D.C. Circuit Upholds the Anthropic Ban: What It Means for Federal Contractors

Robyn N. Burrows, Michael J. Montalbano, and Justin A. Chiarodo ●


On September 25, 2026, the U.S. Court of Appeals for the D.C. Circuit issued its much-anticipated decision in Anthropic PBC v. U.S. Department of War, No. 26-1049, upholding the Department of War’s (“DOW”) exclusion of Anthropic’s Claude artificial intelligence (“AI”) models from its supply chain under the Federal Acquisition Supply Chain Security Act of 2018 (“FASCSA”), 41 U.S.C. § 4713. The ruling means the Government may continue its efforts to require contractors to cease the use of Anthropic as part of the performance of federal contracts. This post summarizes the decision and steps contractors should consider taking in response.

Background

As we covered in our prior blog post, the dispute between Anthropic and the federal government began with a contract disagreement over AI usage restrictions (Anthropic held a $200 million Pentagon contract and was the first frontier AI company to deploy models on classified government networks). Anthropic maintained two “red lines”: it refused to allow its Claude AI model to be used for mass domestic surveillance of Americans or in fully autonomous weapons systems. When the DOW demanded that Anthropic agree to “all lawful use” of its technology without these restrictions, Anthropic refused. On February 27, 2026, President Trump and Secretary of War Pete Hegseth announced on social media their intention to remove Anthropic from the federal supply chain.

On March 3, 2026, Secretary Hegseth issued a formal determination under FASCSA to take covered procurement actions against Anthropic, finding that the continued integration of Claude into DOW systems presented a “significant supply chain risk,” that removal was “necessary to protect national security,” and that no “less intrusive measures” were “reasonably available.” The Secretary also determined that an “urgent national security interest” required immediate action. The DOW’s Chief Information Officer then ordered removal of all Anthropic products from DOW systems within 180 days and prohibited contractors from using Anthropic products in DOW work.

Continue reading “D.C. Circuit Upholds the Anthropic Ban: What It Means for Federal Contractors”

CUI, FOCI, Quantum, and CMMC: The Federal Government Issues a Wave of Proposed Rules to Safeguard Government Information

Michael J. Montalbano ●

Ernest Hemingway once wrote about bankruptcy that it happens “gradually and then suddenly.” The same can be said about federal information safeguarding rules. The Cybersecurity Maturity Model Certification (“CMMC”) program has been around for seven years. The Controlled Unclassified Information (“CUI”) program for over 15 years. Information safeguarding used to be a slow process with progress measured in years. Not anymore.

Over the past three months, the federal government has issued a wave of proposed rules designed to better safeguard federal information and harden contractor information systems.

FOCI Rule for Non-Cleared Contractors

The Department of Defense (“DoD”) issued a proposed rule in May 2026 that would significantly expand Foreign Ownership, Control, and Influence (“FOCI”) reporting requirements beyond the cleared contractor community, reaching existing and prospective contractors and subcontractors at any tier with DoD contracts or subcontracts exceeding five million dollars, even where no classified information is involved.

Continue reading “CUI, FOCI, Quantum, and CMMC: The Federal Government Issues a Wave of Proposed Rules to Safeguard Government Information”

GSA Issues New Framework for Protecting CUI in Contractor Systems

Michael Joseph Montalbano ●

Last month the General Services Administration’s (“GSA”) Office of the Chief Information Security Officer (“OCISO”) issued CIO-IT Security-21-112 Rev. 1, a procedural guide governing how Controlled Unclassified Information (“CUI”) must be protected when it resides in nonfederal contractor systems. Although styled as internal process guidance rather than a regulation, the document establishes a detailed approval framework that will determine which contractors are eligible for GSA contracts that include CUI.

Background and Scope

The guide, which implements GSA’s approach to safeguarding CUI, uses National Institute of Standards and Technology (“NIST”) SP 800-171, Revision 3, selected enhanced requirements from NIST SP 800-172, and selected privacy controls from NIST SP 800-53, Revision 5. It applies where CUI is resident in a contractor system that is not operated on behalf of the federal government, and therefore is not subject to the Federal Information Security Modernization Act or the Federal Risk and Authorization Management Program (“FedRAMP”). Use of this process requires coordination with OCISO and approval by the GSA Chief Information Security Officer. GSA intends to eventually incorporate these requirements into applicable contracts and solicitations.

Continue reading “GSA Issues New Framework for Protecting CUI in Contractor Systems”

This Is Not a Drill: Department of Defense Issues Long-Awaited Final CMMC DFARS Rule

Michael Joseph Montalbano ●

After years of drafts and interim measures, the Department of Defense (“DOD”) has issued the final Defense Federal Acquisition Regulation Supplement (“DFARS”) rule implementing the Cybersecurity Maturity Model Certification (“CMMC”) program. This long-awaited development cements CMMC as a contractual requirement and clarifies key aspects of the rule’s certification, compliance, and oversight requirements.

How Will CMMC Work?

Under the final rule, every solicitation where a contractor may store, process, or transmit Federal Contract Information (“FCI”) or controlled unclassified information (“CUI”) will be assigned a CMMC level. Solicitations involving just FCI will have a CMMC Level 1 requirement. Solicitations involving non-Defense CUI will have a CUI Level 2 Self-Attestation requirement. Solicitations involving Defense CUI will have a CUI Level 2 third-party certification (i.e., C3PAO) requirement. Solicitations involving particularly sensitive DOD programs will have a Level 3 requirement. Level 3 requires an assessment by the Defense Industrial Base Cybersecurity Assessment Center (“DIBCAC”).

Continue reading “This Is Not a Drill: Department of Defense Issues Long-Awaited Final CMMC DFARS Rule”

Beyond the Balance Sheet: The Continued Importance of Cybersecurity in M&A

Merle M. DeLancey Jr., Samarth Barot, and Michael Joseph Montalbano ●

In our August 1 post, we discussed how companies that acquire government contractors can inherit the False Claims Act (“FCA”) exposure based on their targets’ cybersecurity violations. Now, the Department of Justice (“DOJ”) delivered another vivid real-world example: a $1.75 million settlement in which a private equity (“PE”) firm, Gallant Capital Partners LLC, was named jointly and severally liable for its portfolio company’s cybersecurity violations on a U.S. Air Force contract.

The outcome underscores two critical truths. First, DOJ will pursue financial sponsors when a contractor in their portfolio fails to comply with its contractual cybersecurity requirements. Second, investors that fail to ask about, document, and remediate a target’s security shortcomings can find themselves financing both the acquisition and the government’s recovery.

Continue reading “Beyond the Balance Sheet: The Continued Importance of Cybersecurity in M&A”

Buyer Beware: Cybersecurity Compliance in M&A

Merle M. DeLancey Jr. and Samarth Barot ●

Samarth Barot headshot image

A recent Department of Justice (“DOJ”) settlement highlights the importance of assessing cybersecurity compliance for government contractors during mergers and acquisitions (“M&A”). In April 2025, DOJ announced an $8.4 million settlement with a defense contractor resolving alleged cybersecurity noncompliance by a company it acquired. Notably, under the settlement, the acquiring company was liable for cybersecurity noncompliance that occurred prior to the acquisition.

In the M&A context, successor liability arises when an acquiring company becomes responsible for liabilities, obligations, or wrongful acts committed by the company to be acquired prior to the acquisition. Fundamentally, successor liability ensures that a corporate acquisition does not allow the acquired entity to escape accountability. In the settlement, DOJ explicitly named the acquiring company as the “successor in liability” for the acquired company’s alleged violations, even though the conduct at issue occurred years before the acquisition. This underscores the importance for acquirers to add cybersecurity compliance to the issues vetted during due diligence.

Continue reading “Buyer Beware: Cybersecurity Compliance in M&A”

Defense Contractors’ Restrictions When Contracting with Chinese Companies

Merle M. DeLancey, Jr. and Oliver E. Jury ●

In the current economic climate, the obvious focus of many companies is on the administration’s imposition of tariffs. However, government contractors, especially those contracting with the U.S. Department of Defense (“DoD”), must not lose sight of their current and potential future direct and indirect relationships with certain Chinese entities.

Contractors’ compliance obligations regarding relationships with Chinese entities flow from:

  • FAR 52.204-25 (Section 889 of the 2019 National Defense Authorization Act (“NDAA”)), and
     
  • The Chinese Military Companies (“CMC”) List (Section 1260H of the 2021 NDAA) (also known as the “1260H List”).

Continue reading “Defense Contractors’ Restrictions When Contracting with Chinese Companies”

What CMMC Level Do I Need? The Department of Defense Issues New Guidance for Determining Appropriate CMMC Compliance Level

Michael Joseph Montalbano ●

The Department of Defense (“DOD”) recently issued new guidance outlining how it will determine Cybersecurity Maturity Model Certification (“CMMC”) levels for its solicitations and contracts. Prior to this guidance, contractors generally understood that contracts with only Federal Contract Information (“FCI”) would require a CMMC Level 1 self-assessment; contracts with Controlled Unclassified Information (“CUI”) would require either a CMMC Level 2 self-assessment or a CMMC Level 2 certification; and DOD contracts “supporting its most critical programs and technologies” would require a CMMC Level 3 certification. DOD’s new guidance provides additional information contractors can use to help them determine which CMMC Level they should achieve.

Continue reading “What CMMC Level Do I Need? The Department of Defense Issues New Guidance for Determining Appropriate CMMC Compliance Level”

The FAR Council Publishes Long-Awaited CUI Rule

Michael Joseph Montalbano ●

On January 15, 2025, the Federal Acquisition Regulation (“FAR”) Council issued its long-awaited “CUI Rule.” CUI, or Controlled Unclassified Information, is information that the government creates or possesses, or that an entity creates or possesses for or on behalf of the government, that a law, regulation, or governmentwide policy requires or permits an agency to handle using safeguarding or dissemination controls. For nearly 15 years, contractors have struggled to determine what information meets this definition. The CUI rule is an opportunity for the federal government to finally provide contractors with the guidance needed to better identify and safeguard the CUI they receive in connection with their federal contracts.

Continue reading “The FAR Council Publishes Long-Awaited CUI Rule”

Department of Defense Issues Final CMMC Rule

Michael Joseph Montalbano ●

On October 11, 2024, the Department of Defense (“DoD”) issued the first part of its final rule establishing the Cybersecurity Maturity Model Certification (“CMMC”) program. As expected, the final rule requires companies entrusted with national security information to implement cybersecurity standards at progressively advanced levels, (CMMC level 1, CMMC level 2, and CMMC level 3) depending on the type and sensitivity of the information. While the final rule largely tracks the proposed rule issued in December 2023, we outline below several notable updates DoD included in the final rule and their potential impacts on DoD contractors.

Continue reading “Department of Defense Issues Final CMMC Rule”