GSA Ready Now
Contractor reviewing agency supplement clauses and security attachments for CUI safeguarding obligations
Back to Blog
Compliance Aug 15, 2026 9 min read

Your Agency Already Has a CUI Clause. It Is Not Waiting for the FAR Rule.

Focus keyword: agency specific CUI clauses

The FAR CUI rule remains a proposed rule, and nothing about that status stops a civilian agency from putting CUI safeguarding language in your contract today. Agencies have their own FAR supplements, their own security handbooks, and their own statements of work, and several of them have been imposing CUI and unclassified information system requirements for years. If your compliance plan is "we will start when the FAR rule is final," you are reading the wrong document. The clauses that bind you are the ones printed in your award, not the ones pending in the Federal Register.

Comparison of defense and civilian agency FAR clauses on a balance scale: defense specific provisions and defense layering on the left, civilian specific provisions and civilian layering on the right, with the proposed FAR rule shown as a unified regulatory layer above both.
Defense contracts and civilian contracts already carry their own clause sets. The proposed FAR rule would sit as a unifying layer above both, but until it is final, each side stands on its own existing clauses.

Why Does the Proposed FAR Rule Not Decide What You Owe Today?

The government-wide FAR CUI rule (FAR Case 2017-016) was published as a proposed rule on January 15, 2025. Proposed means exactly that: it is a draft for public comment, and until a final rule is published with an effective date, there is no new government-wide FAR clause to comply with. Nobody can say when or in what form it will be finalized.

Two things are already government-wide and already final. First, FAR 52.204-21 (Basic Safeguarding of Covered Contractor Information Systems) sets fifteen basic requirements. It addresses FCI rather than CUI specifically, but it is the floor and it is in force. Second, the underlying CUI program itself under 32 CFR Part 2002 and the NARA CUI Registry binds agencies, who then reach contractors through contract terms.

Which Civilian Agencies Already Put CUI or Safeguarding Clauses in Contracts?

This list is not exhaustive, and you should verify current clause versions rather than trusting any summary, including this one.

DHS finalized a rule in 2023 adding safeguarding requirements to the Homeland Security Acquisition Regulation, including HSAR 3052.204-72 (Safeguarding of Controlled Unclassified Information) plus companion clauses on contractor employee access and incident notification. It is a final rule that names CUI directly.

GSA has long carried security requirements for unclassified IT resources in the GSAR. Check the current clause list on your Schedule rather than an older copy.

NASA carries its own security requirements clause for unclassified IT resources in the NASA FAR Supplement, backed by internal IT security handbooks incorporated by reference. DOE includes computer security requirements in the DEAR. VA leans on VA Handbook 6500.6 and its contract security appendix, attached to solicitations and flowed to subcontractors.

In most cases the operative language is an agency supplement, a handbook incorporated by reference, or a security section in the statement of work, not a FAR clause number you would recognize.

Where Does This Actually Show Up on a GSA Schedule?

At the order level, not the schedule level. Your Multiple Award Schedule contract is one set of terms. The task or delivery order placed by DHS, VA, NASA, or another agency brings that agency's supplement and security attachments with it.

The common blind spot: a contractor reviews the schedule contract, finds no CUI language, and concludes there is no obligation, while the order has a security attachment referencing a handbook nobody opened.

CUI markings also show up before award. Solicitation packages on SAM.gov carry banners stating the system contains CUI and that anyone viewing, reproducing, or disposing of it must protect it. That obligation attaches at download, before there is a contract to negotiate.

Is Any of This CMMC?

No. CMMC is a Department of War program, flowing through defense contracts alongside DFARS 252.204-7012. On the civilian side there is no equivalent certification program: no civilian CMMC, no civilian assessment body, no certificate to hang on a wall.

What exists instead is contractual safeguarding requirements, self-attestation in many cases, and agency-specific incident reporting. Anyone selling a "civilian CMMC certification" is selling something that does not exist.

If the FAR Rule Is Not Final, Why Does NIST SP 800-171 Keep Coming Up?

Because agencies do not need a FAR rule to cite it. An agency can point to NIST SP 800-171 in a statement of work, security attachment, or supplement, and once incorporated it is a contract requirement.

If the FAR rule is finalized in something close to its proposed form, 800-171 would become the common denominator across civilian contracts. If not, agencies keep citing it the way several already do. Not every civilian contract requires all 800-171 controls today. It depends entirely on the specific contract.

What Is the Reasonable Next Step?

Read your actual awards, not just the schedule contract. That means each active task order and every attachment it incorporates by reference.

Build a simple inventory: contract or order number, customer agency, any security clause or handbook cited, and whether CUI is named anywhere.

Then check whether you are actually receiving or generating CUI. Many contractors assume they are not, and some are right, but others discover drawings, facility information, procurement-sensitive material, or PII arrived months ago with markings nobody logged.

Frequently Asked Questions

Is the FAR CUI rule in effect?

No. FAR Case 2017-016 was published as a proposed rule on January 15, 2025, and a proposed rule is a draft issued for public comment. There is no government-wide FAR CUI clause in force, and no confirmed date for a final rule. Existing obligations come from agency supplements, existing FAR clauses such as 52.204-21, and contract specific security language.

Do civilian contractors need CMMC?

No. CMMC is a Department of War program that reaches contractors through defense contracts. There is no civilian equivalent and no certification available on the civilian side. Civilian CUI obligations are contractual, imposed through agency FAR supplements, statements of work and incorporated security handbooks.

Which agency has the clearest CUI clause right now?

DHS is the clearest example. It finalized a rule in 2023 adding safeguarding of Controlled Unclassified Information to the Homeland Security Acquisition Regulation, with companion clauses on contractor employee access and incident notification. It names CUI explicitly rather than using older language about sensitive information.

Does a GSA Schedule contract include CUI requirements?

Usually the operative requirements arrive at the task order level rather than in the schedule contract itself. The ordering agency brings its own FAR supplement clauses and security attachments with the order. Review each active order and its incorporated documents, not just the underlying schedule terms.

Does NIST SP 800-171 apply to civilian contracts?

It applies when your contract says it applies. Agencies routinely cite 800-171 in statements of work, security attachments and their own supplements, and once incorporated, it is a contract requirement regardless of the FAR rule's status. Whether all controls apply depends on your specific contract language.

When does a CUI obligation start?

Sometimes before award. Solicitation packages on SAM.gov can carry CUI banners requiring anyone who views, reproduces or disposes of the information to protect it, which means the obligation can attach at download. After award, the trigger is whatever your contract and its incorporated documents say.

What are the underlying sources for this?

FAR 52.204-21 (acquisition.gov); the FAR Case 2017-016 proposed rule, published January 15, 2025 (federalregister.gov); 32 CFR Part 2002 and the NARA CUI Registry (archives.gov/cui); and the DHS final rule under HSAR Case 2015-001.

Not sure which agency clauses are actually in your contract file, or whether CUI arrived without anyone logging it? Let us map your active orders and their incorporated security attachments before you spend on controls you may not need.

Run the Gap Assessment

Find Out If You're Ready for a GSA Contract

Take the free 19-question GSA readiness assessment and get a personalized score with a clear action plan — in minutes.

Start Free Assessment