In Revision 1 of its IT Security Procedural Guide "Protecting Controlled Unclassified Information (CUI) in Nonfederal Systems and Organizations Process" (CIO-IT Security-21-112), posted January 5, 2026, the General Services Administration requires nonfederal systems and organizations to implement the security requirements of NIST SP 800-171 Rev. 3, selected enhanced requirements from NIST SP 800-172 Rev. 3, and selected privacy requirements from NIST SP 800-53 Rev. 5. For contractors who assume "the CUI standard" means whatever DFARS 252.204-7012 currently incorporates — Revision 2 — that is a meaningful divergence, and it is already in effect on GSA work.
What Changed in the Guide
The guide is not new. GSA first issued CIO-IT Security-21-112 on May 27, 2022, establishing the agency's process for protecting CUI on nonfederal systems using NIST SP 800-171, NIST SP 800-172, and selected privacy controls from NIST SP 800-53 Rev. 5.
Revision 1, posted January 5, 2026, updates those references: the baseline becomes NIST SP 800-171 Rev. 3, and the enhanced-requirement overlay becomes NIST SP 800-172 Rev. 3 — which was still in draft when GSA issued the revision, and which NIST finalized on May 13, 2026. The selected NIST SP 800-53 Rev. 5 privacy requirements remain part of the package.
That combination matters. Revision 3 of 800-171 is not a cosmetic renumbering of Revision 2. It restructures the requirement families, folds in organization-defined parameters (ODPs) that let the agency specify values a contractor must meet, and changes how implementation is documented and assessed. An organization that built its program to Revision 2 has real work to do to demonstrate Revision 3 conformance — not because the security goals changed, but because the requirement text, parameters, and evidence expectations did.
Why Two Baselines Now Coexist
On the defense side, the CUI baseline incorporated by DFARS 252.204-7012 remains NIST SP 800-171 Rev. 2. DoD has signaled an interim rule to move CMMC assessments to Revision 3, but as of this writing that rule has not published in the Federal Register, and CMMC Phase 2 itself was suspended on July 13, 2026 pending a reform review.
Civilian agencies are not waiting on that process. GSA sets its own contractor security requirements through its CIO policy and procedural guides, and it incorporates them into acquisitions through contract terms rather than through the DFARS. The result is a compliance landscape where the same company, handling the same category of information, can face Revision 2 obligations on a DoD contract and Revision 3 obligations on a GSA contract at the same time.
This is the practical consequence of a point we have made before: CUI obligations are contract obligations. They are not a single national standard that updates for everyone at once. Where an agency's requirement lives in a procedural guide or a solicitation attachment rather than in a FAR or DFARS clause, contractors who only read clause lists will miss it.
What to Do About It
Inventory which of your contracts point to which revision. Read the security requirements in your GSA vehicles and task orders directly — including referenced procedural guides and security attachments — rather than assuming a governmentwide default. Find My Requirements is built for exactly this mapping exercise.
Treat the delta between Rev. 2 and Rev. 3 as a documented gap, not a guess. Update the system security plan for the affected environment to state which revision it implements, and capture the differences in your plan of action so the record shows a deliberate, tracked transition. See frameworks for how the 800-171 and 800-172 families relate.
Watch for organization-defined parameters. Under Revision 3, an agency can specify values inside a requirement. Those values are part of the requirement, so identify where the customer has set them and make sure your implementation matches what the agency actually specified.
Remember that representations follow the contract, not the industry consensus. Civilian-agency cybersecurity representations carry the same False Claims Act weight as a defense contractor's SPRS score — as the Verizon MTIPS settlement illustrates. Certifying to a standard you have not actually implemented is the risk, regardless of which agency wrote the requirement. The enforcement page collects that pattern.
Do not assume subcontractors know. If you flow CUI down on GSA work, your suppliers may be sizing their program to the defense baseline. Confirm the standard in writing.
Key Takeaways
- GSA's CIO-IT Security-21-112 Rev. 1, posted January 5, 2026, requires contractors handling GSA CUI to implement NIST SP 800-171 Rev. 3, selected NIST SP 800-172 Rev. 3 enhanced requirements, and selected NIST SP 800-53 Rev. 5 privacy requirements.
- The DFARS 252.204-7012 baseline remains NIST SP 800-171 Rev. 2, so a single contractor can owe Revision 2 on defense work and Revision 3 on GSA work simultaneously.
- Read the security requirements in each contract and referenced procedural guide, document which revision each environment implements, and identify any agency-set organization-defined parameters before certifying compliance.