EDUCAUSE Encourages Continued Improvement of FAR CUI Requirements

min read


The Trump administration's revamp of the regulations governing federal contracts incorporates positive changes to the controlled unclassified information (CUI) provisions proposed under a prior rulemaking. EDUCAUSE comments on the currently proposed regulations, however, highlight the need for additional improvements.

In April 2025, the Trump administration issued an executive order launching a "revolutionary overhaul" of the Federal Acquisition Regulation (FAR), which governs federal contracting.Footnote1 Through this process, the administration hoped to radically streamline federal contracting requirements that had grown to thousands of pages, adding greatly to the complexity and cost of working with federal agencies.

By late June of this year, the Federal Acquisition Regulatory (FAR) Council, which encompasses representatives from the White House Office of Management and Budget (OMB), the General Services Administration (GSA), the U.S. Department of Defense (DoD), and the National Aeronautics and Space Administration (NASA), was ready to begin overhauling the FAR. It released four separate notices of proposed rulemaking (NPRMs) that presented a myriad of potential contracting regulation reductions, revisions, and eliminations. Fortunately for higher education institutions, one of the NPRMs covers the proposed FAR controlled unclassified information (CUI) provisions.Footnote2

The FAR Council had released a specific rulemaking on CUI requirements for the FAR in the closing days of the Biden administration. A group of research-focused higher education associations joined EDUCAUSE in submitting a joint response to the Council highlighting the following problems with the proposed regulations:Footnote3

  • The proposed definition of CUI in the regulations did not match the definition established in the CUI program's implementing regulations, creating unnecessary compliance risks for institutions and other organizations contracting with federal agencies.
  • The proposed definitions of CUI and "covered federal information" (CFI) explicitly excluded fundamental research, as higher education institutions would expect given established federal policy.Footnote4 However, the proposed exclusion could be interpreted as applying only to fundamental research in science, technology, and engineering. Under this interpretation, fundamental research in other fields conducted under contract for federal agencies could remain subject to CUI and CFI cybersecurity requirements.
  • The deadline for reporting CUI security incidents to a project's federal contracting officer would be only eight hours under the proposed regulations, which we argued was an unduly brief amount of time given that a similar DoD contracting requirement allowed seventy-two hours for such reporting.
  • The proposed requirements for contractors to safeguard possible CUI that the contracting agency had failed to mark or had marked incorrectly were overly expansive. Under the proposal, most of the burden for assessing and securing such information would be placed on the contractor, despite the potential confusion and uncertainty that affected entities would face in trying to determine if there was a sufficient basis for applying CUI security measures.Footnote5

Rather than finalizing the Biden-era FAR CUI proposal, the Trump administration chose to integrate the addition of CUI provisions to the FAR through its FAR overhaul project. In our comments on the CUI requirements in the overhaul regulations, EDUCAUSE noted that the proposed provisions addressed the concerns we had raised during last year's rulemaking:

  • The fundamental research exclusions in the currently proposed versions of the CUI and CFI definitions appear to encompass fundamental research in general—not just in the fields of science, technology, and engineering—as we requested.
  • Contractor responsibility for unmarked or mismarked CUI is limited only to those cases where clear evidence exists that the information in question might be CUI.
  • The deadline for reporting CUI cyber incidents now aligns with the seventy-two-hour reporting deadline that already exists for DoD contracts.

Another change we agree with, although it was not a major part of our comments on the prior rulemaking, is the exclusion of one-size-fits-all CUI training mandates for contractors proposed under the Biden administration. Instead, the new proposed regulations would give contractors the flexibility to train relevant staff consistent with their job responsibilities and the contractor's compliance requirements.Footnote6

While the FAR overhaul CUI requirements represent positive moves toward EDUCAUSE member interests, member representatives from our research cybersecurity community asked that the EDUCAUSE comments on the relevant NPRM encourage the FAR Council to make modest additional improvements, including the following:

  • The "clear evidence" standard for determining whether information might legitimately be unmarked or mismarked CUI should incorporate objective identifiers on which a contractor might reasonably base such a determination (e.g., government markings, labels or other formal identifiers, or metadata identifying CUI).
  • The official form that agencies use to identify the CUI involved in a project should include guidance stating that contractors are not required to independently infer CUI status in the absence of objective indicators and should not attempt to do so. Federal program and contracting officers are responsible for making those determinations.
  • Given the demonstrated potential for federal program and contracting officers to make mistakes in identifying and marking CUI, the government should add to the standard project CUI form a structure or taxonomy for listing CUI, including consistent categories and identifying elements.
  • The DoD said it intends to update Cybersecurity Maturity Model Certification (CMMC) Level 2 standards from NIST SP 800-171 Revision 2 to NIST SP 800-171 Revision 3, which is the version of 800-171 that the new FAR CUI regulations propose to incorporate. However, given the potential for delays in the DoD's action, the final FAR overhaul regulations should state that the version of NIST SP 800-171 with which a contractor must comply is established at the time a contract is awarded and that any subsequent changes must be negotiated between the agency and the contractor.
  • Since the proposed regulations allow organizations competing for a contract to use plans of action and milestones (POA&Ms) to explain, in a timely manner, how they will address gaps in their CUI security readiness during an award period, the regulations should include steps to ensure that the inclusion of a POA&M in a contract proposal will not put an organization at a competitive disadvantage (e.g., contracting guidance to agencies should require them to evaluate POA&M disclosures on the credibility of the proposed remediation plan, not the extent of existing compliance gaps).Footnote7

Comments on the current FAR overhaul NPRMs were due in late July, and EDUCAUSE met that deadline. It is not yet clear when the final version of the regulations, including the current CUI proposals, will be released. The EDUCAUSE policy team will continue to watch for the final regulations to be made available in the hope that the FAR CUI requirements will continue to move in a positive direction for EDUCAUSE members.

Notes

  1. Donald J. Trump, "Restoring Common Sense to Federal Procurement" (Executive Order 14275), Federal Register, Vol. 90, No. 74, April 15, 2025, pp. 16447–16449. Jump back to footnote 1 in the text.
  2. Office of Federal Procurement Policy et al., "Federal Acquisition Regulation: Revolutionary Federal Acquisition Regulation Overhaul Parts 1, 2, 4, 33, 39, 40, and 53," Federal Register 91, no. 119 (June 2026): 37550–37634. Jump back to footnote 2 in the text.
  3. Jarret Cummings, "EDUCAUSE Recommends Changes to Proposed FAR CUI Rules," EDUCAUSE Review, April 23, 2025. Jump back to footnote 3 in the text.
  4. The proposed CFI definition was intended to replace the existing "federal contracting information" (FCI) definition in the FAR. Jump back to footnote 4 in the text.
  5. Jarret Cummings, "EDUCAUSE Recommends Changes to Proposed FAR CUI Rules." EDUCAUSE Review, April 23, 2025. Jump back to footnote 5 in the text.
  6. EDUCAUSE letter to William F. Clark, Director, Office of Government-wide Acquisition Policy, General Services Administration, "Comments regarding FAR Case 2026-001, "Federal Acquisition Regulation: Revolutionary Federal Acquisition Regulation Overhaul Parts 1, 2, 4, 33, 39, 40, and 53, (Proposed Rule), submitted at https://www.regulations.gov/commenton/FAR-2026-0001-0001, July 23, 2026. Jump back to footnote 6 in the text.
  7. Ibid. Jump back to footnote 7 in the text.

Jarret Cummings is Senior Advisor, Policy and Government Relations at EDUCAUSE.

© 2026 EDUCAUSE. The content of this work is licensed under a Creative Commons BY-NC-ND 4.0 International License.