Federal contractors handling controlled unclassified information (CUI) may soon face new federal rules requiring stronger security controls and 72-hour breach reporting. The proposal could also expand False Claims Act exposure and require contractors to push CUI protections down to subcontractors. #CUI #CISA #CIRCIA #NISTSP800171 #FalseClaimsAct
Keypoints
- Federal rules for protecting CUI are nearing finalization.
- Contractors would have to report unauthorized access within 72 hours.
- The proposal aligns civilian agency reporting with CISAβs CIRCIA framework.
- Contractors must follow NIST SP 800-171 security standards.
- Subcontractors handling CUI would also need oversight and compliance.
Read More: https://cyberscoop.com/federal-contractors-cui-cybersecurity-rules/