The FAR overhaul is now in the formal rulemaking phase, and one of the most practical contractor issues sits in the proposed changes to information security and controlled unclassified information. On June 23, 2026, the FAR Council published proposed rules tied to the Revolutionary FAR Overhaul, including a rule covering FAR Parts 1, 2, 4, 33, 39, 40, 52, and 53. Comments are due July 23, 2026.
Why This Rule Matters
The proposed CUI rule would continue the government’s broader effort to streamline the FAR, move recurring definitions into the right location, clarify commercial-acquisition clause applicability, and organize information security and supply-chain requirements in FAR Part 40. The rule also includes proposed clauses connected to security prohibitions, covered federal information systems, controlled unclassified information, and related subcontract flowdowns. Contractors should review the Federal Register text directly because the operational requirements will come from the proposed clauses and prescriptions, not from summaries.
The July 23 Comment Window Is Short
The first rulemaking tranche gives interested parties 30 days to comment. That is not much time for contractors that need input from legal, compliance, capture, IT, security, contracts, and delivery teams.
I suggest that contractors to start with a practical triage rather than trying to digest the entire FAR overhaul at once. The key question is: which proposed changes could affect your company’s current contracts, future bids, subcontract terms, or internal control evidence?
Coley GCS is Available to Help
Since 2001, Coley GCS has helped thousands of companies successfully win and manage GSA MAS Schedules, GWACs, and IDIQ contracts.
Book Your Free Consultation or Contact us by Email or at (210) 402-6766
What Contractors Should Review First
1. CUI responsibilities and notice language. Contractors should compare the proposed CUI notice and safeguarding language against current contract clauses, subcontract templates, security plans, and proposal assumptions. The rule appears designed to make CUI communication more uniform, but contractors still need to know how CUI will be identified, where reporting must go, and what evidence they must keep.
2. Cloud and FedRAMP expectations. If a contractor stores, processes, or transmits CUI in a cloud environment, it should evaluate whether current architecture, vendor agreements, and customer commitments align with the proposed treatment. This is especially important for SaaS providers, managed-service firms, data analytics companies, and support contractors that touch government information indirectly.
3. Incident reporting readiness. A 72-hour incident-reporting concept only works if internal escalation paths are already clear. Contractors should check whether employees, subcontractors, managed service providers, and cloud vendors know how quickly they must notify the prime contractor or customer team when a potential incident involves government information.
4. Flowdown obligations. The proposed rule includes tables addressing whether covered clauses apply to commercial products, commercial services, COTS items, and commercial subcontracts. Contractors should not assume commercial status removes cyber or CUI obligations. Prime contractors should also review whether subcontract language supports timely information, auditability, and incident coordination.
5. Proposal and pricing assumptions. Cybersecurity requirements affect staffing, tooling, cloud choices, documentation, and subcontractor management. If proposed clauses become final, contractors may need to update proposal templates, compliance matrices, and pricing assumptions for opportunities involving federal information systems or CUI.
How This Connects to Enforcement Risk
The FAR proposal should also be read against the current enforcement environment. On June 18, 2026, the Justice Department announced that LOGZONE Inc. agreed to pay $507,144 to resolve False Claims Act allegations involving Navy contract cybersecurity requirements and NIST SP 800-171 implementation. DOJ said the allegations included a Defense Contract Management Agency assessment score of -170 after alleged noncompliance with required controls.
The LOGZONE matter is separate from the FAR proposed rule, and the settlement states that the claims were allegations only with no determination of liability. Still, the practical message for contractors is straightforward: cybersecurity representations, SPRS scores, control implementation, and remediation evidence need to be treated as contract performance records, not marketing language.
Recommended Next Steps
Contractors do not need to panic, but they should move quickly. The proposed rule is a chance to identify ambiguities, cost drivers, operational concerns, and implementation questions before the language becomes final.
A practical review plan should include:
- Identify active contracts and pipeline opportunities involving CUI, federal information systems, cloud services, cyber support, managed IT, software, or data services.
- Compare current cybersecurity policies, system security plans, incident-response procedures, and subcontract clauses against the proposed FAR Part 40 and Part 52 language.
- Decide whether the company should submit comments by July 23, either directly or through an industry association.
- Document remediation activity for any known gaps in NIST SP 800-171, SPRS, CUI handling, or cloud authorization support.
- Update capture and proposal teams so they can spot the issue early when solicitations begin using revised clauses.
Where Coley GCS Can Help
Coley GCS helps contractors understand how federal acquisition changes affect contract access, proposal readiness, and ongoing contract management. For GSA Schedule, GWAC, IDIQ, and federal contracting clients, the FAR overhaul is not just a legal update. It is a business-readiness issue.
If your team needs help reviewing how FAR changes may affect your government contracting strategy, GSA Schedule management, or opportunity pipeline, Coley GCS can help translate the rulemaking into practical next steps.


0 Comments