One of the most significant issues of CMMC preparation has been the lack of clarity around CUI identification in contracts. Many organizations struggled to determine whether they were handling CUI and what security measures were required.
The January 16 Federal Acquisition Regulation (FAR) update introduces new requirements that mandate all agencies and contractors align with NIST 800-171, a critical standard for protecting CUI. A key component of this regulation is the introduction of Form SFXXX, which requires agencies to clearly define CUI in contracts, solving one of the most significant implementation challenges in CMMC compliance. Form SFXXX addresses this gap by requiring federal agencies to explicitly define CUI within each contract, ensure uniform classification of CUI across agencies, and facilitate contractor understanding of compliance expectations.
The rule requires federal agencies and their contractors to follow NIST 800-171 standards for handling, processing, and securing CUI. Organizations have previously struggled with ambiguous expectations regarding CUI management, often facing inconsistent guidelines between contracts. With this rule, agencies must provide clear CUI definitions upfront, ensuring contractors understand their security obligations before engaging in federal work.
There are a few steps organizations can proactively take to ensure compliance:
- Conduct a NIST 800-171 gap assessment – Evaluate current cybersecurity practices against the 110 required controls and address deficiencies.
- Review and update contracts – Work with legal and compliance teams to analyze Form SFXXX for CUI classifications in new and existing agreements.
- Implement security enhancements – Strengthen access controls, encryption, and monitoring to meet CUI handling requirements.
- Prepare for CMMC certification – Since CMMC is built on NIST 800-171, ensuring compliance now will reduce costs and effort for future CMMC assessments.
- Train teams on CUI handling – Educate employees on proper data protection protocols to align with the new FAR and CMMC requirements.
As a Registered Practitioner Organization (RPO), Tego’s Advisory Services team has been helping organizations implement NIST 800-171 controls and objectives including preparation for CMMC compliance. Contact us today to get started.