What GSA CUI Incident Reporting Actually Requires
Say you hold a GSA Multiple Award Schedule or a government-wide acquisition contract. One of your non-federal systems touches Basic Controlled Unclassified Information, or CUI. Once a GSA contracting officer applies the guide to that work, GSA can refuse to authorize that system. One failure out of nine specific controls is enough. The guide also sets a one-hour clock on CUI incident reports, timed from identification. Every other federal cyber-incident regime this outlet has documented allows 72 hours. A failed control leaves no fallback. GSA will not accept a Plan of Action and Milestones, or POA&M, the standard workaround elsewhere in federal cybersecurity.
The guide took effect in January 2026, and GSA contracting officers can apply it to new solicitations at their own discretion. GSA CUI incident reporting sits inside a broader authorization framework. That framework can gate whether you keep processing CUI under the GSA work you already hold. So this is a defend-your-existing-business problem, not a new-opportunity story.
GSA published the guide on January 5, 2026, as document CIO-IT Security-21-112, Revision 1. Its title is “Protecting Controlled Unclassified Information (CUI) in Nonfederal Systems and Organizations Process.” This outlet could not retrieve GSA’s own hosted copy across four attempts. The operative language quoted here comes from Skadden, Arps, Slate, Meagher & Flom’s direct reading of the guide. Several other law firms corroborate that reading. The document number implies an earlier version, but this outlet did not confirm what Revision 1 changed.
The guide requires NIST SP 800-171 Revision 3, plus select controls from draft NIST SP 800-172 Revision 3. Available sourcing does not establish how that compares to the NIST baseline already cited in contractors’ existing GSA flowdowns. The guide covers any non-federal system that processes, stores, or transmits Basic CUI and isn’t already covered by FISMA or FedRAMP. There is no stated compliance deadline.
- GSA issued the guide as internal procedural direction, not a FAR or GSAR rule. It skipped notice-and-comment entirely.
- The one-hour clock runs far faster than the 72-hour DFARS/CMMC norm (see the table below).
- Nine specific controls carry zero tolerance. If one fails, the guide states GSA will not accept a POA&M, the usual path to staying authorized while a gap gets closed.
Why This Reads as a Defense Problem, Not a Sales Pitch
Nothing here creates a new federal purchase. This outlet found no request for proposals, sources-sought notice, or acquisition forecast tied to this guide. The stake is narrower. Contractors who already hold GSA business touching CUI face an authorization gate that attaches whenever a contracting officer applies the guide.
How GSA Issued CIO-IT Security-21-112 Without FAR Rulemaking
GSA didn’t need Federal Acquisition Regulation, or FAR, Council rulemaking for this. It issued the document as an IT Security Procedural Guide. That’s GSA’s own label for internal agency direction, not a codified regulation. No source found here says whether the guide would hold up if a contractor challenged its binding effect. Either way, contractors got no comment period to influence the guide and no rulemaking backstop to delay it. The federal government already runs a formal, government-wide process for this same problem. GSA didn’t wait for that process, and neither should the contractors this guide applies to. The internal readiness check applies now, regardless of when that formal process finishes.
That government-wide process is FAR Part 40, filed as FAR Case 2017-016. GSA, DoD, and NASA built that FAR Council rule jointly. It extends CUI safeguarding requirements to civilian-agency contractors for the first time, through self-attestation. The goal is one CUI standard, not fifty agency interpretations. GSA CUI incident reporting requirements exist today as agency direction, regardless of when, or whether, that consistency arrives.
GSA’s guide runs in parallel to that unfinished rule. This outlet found no evidence either way of coordination between them:
- GSA’s guide: an internal procedural document, in effect since January 2026, issued with no public comment period.
- FAR Part 40: a formal FAR Council rulemaking whose comment period closed July 23, 2026 (Federal Register 2026-12559), still awaiting a final rule.
- Neither document states how the two will reconcile once FAR Part 40 becomes final.
The Nine “Showstopper” Controls: Zero Tolerance, No POA&M
DFARS 252.204-7012, CMMC, and FedRAMP all let contractors document a gap in a POA&M and close it on a timeline. GSA’s guide removes that option for nine specific controls. Its Appendix C lists them, reported here as read directly by Skadden, Arps, Slate, Meagher & Flom:
- Access enforcement
- Remote access, limited to authorized control points
- Multi-factor authentication, phishing-resistant for remote access
- Vulnerability monitoring and scanning
- Boundary protection
- Transmission and storage confidentiality
- Cryptographic protection
- Flaw remediation
- Replacement of unsupported system components
These nine sit inside a five-phase authorization lifecycle GSA built around the NIST Risk Management Framework. The phases are Prepare, Document, Assess, Authorize, and Monitor (Holland & Knight, March 2026). Assessment isn’t self-attestation. Per Skadden’s reading of the guide, it requires a Third-Party Assessment Organization or a GSA-approved assessor. That assessor builds a Security Assessment Plan.
How GSA’s 1-Hour Clock Compares to Every Other Federal Cyber-Incident Deadline
A one-hour reporting window sounds aggressive on its own. It is an outlier. No other federal cyber-incident clock this outlet has documented from primary sources comes close.
| Regime | Incident-reporting window | Legal vehicle | Status |
|---|---|---|---|
| GSA CIO-IT Security-21-112 | 1 hour from identification | Internal procedural guide | In effect as agency direction since 2026-01-05; attaches at CO discretion |
| DFARS 252.204-7012 / CMMC | 72 hours | Codified DFARS clause | In effect |
| CIRCIA (covered entities) | 72 hours (24 hours for ransom payments) | Statute, 6 U.S.C. 681b(a) | Statute in force; implementing rule not yet final |
| FAR Part 40 (proposed) | None proposed (the rule addresses safeguarding via self-attestation, not incident reporting) | FAR rulemaking (comment period closed) | Comment period closed 2026-07-23; not final |
GSA’s own guide tells contractors not to wait for facts before reporting. Per Skadden’s reading of the guide, contractors must “not delay reporting in order to collect additional details” about the incident’s scope or the attacker’s identity. The guide never explains why GSA chose one hour over the 72-hour baseline every other regime this outlet has documented uses.
Who Actually Has to Comply, and Who’s Exempt
The guide’s scope is narrower than “every GSA contractor.” Its exemptions also leave out the one a compliance team would most expect. Per Skadden’s and Holland & Knight’s reading of the guide, current CMMC Level 2 certification does not exempt a system from this guide. Three conditions put a system in scope. CMMC certification changes neither of the first two, and whether it triggers the third exemption is unsettled.
- The guide applies only to Basic CUI, not Specified CUI. Specified CUI carries its own handling rules beyond the general baseline.
- It applies only when the CUI sits on a non-federal system. That’s one the contractor operates for itself, not one it operates on GSA’s behalf. Systems already authorized under FISMA or FedRAMP are out of scope for this specific guide.
- It applies when no other law or regulation already prescribes safeguarding requirements for that CUI category.
CMMC and GSA’s CUI guide test different things. CMMC evaluates whether a Defense Industrial Base contractor’s environment meets DoD’s cybersecurity maturity model, under DFARS 252.204-7012. GSA’s guide tests whether one specific non-federal system clears GSA’s own nine-control bar and one-hour reporting clock. Available sourcing doesn’t address whether the guide’s “no other regulation” exemption reaches a system already covered by DFARS 252.204-7012. A contractor can pass one and still fail the other.
This authorization-gate exposure applies as much to small business and mid-market GSA schedule holders as to systems integrators and other large vehicle holders. The guide does not scale its requirements down for company size. The guide also creates a private-market signal, not a federal one. MSP, MSSP, and GRC vendors may find demand for third-party assessment services built around this framework. This outlet found no federal buyer, contract vehicle, or procurement notice tied to CIO-IT Security-21-112.
What Happens If You Fail One of the Nine Controls
Authorization failure turns this compliance document into a revenue question. Once a contracting officer applies the guide to a piece of GSA business, system authorization decides whether the contractor can keep processing CUI under that work. Fail a showstopper control at that point, and GSA will not authorize the system. No POA&M option exists to keep operating while you fix it.
That’s a defend-your-incumbency problem, not a new-business pitch. It lands on any current GSA Multiple Award Schedule or GWAC holder whose non-federal systems touch Basic CUI outside FISMA or FedRAMP coverage. No confirmed instance yet exists of a contracting officer inserting CIO-IT Security-21-112 into a live solicitation. The evidence supports something narrower. This is a gate that applies to GSA CUI work whenever a contracting officer reaches for it, on a timeline no document sets.
- Confirm whether any non-federal system in your environment processes, stores, or transmits Basic CUI tied to GSA contract work, on a system not already covered by FISMA or FedRAMP.
- Check that system against all nine showstopper controls in Appendix C. A single failure blocks authorization outright, with no POA&M option, once a contracting officer applies the guide to that work.
- Rebuild your incident-response runbook around a 1-hour reporting clock, not the 72-hour assumption in most DFARS/CMMC-oriented plans. Per Skadden’s reading of the guide, GSA requires notice to the contracting GSA Information System Security Officer (ISSO), Information System Security Manager (ISSM), and Contracting Officer’s Representative (COR), plus GSA’s own Incident Response Team.
- Confirm your CMMC Level 2 certification does not satisfy this guide on its own. Per Skadden’s and Holland & Knight’s reading of the guide, it doesn’t.
FAQ
What is GSA’s CIO-IT Security-21-112 guide, and who does it apply to?
CIO-IT Security-21-112 is GSA’s own IT Security Procedural Guide, issued January 5, 2026. Its title is “Protecting Controlled Unclassified Information (CUI) in Nonfederal Systems and Organizations Process.” It applies to GSA contractors whose non-federal systems process, store, or transmit Basic CUI and aren’t already covered by FISMA or FedRAMP.
Is GSA’s CUI guide the same thing as the FAR Part 40 CUI rule?
No. FAR Part 40 is a government-wide FAR Council rule meant to set one CUI standard across all civilian agencies. Its comment period closed July 23, 2026, with no final rule published yet. GSA’s guide is a separate, agency-specific procedural document.
Does having CMMC Level 2 certification satisfy GSA’s CUI guide?
No. CMMC and GSA’s guide evaluate different things. CMMC Level 2 certifies a Defense Industrial Base contractor’s cybersecurity maturity against DoD’s model. GSA’s guide separately requires a non-federal system to pass all nine showstopper controls and clear GSA’s own authorization process. Neither one substitutes for the other.
When do I have to comply with GSA’s CUI guide?
There is no stated compliance deadline or phase-in period in the sourcing this outlet reviewed. GSA contracting officers can apply the guide to new solicitations immediately, at their own discretion.
What happens if my system fails one of the nine showstopper controls?
GSA’s guide states the system cannot be authorized, and that GSA will not accept a Plan of Action and Milestones as a workaround. That’s stricter than DFARS, CMMC, or FedRAMP. All three allow a POA&M while a contractor closes a gap on a documented timeline. The sourcing this outlet reviewed doesn’t address whether a failed system authorization also affects your broader GSA Multiple Award Schedule or GWAC eligibility. Treat that as unconfirmed, not settled either way.
BD classification: DEFEND Confidence: Moderate Evidence that would upgrade this: A confirmed instance of a GSA contracting officer inserting this requirement into a live solicitation or contract modification, or a named contractor’s CUI authorization being denied or revoked under this guide. Evidence that would downgrade this: GSA rescinding, pausing, or materially revising CIO-IT Security-21-112, or a final FAR Part 40 rule that explicitly preempts or supersedes agency-specific guides like this one.

