CUI, FOCI, Quantum, and CMMC: The Federal Government Issues a Wave of Proposed Rules to Safeguard Government Information

Michael J. Montalbano ●

Ernest Hemingway once wrote about bankruptcy that it happens “gradually and then suddenly.” The same can be said about federal information safeguarding rules. The Cybersecurity Maturity Model Certification (“CMMC”) program has been around for seven years. The Controlled Unclassified Information (“CUI”) program for over 15 years. Information safeguarding used to be a slow process with progress measured in years. Not anymore.

Over the past three months, the federal government has issued a wave of proposed rules designed to better safeguard federal information and harden contractor information systems.

FOCI Rule for Non-Cleared Contractors

The Department of Defense (“DoD”) issued a proposed rule in May 2026 that would significantly expand Foreign Ownership, Control, and Influence (“FOCI”) reporting requirements beyond the cleared contractor community, reaching existing and prospective contractors and subcontractors at any tier with DoD contracts or subcontracts exceeding five million dollars, even where no classified information is involved.

Continue reading “CUI, FOCI, Quantum, and CMMC: The Federal Government Issues a Wave of Proposed Rules to Safeguard Government Information”

Debarment or Suspension Based on a DEI Program? Let’s Think It Through

Dominique L. Casimir

Suspension and debarment are powerful administrative tools that the Government uses to exclude from federal contracting entities that are not “presently responsible.” These exclusions can be lengthy, effectively shutting debarred or suspended contractors out of the lucrative federal marketplace for years. Even after the period of exclusion ends, disclosure requirements in connection with proposal submissions and teaming arrangements make it difficult for a previously debarred or suspended contractor to shed the stain of a prior exclusion. Because of these severe consequences, contractors shape their compliance programs, organizational cultures, and conduct to minimize the risk of creating cause for debarment or suspension.

To read the full article, please click here.

“Debarment or Suspension Based on a DEI Program? Let’s Think It Through,” by Dominique Casimir, was published in The Government Contractor, Volume 68 Issue 21, on June 3, 2026.

DoD Seeks “Unprecedented Level of Visibility” into the Supply Chain Under Newly Proposed Regulations

Michael Joseph Montalbano ●

The Department of Defense (“DoD”) released a proposed rule on May 7, 2026, that would significantly expand Foreign Ownership, Control, and Influence (“FOCI”) and beneficial ownership disclosure requirements beyond cleared contractors to a much broader segment of the Defense Industrial Base. Soon, any contractor or subcontractor with a DoD contract exceeding five million dollars will need to report its FOCI status in the National Industrial Security System (“NISS”).

Who Is Covered Under the Proposed Rule

The proposed rule would apply to any existing or prospective contractor or subcontractor, at any tier, holding a DoD contract valued in excess of five million dollars—regardless of whether classified information is involved. The reporting and review framework will be established under a new DFARS Part 240, “Information Security and Supply Chain Security.” The DoD does not mince words. The rule is designed to provide an “unprecedented level of visibility” into the ownership structures of its partners and to prevent foreign adversaries from accessing sensitive unclassified information and critical technologies.

Continue reading “DoD Seeks “Unprecedented Level of Visibility” into the Supply Chain Under Newly Proposed Regulations”

What Does IBM’s $17 Million FCA Settlement Portend for Government Contractors Wrestling with Compliance?

Jennifer A. Short, Dominique L. Casimir, Brooke T. Iley ●

Jennifer A. Short headshot image

On Friday, April 10, 2026, the Department of Justice (“DOJ”) announced a $17 million False Claims Act (“FCA”) settlement with International Business Machines (“IBM”), based on the company’s alleged violations of federal anti-discrimination laws. The settlement is the first under the DOJ’s Civil Rights Fraud Initiative, created last May with the objective of investigating and prosecuting “illegal DEI” practices, primarily through an FCA lens. Coupled with a new Executive Order—issued on March 26—that imposes contract prohibitions on “racially discriminatory DEI activities” in federal government contracts and subcontracts, the IBM settlement signals an escalation in the government’s focus on DEI programs and employment policies.

The DOJ Press Release and Settlement Agreement

The Alleged “Covered Conduct” Identifies Specific Problematic Practices. 

DOJ alleged that IBM improperly made employment decisions based on protected characteristics through specific programs and actions, described as the “Covered Conduct” for purposes of the settlement agreement:

  • Compensation Incentives: A “diversity modifier” linking bonus compensation to demographic targets
  • Hiring and Promotion Criteria: Basing interview eligibility or prioritization on race, sex, or national origin
  • Demographic Goals for Business Units: Developing race and gender targets tied to employment decisions
  • Limited-Access Programs: Limiting training, mentoring, and leadership development to employees meeting specific demographic criteria, such as minorities.

To read the full alert, please visit our website.

Decoupling from Chinese Chips: Unpacking the Proposed Section 5949 Supply Chain Ban

Robyn N. Burrows and Samarth Barot

Samarth Barot headshot image

In December 2022, we discussed the passage of Section 5949 of the Fiscal Year 2023 National Defense Authorization Act (“NDAA”), which introduced prohibitions on certain semiconductor products and services from designated Chinese manufacturers. At the time, the statute’s scope remained unclear, particularly regarding whether the restrictions would apply only to federal sales or extend to contractor “use” of covered technologies, similar to Section 889’s Part B prohibition. On February 17, 2026, the Federal Acquisition Regulatory (“FAR”) Council released a proposed rule that provides important clarity on these questions and establishes a compliance framework for government contractors.

Continue reading “Decoupling from Chinese Chips: Unpacking the Proposed Section 5949 Supply Chain Ban”

Understanding the Potential Anthropic Ban: Key Considerations for Federal Contractors

Robyn N. Burrows and Merle M. DeLancey, Jr. ●

On February 27, 2026, President Trump posted on Truth Social directing all federal agencies to “immediately cease” use of Anthropic’s artificial intelligence (“AI”) technology. Simultaneously, Defense Secretary Pete Hegseth announced on X he was designating the company a “supply chain risk to national security” and prohibiting federal contractors from doing any business with Anthropic. This unprecedented action against a domestic company has significant supply chain implications for government contractors. Below, we summarize what led to this development, the legal authorities pertaining to supply chain bans, and practical guidance for contractors navigating this evolving situation.

1. Background: From Contract Dispute to Presidential Directive

The conflict between Anthropic and the federal government emerged from a contract dispute over the company’s AI usage restrictions. Anthropic, which holds a $200 million Pentagon contract and was the first frontier AI company to deploy its models on classified government networks, maintained two “red lines” in its contract negotiations: it refused to allow its AI model, Claude, to be used for mass domestic surveillance of Americans or in fully autonomous weapons systems.

The Pentagon demanded that Anthropic agree to “all lawful use” of its technology without Anthropic’s proposed restrictions. Anthropic’s refusal led President Trump and Secretary Hegseth to announce their decisions against Anthropic on social media. Secretary Hegseth stated that Anthropic would be “immediately” designated a supply chain risk, prohibiting any federal contractor working with the military from “any commercial activity with Anthropic.”

Anthropic has announced it will challenge the supply chain risk designation in court, calling it “legally unsound.”

Continue reading “Understanding the Potential Anthropic Ban: Key Considerations for Federal Contractors”

Top 10 Points for Contractors from DOJ’s February 19 Comments on “DEI” Enforcement

Luke W. Meier ●

Yesterday, Brenna Jenny, Deputy Assistant Attorney General, Commercial Litigation Branch, Department of Justice (“DOJ”) Civil Division, offered remarks on False Claims Act enforcement related to so-called “illegal DEI.” Other outlets have broadly recapped these remarks, a rare opportunity for direct insight into DOJ’s thinking on these issues.

Below are 10 key points for government contractors from the remarks of Ms. Jenny (who spoke for herself, and not officially for the DOJ).

Continue reading “Top 10 Points for Contractors from DOJ’s February 19 Comments on “DEI” Enforcement”

GSA Issues New Framework for Protecting CUI in Contractor Systems

Michael Joseph Montalbano ●

Last month the General Services Administration’s (“GSA”) Office of the Chief Information Security Officer (“OCISO”) issued CIO-IT Security-21-112 Rev. 1, a procedural guide governing how Controlled Unclassified Information (“CUI”) must be protected when it resides in nonfederal contractor systems. Although styled as internal process guidance rather than a regulation, the document establishes a detailed approval framework that will determine which contractors are eligible for GSA contracts that include CUI.

Background and Scope

The guide, which implements GSA’s approach to safeguarding CUI, uses National Institute of Standards and Technology (“NIST”) SP 800-171, Revision 3, selected enhanced requirements from NIST SP 800-172, and selected privacy controls from NIST SP 800-53, Revision 5. It applies where CUI is resident in a contractor system that is not operated on behalf of the federal government, and therefore is not subject to the Federal Information Security Modernization Act or the Federal Risk and Authorization Management Program (“FedRAMP”). Use of this process requires coordination with OCISO and approval by the GSA Chief Information Security Officer. GSA intends to eventually incorporate these requirements into applicable contracts and solicitations.

Continue reading “GSA Issues New Framework for Protecting CUI in Contractor Systems”

DOJ Announces Record-Breaking False Claims Act Recoveries in FY 2025: What the Stats Portend for 2026

Jennifer A. Shortand Oliver E. Jury ●

Jennifer A. Short headshot image

Fiscal Year (“FY”) 2025 yielded a historic high of over $6.8 billion in False Claims Act (“FCA”) settlements and judgments, underscoring the Department of Justice’s (“DOJ”) aggressive enforcement. DOJ’s annual report, released January 16, 2026, showed that healthcare fraud matters again dominated the lion’s share of the moneys recovered, accounting for more than $5.7 billion, and reaffirming the sector’s centrality to FCA priorities. Qui tam lawsuits also retained an outsized influence, representing approximately $5.3 billion in recoveries for both intervened ($3.0 billion) and declined ($2.3 billion) cases. On the flip side, that means the government recovered some $1.5 billion without the aid of an underlying whistleblower complaint. The pipeline of new cases looks robust moving forward: whistleblowers filed a record 1,297 new qui tam suits, and DOJ opened 401 new investigations.

Continue reading “DOJ Announces Record-Breaking False Claims Act Recoveries in FY 2025: What the Stats Portend for 2026”

E‑Verify, FAR 52.222‑54, and Renewed FCA Risk: What Contractors Need to Know

Jennifer A. Short, and Oliver E. Jury ●

Jennifer A. Short headshot image

The current administration’s focus on immigration played out in a recent False Claims Act (“FCA”) matter in which a federal contractor was alleged to have billed for unauthorized workers in violation of FAR 52.222‑54 (Employment Eligibility Verification, “E-Verify”).

On September 18, 2025, the Department of Justice (“DOJ”) announced that Bayonne Drydock and Repair Corporation (“Bayonne”) agreed to pay $4,043,810.56 to resolve allegations that unauthorized workers worked on Bayonne’s Navy contracts over multiple years.

According to DOJ’s press release, in 2016, the Department of Homeland Security (“DHS”) sent a “Notice of Suspect Documents” to a subcontractor controlled by Bayonne’s Risk Manager, questioning the work authorization of certain subcontractor employees. While the Risk Manager terminated the unauthorized employees, she re-hired some of them through another subcontractor that she controlled. Bayonne’s settlement agreement with DOJ asserts that between 2016 and 2020, Bayonne billed the government for the work of approximately 52 unauthorized employees working for entities owned or controlled by Bayonne’s Risk Manager. The settlement agreement also confirmed that the Risk Manager pled guilty to criminal charges stemming from her role with Bayonne and its subcontractors.

Continue reading “E‑Verify, FAR 52.222‑54, and Renewed FCA Risk: What Contractors Need to Know”