Comment on FR Doc # 2026-12559
Kay WilsonSupportBusiness
Summary: Kay Wilson of VPM Consulting submits a supplemental amendment proposing specific machine-readable data requirements for FAR Part 40 and NIST SP 800-171 flow-downs. The commenter argues that these requirements will improve clarity, consistency, and scalability for subcontractors while reducing administrative burdens.
Re: FAR Case 2026-001, Docket No. FAR-2026-0001, RIN 9000-AO86
Federal Acquisition Regulation: Revolutionary Federal Acquisition Regulation Overhaul, Parts 1, 2, 4, 33, 39, 40, and 53
I respectfully submit this supplemental amendment and corrected attachment for consideration in connection with FAR Case 2026-001.
This submission supplements my prior comment and is intended to supersede the previously submitted attachment. The revised attachment reframes the proposal as a set of minimum Federal Acquisition Regulation (FAR) data requirements for machine-readable implementation of FAR Part 40, controlled unclassified information (CUI), National Institute of Standards and Technology Special Publication (NIST SP) 800-171 Revision 3, and Open Security Controls Assessment Language (OSCAL)-compatible flow-down packages.
This corrected attachment is submitted as a proposed machine-readable implementation solution responsive to the concerns raised in the Win-Tech, Inc. comment dated July 8, 2026, submitted in connection with FAR Case 2026-001, Docket No. FAR-2026-0001, RIN 9000-AO86. Those concerns include overbroad flow-downs, unclear CUI identification, inconsistent supplier instructions, duplicative questionnaires, unexplained contract changes, and the impact of these burdens on small business subcontractors (DIB).
The revised attachment does not disclose a proprietary system design, software architecture, database structure, workflow automation method, artificial intelligence model, implementation schema, or commercial product design. It identifies only the minimum data elements that should be required for a subcontractor to understand, implement, and provide evidence for flowed-down CUI and NIST SP 800-171 Revision 3 requirements.
At minimum, a machine-readable FAR Part 40 flow-down package should identify:
1. Contract requirement or flow-down authority;
2. CUI involvement;
3. CUI category and source;
4. Applicable FAR, Defense Federal Acquisition Regulation Supplement (DFARS), or agency clause;
5. Applicable NIST SP 800-171 Revision 3 requirements;
6. Organization-defined parameters (ODPs), including assigned value, assigning authority, source, date, and scope;
7. Supplier-declared System-ID;
8. Supplier-declared Boundary-ID;
9. CUI data flow;
10. Required evidence references;
11. Metadata, including version, responsible party, approval authority, and effective date;
12. Change history, including whether each requirement is new, changed, renumbered, relocated, removed, or unchanged.
The government and prime contractor should identify the contractual CUI requirement, applicable clause, CUI source, CUI category, applicable NIST SP 800-171 Revision 3 requirements, and any assigned ODPs. The subcontractor should identify the covered system and boundary that will process, store, transmit, or protect that CUI. The subcontractor-assigned System-ID and Boundary-ID should be provided back to the prime contractor through an OSCAL-compatible System Security Plan (SSP), supplier onboarding response, or CUI applicability package before CUI is released or performance involving CUI begins.
The System-ID and Boundary-ID should not be assigned by the government or prime contractor unless the government or prime contractor owns or operates the system. For subcontractor environments, these identifiers should be supplier-assigned. This preserves the subcontractor’s responsibility for defining its own system boundary giving the prime contractor and government customer the minimum metadata to confirm that flowed-down CUI requirements are tied to a specific covered system.
The revised attachment recommends that OSCAL-compatible machine-readable flow-downs be required as the default implementation method for FAR Part 40 CUI and NIST SP 800-171 Revision 3 requirements. Where an agency or prime contractor does not use OSCAL, the agency or prime contractor should be required to document why the alternative format provides equivalent structure, metadata support, traceability, interoperability, automation support, version control, and supplier usability.
Additional proprietary implementation details, including system design methods, automation logic, internal workflows, data normalization methods, artificial intelligence-assisted evaluation methods, user interface design, and commercial implementation approaches, are retained as trade secrets and are not included in this public comment. If the FAR Council requires additional technical detail, such information should be requested only through an appropriate non-public process that protects confidential commercial information and trade secrets.
This amendment does not propose a new cybersecurity requirement. It proposes minimum machine-readable FAR data requirements that would make existing requirements clearer, more consistent, reusable, auditable, and scalable across the defense industrial base.
Respectfully submitted,
Kay Wilson
VPM Consulting
July 9, 2026