EPISODE · Mar 10, 2026 · 1 MIN
GSA’s New CUI Rules NIST r3 vs CMMC r2
from CMMC Academy · host Armada Cyber Defense LLC
GSA recently updated its cybersecurity requirements for contractors handling Controlled Unclassified Information (CUI). While similar in concept to DoD’s CMMC program, GSA’s approach is based on NIST SP 800-171 Revision 3, while CMMC currently relies on Revision 2. This difference could force contractors that work with both agencies to meet two separate cybersecurity standards. Industry experts warn that this may create a fragmented compliance environment across federal agencies and increase costs until a government-wide CUI rule is finalized. Thank you for visiting our podcasts on CMMC Cybersecurity! Explore more insights, updates, and expert discussions on our blog: https://cybercomply.us/blog-listLuis G. Batista C.P.M., CPSMFounder & CEO, Armada Cyber Defense | CyberComply [email protected]: (305) 306-1800 Ext. 800CAGE: 9QG33 UEI: K6UZHLE1WUA7Schedule Introduction: https://calendly.com/cybercomplygrc/schedule-armada-cyber-defense-cybercomply-introduction LinkedIn: https://www.linkedin.com/in/luis-g-batista/ArmadaCyberDefense.us: https://www.armadacyberdefense.us/CyberGap.us https://cybercomply.us/cybergap (Free CMMC Level 1 & 2 Gap Assessment Tool)CyberComply.us: https://cybercomply.us/ (CMMC Level 1 & 2 GRC)
Embed this episode
What this episode covers
GSA recently updated its cybersecurity requirements for contractors handling Controlled Unclassified Information (CUI). While similar in concept to DoD’s CMMC program, GSA’s approach is based on NIST SP 800-171 Revision 3, while CMMC currently relies on Revision 2. This difference could force contractors that work with both agencies to meet two separate cybersecurity standards. Industry experts warn that this may create a fragmented compliance environment across federal agencies and inc...
NOW PLAYING
GSA’s New CUI Rules NIST r3 vs CMMC r2
No transcript for this episode yet
Similar Episodes
No similar episodes found.