The proposed rule is now history. On August 11, 2026, the Small Business Administration (SBA) published its final rule, Reforms to 13 CFR 124.103 To Remove SBA’s 8(a) Program’s Rebuttable Presumption of Social Disadvantage for Individually Owned Firms Only, 91 Fed. Reg. 51568 (Aug. 11, 2026) (the Rule). The Rule takes effect September 10, 2026, and by its own terms applies to all pending applications of individually-owned applicants as of that date. A firm with an application sitting in the queue will therefore be measured against a test that did not exist when it applied.
Continue Reading Prove the Policy, Not the Story: SBA’s Final Rule Rewrites the 8(a) Social Disadvantage Test
Alex Major
Mr. Major is a partner and co-leader of the firm’s Government Contracts & Export Controls Practice Group. Mr. Major focuses his practice on federal procurement, cybersecurity liability and risk management, and litigation. A prolific author and thought leader in the area of cybersecurity, his professional experience involves a wide variety of litigation and counseling matters dealing with procurement laws and federal regulations and standards. His diverse experience includes complex litigation in federal court under the qui tam provisions of the False Claims Act and bid protest actions. He counsels all sizes of companies on issues relating to compliance with government regulations including, among other things, cybersecurity (NIST, FIPS, FedRAMP, and DFARS) requirements, multiple award schedule compliance, Section 508 issues, country of origin requirements under the Buy American and Trade Agreements Acts, cost accounting, and small business requirements. He also regularly conducts internal investigations to assist companies ensure that they are in full compliance with the law.
Meet George Jetson’s Government Contractor: 3D Printing, CUI, and Who Owns the Recipe
I’m totally aging myself (due to reruns) but The Jetsons (created by William Hanna and Joseph Barbera (1962-63)), promised us a future where you pushed a button and the “Food-a-Rac-a-Cycle,” a machine, made whatever you wanted. Dinner. Clothes. Maybe an off-brand Spacely sprocket or two. Additive manufacturing has gotten us remarkably close. Give a 3D printer the right digital file, the right material, and the right process parameters, and out comes the part. George Jetson would recognize the concept immediately. What George did not have was the Defense Federal Acquisition Regulation Supplement (DFARS).
Continue Reading Meet George Jetson’s Government Contractor: 3D Printing, CUI, and Who Owns the RecipeDoD Suspends CMMC Phase 2. What Happened, What It Means, and What Nobody Is Telling You
On July 13, 2026, the Department of Defense (DoD) announced the immediate suspension of the Cybersecurity Maturity Model Certification (CMMC) Phase 2, which had been scheduled to take effect on November 10, 2026. Phase 2 would have made third-party assessment organization (C3PAO) certification at CMMC Level 2 a condition of award for applicable contracts involving controlled unclassified information (CUI). The suspension is broader than the headline suggests. Phases 3 and 4 and all future implementation milestones are frozen until further notice.
Before you pause your compliance spend, ask the right questions:
- With no third-party assessor, whose signature now carries the legal risk? Yours.
- Does your prime contract care what the Pentagon announced? No, and it still binds you.
- That gap assessment in your files documenting your shortfalls? It did not evaporate.
- Why a memo instead of a regulation? Because a memo can be reversed just as fast.
A new CMMC Reform Task Force, reporting to the DoD Chief Information Officer (CIO), will review the program and report within 60 days, drawing on responses to a public request for information due August 14, 2026. DoD’s CIO stated that Small Business Administration data suggest future CMMC phases could cost small and midsize businesses more than $7 billion annually. Expectations are also misaligned due to an assessor shortage, with more than 100,000 companies needing assessments and roughly 100 authorized C3PAOs. Officials declined to rule out ending the program entirely, and the Cyber AB was not told before the announcement.
Continue Reading DoD Suspends CMMC Phase 2. What Happened, What It Means, and What Nobody Is Telling YouA Field Guide To NDC Status: Identifying The Defense Industry’s Newest (And Oldest) Protected Species
In December 2025, Section 1826 of the FY 2026 NDAA created one of the most valuable classifications in defense contracting and most companies that qualify don’t know it yet. Qualify as a “nontraditional defense contractor” and you’re exempt from certified cost or pricing data, FAR Part 31, and the entire DFARS business-systems architecture. The kicker?
China Supply Chain Compliance Is Becoming Whack-a-Mole
Why a clean name-match screen is no longer enough, and why the diligence meant to find hidden China exposure can create risk on the other side of the Pacific.
Picture the boardwalk version of supply-chain compliance. It’s August. Fingers are that odd combination of french fry-greasy and ice cream-sticky The arcade is humming. Someone hands you the mallet. The first mole pops up with a familiar name: Huawei. Easy. Then SMIC. Fine. Then a listed Chinese military company. Also easy. You swing, you hit the obvious targets, and for a moment the game looks like it’s under control.
Then the real game starts.
Continue Reading China Supply Chain Compliance Is Becoming Whack-a-MoleSection 847 and the New Era of DOD Continuous FOCI Monitoring
The Department of Defense’s proposed rule implementing Section 847 of the FY 2020 NDAA could fundamentally reshape how foreign ownership, control, or influence (FOCI) is monitored across the defense industrial base. Through proposed DFARS Part 240, the rule would extend recurring FOCI disclosure, National Industrial Security System (NISS) reporting, and Defense Counterintelligence and Security Agency (DCSA) oversight far beyond the traditional facility-clearance context and into ordinary government contracting. For foreign-owned contractors, allied-country suppliers, private equity sponsors, and federal subcontractors, the proposal signals the emergence of a permanent compliance regime built around continuous visibility rather than one-time vetting.
Friends, Romans, contractors, lend me your ears;
I come to disclose your owners, not to debar them.
The FOCI that contractors do is oft assessed;
The clearances are oft interred with their bones.
So let it be with allies. The honorable rule
Hath told you that we treat all foreigners alike;
If it be so, it is a grievous form,
And grievously hath the SF-328 answered it.
The speech may be a little ridiculous, but in its way, it’s also a little accurate. The proposed DFARS rule implementing Section 847 of the FY 2020 NDAA is not unkind to allies. It is, as was Mark Antony, scrupulously polite to them, right up to the moment it asks them to register as suspects.
Continue Reading Section 847 and the New Era of DOD Continuous FOCI MonitoringFAR 52.222-90 Goes Global: Cross-Border Supply Chains and the Limits of a US Flowdown
If your supply chain crosses a border, your FAR 52.222-90 flowdown is probably already wrong. Either it overpromises in ways an EU, UK, or South African supplier cannot sign without violating local law, or it underpromises and creates False Claims Act (FCA) exposure on the US side. Both versions of the problem land on the same desk, and they land on a clock.
As we covered in a prior post, FAR 52.222-90 is not a routine flowdown. It reaches subcontract administration, records access, reporting obligations, bilateral modifications, suspension and debarment, and FCA materiality. In cross-border scenarios, those same hooks meet a thicket of foreign equality, pay-transparency, sustainability, human-rights, privacy, and disclosure-blocking regimes. The result is predictable confusion, and confusion in this clause is expensive.
Continue Reading FAR 52.222-90 Goes Global: Cross-Border Supply Chains and the Limits of a US FlowdownEverything Everywhere All at Once: The Contractor DEI Clause Hits HR, Supply Chains, Invoices, and Subcontracts
Federal contractors looking for the “DEI issue” in FAR 52.222-90 may be looking in the wrong place. Yes, the clause is about what Executive Order 14398 calls “racially discriminatory DEI activities.” But that’s only the starting point. The new clause also reaches subcontract flowdowns, records access, reporting obligations, bilateral modifications, suspension and debarment, and False Claims Act (FCA) risk. This isn’t just an HR issue, and it isn’t just a DEI issue. It is a contract-administration issue, a supply-chain issue, and an invoice issue all at once.
Continue Reading Everything Everywhere All at Once: The Contractor DEI Clause Hits HR, Supply Chains, Invoices, and SubcontractsBeyond the Headlines: The Real Contractor Risks in the New DEI Executive Order
The biggest danger may be misreading the order—and creating new exposure in the process.
On March 26, 2026, President Trump issued an executive order (EO) titled “Addressing DEI Discrimination by Federal Contractors.” Read at the headline level, the order can sound like another broad anti-diversity, equity, and inclusion (DEI) pronouncement. Read as a procurement directive, however, it is something more concrete and more consequential: a command to federal agencies to begin inserting a mandatory clause into covered contracts and contract-like instruments, including subcontracts and lower-tier subcontracts, within 30 days. That shift, from messaging to mechanics, is the real story.
Continue Reading Beyond the Headlines: The Real Contractor Risks in the New DEI Executive OrderDon’t Panic! How Federal Contractors Should Navigate the Anthropic Designation
In every crisis, half the room runs in circles while the other half picks up a clipboard and starts taking stock. The Anthropic-Pentagon dispute is that crisis, and defense contractors are deciding which half they want to be in.
The short version: The government designated a FedRAMP-authorized, facility-cleared American AI company a national security supply chain threat, via social media, after the company refused to remove safety restrictions on autonomous weapons and mass surveillance. Anthropic sued days later, with the Pentagon’s own officials on the record stating the designation was “ideologically driven” with “no evidence of supply chain risk.”
Continue Reading Don’t Panic! How Federal Contractors Should Navigate the Anthropic Designation