The Post-Quantum Executive Order: What the 2030 Contractor Deadline Means — Plus 15 Federal Cyber Opportunities
A June 22 executive order gives federal contractors until December 31, 2030 to go quantum-safe. Plus this week's full pipeline: a DoD water-plant OT contract, a VA patient-safety system, State Dept vetting work, and 12 more — curated for small business.
FedRAMP's CR26 Overhaul Is Here — and It Changes How You Vet Cloud Tools for CMMC
FedRAMP released its Consolidated Rules for 2026 on June 25, effective July 1. Authorizations become certifications, impact levels become classes, and the labels you rely on to evaluate SaaS for a CMMC Level 2 assessment are changing.
CMMC Self-Assessment vs C3PAO: How the Assessment Actually Works
For CMMC Level 2, your contract assigns one of two paths: a self-assessment you attest to, or a third-party C3PAO certification. Here's how each works.
FAR Overhaul 2026: First Proposed Rules Out, Comments Due July 23
The first four proposed rules consolidate federal security requirements into a new FAR Part 40 and touch IT acquisition directly. Small-business rules are still coming. The comment window is the minimum 30 days.
Post-Quantum FAR Rule Is Now in Motion — and It Carries a 2030 Deadline
Trump's June 22 executive order directs the FAR Council to require civilian-agency contractors to meet NIST's post-quantum standards by the end of 2030, plus a second rule folding cryptographic flaws into vulnerability disclosure. DoD work stays on its own track.
CMMC Grants for Small Business: What Congress Just Proposed — Plus 15 Live Federal Cyber Opportunities
Senate's FY2027 NDAA proposes up to $100K per firm for CMMC compliance. Plus this week's full pipeline: Air Force COMSEC support, USMC SCADA, DoD cyber range, and 12 more vetted opportunities — curated for small business.