Defense & National Security

The FY2026 National Defense Authorization Act (NDAA) became law on December 18, 2025, enacting a tidal wave of the Trump administration’s priorities with respect to Department of Defense (DoD) procurement. One key priority reflected in the NDAA is reducing compliance burdens so that (i) established DoD contractors are incentivized to pursue awards and (ii) more companies opt in to being a DoD contractor to grow the industrial base. Importantly, Section 1804 and Section 1806 of the NDAA take action on this priority by raising the dollar thresholds for complex domains of government contracting: the Cost Accounting Standards (CAS) and submission of certified cost or pricing data. While these changes are welcome developments, companies should be cognizant that a steady stream of compliance requirements remains even with these increased thresholds.

Continue Reading Swept Away: FY2026 NDAA Updates to CAS and Certified Cost or Pricing Data Thresholds

Congress has once again reshaped the protest landscape—this time with a narrow but consequential change targeted squarely at Department of Defense (DoD) procurements. The Fiscal Year 2026 National Defense Authorization Act (NDAA), signed into law by the president on December 18, 2025, includes a new provision designed to discourage meritless protests at the Government Accountability Office (GAO), particularly where an incumbent contractor continues performing work during the protest. Although the language is focused and does not overhaul the protest system more broadly, it introduces a real financial risk calculus that unsuccessful incumbent offerors will now need to consider before pulling the protest trigger.

Continue Reading Cracking the Kitchen Sink: FY2026 NDAA Brings Bid Protest Reforms for Defense Contractors That Lodge Meritless Protests

On December 18, 2025, the Fiscal Year 2026 National Defense Authorization Act (FY2026 NDAA) became law. True to each year’s NDAA being a sprawling piece of legislation, the FY2026 NDAA contains many priorities of the current Administration. Nestled among its myriad provisions, federal grant recipients should take note of Section 230, the “Prohibition on Modification of Indirect Cost Rates for Institutions of Higher Education and Nonprofit Organization.” This section provides a speed bump for rapid changes to indirect cost rates for Department of Defense grantees and reflects congressional sympathy to grantee concerns, particularly those of institutes of higher education (IHEs).

Continue Reading College Prep: What Colleges with DoD Grants Should Do Now Under the FY2026 NDAA

Drumroll, please. On November 7, 2025, the Department of Defense (DoD) released three memoranda signaling changes to its approach to procurement and Foreign Military Sales/Direct Commercial Sales in the years to come: “Unifying the Department’s Arms Transfer and Security Cooperation Enterprise to Improve Efficiency and Enable Burden-Sharing”; “Reforming the Joint Requirements Process to Accelerate Fielding of Warfighting Capabilities”; and “Transforming the Defense Acquisition System into the Warfighting Acquisition System to Accelerate Fielding of Urgently Needed Capabilities to Our Warriors.” The latter memorandum appends the DoD’s Acquisition Transformation Strategy (the Strategy), which is aimed at dramatically reforming how the DoD’s acquisition system operates with an eye toward increasing the speed and flexibility of DoD procurements and the acquisition workforce. This document begins the march toward sunsetting the existing Defense Acquisition System in favor of what is envisioned to be a more rapid and effective system designed to provide the DoD with the capabilities it needs to meet its mission requirements.

Continue Reading The Drumbeat of Progress: DOD’s Acquisition Transformation Strategy

July’s “Winning the Race: America’s AI Action Plan,” released by the White House, contains helpful recommendations for the energy sector as the use of AI becomes more prevalent and, with it, the need for more energy. The plan recommends the use of an existing consultation and coordination process for expediting the federal permitting and review of large infrastructure projects to cover all eligible data center and data center energy projects. It also recommends optimizing existing grid resources, prioritizing the interconnection of reliable power sources, ensuring sufficient generation exists to support data centers, and embracing new technology and sources of energy.

Continue Reading Power Up: What the AI Action Plan Means for the Energy Sector

On June 6, 2025, President Trump issued a new executive order, “Sustaining Select Efforts to Strengthen the Nation’s Cybersecurity and Amending Executive Order 13694 and Executive Order 14144” (EO), signaling the construction of a fortified cyber defense across federal operations. This directive updates the nation’s digital stronghold, modernizing risk management, defending against quantum and artificial intelligence (AI) threats, and drawing sharper lines in the battle against foreign cyber adversaries. For technology companies and federal suppliers, this is a clarion call to reinforce their digital walls and sharpen their defenses. Agencies will soon build these secure-by-design principles into every contract and procurement decision. In this era of fortress-building, failing to meet these standards not only will leave your gates unguarded but also could bar you from the entire federal marketplace. The EO may read like ordinary policy, but don’t be misled: It’s a direct command for companies to strengthen their cyber defenses or be locked out of federal opportunities altogether.

Continue Reading Building the Cyber Fortress: New Cybersecurity Executive Order Targets Quantum, AI, and Supply Chain Security

The Department of Defense (DoD) is revving its engines again—this time to rocket past its own software acquisition drag. Launched via an April 24 memo from Acting DoD CIO Katie Arrington, the DoD’s Software Fast Track (SWFT) Initiative entered a 90‑day sprint to redefine Accelerating the Authority to Operate (ATOs), aiming to replace the outdated Risk Management Framework (RMF) with AI‑enabled, continuous compliance workflows. Officially live on June 1, 2025, SWFT isn’t a fully cleared runway—it’s a mission in motion, with Requests for Information (RFIs) out and industry poised to respond. But the real turbulence won’t be technical—it’ll be cultural: Can Pentagon policy and personnel move at Top Gun pace?

Continue Reading The Need for Speed: DoD’s “Software Fast Track” Targets Bureaucracy at Mach 2

On April 15, 2025, the Department of Defense (DoD) released official guidance on Organizationally Defined Parameters (ODPs) appearing in the newly published NIST SP 800-171 Revision 3. At the same time, the DoD reaffirmed that contractors must continue complying with Revision 2 thanks to a previously issued class deviation. What does this mean in plain terms? The DoD is slowly pulling back the curtain on the next major shift in cybersecurity compliance. Still, the full prestige hasn’t happened yet.

Continue Reading The “Prestige”: DoD Unveils NIST SP 800-171 Revision 3, Organizationally Defined Parameters

Sequels are rarely better than the films that precede them, and yet, sometimes a story is just too compelling to be limited to just one film. At the tail end of a summer full of Hollywood sequels, the Department of Defense (DoD) released a long-gestating sequel of its own. On August 15, 2024, DoD published a Proposed Rule that would revise the DoD Federal Acquisition Regulation Supplement (DFARS) to implement Cybersecurity Maturity Model Certification (CMMC) 2.0 into DoD contracts in the near(ish) future. This follows a December 2023 Proposed Rule, discussed here, establishing the CMMC 2.0 requirements in broad strokes. In this latest Proposed Rule, DoD proposes several changes to the DFARS that would do the following:

Continue Reading CMMC and DFARS 252.204-7021—Is the Sequel Better than the Original?