US nears unified data protection rules for federal contractors
Federal contractors handling controlled unclassified information (CUI) could soon face unified cybersecurity and reporting rules. The proposal mandates reporting unauthorized access within 72 hours and compliance with NIST SP 800-171 standards.
- Rules could be finalized by the end of 2026
- CUI incidents must be reported within 72 hours
- Contractors must follow NIST SP 800-171 standards
- Violations could trigger False Claims Act penalties
Read next
Policy