Skip to content

New ISOO Guidance Requires Clearer Contract Direction on CUI and Tightens Agency Waiver Oversight

September 8, 2026

On September 2, 2026, the Information Security Oversight Office (ISOO) issued two notices reinforcing federal agency responsibilities for implementing the Controlled Unclassified Information (CUI) Program under Executive Order 13556 and 32 C.F.R. Part 2002. With an increase in “sophisticated” cyber threats, foreign intelligence collection, and unauthorized disclosure risks, these notices dictate added protections that federal agencies must now institute to protect sensitive government information. ISOO Notice 2026-07 requires every contract requiring access to CUI to include specific agency guidance to the prime contractor covering markings, safeguarding, training, reporting, and penalties for misuse. Concurrently, ISOO Notice 2026-08 substantially tightens the oversight and reporting requirements for agency CUI waivers, elevating the threshold for exigent-circumstances waivers.

What Does This Mean for Your Business?

These notices serve as a stark reminder that CUI compliance involves far more than implementing technical cybersecurity controls. Contractors must also address identification, marking, access, training, reporting, disposition, and supply-chain oversight.

  • Expanded Duties for Prime Contractors: Prime contractors should expect solicitations and contracts to contain more structured, detailed CUI instructions. This will shift greater contract-administration responsibility to primes, who must reconcile CUI instructions dispersed across contract clauses and agency policies, while translating these rules into accurate subcontract requirements.
  • Subcontractor and Supply-Chain Squeeze: Subcontractors should anticipate more precise requirements regarding CUI identification, system restrictions, cyber incidents, and lower-tier dissemination. Failure to validate whether prime contractor requirements accurately reflect the underlying contract can create unnecessary exposure, including uncompensated compliance expenses and performance disputes.
  • Formalization of Waivers: An informal agency accommodation is no longer sufficient. Notice 2026-08 makes clear that administrative burden alone does not justify an exigent-circumstances waiver. Contractors receiving information under a claimed waiver face strict documentation requirements and must obtain written direction detailing the waiver’s scope, alternate protections, and duration.
  • The Bottom Line: Federal agencies must provide clearer and more comprehensive CUI direction in contracts, and agencies now face stronger documentation and ISOO oversight requirements when using waivers. Strong CUI governance is rapidly becoming a de facto standard of care for contractors seeking to protect existing work and position for future federal opportunities; waiting for the CMMC review to conclude creates unnecessary exposure.

Recommendations

Proactive preparation is essential. Contractors may want to take the following steps:

  • Create a Contract-Level CUI Requirements Matrix: Compare every contract involving CUI against the 12 categories of guidance identified in Notice 2026-07. Identify government-furnished information designated as CUI, required safeguards, reporting duties, and decontrol instructions. Elevate missing or inconsistent requirements through formal contract-administration channels. Documentation is key.
  • Formalize CUI Challenge Procedures: Train personnel to recognize missing, inconsistent, or potentially improper CUI markings. Establish an internal escalation process to submit a documented challenge or request for clarification rather than unilaterally removing markings or relaxing safeguards.
  • Require Written Waiver Direction: Do not rely on informal assurances that an agency has waived CUI requirements. Obtain written documentation identifying the waiver category, approving authority, covered information, alternate safeguards, and conditions for reinstating ordinary requirements.
  • Strengthen Supply-Chain Oversight: Review subcontract clauses, system-access arrangements, training requirements, and disposition procedures. Flow down applicable requirements accurately rather than imposing blanket requirements unsupported by the prime contract.
  • Validate Contractually Required Cybersecurity Controls: Where NIST SP 800-171 applies, rigorously adhere to those requirements, confirm that the System Security Plan reflects the actual operating environment, and ensure that sufficient evidence supports each implemented requirement.
  • Account for Compliance Costs in Proposals: Evaluate whether enhanced CUI requirements will necessitate new technology, training, supplier monitoring, or legal review. Incorporate those costs into proposal strategies to protect margins and avoid uncompensated performance obligations.

If you have questions about specific jurisdictions or need further assistance, contact one of these Clark Hill Government Contracts and Regulations Team attorneys managing the tracker:

Browse more Government Contracts and Regulations attorneys and subscribe to our newsletter to receive future Clark Hill alerts directly to your inbox.

This publication is intended for general informational purposes only and does not constitute legal advice or a solicitation to provide legal services. The information in this publication is not intended to create, and receipt of it does not constitute a lawyer-client relationship. Readers should not act upon this information without seeking professional legal counsel. The views and opinions expressed herein represent those of the individual author only and are not necessarily the views of Clark Hill PLC. Although we attempt to ensure that postings on our website are complete, accurate, and up to date, we assume no responsibility for their completeness, accuracy, or timeliness.

Subscribe for the latest

Subscribe