Comment on FR Doc # 2026-12560

Rob LeslieSupportBusiness
Summary: Robert T. Leslie of Computer Solutions Unlimited, Inc., a small business, supports the goal of a uniform CUI framework but requests specific modifications to reduce the compliance burden on small entities. He asks the Council to explicitly recognize "scope minimization" (bounded CUI enclaves) as a valid cost-reduction strategy and to provide clear, direct guidance on which NIST SP 800-171 revision governs compliance to avoid confusion between FAR and DFARS/CMMC requirements.
Re: FAR Case 2026-001, Controlled Unclassified Information (CUI) Requirements (FAR Part 40, Subpart 40.3; proposed clause FAR 52.240-7) Submitted by: Robert T. Leslie, Computer Solutions Unlimited, Inc., a veteran-owned small business providing CUI compliance infrastructure to small and mid-sized Defense Industrial Base manufacturers in New Jersey and the surrounding region. I submit this comment based on direct, hands-on experience building and operating CUI-compliant environments for small manufacturers, not as a policy generalist. I support the Council's goal of a uniform, government-wide CUI framework, and I ask the Council to consider two points from that operational vantage point. Scope minimization should be recognized explicitly as a cost-reduction path for small entities. The rule's own regulatory impact analysis, from the January 2025 proposed rule this action supersedes, estimated small business compliance costs at $175,700 in the first year and $103,800 annually thereafter. I have delivered functionally equivalent CUI safeguarding for a fraction of that cost, on a fixed-price basis, by physically isolating the systems that touch CUI into a defined, minimal boundary rather than applying the full control set across a client's entire IT environment. This is a standard, well-understood architecture pattern, not a novel one, and it directly addresses the compliance burden the Council's own analysis identifies as its central small-business concern. I ask the Council to explicitly recognize scope minimization, i.e., a properly bounded CUI enclave rather than an enterprise-wide control deployment, as a legitimate and encouraged cost-reduction strategy for small entities, consistent with the boundary-definition concepts already present in existing NIST and CMMC assessment guidance. The relationship between this rule's safeguarding baseline and the DFARS/CMMC baseline needs to be stated plainly, not left to inference. The preamble indicates that the new Standard Form (SF XXX) will identify Organization-Defined Parameters aligned to NIST SP 800-171 Revision 3, harmonized to the values to be codified in 32 CFR Part 170. However, 32 CFR Part 170, the CMMC program rule, currently remains pinned to NIST SP 800-171 Revision 2 under DoD's existing class deviation. A small business that holds both a DoD contract subject to DFARS 252.204-7012 (Revision 2) and a civilian agency contract subject to this rule's CUI clause could reasonably read the current text as requiring simultaneous compliance with two different control baselines. I ask the Council to state directly, rather than leave to inference, which NIST SP 800-171 revision governs compliance under FAR 52.240-7 as of the final rule's effective date; to confirm whether a contractor's Revision 3 implementation will be treated as satisfying a concurrent Revision 2 DFARS obligation, or vice versa, during whatever transition period applies; and to provide a clear timeline for when the FAR baseline and the DFARS/CMMC baseline are expected to converge on a single revision. Small entities operating across both defense and civilian contracts cannot efficiently budget for, or design systems around, a standard that may change baseline twice within a short window. In summary, I ask the Council to take two concrete actions in the final rule: first, explicitly recognize physical scope minimization, a properly bounded CUI enclave rather than an enterprise-wide control deployment, as a legitimate cost-reduction strategy for small entities; and second, state directly which NIST SP 800-171 revision governs compliance under FAR 52.240-7, confirm how a Revision 3 implementation is treated against a concurrent DFARS Revision 2 obligation, and provide a timeline for when the two baselines are expected to converge. Both changes would reduce real, avoidable compliance burden on small Defense Industrial Base manufacturers without weakening the safeguarding standard itself. Thank you for the opportunity to comment. Robert T. Leslie Computer Solutions Unlimited, Inc.

View on Regulations.gov