Skip to main content
Should You Wait for a Phase-In That Isn't Coming?Training & Monitoring
5 min readFor Compliance Training Managers

Should You Wait for a Phase-In That Isn't Coming?

The question at hand

Your organization just secured a GSA contract that involves handling Controlled Unclassified Information (CUI). A colleague at a defense contractor mentions they're holding off on major security investments, waiting to see how CMMC requirements evolve. You're wondering: can you take a similar wait-and-see approach with GSA's CUI assessment requirements?

The short answer is no. This situation reveals a larger strategic question for federal contractors. When one agency pauses enforcement while another demands immediate compliance, how do you allocate your security budget and training resources?

GSA revised its procedural guide on January 5, 2026, establishing NIST SP 800-171 Revision 3 as the baseline and adding selected enhanced requirements from draft SP 800-172 Revision 3. Notably absent: any transition period, tiering by organization size, or self-assessment option. If you store, process, or transmit CUI on a GSA contract, you need third-party attestation now.

The case for immediate action

The argument for treating GSA CUI assessments as urgent rests on three practical realities.

First, the approval process takes time you probably haven't budgeted for. Before your third-party assessor can begin testing, four separate approvals are required: your system owner, your security officer, the GSA ISSO, and the GSA ISSM. This isn't a rubber-stamp process. You'll need a complete System Security and Privacy Plan that accurately documents your boundary, information types, and technical safeguards before anyone signs off.

Second, GSA maintains a list of nine showstopper requirements that cannot be deferred to a Plan of Action and Milestones. If you're missing multi-factor authentication on both privileged and non-privileged accounts (03.05.03), or if your flaw remediation process (03.14.01) isn't fully implemented, your authorization stops cold. No conditional approval, no 180-day remediation window. These aren't aspirational controls you can phase in later.

Third, the incident reporting timeline is unforgiving. GSA requires notification within one hour of identifying a CUI-related incident. That's not the 72-hour window you might be used to under DFARS 252.204-7012. If your current incident response plan assumes you have three days to assess, escalate, and notify, you're not compliant. Testing that plan against a one-hour clock isn't something you can defer until the week before your assessment.

Organizations that move quickly also gain a practical advantage: early selection of a FedRAMP-accredited 3PAO. The assessor needs GSA acceptance before work begins, and qualified assessors have limited availability. Waiting until you're under contract pressure to find and vet an assessor adds risk you don't need.

The case for strategic pacing

The counterargument isn't that you should ignore GSA requirements entirely. It's that rushing to full compliance before you've clarified your CUI footprint and system boundaries can lead to wasted effort and misallocated resources.

Some contractors discover during their initial scoping that what they assumed was CUI actually isn't, or that the CUI they handle can be isolated to a much smaller system boundary than they originally thought. Investing in enterprise-wide controls before you've confirmed where CUI actually lives in your environment means you might secure systems that don't need securing while overlooking the ones that do.

There's also the documentation burden. The GSA assessment involves completing a 515-requirement workbook and producing a Security Assessment Report built on NIST SP 800-30 risk determinations. If your current documentation consists of outdated policies and spreadsheets that haven't been updated since your last audit, jumping straight to a third-party assessment sets you up for failure. Better to spend three months building accurate, sufficient documentation than to fail an assessment because your System Security and Privacy Plan doesn't reflect your actual environment.

The pacing argument also acknowledges budget realities. A robust privacy program covering 77 controls from NIST SP 800-53 isn't something you implement in a quarter, especially if privacy has historically been an afterthought in your security planning. Organizations with mature SOC 2 or ISO 27001 programs can use existing evidence and controls, but if you're starting from scratch, a phased buildout might be more sustainable than a crash program that exhausts your team.

Where practitioners actually land

Most compliance managers I've spoken with aren't choosing between immediate action and strategic delay. They're doing both, in sequence.

They start with a rapid CUI scoping exercise: confirm what information GSA considers CUI in your contracts, map where that data is stored, processed, or transmitted, and define the system boundary you'll need to secure. This isn't a six-month architecture project. It's a focused effort to understand your actual compliance obligation.

Then they run internal self-assessments focused specifically on the nine showstopper requirements. You don't need a third-party assessor to tell you whether you've implemented multi-factor authentication or vulnerability scanning. If you're missing those controls, you know your timeline immediately.

The documentation work happens in parallel. Your System Security and Privacy Plan needs to exist before Phase 3 begins, so starting that writing process early, while you're still remediating technical gaps, keeps you moving forward.

What practitioners aren't doing is waiting for GSA to announce a phase-in period or hoping the requirements will soften. The Department of Defense paused CMMC Level 2 requirements in July 2026, but GSA's requirement is not paused, phased, or under review. Treating them as equivalent risks is a planning error.

Our take

The wait-and-see approach made sense when regulatory guidance was still in draft form or when agencies were signaling flexibility. Neither applies here.

GSA's January 2026 revision was clear: third-party attestation is required, no self-assessment option exists, and the baseline is Revision 3 now. The nine showstopper requirements leave no room for conditional authorization. Your one-hour incident reporting obligation starts the moment you handle CUI, not the moment you complete your assessment.

That said, rushing into a third-party assessment before you've scoped your CUI footprint and built sufficient documentation wastes money and sets your team up for a failed audit. The right sequence is: scope fast, self-assess the showstoppers, document accurately, then engage your 3PAO.

If you're a GSA contractor handling CUI and you haven't started this process, you're not strategically pacing. You're behind. The question isn't whether to act, it's whether you'll finish before your contract requires it.

You Might Also Like