July 8, 2026
CMMC 3.0 coming sooner than you thought!
This little gem popped up earlier this week: "This amendment defines a deadline and period for transition from the requirement to comply with NIST SP 800-171 Revision 2, to a requirement to comply with NIST SP 800-171 Revision 3." This aligns with ISACA's decision to produce all new CCP and CCA training materials based on r3 (expected in January).
Deep Dive into the new proposed FAR CUI Rule
As promised, I have done my deep dive and come up with what I consider the most significant changes from the previous version. Keep reading for fun & profit!
Things I am grateful for:
We will still get the glorious new Standard Form XXX "to enable a uniform process for communicating the information contractors must manage and safeguard as well as identify where a CUI incident must be reported and when there are CUI incident reporting requirements that differ from or are in addition to those in the clause at FAR 52.240-7(e)" I sincerely hope that KOs will take this seriously, and contractors will start getting properly-marked CUI with instructions on how to handle it. Hooray! Also note that there is no requirement to include the SF XXX or modified version of the SF XXX in subcontracts. Contractors can decide how best to flow down the requirements in the SF XXX. Here's to the end of indiscriminate flowdowns!!
The timeline for reporting CUI incidents has changed to 72 hours from discovery, which aligns with 7012 and is much more reasonable than the 8 hours in the earlier proposed rule.
The clause at FAR 52.240-YY, Identifying and Reporting Information That Is Potentially Controlled Unclassified Information, was removed. That one opened a real can of worms and contradicted other, more reasonable clauses.
The definition of CUI incident was updated to clarify that improper handling of CUI ( e.g., unmarked or mismarked CUI) is not a CUI incident unless the improper handling has resulted in unauthorized disclosure, improper modification, or improper destruction of CUI. That's really good news IMO.
The definition of CUI now includes a specific exception for information a contractor creates or possesses that a law, regulation, or Governmentwide policy does not specifically require the contractor to handle using safeguarding or dissemination controls.
What don't I love? Well, this time around the rule is hardcoded to NIST SP 800-171r3, not r2, and includes the Organization-Defined Parameters (ODPs) published by DoD/DoW last year. Since the FAR supersedes supplements like DFARS, this rule could bring r3 requirements to the DIB much sooner than anticipated. Also of note, there isn't an updated Regulatory Impact Analysis, so apparently the authors don't realize that r3 is about 30% more work than r2 and thus will be considerably more expensive to implement.
The public comment period ends July 23, so if you have opinions, don't delay!
Wanna chat? Reach out.
Sincerely,
Glenda R. Snodgrass, CCP/CCA/Lead CCA
grs@theneteffect.com
The Net Effect, LLC
www.theneteffect.com
251-433-0196 x107

