Gordon Rees Scully Mansukhani’s Government Contracts Practice Group highlights the key developments from the past month and their implications for federal contractors. Our team tracks significant decisions, regulatory changes, and practical updates to help contractors stay compliant in a rapidly changing environment.
Tune in to The Essential GovCon Brief podcast on Spotify or YouTube for a discussion on the issues highlighted here.
Department of War Suspends CMMC Phase II Requirements and Launches Program Review
On July 13, 2026, the Department of War (DoW) announced the immediate suspension of Phase II of the Cybersecurity Maturity Model Certification (CMMC) program, delaying requirements that had been scheduled to take effect on November 10, 2026. The department also established a CMMC Reform Task Force to conduct a comprehensive review of the program and recommend potential reforms within 60 days.
The suspension represents a significant change in the department’s implementation of CMMC. Under the previously planned rollout, Phase II would have expanded the use of CMMC Level 2 third-party assessments for applicable solicitations and contracts. Instead, the department has suspended the transition to Phase II, as well as pending and future Phase II implementation milestones in DoW solicitations and contracts. CMMC Phase I self-assessment requirements remain in effect.
According to DoW, the decision reflects concerns that the existing CMMC framework imposes substantial compliance costs and administrative burdens, particularly on small, medium-sized, and nontraditional defense contractors. During the review period, the department will enforce cybersecurity compliance through self-assessments and select government-led assessments, prioritizing tangible cyber hygiene over third-party certification and administrative burdens. The newly established CMMC Reform Task Force has been directed to consider reforms that reduce those burdens while maintaining cybersecurity and operational resilience across the Defense Industrial Base. In connection with that review, the department issued a Request for Information seeking industry feedback on CMMC compliance costs, administrative challenges, the use of commercial cybersecurity capabilities and self-attestation, and potential regulatory reforms.
Importantly, the suspension of Phase II does not eliminate contractors’ underlying cybersecurity obligations. Defense contractors and subcontractors remain responsible for safeguarding covered defense information in accordance with DFARS 252.204-7012, and the department has emphasized that cybersecurity requirements will continue to be enforced during the review. Contractors therefore should not view the suspension as a reason to abandon existing cybersecurity compliance efforts. The Reform Task Force’s review is expected to run through mid-September, and its recommendations could materially reshape the certification and assessment requirements that ultimately apply to the Defense Industrial Base. Companies preparing for CMMC should watch that process closely.
Defense Contractor Pays $7.75 Million to Resolve False Claims Act Allegations Involving Organizational Conflict of Interest
On July 28, 2026, the Department of Justice (DOJ) announced that defense contractor Sierra Nevada Company, LLC (SNC) agreed to pay $7.75 million to resolve False Claims Act allegations arising from its employment of a government official who allegedly participated personally and substantially in three government contracts awarded to SNC. The settlement highlights the potential False Claims Act consequences when contractors fail to identify and disclose organizational conflicts of interest in connection with federal procurements.
According to DOJ, from July 2019 through June 2020, SNC retained Michael Henry, an employee of the Department of War’s Joint Staff/J6, as a consultant while Henry continued his government employment. In his government role, Henry was involved with three contracting vehicles involving SNC: an Army subcontract awarded in 2019, a General Services Administration indefinite-delivery, indefinite-quantity (IDIQ) contract awarded in 2020, and task orders under a Special Operations Command IDIQ contract awarded in 2018. After becoming an SNC consultant, Henry allegedly continued participating personally and substantially in those contracts in his government capacity by evaluating and obtaining approvals for SNC products. At the same time, DOJ alleged that Henry participated in the contracts on SNC’s behalf by recommending SNC products for government purchase.
The government alleged that SNC’s employment of Henry and his participation in the contracts on the company’s behalf created an organizational conflict of interest under the Federal Acquisition Regulation (FAR). According to DOJ, SNC knowingly made or caused material false statements, false certifications, and omissions concerning the absence of an organizational conflict of interest, which induced the government to award the contracts. DOJ alleged that SNC consequently submitted or caused the submission of false claims and statements in connection with those contracts. Henry separately pleaded guilty in 2025 to a criminal charge involving acts affecting a personal financial interest.
The settlement provides an important reminder that organizational conflicts of interest can create risks extending beyond traditional procurement remedies, such as disqualification or loss of an award. A contractor’s failure to identify and disclose a potential OCI may also create False Claims Act exposure when representations concerning the absence of conflicts are material to the government’s award or payment decisions. Contractors should maintain procedures for identifying potential conflicts involving employees, consultants, and former or current government personnel and ensure that potential conflicts are disclosed and addressed before they affect the award or performance of a federal contract. The settlement resolves allegations only, and there has been no determination of civil liability.
Executive Order Directs New Supply Chain Requirements for Defense Contractors
On July 20, 2026, President Trump issued Executive Order 14415, Securing America’s Defense Supply Chains and Ensuring Domestic Acquisition of Critical Materials, directing the Department of War (DoW) to strengthen domestic and allied sourcing requirements and increase visibility into defense contractor supply chains. The Executive Order declares a policy of ensuring that not only finished military equipment, but also the critical materials and components necessary to manufacture, maintain, sustain, and repair that equipment, are sourced domestically or from allied nations.
Among its most significant provisions, the Executive Order directs DoW, within 180 days, to develop policy and implementation guidance requiring prime contractors and subcontractors at any tier to map and illuminate critical supply chains for national-security-related acquisitions, from raw materials through the end products delivered to the department. The contemplated implementing regulations are to require contractors to submit a complete indentured Bill of Materials tracing components, parts, equipment, software, and materials back to the origin of raw materials. Contractors also will be required to establish procedures for vetting suppliers and subcontractors for financial risks, foreign ownership, control, or influence, and manufacturing and supply risks.
The Executive Order also contemplates significant reporting and mitigation obligations when contractors identify supply chain risks. The forthcoming regulations are to require contractors to notify DoW of significant supply chain risks within 15 days after completing required vetting activities and to submit a written corrective action plan within 45 days detailing implemented mitigation measures and a timeline for completing them. The Executive Order also directs DoW to require contractors relying on materials or components from designated “unreliable foreign suppliers” to qualify and use alternative sources when available. Failure to qualify an alternative source may be considered by DoW in deciding whether to suspend or terminate task orders, decline to exercise contract options, or terminate an existing contract.
The Executive Order separately tightens the availability of waivers under 10 U.S.C. § 4872(c)(1) and (e) for certain covered materials. Beginning January 1, 2027, the Secretary of War and the secretaries of the military departments generally will cease issuing such waivers unless the contractor submits an acceptable mitigation plan identifying the noncompliant source, documenting efforts to obtain compliant materials, describing the steps to remove the noncompliant material from the supply chain, and establishing a timeline for doing so. The Executive Order does not repeal the underlying statutory waiver authorities in Section 4872(c) or (e); instead, it imposes additional conditions on their use.
Much of the Executive Order’s impact depends on implementation that has not yet occurred, and contractors should not expect immediate compliance changes as a result of the order alone. The mapping, Bill of Materials, and vetting obligations described above will depend on DoW’s issuance of implementing guidance and regulations. The Executive Order likewise does not impose an immediate, across-the-board domestic content mandate; its more immediate effect is the narrowing of waiver availability under Section 4872 beginning January 1, 2027.
Beginning January 1, 2027, § 4872(c)(1) waivers generally require the mitigation-plan route; § 4872(e) waivers have that route plus a separate route involving a request to the Assistant to the President for National Security Affairs. The drafts currently make the mitigation plan sound like the only route for both. Securing America’s Defense Supply Chains and Ensuring Domestic Acquisition of Critical Materials – The White House: “Waivers issued under 10 U.S.C. 4872(e) will only be issued as provided in subsection (b) of this section or following a request from the Secretary or the Secretary of the military department to the Assistant to the President for National Security Affairs.”
Although the pace and scope of implementation remain to be seen, the direction of the new policy is clear: defense contractors should expect to develop substantially greater visibility into the origin, ownership, and resilience of their supply chains, including suppliers several tiers removed from the prime contract. Contractors supporting national security acquisitions should begin evaluating whether their existing supply chain management systems can provide the level of traceability and supplier-risk information contemplated by the Executive Order and monitor DoW’s forthcoming implementation closely.
$10 Million TINA Threshold Takes Effect for Defense Contracts
A significant increase in the threshold for requiring certified cost or pricing data took effect for certain defense contracts on July 1, 2026. Section 1804 of the Fiscal Year 2026 National Defense Authorization Act increased the threshold under the Truth in Negotiations Act (TINA), now formally known as the Truthful Cost or Pricing Data statute, from $2.5 million to $10 million for covered DoW procurements. Under 10 U.S.C. § 3702, offerors for covered prime contracts entered into after June 30, 2026, generally must submit certified cost or pricing data when the expected contract price exceeds $10 million, assuming no statutory exception applies.
The new $10 million threshold also applies to covered contract modifications and certain subcontracts under prime contracts entered into after June 30, 2026. Contractors should be mindful, however, that the new threshold does not apply to subcontracts under prime contracts entered into on or before June 30, 2026, which remain subject to the preexisting requirements. The change is also specific to defense procurement and does not establish a $10 million TINA threshold government-wide.
The substantially higher threshold should reduce the number of defense procurements subject to TINA’s certification requirements and, correspondingly, contractors’ potential exposure to defective pricing remedies for transactions falling below the new threshold. The change does not, however, mean that contractors below the $10 million threshold are necessarily relieved of pricing-data requirements altogether. Contracting officers remain responsible for determining that proposed prices are fair and reasonable and may request data other than certified cost or pricing data when necessary to make that determination.
Contractors should also be aware that the FAR has not yet caught up with the statutory change. FAR 15.403-4 continues to reflect the $2.5 million threshold, creating a period in which the regulatory text does not align with the new statutory threshold applicable to covered defense procurements. Contractors preparing proposals or negotiating contract actions should therefore carefully consider the applicable statutory and regulatory requirements while implementation of the new threshold continues.
GRSM Government Contracts Practice Group
GRSM’s Government Contracts team supports contractors throughout the entire procurement lifecycle, providing both proactive counseling and representation in disputes.
Our attorneys advise on compliance, small business programs, cost and pricing requirements, cybersecurity, subcontracting, and other regulatory issues, while also litigating bid protests, claims, and agency matters nationwide.
Please contact Patrick Burns, Meredith Thielbahr, or Quyen Dang with any questions or for additional information.