Linkedin
  • Home
  • Demo & Video
  • Blog
  • About Us
  • Try Free Self-Assessment Tool
Menu Categories
  • Home
  • Demo & Video
  • Blog
  • About Us
  • Try Free Self-Assessment Tool
Linkedin
Cart To use Cart please install WooCommerce plugin
The CMMC Pause Didn't Touch Your Civilian Contracts: The FAR CUI Rule, Explained | Overwatch Tools
The Second Front · Part 1 of 4

The CMMC Pause Didn't Touch Your Civilian Contracts

On July 13 the Department of War suspended CMMC Phase II. Eighteen days earlier, the FAR Council had proposed a governmentwide CUI rule that reaches contractors CMMC never did. One of those two things stopped. The other did not.

By Rob Maupin, founder of Overwatch Tools and author of the CMMC Practical Guides series — Volume 1: CMMC Level 1 and Volume 2: CMMC Level 2.

Published September 1, 2026. This article describes a proposed rule published June 23, 2026 at 91 FR 37550, whose comment period closed July 23, 2026. Proposed language changes before it becomes final. It also reflects the Department of War announcement of July 13, 2026; the CMMC Reform Task Force is expected to deliver findings roughly mid-September 2026 and guidance may change. We will update this article as the situation develops.

Since July 13, the conversation among small defense contractors has been almost entirely about one thing: the Department of War suspended CMMC Phase II, the third-party assessment requirement scheduled to land November 10, 2026. We covered what that suspension did and didn't do in a piece the day after it happened.

What got almost no attention in the small-contractor world is what the Federal Acquisition Regulatory Council had done eighteen days earlier.

On June 23, 2026, as part of the Revolutionary FAR Overhaul, the FAR Council published a substantially rewritten proposed rule governing how contractors protect Controlled Unclassified Information (CUI) — not just for the Department of War, but for every civilian agency in the federal government. It replaced a standalone version issued in January 2025, and its comment window closed July 23.

The Department of War paused one verification mechanism inside its own program. The FAR Council kept building an obligation that applies across the whole government. If those two facts have blurred together in your inbox, you're not alone — and if you hold work on both sides, the blur is expensive.

One Pause, Two Regimes

The cleanest way to hold this is to stop treating "CMMC" as a synonym for "federal cybersecurity requirements." CMMC is a Department of War program with its own rule, phase schedule, and — since July — a review underway. The FAR is the acquisition regulation governing contracting across the entire federal government, and it has its own separate track for CUI.

❌ Paused in July

  • CMMC Phase II — the November 10, 2026 transition to third-party assessment as a condition of award
  • Phases III and IV and future CMMC implementation milestones
  • C3PAO certification as a prerequisite for applicable Department of War contracts involving CUI

✅ Never Paused

  • The FAR CUI rule — proposed June 23, 2026, comments closed July 23
  • CMMC Phase I — Level 1 and Level 2 self-assessment requirements still appear in solicitations
  • DFARS 252.204-7012 — the safeguarding and cyber incident reporting clause is fully intact
  • NIST SP 800-171 — the underlying standard was never the thing that was suspended

Read the right column again. Every item in it is live today. The suspension covered a verification step in one department's program — not the obligation to protect federal information, and not the separate governmentwide rulemaking that has been grinding forward since 2010.

What the Proposed Rule Would Actually Require

The June 2026 version is not a light edit of the January 2025 proposal. It moved house, changed clause numbers, raised the baseline standard, and rewrote the incident reporting timeline. Here are the pieces that matter most to a small contractor.

A new home in FAR Part 40

The January 2025 version put CUI requirements in FAR Part 4. The June 2026 version relocates them into an expanded FAR Part 40, Information Security and Supply Chain Security. Practically, that puts CUI obligations in the same neighborhood as the Section 889 telecommunications restrictions and supply chain security rules — one place to look instead of four.

The SF XXX — the agency tells you what you're holding

This is the structural change most worth understanding, and it's genuinely good news for small contractors. The proposed rule carries forward a standardized form — designated SF XXX in the draft — that the contracting officer completes for every solicitation and contract. It identifies whether CUI will be involved in performance, which categories are at issue, where the CUI will reside, and which safeguarding and reporting requirements apply.

If you've ever spent a week trying to work out whether a deliverable was CUI or just sensitive, you understand why that matters. The proposal shifts the first move of identification onto the agency rather than leaving contractors to guess. It doesn't eliminate your judgment entirely — the draft still expects contractors to notify the contracting officer when CUI arrives improperly marked — but it changes the starting position.

New clauses: FAR 52.240-6 and 52.240-7

Where CUI is involved in performance, contracting officers would include FAR 52.240-7, carrying the substantive safeguarding and incident-reporting requirements. The June version also drops a January 2025 clause that would have imposed obligations in contracts where no CUI was identified but might turn up anyway — a direct response to contractor complaints about open-ended obligations.

72-hour incident reporting

The January 2025 draft required reporting a suspected CUI incident within eight hours. Commenters pushed back hard, and the June 2026 version revises it to 72 hours, which aligns with the timeline under DFARS 252.204-7012 and the Cyber Incident Reporting for Critical Infrastructure Act. The draft also allows an initial report with whatever data you have, followed by supplemental reports once the investigation is substantially complete.

For a shop without a security operations center, the difference between eight hours and 72 hours is the difference between a requirement you cannot meet and one you can — if you've written the procedure in advance and know who makes the call.

NIST SP 800-171 Rev. 3 as the baseline

Both versions require contractors whose SF XXX identifies CUI to implement NIST SP 800-171. The June 2026 version raises that to Rev. 3. A limited set of contractors handling CUI tied to critical programs or high-value assets could also face the enhanced requirements of NIST SP 800-172.

If the rule finalizes as written, contractors already built to Rev. 2 — which is to say, essentially every defense contractor with a mature DFARS 252.204-7012 program — will need to work the delta between the two revisions. That's the subject of Part 3 in this series, and it's the piece with the longest lead time, which is why it's worth starting before a final rule exists.

Flow-down through every subcontract tier

Prime contractors would flow CUI requirements down through all subcontract tiers where a subcontractor handles CUI, preparing and distributing an SF XXX downstream. The mechanism mirrors the flow-down model under DFARS 252.204-7012. The FAR Council's own estimate is that roughly 7,560 subcontractors per year would be pulled into these requirements.

That number is the one to sit with if you're a subcontractor who has never held a prime contract and has assumed none of this reaches you.

Commercial contracts are not exempt

The clauses would apply to contracts for commercial products and services, with a narrow exception for contracts solely for commercially available off-the-shelf items. Commercial status is not a shield here.

Who This Actually Reaches

Sort yourself into one of three groups.

Your portfolio What July 13 changed for you What the FAR CUI rule would add
Department of War only Third-party assessment paused. Phase I self-assessment, DFARS 252.204-7012, and NIST SP 800-171 all still apply. Nothing directly — but the Rev. 3 baseline signals where the wider federal standard is heading.
Civilian agencies only (GSA, VA, DHS, and others) Nothing. CMMC was never your program. A first-time, FAR-level CUI safeguarding obligation where you previously faced a patchwork of agency-specific requirements.
Mixed portfolio Relief on the defense side's assessment step only. A second regime on the civilian side, with its own clauses, its own form, and a higher baseline revision.

The mixed-portfolio contractor is the one most likely to have misread July 13 as general relief. It wasn't. It was department-specific relief on one mechanism, arriving in the same summer that the civilian side moved toward requirements it had never carried before.

The identification problem comes first

Before any of this becomes actionable, you have to answer a question most small contractors have never had to answer on the civilian side: do I hold CUI at all, or just Federal Contract Information? That distinction drives everything downstream — scope, cost, and which requirements attach. It's the whole subject of Part 2 in this series, and it gets a full treatment in both volumes of the CMMC Practical Guides, because getting it wrong is the most expensive mistake available at either level.

📘 The two-volume reference behind this series

Everything in this article assumes you can tell FCI from CUI, scope a boundary, and recognize when a requirement is finite versus when your scope is negotiable. Those are the two volumes' subject matter.

  • CMMC Level 1: A Practical Guide for Small to Medium GovCon Contractors — all fifteen Level 1 practices, the evidence behind each, the system description, and the annual affirmation. Volume 1 on Amazon →
  • CMMC Level 2: A Practical Guide for Small to Medium GovCon Contractors — the 110 practices across 14 domains, enclave scoping, and what a defensible Level 2 posture actually looks like at small scale. Volume 2 on Amazon →

Both available in Kindle, paperback, and hardcover — Kindle from $12.99. See the series →

The Head Start Defense Contractors Already Have

Here's the part that reframes this from burden into advantage: contractors with mature DFARS 252.204-7012 compliance programs have a meaningful head start on the FAR CUI requirements. Same safeguarding family, matching incident timeline, familiar flow-down model. What doesn't transfer automatically is the civilian-specific machinery — the SF XXX, the Part 40 structure, and the Rev. 3 delta.

Which produces an unusual situation. The work you did for the defense side, during the period when the defense side's assessment requirement is paused, is the same work that positions you for a civilian requirement that never paused at all. If you wanted a reason to keep momentum through the quiet period, that's a better one than any deadline.

June 23 2026 — proposed rule published at 91 FR 37550
72 hrs Proposed CUI incident reporting window, revised up from 8 hours
Rev. 3 NIST SP 800-171 revision proposed as the civilian baseline

Start With Where You Actually Stand

Our free CMMC assessment tool walks all 15 Level 1 practices, produces an instant gap report and a prioritized remediation roadmap, and flags whether Level 2 may apply to you. Under 30 minutes. No credit card.

Run the Free Assessment →

What This Doesn't Mean

Three things, stated plainly, because the alternative is contributing to exactly the noise this article is trying to cut through.

⚠️ This is a proposed rule, not a final one

Nothing described above binds anyone today. Obligations attach when a final rule issues and the clauses appear in your contracts — not before. Proposed language routinely changes between draft and final; the eight-hour reporting window becoming 72 hours is proof of exactly that. Anyone telling you that you are currently out of compliance with the FAR CUI rule is selling something.

Second: nothing here is a forecast of the CMMC Reform Task Force's findings, which are expected roughly mid-September. We'll cover them once they exist.

Third: this is not a reason to panic-buy anything. The FAR Council has said it expects to finalize the Overhaul rules, including the CUI requirements, before the end of 2026 — and that once finalized and inserted into contracts, there would be no phase-in period. That's the fact worth planning around. Not urgency; lead time. The work takes months whether you start it in September or in December, and only one of those is on your schedule rather than a contracting officer's.

What to Do in the Next 30 Days

1

Inventory your civilian work for CUI exposure

Pull your active civilian-agency contracts and your near-term pipeline. For each, ask whether performance involves information the agency would likely designate as CUI. You're not making a legal determination — you're building a list of contracts to watch when the final rule lands and the SF XXX starts appearing in solicitations.

2

Treat your defense-side documentation as reusable, not disposable

If you have a system description, artifacts, and evidence built for the defense side, that material is the raw input for a civilian-side posture — not a parallel effort. Contractors who scrapped their compliance work after July 13 are the ones who will rebuild it twice.

3

Make the scope decision before the requirement forces it

Whole-company or dedicated enclave? That decision drives cost more than any other single choice, and it's much cheaper to make deliberately in September than reactively when a clause shows up in an award. Part 4 of this series works through it in detail.

4

Watch the right signals

For the FAR side: publication of a final rule and the clauses appearing in solicitations. For the CMMC side: a class deviation, a DFARS rule change, or an amendment to 32 CFR Part 170 — those are the mechanisms that constitute real regulatory change. A memo changes discretion; a rule changes obligations.

Where a CUI Enclave Fits

We build enclaves rather than hardening entire companies because the requirement attaches to where the CUI lives. Narrow the boundary and you narrow everything downstream — practices in scope, artifacts, evidence, ongoing maintenance. That logic doesn't change when a second regime shows up: a dedicated enclave is one environment answering to whichever requirements attach to it. What changes is the control revision and the clause set — not the architecture.

⚠️ Self-Assessment Programs Only. The L2 CUI Enclave Package is scoped for CMMC Level 2 programs eligible for annual self-assessment. Programs required to use a C3PAO are not in scope.

Two things are worth being precise about, because the market is not. Level 2 always sits on top of Level 1, not instead of it. The enclave holds CUI; your main business environment still holds Federal Contract Information (FCI) and still carries its own Level 1 obligation — fifteen practices, a system description, a self-assessment scored MET or NOT MET, and an annual affirmation. That's why the two packages are a stack rather than a menu.

And the division of labor is fixed: we provide the templates, the configuration guides, and the consulting sessions. You implement. The L2 CUI Enclave Package maps 110 practices across 14 domains to 182 defined artifacts, with a pre-filled System Security Plan, a POAM framework, a Risk Register, an evidence checklist, and dedicated enclave configuration guides for Google Workspace or Microsoft 365 GCC High. No Active Directory, no SIEM, no full-time security staff, and time estimates on every task so it stays implementable part-time.

The stack, priced

  • Free CMMC Assessment Tool — 15 Level 1 practices, instant gap report, under 30 minutes
  • L1 Turnkey Package — $2,495/year (limited time, save $500 off the regular $2,995). 8 bi-weekly consulting sessions · 15 practices mapped to 142 artifacts · Microsoft 365 or Google Workspace templates · 8 device and network configuration guides · Evidence Locker · date-stamped self-assessment documentation. Most clients complete in 2–4 weeks, varying with existing infrastructure and responsiveness.
  • L2 CUI Enclave Package — $3,495/year. 12 bi-weekly consulting sessions · 110 practices mapped to 182 artifacts.
  • Combined L1 + L2 — $5,990/year. The full stack: Federal Contract Information in the main environment, CUI in the enclave.
⚠️ Self-Assessment Programs Only. The L2 CUI Enclave Package is scoped for CMMC Level 2 programs eligible for annual self-assessment. Programs required to use a C3PAO are not in scope.

Not Sure Which Side of the Line You're On?

Thirty minutes, no cost, no obligation. Bring your contract portfolio and we'll work through what you're actually holding and where the boundary should sit.

Book a Free Consultation → See the Packages

The Second Front — a four-part series

  1. The CMMC pause didn't touch your civilian contracts (you are here)
  2. Do you actually hold CUI on a civilian contract? Identification and scoping under the SF XXX
  3. Rev. 2 to Rev. 3: what changes for a small enclave, and why lead time matters
  4. One enclave, two regimes: scoping a boundary that answers to both

About the author

Rob Maupin is the founder of Overwatch Tools, a CMMC compliance practice for small to medium defense contractors, and the author of the CMMC Practical Guides series — CMMC Level 1: A Practical Guide for Small to Medium GovCon Contractors and CMMC Level 2: A Practical Guide for Small to Medium GovCon Contractors, both from Overwatch Press. He works with 5- to 50-employee GovCon firms on right-sized compliance.

A guided documentation path for the L2 CUI Enclave Package is in development.

Sources

  • Federal Register — Federal Acquisition Regulation: Revolutionary Federal Acquisition Regulation Overhaul, published June 23, 2026 (91 FR 37550): federalregister.gov
  • Federal Register — Federal Acquisition Regulation: Controlled Unclassified Information, January 15, 2025 (90 FR 4278, FAR Case 2017-016): federalregister.gov
  • Hunton Andrews Kurth — FAR Council Releases Updated CUI Proposed Rule as Part of the Revolutionary FAR Overhaul, June 30, 2026: hunton.com
  • Department of War release on the suspension of CMMC Phase II requirements: war.gov
  • SBA Office of Advocacy — DoW Requests Information for CMMC Reform Task Force, July 20, 2026: advocacy.sba.gov
  • NIST SP 800-171: csrc.nist.gov

This article is general information about a proposed regulation, not legal advice. Contract interpretation and any question touching False Claims Act exposure should go to your attorney.

Tags: cmmc, FCI_vs_CUI, Google, L1, L2, Level 1, Level 2, MS365, NIST
Share Post
  • Twitter
  • Facebook
  • Pinterest
  • Linkedin
Finish Before the Report: The ...
Finish Before the Report: The L1 + L2 Sprint That's Right in Every Outcome
Do You Actually Hold CUI on a Civilian Contract?
Do You Actually Hold CUI on a ...

Related posts

Your Whole Office Doesn't Need to Be Level 2
Read more

Your Whole Office Doesn’t Need to Be Level 2

Your Whole Office Doesn’t Need to Be Level 2 | Overwatch Tools The Enclave Build · Part 1 of 6 Your Whole Office Doesn’t Need to Be Level 2 If your CUI lives on one or two contracts, a Level 1 workplace with a small Level 2 enclave is often the better build: easier to work in,... Continue reading
What a Task Force Report Can and Cannot Change
Read more

What a Task Force Report Can and Cannot Change

What a Task Force Report Can and Cannot Change | Overwatch Tools Reference · The Deviation, Part 3 What a Task Force Report Can and Cannot Change The report will be read as a verdict. It is closer to an opening argument. Here is how to read it when it arrives, and the three documents that actually... Continue reading
The Department Asked Seven Questions. Read Them Closely.
Read more

The Department Asked Seven Questions. Read Them Closely.

The Department Asked Seven Questions. Read Them Closely. | Overwatch Tools Analysis · The Deviation, Part 2 The Department Asked Seven Questions. Read Them Closely. The Task Force report isn’t public. The questions that shaped it have been public since July — and almost nobody has read them carefully. By Rob Maupin, Overwatch Tools — author of... Continue reading
"Suspended" Is the Wrong Word. So Is "Cancelled."
Read more

“Suspended” Is the Wrong Word. So Is “Cancelled.”

“Suspended” Is the Wrong Word. So Is “Cancelled.” | Overwatch Tools Industry Update · The Deviation, Part 1 “Suspended” Is the Wrong Word. So Is “Cancelled.” The CMMC pause stopped living in a memo in July. And the September document that half the industry read as the end of the program did not change the CMMC text... Continue reading
Rev. 2 to Rev. 3: What Changes for a Small Enclave
Read more

NIST Rev. 2 to Rev. 3: What Changes for a Small Enclave

Rev. 2 to Rev. 3: What Changes for a Small Enclave | Overwatch Tools The Second Front · Part 3 of 4 Rev. 2 to Rev. 3: What Changes for a Small Enclave The Department of War enforces one revision of NIST SP 800-171. The proposed FAR CUI rule reaches for the next one. If both touch... Continue reading

Comments are closed

Company Address

  • Overwatch Tools, Inc.
  • 300 Woodards Ford Road
  • Chesapeake Virginia 23322
  • E-Mail: info@overwatchtools.com
  • Outervision Capitol Company
  • Privacy Policy

,Copyright © 2025 Overwatch Tools, Inc.

Home
Shop
Contact us
More
More
  • Home
  • Demo & Video
  • Blog
  • About Us
  • Try Free Self-Assessment Tool