CyberScoop reported on 7 October that federal contractors may soon face new rules for controlled unclassified information (CUI). This is sensitive data that is not classified, such as Social Security numbers. As currently written, contractors would have to report unauthorized access, including by cyberattack, within 72 hours of discovery. The rules would also set minimum electronic security standards.
Timing and final wording are still open. Attorneys told CyberScoop the rules could come by the end of this year, and likely no later than the end of President Trump's term. The Aerospace Industries Association said in filed comments that the timelines would be hard and costly to meet. Experts said firms that fall short on cyber guidelines could face False Claims Act penalties, which the government has used more often since 2022.
Our reading: a clock that starts at discovery only works if a firm can see what happens to its data. An industry source told CyberScoop that agencies do not always mark information as CUI, and contractors may not know what counts. Unmarked data is hard to watch, so unauthorized access could go unnoticed. Questions for budget owners: Where is our CUI stored? Who can open it? Would our logs show a break-in within hours?