
FAR Cyber Incident Reporting Moves to Final Rule — Every Federal Contractor Gets the Clause, Not Just the DIB
Compliance Pulse · Thursday, August 27, 2026
Most defense contractors are watching the CMMC pause and waiting on September. Right instinct, wrong docket. The FAR Council's August 14 regulatory agenda quietly moved Cyber Threat and Incident Reporting — FAR Case 2021-017 — into final rule stage. It applies government-wide. Most civilian-agency contractors have never read it.
FAR Council: 2021-017 Reaches Final Rule Stage
The rule has been sitting since its October 2023 proposal. The August 14 agenda lists it under RIN 9000-AO34 in final rule stage, targeting September 2026. What it does: puts incident-reporting clauses into federal contracts government-wide, routes reports to CISA rather than a DoD portal, and expands threat-information sharing between agencies and service providers.
For DIB firms this is familiar plumbing — DFARS 252.204-7012 has required 72-hour reporting for years. For the far larger population of civilian-agency contractors — GSA schedule holders, HHS, DHS and DOT vendors, and every reseller underneath them — it is the first time an incident-reporting obligation lands in the contract itself.
Bottom line for federal contractors outside the DIB: the clause you have been reading about as a defense requirement is about to become an award condition on your side of the house.
The CUI Rule Sets Rev 3 as the Government-Wide Floor
Running in parallel: FAR Case 2026-001, the CUI rule inside the Revolutionary FAR Overhaul, published June 23 with comments closed July 23. It requires NIST SP 800-171 Rev 3 for CUI on nonfederal systems, 72-hour CUI incident reporting, and 90-day preservation of incident data.
Watch what happened to the burden. The January 2025 version demanded 8-hour reporting and obligated contractors to flag unmarked or mismarked CUI. Both are gone. The relief is real — and it arrives bundled with Rev 3 as the baseline, one revision ahead of what most DoD contractors are assessed against today.
Bottom line for GRC leads: you may be running a Rev 2 program for DoD and inheriting a Rev 3 obligation on civilian work in the same fiscal year.
September Is Now a Convergence Month
Three decisions land inside roughly thirty days. FAR 2021-017 targets September. CISA still targets September for the CIRCIA final rule — 72-hour substantial-incident and 24-hour ransom-payment reporting. And the CMMC Reform Task Force reports on or about September 13.
None of them pauses the others. A maritime facility operator could end the quarter holding a CIRCIA reporting duty, a FAR contract clause, and an unchanged July 16, 2027 MTSA deadline for its Cyber Assessment, Cyber Plan, and CySO designation.
Bottom line for CISOs and board members: treat September as one planning event, not three headlines.
What This Means for Contractors and Their Boards
Incident reporting is converging on a common shape — 72 hours, a federal portal, preserved evidence — across regimes answering to different agencies. Operationally that helps: one well-built playbook serves several duties. Contractually it does not, because each duty attaches to a different instrument, and missing one is an award-eligibility and False Claims Act problem, not a control-maturity problem. Contract eligibility is the asset being protected here.
Build the reporting decision tree before the rules land. Whoever declares “reasonable belief” at 2 a.m. should not be meeting that question for the first time in October.
If you hold civilian-agency contracts, has anyone on your team actually read FAR Case 2021-017? I'm curious how many are tracking it alongside CMMC — reply or DM me.