US Federal Contractor Data Rules Near Finalisation, With a 72-Hour Breach Reporting Deadline
US federal contractors that handle sensitive information could soon face what one lawyer called a "sea change" in how they must protect that data and report breaches. Pending federal regulations cover "controlled unclassified information" (CUI), a category of sensitive data that falls short of classified. It includes personal information such as Social Security numbers, and information that could expose vulnerabilities in critical infrastructure. Procurement attorneys say the rules could arrive as soon as the end of this year, but likely no later than the end of President Donald Trump's term. They form part of a larger overhaul of federal contracting rules.
As currently written, the proposed rules would require any unauthorised access to CUI, including through a cyberattack, to be reported to the federal government within 72 hours of discovery. The rules are a companion for most federal agencies to existing Defense Department rules on the same subject. The 72-hour window is also deliberately aligned with forthcoming CISA rules under CIRCIA, which will require critical infrastructure owners and operators to report major cyber incidents.
Contractors would also have to meet minimum electronic security standards for protecting this information. Experts said those who fail to comply with cybersecurity guidelines could face penalties under the False Claims Act, which the US government has increasingly used since 2022 to punish contractors over weak cyber safeguards. Ryan Burnette of Covington said that if finalised in its current form, it will be a fairly significant change for federal contractors.