DFARS

On July 13, 2026, the Department of Defense (DoD) announced the immediate suspension of the Cybersecurity Maturity Model Certification (CMMC) Phase 2, which had been scheduled to take effect on November 10, 2026. Phase 2 would have made third-party assessment organization (C3PAO) certification at CMMC Level 2 a condition of award for applicable contracts involving controlled unclassified information (CUI). The suspension is broader than the headline suggests. Phases 3 and 4 and all future implementation milestones are frozen until further notice.

Before you pause your compliance spend, ask the right questions:

  • With no third-party assessor, whose signature now carries the legal risk? Yours.
  • Does your prime contract care what the Pentagon announced? No, and it still binds you.
  • That gap assessment in your files documenting your shortfalls? It did not evaporate.
  • Why a memo instead of a regulation? Because a memo can be reversed just as fast.

A new CMMC Reform Task Force, reporting to the DoD Chief Information Officer (CIO), will review the program and report within 60 days, drawing on responses to a public request for information due August 14, 2026. DoD’s CIO stated that Small Business Administration data suggest future CMMC phases could cost small and midsize businesses more than $7 billion annually. Expectations are also misaligned due to an assessor shortage, with more than 100,000 companies needing assessments and roughly 100 authorized C3PAOs. Officials declined to rule out ending the program entirely, and the Cyber AB was not told before the announcement.

Continue Reading DoD Suspends CMMC Phase 2. What Happened, What It Means, and What Nobody Is Telling You

In December 2025, Section 1826 of the FY 2026 NDAA created one of the most valuable classifications in defense contracting and most companies that qualify don’t know it yet. Qualify as a “nontraditional defense contractor” and you’re exempt from certified cost or pricing data, FAR Part 31, and the entire DFARS business-systems architecture. The kicker?

Clear and precise recognition and treatment of intellectual property (IP) are critical in government contracting because the ownership and use of preexisting IP, so-called “Background IP,” turn on the timing of, and funding sources for, the development of the IP. Therefore, internal documentation and standardized procedures for tracking and marking IP are crucial in the event of a dispute regarding the development, use, or ownership of IP before, during, and after performance on a government contract.

Continue Reading Don’t Put Your Background IP into It: Protecting What’s Yours

The FY2026 National Defense Authorization Act (NDAA) became law on December 18, 2025, enacting a tidal wave of the Trump administration’s priorities with respect to Department of Defense (DoD) procurement. One key priority reflected in the NDAA is reducing compliance burdens so that (i) established DoD contractors are incentivized to pursue awards and (ii) more companies opt in to being a DoD contractor to grow the industrial base. Importantly, Section 1804 and Section 1806 of the NDAA take action on this priority by raising the dollar thresholds for complex domains of government contracting: the Cost Accounting Standards (CAS) and submission of certified cost or pricing data. While these changes are welcome developments, companies should be cognizant that a steady stream of compliance requirements remains even with these increased thresholds.

Continue Reading Swept Away: FY2026 NDAA Updates to CAS and Certified Cost or Pricing Data Thresholds

On April 15, 2025, the Department of Defense (DoD) released official guidance on Organizationally Defined Parameters (ODPs) appearing in the newly published NIST SP 800-171 Revision 3. At the same time, the DoD reaffirmed that contractors must continue complying with Revision 2 thanks to a previously issued class deviation. What does this mean in plain terms? The DoD is slowly pulling back the curtain on the next major shift in cybersecurity compliance. Still, the full prestige hasn’t happened yet.

Continue Reading The “Prestige”: DoD Unveils NIST SP 800-171 Revision 3, Organizationally Defined Parameters

The U.S. Department of Defense’s Cybersecurity Maturity Model Certification (CMMC) Program will become operational at some point in fiscal year 2025. In October, the DOD issued a Final Rule to address evolving cybersecurity requirements and cyber threats while defining the security controls that DOD intends defense contractors and subcontractors to implement. The program will require

Sequels are rarely better than the films that precede them, and yet, sometimes a story is just too compelling to be limited to just one film. At the tail end of a summer full of Hollywood sequels, the Department of Defense (DoD) released a long-gestating sequel of its own. On August 15, 2024, DoD published a Proposed Rule that would revise the DoD Federal Acquisition Regulation Supplement (DFARS) to implement Cybersecurity Maturity Model Certification (CMMC) 2.0 into DoD contracts in the near(ish) future. This follows a December 2023 Proposed Rule, discussed here, establishing the CMMC 2.0 requirements in broad strokes. In this latest Proposed Rule, DoD proposes several changes to the DFARS that would do the following:

Continue Reading CMMC and DFARS 252.204-7021—Is the Sequel Better than the Original?

Johnny, rosin up your bow and play your fiddle hard
’Cause Hell’s broke loose in Georgia and the Devil deals the cards
And if you win, you get this shiny fiddle made of gold
But if you lose the Devil gets your soul
~ The Charlie Daniels Band

Some might say there’s little difference between dealing with the devil and being a federal contractor. And for the unwary or unprepared, that may not be far off. Federal contracting comes with a litany of “fine print” that would make “Old Scratch” proud. However, as most savvy contractors recognize, it’s all hiding in plain sight, with the devil in the details. Take, for example, the cybersecurity requirements found in the Federal Acquisition Regulations (FAR) at 52.204-21 and the Department of Defense (DoD) FAR Supplement (DFARS) at 252.204-7012, -7019, and -7020. These requirements have been the topic of countless articles, trainings, webinars, whole conferences, etc., so it is surprising while simultaneously not surprising that they form the basis of a federal False Claims Act (FCA) claim the Department of Justice (DOJ) recently filed in its complaint in intervention.

Continue Reading DOJ Went Down to Georgia: Lessons Learned from Recent Cybersecurity Enforcement Actions