate improved reporting while reducing compliance costs."
- [13]
"72 hours is largely a policy decision, based on extensive public-private deliberation"
- [14]
The Chamber of Commerce wrote that the 72-hour window is a significant improvement over the 8-hour window in the January 2025 proposal, but that the June 2026 rulemaking still appears to require reporting to agency-specific points of contact "rather than to a single centralized hub."
- [15]
Susan Cassidy said the proposed regulation is part of a journey that began with a 2010 executive order, when officials realized they could not have consistent CUI requirements because agencies used different terminology such as "sensitive but unclassified" and "for official use only."
- [16]
"If it's finalized in the form that it's in now, it will be a fairly significant change for federal contractors."
- [17]
"going to be a sea change for a lot of companies"
- [18]
CUI is a category of sensitive data short of classified that includes personal information such as Social Security numbers and information that could expose vulnerabilities in critical infrastructure.
- [19]
The 72-hour window is nine times the 8-hour window in the January 2025 draft.
- [20]
The AIA's requested 30 calendar days equals 720 hours, ten times the proposed 72-hour window.
Sources
1 independent publisher whose own reporting we read for this story.
- cyberscoop.comMajor rules for federal contractors handling sensitive data are nearing the finish line
1 article · October 7, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.
Topics
- Government Contractor CybersecurityFollow
- Controlled Unclassified InformationFollow
- Federal ProcurementFollow
- Cyber and Incident ReportingFollow