Skip to content
TrackPodcasts
educationMar 10, 20261:45failed

GSA’s New CUI Rules NIST r3 vs CMMC r2

CMMC Academy

About this episode

 GSA recently updated its cybersecurity requirements for contractors handling Controlled Unclassified Information (CUI). While similar in concept to DoD’s CMMC program, GSA’s approach is based on NIST SP 800-171 Revision 3, while CMMC currently relies on Revision 2. This difference could force contractors that work with both agencies to meet two separate cybersecurity standards. Industry experts warn that this may create a fragmented compliance environment across federal agencies and increase costs until a government-wide CUI rule is finalized. 



Thank you for visiting our podcasts on CMMC Cybersecurity!
Explore more insights, updates, and expert discussions on our blog: https://cybercomply.us/blog-list


Luis G. Batista C.P.M., CPSM
Founder & CEO, Armada Cyber Defense | CyberComply
[email protected]
Office: (305) 306-1800 Ext. 800
CAGE: 9QG33   UEI: K6UZHLE1WUA7

Schedule Introduction: https://calendly.com/cybercomplygrc/schedule-armada-cyber-defense-cybercomply-introduction 

LinkedIn: https://www.linkedin.com/in/luis-g-batista/

ArmadaCyberDefense.us: https://www.armadacyberdefense.us/

CyberGap.us https://cybercomply.us/cybergap (Free CMMC Level 1 & 2 Gap Assessment Tool)

CyberComply.us: https://cybercomply.us/ (CMMC Level 1 & 2 GRC)

Get every episode summarized

Each time CMMC Academy publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.

Email me new episodes

Free for 3 shows. No card needed.

Hosts & guests

No transcript yet

This episode has not been transcribed. Request it and it moves to the front of the queue.

GSA’s New CUI Rules NIST r3 vs CMMC r2

CMMC Academy

0:00
1:45

More episodes

More from CMMC Academy

View all episodes →