Mayer Brown·GOVERNMENT CONTRACTS / DEFENSE

FAR Council Proposes CUI Rule Updates, DoW Pauses CMMC Rollout

Federal contractors and subcontractors handling controlled unclassified information must monitor evolving CUI compliance rules as the FAR Council proposes updated safeguarding and incident reporting requirements while the DoW pauses CMMC implementation.

The FAR Council has issued a proposed rule updating federal contractor obligations for safeguarding controlled unclassified information (CUI), including revised security control standards and shortened incident reporting timelines for CUI breaches. Concurrently, the Department of Defense has paused its full Cybersecurity Maturity Model Certification (CMMC) rollout, delaying mandatory third-party cybersecurity assessments for most defense contractors. Contractors handling CUI for federal agencies should review the proposed FAR rule for alignment with existing compliance programs, submit public comments during the open comment period, and update interim compliance roadmaps to account for the CMMC pause while monitoring for future DoW implementation updates.

far-councilcui-compliancecmmcfederal-contractorscybersecurity-regulations
Read the original firm alert →Thursday, July 16, 2026

Stay ahead

Join the digest.

One email when the daily AmLaw 100 briefing ships. No noise, no pitch decks — just the grade 4–5 signal.