Major rules for federal contractors handling sensitive data are nearing the finish line

Major rules for federal contractors handling sensitive data are nearing the finish line
Federal contractors handling controlled unclassified information (CUI) may soon face new federal rules requiring stronger security controls and 72-hour breach reporting. The proposal could also expand False Claims Act exposure and require contractors to push CUI protections down to subcontractors. #CUI #CISA #CIRCIA #NISTSP800171 #FalseClaimsAct

Keypoints

  • Federal rules for protecting CUI are nearing finalization.
  • Contractors would have to report unauthorized access within 72 hours.
  • The proposal aligns civilian agency reporting with CISA’s CIRCIA framework.
  • Contractors must follow NIST SP 800-171 security standards.
  • Subcontractors handling CUI would also need oversight and compliance.

Read More: https://cyberscoop.com/federal-contractors-cui-cybersecurity-rules/