Updated GSA Contractor CUI Protection Requirements
ID: 47a5dc32-7649-52e6-8afe-acf55bc5c87c
STIX ID: report--47a5dc32-7649-52e6-8afe-acf55bc5c87c
Feed Name: TrustedSec blog
GSA updated its CUI protection requirements (January 2026), moving contractor obligations from NIST SP 800-171 Revision 2 to Revision 3, adding selected controls from NIST SP 800-172 and NIST SP 800-53, and requiring periodic independent assessments and various deliverables (quarterly vulnerability scans, document updates, optional annual penetration tests, and independent assessments every three years). The changes apply immediately to new GSA contracts for contractors handling or creating CUI, broaden the scope of in-scope system components, introduce "showstopper" controls with possible provisional approvals via POA&Ms, and rely on FedRAMP/FISMA distinctions for cloud vs non-cloud environments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
