I’m totally aging myself (due to reruns) but The Jetsons (created by William Hanna and Joseph Barbera (1962-63)), promised us a future where you pushed a button and the “Food-a-Rac-a-Cycle,” a machine, made whatever you wanted. Dinner. Clothes. Maybe an off-brand Spacely sprocket or two. Additive manufacturing has gotten us remarkably close. Give a 3D printer the right digital file, the right material, and the right process parameters, and out comes the part. George Jetson would recognize the concept immediately. What George did not have was the Defense Federal Acquisition Regulation Supplement (DFARS).
Continue Reading Meet George Jetson’s Government Contractor: 3D Printing, CUI, and Who Owns the RecipeCMMC
DoD Suspends CMMC Phase 2. What Happened, What It Means, and What Nobody Is Telling You
On July 13, 2026, the Department of Defense (DoD) announced the immediate suspension of the Cybersecurity Maturity Model Certification (CMMC) Phase 2, which had been scheduled to take effect on November 10, 2026. Phase 2 would have made third-party assessment organization (C3PAO) certification at CMMC Level 2 a condition of award for applicable contracts involving controlled unclassified information (CUI). The suspension is broader than the headline suggests. Phases 3 and 4 and all future implementation milestones are frozen until further notice.
Before you pause your compliance spend, ask the right questions:
- With no third-party assessor, whose signature now carries the legal risk? Yours.
- Does your prime contract care what the Pentagon announced? No, and it still binds you.
- That gap assessment in your files documenting your shortfalls? It did not evaporate.
- Why a memo instead of a regulation? Because a memo can be reversed just as fast.
A new CMMC Reform Task Force, reporting to the DoD Chief Information Officer (CIO), will review the program and report within 60 days, drawing on responses to a public request for information due August 14, 2026. DoD’s CIO stated that Small Business Administration data suggest future CMMC phases could cost small and midsize businesses more than $7 billion annually. Expectations are also misaligned due to an assessor shortage, with more than 100,000 companies needing assessments and roughly 100 authorized C3PAOs. Officials declined to rule out ending the program entirely, and the Cyber AB was not told before the announcement.
Continue Reading DoD Suspends CMMC Phase 2. What Happened, What It Means, and What Nobody Is Telling YouAI Heats Up: New Executive Order on Promoting Advanced Artificial Intelligence Innovation and Security
What Federal Contractors Should Be Watching This Summer
Summer 2026 has arrived with a new wave of artificial intelligence (AI) policy from the White House. On June 2, 2026, President Trump signed an Executive Order titled “Promoting Advanced Artificial Intelligence Innovation and Security” (the Order). The Order directs federal agencies—on aggressive 30‑ and 60‑day timelines, with key deliverables due by July 2, 2026 and August 1, 2026—to harden federal information systems with AI‑enabled defenses, establish a voluntary framework for pre‑release federal access to so‑called “covered frontier models,” and prioritize criminal enforcement against malicious AI‑enabled cyber activity. Although the Order is framed as innovation‑and‑security policy and expressly disclaims any “mandatory governmental licensing, preclearance, or permitting requirement” for new AI models, it will have immediate operational consequences for federal information‑technology and cyber contractors, AI developers, critical‑infrastructure operators, and their service providers.
Continue Reading AI Heats Up: New Executive Order on Promoting Advanced Artificial Intelligence Innovation and SecurityDon’t Panic! How Federal Contractors Should Navigate the Anthropic Designation
In every crisis, half the room runs in circles while the other half picks up a clipboard and starts taking stock. The Anthropic-Pentagon dispute is that crisis, and defense contractors are deciding which half they want to be in.
The short version: The government designated a FedRAMP-authorized, facility-cleared American AI company a national security supply chain threat, via social media, after the company refused to remove safety restrictions on autonomous weapons and mass surveillance. Anthropic sued days later, with the Pentagon’s own officials on the record stating the designation was “ideologically driven” with “no evidence of supply chain risk.”
Continue Reading Don’t Panic! How Federal Contractors Should Navigate the Anthropic DesignationOrbiting A.I.-deraan? A Disturbance in the Force for the Defense Industrial Base
“I felt a great disturbance in the Force, as if millions of voices suddenly cried out in terror and were suddenly silenced.”
When Obi-Wan Kenobi says this in Star Wars: Episode IV – A New Hope, he senses that something profound just changed in the galaxy. A powerful presence has vanished. The balance of power shifting in ways that will ripple far beyond the immediate moment. As Yoda later describes the Force: “Life creates it, makes it grow. Its energy surrounds us, binds us.” In this way, artificial intelligence (AI) is beginning to play a role for the US Defense Industrial Base (DIB) not unlike the Force itself—quietly enhancing the capabilities of engineers, analysts, and compliance professionals across thousands of organizations supporting national defense programs.
So what could happen if a major AI player suddenly disappears from the board?
Continue Reading Orbiting A.I.-deraan? A Disturbance in the Force for the Defense Industrial BaseFeature Comment: CMMC Crosses The Finish Line—But Defense Contractors’ Race Ain’t Over
The DoD has finally crossed the CMMC finish line, but for contractors, the race is just beginning. With the Final Rule effective Nov. 10, award eligibility will hinge on a “current” CMMC status in SPRS, backed by annual affirmations and strict compliance. The next two months are critical for getting race-ready. In this Featured Comment…
Feature Comment: The CUI Program: DOD, We Have A Problem (Part II)

In Part I of this series we introduced readers to what Controlled Unclassified Information (CUI) is understood to consist of under the CUI Program at 32 CFR pt. 2002, differentiating and safeguarding CUI, CUI Program Authority and Control, and CUI policy as promulgated under the U.S. Department of Defense CUI Program. (See 66 GC ¶…
Feature Comment: The CUI Program: DOD, We Have a Problem

The U.S. Department of Defense’s Cybersecurity Maturity Model Certification (CMMC) Program will become operational at some point in fiscal year 2025. In October, the DOD issued a Final Rule to address evolving cybersecurity requirements and cyber threats while defining the security controls that DOD intends defense contractors and subcontractors to implement. The program will require…
A Standard on Many Levels: A Look at CMMC 2.0 in Final

Over the course of the past few years, gallons of ink have been spilled addressing the seemingly ever-pending US Department of Defense’s (DoD) Cybersecurity Maturity Model Certification (CMMC) Program. After keeping us waiting for years, it finally arrived when, on October 15, 2024, DoD published its Final Rule to establish the CMMC Program. See 89 Fed. Reg. 83092 (Oct. 15, 2024). Effective December 16, 2024, the Rule will require certain defense contractors to have implemented security measures to achieve a particular CMMC level necessary to safeguard Federal Contract Information (FCI) or Controlled Unclassified Information (CUI) as a condition of contract award. Codified at 34 C.F.R. Part 170, the CMMC Program will be augmented by a separate proposed acquisition rule to add a new 48 C.F.R. Part 204, amending the Defense Federal Acquisition Regulation Supplement (DFARS) to address procurement considerations related to the CMMC Program, including allowing DoD to require a specific CMMC level in a solicitation or contract. See 89 Fed. Reg. 66327 (Aug. 15, 2024) or our analyses here and here. The date when that DFARS clause will become final is still unclear, but most suspect it will be soon.
Continue Reading A Standard on Many Levels: A Look at CMMC 2.0 in FinalFeature Comment: The New Madness? CMMC-Mania — It’s Arrived!
The arrival of the Cybersecurity Maturity Model Certification (CMMC) program will bring redefining changes to all companies selling to the DoD, suggests Alex Major in this Feature Comment for The Government Contractor.

