On September 10, 2025, the U.S. Department of Defense (DoD) issued the CMMC Procurement Rule, which made cybersecurity compliance a condition of doing business with that agency by requiring contractors and subcontractors to meet specified security standards before accessing Federal Contract Information (FCI) or Controlled Unclassified Information (CUI). We previously covered the CMMC Procurement Rule
Controlled Unclassified Information (CUI)
GSA Introduces a New Framework for Protecting CUI in Contractor Systems
By Roma Patel on
Posted in Enforcement + Litigation
In January, the General Services Administration’s (GSA) Office of the Chief Information Security Officer issued a new procedural guide, CIO-IT Security-21-112 Rev. 1, that sets expectations for protecting Controlled Unclassified Information (CUI) when it resides in nonfederal contractor systems. Although the document is internal guidance, it creates an approval framework that may soon determine…