Gordon Rees Scully Mansukhani’s Government Contracts Practice Group highlights the key developments from the past month and their implications for federal contractors. Our team tracks significant decisions, regulatory changes, and practical updates to help contractors stay compliant in a rapidly changing environment.
Tune in to The Essential GovCon Brief podcast on Spotify or YouTube for a discussion on the issues highlighted below.
SBA Proposes Major Overhaul of Small Business Size Standards
On August 20, 2026, the Small Business Administration (SBA) published two related proposals that would significantly overhaul how it establishes small-business size standards, replacing the seven-factor methodology adopted in 2024 with a market-based approach designed to give businesses more room to grow before losing small-business status. Key elements include:
- North American Industry Classification System (NAICS) Consolidation: SBA proposes consolidating size standards primarily at the four- and five-digit NAICS levels, reducing the number of individual size standards from nearly 1,000 to 338.
- Employee-Based Shift: Numerous industries currently measured by annual receipts would move to employee-based standards, which SBA believes will reduce fluctuations in small-business status resulting from increases or decreases in revenue.
- Productivity Adjustment: For the first time, receipts-based standards would be adjusted for productivity growth in addition to inflation, recognizing that businesses can generate greater output with the same workforce and resources as productivity increases over time.
- Expanded Small-Business Eligibility: SBA estimates that the proposals would increase the number of businesses classified as small by 114,541 firms, or roughly 1.8%, while only 172 currently small businesses would lose that status. Some proposed standards would increase substantially. For example, SBA proposes a $531 million receipts standard for four-digit NAICS 5415, Computer Systems Design and Related Services.
The changes are contained in a companion pair of proposals, one setting forth SBA’s revised methodology and another applying that methodology to proposed industry-specific size standards, both published in the Federal Register on August 20. Public comments are due September 21, 2026.
If finalized, the proposals could represent one of the most consequential changes to small-business contracting eligibility in years. Companies approaching their existing size thresholds should closely evaluate the proposed standard applicable to their industry, as a higher receipts threshold or change to an employee-based standard could significantly extend their eligibility for small-business set-asides. At the same time, existing small businesses could face increased competition as larger firms become newly eligible to compete for set-aside work.
Honeywell Pays $2 Million to Resolve Cybersecurity False Claims Act Allegations
On September 1, 2026, the Department of Justice (DOJ) announced that Honeywell Aerospace Inc. agreed to pay approximately $2.04 million to resolve allegations that a Honeywell business unit violated the False Claims Act (FCA) by failing to comply with cybersecurity requirements under a Department of Defense contract.
According to DOJ, from April 2020 through December 2023, the Honeywell business unit allegedly submitted false claims for payment while failing to comply with cybersecurity requirements contained in National Institute of Standards and Technology (NIST) Special Publication 800-171 with respect to one of its networks, as required by its contract and applicable regulations. DOJ did not identify the particular NIST SP 800-171 controls that Honeywell allegedly failed to implement. The settlement resolves allegations only, and there has been no determination of liability.
The case originated as a whistleblower action filed under the qui tam provisions of the FCA by a former Honeywell employee, who will receive approximately $375,000 from the settlement.
The settlement is another reminder that cybersecurity compliance remains an active area of FCA enforcement for federal contractors. As discussed in last month’s update, the Department of War recently suspended implementation of Phase II of the Cybersecurity Maturity Model Certification (CMMC) program while it conducts a review of the program. That suspension, however, does not eliminate contractors’ existing contractual obligations to comply with NIST SP 800-171 or other applicable cybersecurity requirements. Contractors should therefore continue to evaluate whether their actual cybersecurity practices align with the requirements incorporated into their contracts and with any representations made to the government regarding compliance.
Deloitte Pays $21.5 Million to Resolve FCA Allegations Based on Employment Discrimination
On August 25, 2026, the DOJ announced that Deloitte agreed to pay $21.5 million to resolve allegations that it violated the FCA by falsely certifying compliance with anti-discrimination requirements in its federal contracts while engaging in employment practices that considered race or sex. The settlement is part of the DOJ’s Civil Rights Fraud Initiative, launched in May 2025 to use the FCA to address alleged violations of federal civil rights laws by recipients of federal funds.
According to DOJ, from 2017 to the present, Deloitte certified compliance with federal contracting requirements prohibiting discrimination based on race or sex while allegedly considering those characteristics in hiring, promotion, staffing, and professional-development decisions. Among other things, DOJ alleged that Deloitte established race- and sex-based workforce composition goals, provided business units with monthly reports tracking progress toward those goals, and evaluated certain senior personnel in part on their contributions toward achieving them. DOJ also alleged that Deloitte considered race and sex when identifying employees for staffing on federal contracts and limited eligibility for certain training, mentoring, leadership development, and educational opportunities based on race or sex.
The settlement resolves a qui tam action brought by the American Alliance for Equal Rights, which will receive $4.3 million as its share of the recovery. Deloitte received cooperation credit under DOJ’s False Claims Act guidelines and denies that it engaged in the alleged conduct. The settlement resolves allegations only, and there has been no determination of liability.
The settlement is significant for federal contractors because it illustrates DOJ’s willingness to use the FCA to enforce contractual certifications concerning compliance with federal anti-discrimination requirements. Contractors should therefore consider whether employment, diversity, staffing, promotion, and professional development programs are consistent not only with applicable employment laws, but also with representations and certifications made in connection with federal contracts. Practices that DOJ views as inconsistent with those certifications may create potential FCA exposure in addition to traditional employment law risks.
GAO Sustains Rule of Two Protest Over NIH Multiple-Award Contract
On August 14, 2026, the Government Accountability Office (GAO) sustained a protest by LJR Solutions, LLC challenging the National Institutes of Health’s (NIH) decision to conduct a multiple-award indefinite delivery/indefinite quantity (IDIQ) procurement for professional, scientific, and technical services on a full-and-open basis rather than as a small-business set-aside. Under the Rule of Two, a procurement above the simplified acquisition threshold generally must be set aside when the agency reasonably expects to receive competitive offers in terms of fair market price, quality, and delivery from at least two responsible small businesses.
GAO found that NIH’s determination that the Rule of Two was not satisfied was unreasonable and inadequately documented. NIH’s 2024 market research had identified three small businesses capable of performing the requirement, but the agency’s subsequent analysis did not meaningfully explain why those businesses were no longer considered capable. GAO also questioned NIH’s reliance on the fact that small businesses would need subcontractors to perform portions of the requirement. The agency itself had concluded that no offeror, large or small, could independently perform the entire scope of work, and the solicitation expressly permitted subcontractors, including for major or critical aspects of the requirement.
GAO further found that NIH had not adequately considered a partial small-business set-aside before proceeding with full-and-open competition accompanied by a small-business reserve. Under the applicable regulations, an agency may use a small-business reserve in a multiple-award procurement only where both a total and partial set-aside are not feasible. Although NIH acknowledged that some small businesses could perform portions of the requirement, the record did not demonstrate that the agency considered whether a partial set-aside was feasible.
GAO recommended that NIH reconsider whether the procurement should be fully or partially set aside for small businesses, including by conducting new market research if appropriate. The decision reinforces that agencies retain discretion in conducting Rule of Two analyses, but their conclusions must be supported by sufficient facts and contemporaneous documentation. The decision also underscores that an agency should not discount otherwise capable small businesses based merely on their anticipated use of subcontractors where the solicitation permits subcontracting and the firms can perform in compliance with applicable limitations on subcontracting.
GRSM Government Contracts Practice Group
GRSM’s Government Contracts team supports contractors throughout the entire procurement lifecycle, providing both proactive counseling and representation in disputes.
Our attorneys advise on compliance, small business programs, cost and pricing requirements, cybersecurity, subcontracting, and other regulatory issues, while also litigating bid protests, claims, and agency matters nationwide.
Please contact Patrick Burns, Meredith Thielbahr, or Jeremy Camacho with any questions or for additional information.