What Is a GSA Nonfederal CUI Assessment? What Contractors Need to Know Before It’s Too Late

By Mark Larson Published on September 2, 2026
In this Article
Guide to GSA NonFederal CUI Assessments

A GSA nonfederal Controlled Unclassified Information (CUI) assessment is an independent review of a contractor’s system against the security and privacy requirements the GSA initially published in May 2022, with version 1 adopted in January 2026. If an organization stores, processes, or transmits CUI on a GSA contract, that organization requires a third-party attestation to confirm compliance with GSA requirements. Deliverables include a GSA-approved plan, assessor, and concluding report.

Self-Attestation Ended, With No Phase-In

GSA issued Revision 1 of its procedural guide on January 5, 2026, moving the baseline to NIST SP 800-171 Revision 3 and adding selected enhanced requirements from draft SP 800-172 Revision 3. What it did not include was a transition period: no tiering by organization or contract size, no grandfathering of prior attestations, and no self-assessment options for smaller organizations. It should also be noted that although NIST SP 800-171 and 172 requirements are the primary focus of the assessment, 77 privacy controls from NIST SP 800-53 are also included in the assessment scope. While security takes center stage, an organization should ensure they have a robust Privacy program in place to satisfy the 77 privacy requirements pulled from NIST SP 800-53.

What the GSA CUI Assessment Involves

The GSA procedural guide defines five phases for protecting CUI:

  • Phase 1: Prepare
  • Phase 2: Document
  • Phase 3: Assess
  • Phase 4: Authorize
  • Phase 5: Monitor

The third-party assessment does not take place until Phase 3, so the boundary, information types, and the System Security and Privacy Plan need to be written and approved before testing begins. Phase 3 then produces three deliverables: a Security Assessment Plan identifying the assessment scope, the assessment itself, which includes the completion of a 515 requirement workbook, and a Security Assessment Report with risk determinations built on NIST SP 800-30.

One important item to note is that the initial assessment plan requires four approvals. The organization’s system owner and security officer, as well as the GSA ISSO and ISSM, must approve before the assessment can take place. It’s critical that organizations seeking certification follow the process defined in the GSA procedural guide.

Although approvals must be obtained prior to scheduling the assessment, organizations would be wise to select a third-party assessor early, as the GSA requires a FedRAMP-accredited 3PAO to perform the assessment.

The 3PAO requirement has generated some confusion, as the GSA procedural guide specifically calls out CUI and NIST 800-172, which is the prime focus of CMMC Level 2 assessments. While a CMMC Level 2 assessment needs to be completed by a C3PAO, in the case of a GSA CUI assessment, it must be performed by a 3PAO, not a C3PAO.

 

GSA Compliance

Being CMMC Compliant Does Not Make You GSA Compliant

Although the GSA CUI framework and CMMC framework share many similar control objectives and requirements, there are significant differences that must be accounted for. One significant current consideration that must be understood by a GSA contractor is that although the Department of Defense announced a pause in CMMC Level 2 requirements in July 2026, the GSA’s requirement is not paused, phased, or under review.

Requirement GSA CUI Framework CMMC
NIST Baseline SP 800-171 Revision 3, plus selected draft Revision 3 enhanced requirements from SP 800-172 and SP 800-53 SP 800-171 Revision 2. A transition to Revision 3 will occur at a future date
Self-Attestation Not available at any tier Level 1 and Level 2 (Self) self-assessments still apply to new contracts
Independent Assessor Required for every in-scope system, and the assessor must be accepted by GSA first Level 2 (C3PAO) and above only, and that requirement was paused in July 2026
Incident Reporting One hour from identification 72 hours under DFARS 252.204-7012
Deferring a Finding A POA&M covers most findings, but never the showstoppers Conditional certification with a POA&M closed inside 180 days

The Nine Requirements That Stop GSA Authorization Cold

GSA flags a short list it calls showstoppers. Most findings can move to a Plan of Action and Milestones. These cannot; if one is not fully implemented, approval does not happen:

  • Access enforcement (03.01.02) and remote access (03.01.12)
  • Multi-factor authentication (03.05.03); privileged and non-privileged accounts both
  • Vulnerability monitoring and scanning (03.11.02)
  • Boundary protection (03.13.01), transmission and storage confidentiality (03.13.08), and cryptographic protection (03.13.11)
  • Flaw remediation (03.14.01)
  • Unsupported system components (03.16.02)

Where Contractors Arrive Underprepared

It’s important that GSA contractors understand what the GSA considers CUI within their contract and environment. GSA contractors need to understand what information they have that the GSA considers CUI. Once that is understood, a GSA contractor can then define the secure environment and technical safeguards that must be implemented to protect the information.

The other challenge frequently encountered during assessments is a lack of sufficient documentation. A GSA contractor can establish and implement a sophisticated and robust security and privacy framework, but unless documentation, specifically the System Security and Privacy Plan (SSPP), has been prepared to accurately and sufficiently reflect the environment and supporting technical safeguards, the assessment will fail. Not only is adequate supporting documentation a requirement, but the better the documentation, the smoother the assessment will go.

 

GSA Assessment Prep

Before Your GSA Assessment Starts

As discussed, consider the following points of focus prior to undergoing:

  • Confirm the existence of CUI in your environment; understand where the data is stored, processed, or transmitted.
  • Conduct self-assessments with a focus on the noted showstoppers first.
  • Test your incident response plan against a one-hour clock. One hour is not a typical timeframe, so ensure you evaluate yourself against this requirement to ensure you are prepared.
  • Obtain required approvals noted above and identify your proposed third-party assessor early to ensure sufficient time to obtain GSA acceptance.

What Is Controlled Unclassified Information?

Information needing safeguarding under law, regulation, or government-wide policy that is not classified. The categories are described in the National Archives CUI Registry; the governing regulation is 32 CFR Part 2002.

How Often Is the GSA Assessment Repeated?

Every three years, or sooner if significant changes are made to the system’s security posture. The Monitor phase carries quarterly and annual deliverables in between, so continuous CUI compliance monitoring is built in.

Does a SOC 2 Report or ISO 27001 Certificate Help?

Yes, the process of pursuing other security certifications, such as a SOC 2 report or ISO 27001 compliance, can help to strengthen an organization’s security posture and represent established safeguards, but those certifications cannot be used as a substitute. An organization’s compliance program can shorten evidence gathering based on maturity, but it does not affect the GSA’s requirement list.

How Can Linford Help With Your GSA CUI Assessment?

Linford & Company has extensive experience with NIST assessments and is both a 3PAO and C3PAO. In addition to being able to perform GSA assessments, we understand NIST and CUI and can help with preparation or assessment services for any NIST attestation requirements, including GSA, FedRAMP compliance, and CMMC assessments.

About The Author

Mark Larson
Mark Larson

Mark Larson started working in the technology industry in 1998 where he worked in a number of different roles prior to transitioning to the public accounting world in 2004 with Ernst & Young (EY). During his 6 years at EY, Mark provided both assurance and advisory services that spanned multiple industries for both public and private companies. After leaving EY, Mark filled leadership roles within Internal Audit, Technology, and Security functions for several companies. Mark specializes in SOC examinations and enjoys helping clients establish, formalize, and report on effective control environments while strengthening their security risk profile.

"*" indicates required fields

This field is for validation purposes and should be left unchanged.
I understand and agree to the Linford & Company LLP privacy policy.**