Search
Logo
Sign Up
Login
Home
Guides
About
Archive
Federal Cyber Brief

News

News

SBA Wants to Redraw Who Counts as Small — Comments Close September 2

SBA Wants to Redraw Who Counts as Small — Comments Close September 2

A proposed rule would cut size standards from nearly 1,000 to 338, move whole sectors from revenue to headcount, and make roughly 114,000 more firms eligible. Your NAICS code may not survive in its current form.

Aug 21, 2026

•

3 min read

The CMMC Reform RFI Closes Friday Here's How a Small Firm Files

The CMMC Reform RFI Closes Friday Here's How a Small Firm Files

DoW is writing the recommendations that reshape CMMC from whatever the defense industrial base submits by August 14. Small firms are the target audience and the least likely to respond.

Aug 10, 2026

•

3 min read

DoW Suspends CMMC Phase 2 — Your Audit Is Off, Your Liability Isn't

DoW Suspends CMMC Phase 2 — Your Audit Is Off, Your Liability Isn't

Third-party assessments are frozen and a 60-day review may rewrite the program entirely. DFARS 252.204-7012 and your SPRS affirmation still bind

Jul 14, 2026

•

3 min read

CMMC's Rev 3 Deadline Rule Is Due This Month

CMMC's Rev 3 Deadline Rule Is Due This Month

The Unified Agenda shows DoD adopting an interim final rule in July that sets the transition from NIST SP 800-171 Rev 2 to Rev 3. Interim final rules take effect on publication.

Jul 13, 2026

•

3 min read

Fixed-Price Is Now the FAR Default — and T&M Contracts Are in Scope

Fixed-Price Is Now the FAR Default — and T&M Contracts Are in Scope

Agencies must update class deviations by July 15. For small IT and cyber firms living on time-and-materials work, the risk shift starts now.

Jul 9, 2026

•

3 min read

FedRAMP's CR26 Overhaul Is Here — and It Changes How You Vet Cloud Tools for CMMC

FedRAMP's CR26 Overhaul Is Here — and It Changes How You Vet Cloud Tools for CMMC

FedRAMP released its Consolidated Rules for 2026 on June 25, effective July 1. Authorizations become certifications, impact levels become classes, and the labels you rely on to evaluate SaaS for a CMMC Level 2 assessment are changing.

Jun 29, 2026

•

3 min read

FAR Overhaul 2026: First Proposed Rules Out, Comments Due July 23

FAR Overhaul 2026: First Proposed Rules Out, Comments Due July 23

The first four proposed rules consolidate federal security requirements into a new FAR Part 40 and touch IT acquisition directly. Small-business rules are still coming. The comment window is the minimum 30 days.

Jun 25, 2026

•

3 min read

Post-Quantum FAR Rule Is Now in Motion — and It Carries a 2030 Deadline

Post-Quantum FAR Rule Is Now in Motion — and It Carries a 2030 Deadline

Trump's June 22 executive order directs the FAR Council to require civilian-agency contractors to meet NIST's post-quantum standards by the end of 2030, plus a second rule folding cryptographic flaws into vulnerability disclosure. DoD work stays on its own track.

Jun 23, 2026

•

2 min read

SBA's EDWOSB Audit Reaches Women-Owned Firms — Respond by June 30

SBA's EDWOSB Audit Reaches Women-Owned Firms — Respond by June 30

The same scrutiny that suspended more than 1,000 8(a) firms is now examining the EDWOSB program. For certified small firms, set-aside eligibility has become a live compliance obligation, not a one-time stamp.

Jun 19, 2026

•

2 min read

Follow on LinkedIn for daily GovCon intelligence

SUBSCRIBE TO OUR NEWSLETTER

Weekly intelligence for federal IT & cybersecurity contractors. Cleared to Bid.

HOME

GUIDES

ABOUT

ARCHIVE

© 2026 Federal Cyber Brief.
beehiivPowered by beehiiv