CUI, FOCI, Quantum, and CMMC: The Federal Government Issues a Wave of Proposed Rules to Safeguard Government Information

Michael J. Montalbano ●

Ernest Hemingway once wrote about bankruptcy that it happens “gradually and then suddenly.” The same can be said about federal information safeguarding rules. The Cybersecurity Maturity Model Certification (“CMMC”) program has been around for seven years. The Controlled Unclassified Information (“CUI”) program for over 15 years. Information safeguarding used to be a slow process with progress measured in years. Not anymore.

Over the past three months, the federal government has issued a wave of proposed rules designed to better safeguard federal information and harden contractor information systems.

FOCI Rule for Non-Cleared Contractors

The Department of Defense (“DoD”) issued a proposed rule in May 2026 that would significantly expand Foreign Ownership, Control, and Influence (“FOCI”) reporting requirements beyond the cleared contractor community, reaching existing and prospective contractors and subcontractors at any tier with DoD contracts or subcontracts exceeding five million dollars, even where no classified information is involved.

Continue reading “CUI, FOCI, Quantum, and CMMC: The Federal Government Issues a Wave of Proposed Rules to Safeguard Government Information”

DoD Seeks “Unprecedented Level of Visibility” into the Supply Chain Under Newly Proposed Regulations

Michael Joseph Montalbano ●

The Department of Defense (“DoD”) released a proposed rule on May 7, 2026, that would significantly expand Foreign Ownership, Control, and Influence (“FOCI”) and beneficial ownership disclosure requirements beyond cleared contractors to a much broader segment of the Defense Industrial Base. Soon, any contractor or subcontractor with a DoD contract exceeding five million dollars will need to report its FOCI status in the National Industrial Security System (“NISS”).

Who Is Covered Under the Proposed Rule

The proposed rule would apply to any existing or prospective contractor or subcontractor, at any tier, holding a DoD contract valued in excess of five million dollars—regardless of whether classified information is involved. The reporting and review framework will be established under a new DFARS Part 240, “Information Security and Supply Chain Security.” The DoD does not mince words. The rule is designed to provide an “unprecedented level of visibility” into the ownership structures of its partners and to prevent foreign adversaries from accessing sensitive unclassified information and critical technologies.

Continue reading “DoD Seeks “Unprecedented Level of Visibility” into the Supply Chain Under Newly Proposed Regulations”
Exit mobile version
%%footer%%