News
Third-party assessments are frozen and a 60-day review may rewrite the program entirely. DFARS 252.204-7012 and your SPRS affirmation still bind
Jul 14, 2026
•
3 min read
The Unified Agenda shows DoD adopting an interim final rule in July that sets the transition from NIST SP 800-171 Rev 2 to Rev 3. Interim final rules take effect on publication.
Jul 13, 2026
Agencies must update class deviations by July 15. For small IT and cyber firms living on time-and-materials work, the risk shift starts now.
Jul 9, 2026
FedRAMP released its Consolidated Rules for 2026 on June 25, effective July 1. Authorizations become certifications, impact levels become classes, and the labels you rely on to evaluate SaaS for a CMMC Level 2 assessment are changing.
Jun 29, 2026
The first four proposed rules consolidate federal security requirements into a new FAR Part 40 and touch IT acquisition directly. Small-business rules are still coming. The comment window is the minimum 30 days.
Jun 25, 2026
Trump's June 22 executive order directs the FAR Council to require civilian-agency contractors to meet NIST's post-quantum standards by the end of 2030, plus a second rule folding cryptographic flaws into vulnerability disclosure. DoD work stays on its own track.
Jun 23, 2026
2 min read
The same scrutiny that suspended more than 1,000 8(a) firms is now examining the EDWOSB program. For certified small firms, set-aside eligibility has become a live compliance obligation, not a one-time stamp.
Jun 19, 2026