GSA Ready Now
Three column comparison of CUI recordkeeping and incident reporting obligations: current civilian agency terms, the proposed FAR CUI rule, and DoD DFARS 7012
Back to Blog
Compliance Sep 28, 2026 9 min read

CUI Incident Reporting and Recordkeeping: What Civilian Agencies Expect Now, and What Is Only Proposed

Focus keyword: CUI incident reporting for civilian contractors

No new government-wide CUI incident reporting requirement took effect this week, for civilian contractors or anyone else. Today your reporting clock and your recordkeeping duties come from your own contract clauses, agency supplements and privacy terms. The FAR CUI rule that would standardize them is still a proposal.

That distinction matters now because the FAR overhaul is producing a lot of proposed rules, and commentary about them is easy to misread. This post covers what applies today, what would change if the FAR CUI rule is finalized as proposed, and how to keep records that hold up either way.

What Happened This Week, and Does It Change My Obligations Today?

In the past week the FAR Council released another round of proposed rules under the FAR overhaul, covering a separate set of FAR parts. The FAR CUI rule itself, including the FAR Part 40 material on definitions and CUI guidance, was revised in an earlier round of the same overhaul, published in June 2026 (FAR Case 2026-001) with a comment period that closed in July 2026. Acquisition.gov has also published a "You Said, We Did" page explaining how public feedback shaped the overhaul's proposed rules generally. As of today the FAR CUI rule remains proposed, not final.

None of this creates a requirement in force. Proposed rules can change before they are final, and some never become final. It is also not settled how the overhaul’s Part 40 text and the standalone FAR CUI rulemaking will fit together in the end. Read both as signals of direction, not as current obligations.

Several items in this week’s news were about other things, such as incurred-cost submission changes. Those matter for cost-type contracts, but they are not CUI recordkeeping or incident reporting, so they are left out here.

What Incident Reporting Do Civilian Agencies Require Right Now?

The honest answer is that it depends on your contract. There is no single government-wide CUI incident reporting clause for civilian contracts today. In practice, reporting duties come from several places:

  • Your contract and task order language. Many agencies write security and incident reporting terms directly into statements of work or task orders. This is where you will find a specific clock and a specific point of contact, if you have one at all.
  • Agency acquisition supplements. Some civilian agencies have their own clauses. For example, the Department of Homeland Security has an HSAR clause on safeguarding CUI (3052.204-72) with its own reporting requirements. Other agencies use their own supplements or agency security policies.
  • Privacy breach terms. OMB Memorandum M-17-12 directs agencies to make sure their contracts require contractors to cooperate with breach response involving personally identifiable information, including reporting. If your CUI includes PII, expect breach reporting terms tied to the agency’s privacy program.
  • The agency’s own obligations. Under the NARA CUI program regulation (32 CFR Part 2002), agencies must handle misuse of and incidents involving CUI. Agencies also have their own tight internal reporting clocks for cyber incidents under federal guidance. That is why they often ask contractors to report quickly, even when no government-wide clause says so.

FAR 52.204-21 is worth mentioning because it applies across agencies. It sets basic safeguarding requirements for contractor systems that hold Federal Contract Information. It does not contain an incident reporting requirement. If you are looking for your reporting clock, look at your contract and the agency’s supplement, not 52.204-21.

What Would the Proposed FAR CUI Rule Add?

The FAR CUI proposed rule (FAR Case 2017-016) was published in the Federal Register in January 2025. As proposed, it would do several things:

  • Use a standard form so agencies tell contractors in a consistent way which CUI is involved and which safeguards apply.
  • Point to NIST SP 800-171 as the baseline for protecting CUI on contractor systems.
  • Require contractors to report suspected or confirmed CUI incidents within 72 hours of discovery (revised from an original 8-hour proposal after industry comment).
  • Set expectations for cooperating with agency incident response.

Each of these is a proposal. The final rule could change again before it is finalized. The reporting window itself has already moved once: the original January 2025 proposal set an 8-hour window, and a June 2026 revision to the rule (FAR Case 2026-001, published as part of the broader FAR overhaul) changed it to 72 hours, aligning it with the DFARS 252.204-7012 timeline. Planning around the current 72-hour window is a reasonable stress test for your incident response process, but it is not a legal requirement today. Do not describe it to customers or partners as one.

How Is This Different From DoD and CMMC?

The defense side works differently, and mixing the two causes real confusion.

Contractors of the Department of War (DoD) that handle covered defense information fall under DFARS 252.204-7012. That clause has a defined rapid reporting requirement to DoD, specific reporting channels, and duties to preserve images of affected systems. CMMC is a DoD program that adds assessment requirements on top of that. Where an assessment is required, it is performed by an authorized third-party assessor (a C3PAO).

None of that carries over automatically to civilian contracts. There is no CMMC equivalent on the civilian side, and no civilian CUI certification exists. Some commentary this week implied that a certified assessor validates controls for CUI on civilian or commercial contracts. That description matches CMMC, not the proposed FAR CUI rule. If a civilian contracting officer or a prime asks you for a certification, ask which clause requires it. The answer will usually point to a DoD flowdown or a contract-specific term.

The reverse also holds. If you have both civilian and defense work, your DoD obligations apply to your DoD contracts. A clause your prime added for defense work does not become a civilian agency requirement.

What Records Should a GSA Schedule Holder Keep Now?

Good records serve three purposes. They show you met your current clauses. They let you report accurately and fast if something goes wrong. And they position you for whatever the final FAR CUI rule requires. A practical baseline:

  • A clause inventory. For each contract and order, list every security, privacy and incident reporting clause, the reporting clock, and the agency point of contact. This is often the most useful single document during an incident.
  • A CUI inventory. Record what CUI you receive, from which agency, under which contract, where it is stored and who can access it. 32 CFR Part 2002 governs how CUI is marked and handled, and your records should show you follow the markings and dissemination limits the agency provides.
  • System security documentation. If your contract calls for NIST SP 800-171, keep a system security plan and a record of how you meet each requirement, plus any open items. SP 800-171 includes families for incident response and for audit and accountability, which cover the logs and response capabilities you would need to report credibly.
  • Logs and incident records. Keep system and access logs long enough to reconstruct events. Keep a record of every suspected incident, including ones you decided not to report, with your reasoning.
  • Training and destruction records. Keep records showing who was trained to handle CUI and how CUI was destroyed when no longer needed.
  • Contract record retention. Current FAR Subpart 4.7 sets general retention periods for contractor records. Check your contract for longer or more specific periods, and watch how the overhaul renumbers this material.

How Should I Prepare Without Overbuilding?

Start with what you are bound to today, then plan for the proposed rule without treating it as final.

  1. 1

    Read your current contracts and orders for reporting and recordkeeping terms.

    Build the clause inventory from what is actually in your awards, not from general guidance.

  2. 2

    Make your incident response plan name names.

    Who decides whether something is reportable, who contacts the agency, and how fast you can do both.

  3. 3

    Run a tabletop exercise against the proposed 72-hour window.

    If you can meet it, you are in a good position whatever the final rule says. If you cannot, you have found a gap to close on your own schedule.

  4. 4

    Track the FAR overhaul Part 40 text and the FAR CUI rulemaking separately.

    Do this until the relationship between them is clear.

  5. 5

    Keep defense and civilian obligations in separate columns of your compliance plan.

    Do this even if one team handles both, so a DoD flowdown never gets mistaken for a civilian requirement.

Frequently Asked Questions

Is the FAR CUI rule in effect?

No. The FAR CUI rule was published as a proposed rule in January 2025 and has not been finalized. Current obligations come from your contract clauses, agency supplements and privacy terms, not from the proposed rule.

What is the incident reporting deadline for civilian contractors handling CUI?

No single government-wide deadline applies to civilian contracts today. Your deadline, if any, is set by your contract, task order or agency supplement. The proposed FAR CUI rule, as revised in June 2026, would set a 72-hour window from discovery (changed from an original 8-hour proposal), but that is still a proposal and could change again.

Does FAR 52.204-21 require incident reporting?

No. FAR 52.204-21 sets basic safeguarding requirements for contractor systems that hold Federal Contract Information, and it applies across agencies. It does not include an incident reporting requirement, so look at your contract and the agency’s supplement for reporting terms.

Is there a CMMC-style certification for civilian agency contracts?

No. CMMC is a Department of War (DoD) program, and no equivalent certification exists for civilian agency contracts. The proposed FAR CUI rule does not create a civilian certification.

What records should I keep if my GSA Schedule work involves CUI?

Keep an inventory of your security and incident reporting clauses, an inventory of the CUI you hold, and your system security documentation. Also keep logs, incident records (including incidents you decided not to report), training records and destruction records. These support compliance today and prepare you for a final FAR CUI rule.

Does the FAR overhaul change CUI obligations right now?

Not yet. The FAR overhaul is still at the proposed rule stage, including its FAR Part 40 material on CUI definitions and guidance. How that material will fit with the separate FAR CUI rulemaking is not settled.

If you want a second set of eyes on your clause inventory or incident response plan before the FAR CUI rule is finalized, reach out to the GSA Ready Now team.

Talk to a Compliance Specialist

Find Out If You're Ready for a GSA Contract

Take the free 19-question GSA readiness assessment and get a personalized score with a clear action plan — in minutes.

Start Free Assessment