
Ernest Hemingway once wrote about bankruptcy that it happens “gradually and then suddenly.” The same can be said about federal information safeguarding rules. The Cybersecurity Maturity Model Certification (“CMMC”) program has been around for seven years. The Controlled Unclassified Information (“CUI”) program for over 15 years. Information safeguarding used to be a slow process with progress measured in years. Not anymore.
Over the past three months, the federal government has issued a wave of proposed rules designed to better safeguard federal information and harden contractor information systems.
FOCI Rule for Non-Cleared Contractors
The Department of Defense (“DoD”) issued a proposed rule in May 2026 that would significantly expand Foreign Ownership, Control, and Influence (“FOCI”) reporting requirements beyond the cleared contractor community, reaching existing and prospective contractors and subcontractors at any tier with DoD contracts or subcontracts exceeding five million dollars, even where no classified information is involved.
Continue reading “CUI, FOCI, Quantum, and CMMC: The Federal Government Issues a Wave of Proposed Rules to Safeguard Government Information”