Executive Gov
  • Home
  • Acquisition & Procurement
  • Agencies
    • DoD
    • Intelligence
    • DHS
    • Civilian
    • Space
  • Cybersecurity
  • Technology
  • Awards
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news
No Result
View All Result
Executive Gov
  • Home
  • Acquisition & Procurement
  • Agencies
    • DoD
    • Intelligence
    • DHS
    • Civilian
    • Space
  • Cybersecurity
  • Technology
  • Awards
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news
No Result
View All Result
Executive Gov
No Result
View All Result
Home Cybersecurity

GSA Updates Guide for Protecting CUI in Nonfederal Systems

by Jane Edwards
February 2, 2026
in Cybersecurity, News
Cybersecurity graphic. GSA issued an updated IT security procedural guide for protecting CUI in nonfederal systems.

GSA has issued an updated IT security procedural guide outlining processes to ensure that nonfederal systems and organizations protect controlled unclassified information.

The General Services Administration has issued an updated IT security procedural guide outlining processes to ensure that nonfederal systems and organizations protect controlled unclassified information, or CUI, in accordance with the requirements of GSA and the National Institute of Standards and Technology.

Table of Contents

    • You might also like
    • Office of Strategic Capital Commits Up to $820M Loan to Performance Drone Works for Domestic Component Manufacturing
    • Maureen Falvella Named NIH Chief Information Officer
    • New NASA Wind Tunnel Opens for Aircraft, Spacecraft Testing
  • What Is the Scope of the GSA IT Security Procedural Guide?
  • What Are the 5 Phases for Protecting CUI in Nonfederal Systems?

You might also like

Office of Strategic Capital Commits Up to $820M Loan to Performance Drone Works for Domestic Component Manufacturing

Maureen Falvella Named NIH Chief Information Officer

New NASA Wind Tunnel Opens for Aircraft, Spacecraft Testing

GSA Updates Guide for Protecting CUI in Nonfederal Systems

As federal agencies continue to update guidance on how contractors protect sensitive information, events like the Potomac Officers Club’s 2026 Cyber Summit offer an opportunity to stay informed about the broader federal cyber environment. Register early to save your seat at this May 21 event!

Issued on Jan. 5, the document, Protecting CUI in Nonfederal Systems and Organizations Process CIO-IT Security-21-112, Revision 1, requires compliance with specific security requirements outlined in NIST Special Publication 800-171r3 and NIST SP 800-172r3 (draft).

What Is the Scope of the GSA IT Security Procedural Guide?

According to GSA, the guide applies when CUI resides in a nonfederal system and the organization is not operating or maintaining that system on behalf of a federal agency.

Under this framework, security and privacy controls apply only to components of nonfederal systems that store, process or transmit CUI.

Organizations must coordinate use of this process with the GSA Office of the Chief Information Security Officer and obtain approval from the agency’s CISO. Once approved, GSA requires the applicable IT security and privacy requirements outlined in its IT Security Procedural Guide 09-48 to be incorporated into contract solicitation documents.

What Are the 5 Phases for Protecting CUI in Nonfederal Systems?

The procedural guide defines five phases that organizations should follow to protect CUI in nonfederal systems: prepare, document, assess, authorize and monitor.

For the initial phase, key activities include identifying and verifying information types and determining the authorization path; participating in a kickoff meeting with GSA to review the process for protecting CUI in nonfederal systems; and presenting a vendor’s solutions architecture and critical capabilities to GSA.

Under the second phase, the vendor must document the system’s security and privacy requirements using the CUI Nonfederal System Security and Privacy Plan Template provided by GSA. According to the agency, privacy requirements are required for systems with a privacy impact assessment.

Stay connected via Google News
Follow us for the latest travel updates and guides.
Add as preferred source on Google
Share5Tweet19
Previous Post

War Department Names Leaders for 6 Critical Technology Areas

Next Post

Senate Confirms Trump Nominee John Lamontagne as USAF Vice Chief of Staff

Recommended For You

Air Combat Command Stands up New Spectrum Warfare Team; Maj. Gen. Case Cunningham Quoted

by Nichols Martin
June 30, 2021
Air Combat Command Stands up New Spectrum Warfare Team; Maj. Gen. Case Cunningham Quoted

Air Combat Command (ACC) has activated a new unit that will focus on efforts to boost the U.S. military's advantage in the electromagnetic spectrum. ACC's new 350th Spectrum...

Read moreDetails

Leidos’ Gerry Fasano & DSCA’s James Hursch Earn 2024 Wash100 Awards

by Ireland Degges
April 2, 2024
2024 Wash100_Gerry Fasano and James Hursch 202442

Executive Mosaic on Tuesday spotlighted Leidos Chief Growth Officer Gerry Fasano and Defense Security Cooperation Agency Director James Hursch in honor of their 2024 Wash100 wins. The Wash100 Award annually identifies...

Read moreDetails

Pentagon Names New Command Senior Enlisted Leader, Advisers at Cybercom, DTRA, DLA

by Jane Edwards
February 10, 2023
Pentagon Names New Command Senior Enlisted Leader, Advisers at Cybercom, DTRA, DLA

The Department of Defense has announced senior leadership assignments at U.S. Cyber Command, Defense Threat Reduction Agency and the Defense Logistics Agency.Air Force Chief Master Sgt. Kenneth Bruce,...

Read moreDetails

Defense News: US Army to Permanently Station Three Armored Brigades in Europe

by Scott Nicholas
March 31, 2016
Defense News: US Army to Permanently Station Three Armored Brigades in Europe

The U.S. Army will deploy three armored brigade combat teams to Europe on nine-month deployments to train with Eastern European allies and address Russian activity along NATO's eastern...

Read moreDetails

Navy Issues Guidance on Adaptive Roadmaps for Capability Investment Decisions

by Elodie Collins
August 12, 2025
Justin Fanelli, chief technology officer at the Department of the Navy. Fanelli promotes the use of adaptive roadmaps

The Department of the Navy has issued guidance for the use of adaptive roadmaps for investment decisions and to enhance the process of delivering new capabilities that support...

Read moreDetails
Sign Up For Our Newsletter
Subscribe to our mailing list to receives daily updates direct to your inbox!
Invalid email address
Your privacy is guranteed.
Thanks for subscribing!

Sponsors

About ExecutiveGov

ExecutiveGov, published by Executive Mosaic, is a site dedicated to the news and headlines in the federal government. ExecutiveGov serves as a news source for the hot topics and issues facing federal government departments and agencies such as Gov 2.0, cybersecurity policy, health IT, green IT and national security. We also aim to spotlight various federal government employees and interview key government executives whose impact resonates beyond their agency.

CATEGORIES

  • Acquisition & Procurement
  • Announcements
  • Articles
  • Artificial Intelligence
  • Awards
  • Big Data & Analytics News
  • C4ISR
  • Civilian
  • Cloud
  • Contract Awards
  • Cybersecurity
  • Defense And Intelligence
  • Defense Security Cooperation
  • DHS
  • Digital Assets
  • Digital Modernization
  • DoD
  • Events
  • Executive Moves
  • Executive Spotlights
  • Federal Civilian
  • Financial Reports
  • Foreign Military Sales
  • General News
  • GovCon Expert
  • Government Cloud
  • Government Technology
  • GSA
  • Healthcare IT
  • Industry News
  • Intelligence
  • Legislation
  • M&A Activity
  • National Security
  • News
  • Policy Updates
  • Press Releases
  • Profiles
  • Space
  • Videos
  • Wash100
Sign Up For Our Newsletter
Subscribe to our mailing list to receives daily updates direct to your inbox!
Invalid email address
Your privacy is guranteed.
Thanks for subscribing!

Copyright 2026 Executive Mosaic. All Rights Reserved. Site Archive

No Result
View All Result
  • Home
  • Acquisition & Procurement
  • Agencies
    • DoD
    • Intelligence
    • DHS
    • Civilian
    • Space
  • Cybersecurity
  • Technology
  • Awards
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news

Copyright 2026 Executive Mosaic. All Rights Reserved. Site Archive

Get your free GovCon news!

Get your latest GovCon news and insights. Become a VIP and subscribe to the GovConWire Daily News.

Invalid email address
We promise not to spam you. You can unsubscribe at any time.
Thanks for subscribing!