As we welcome 2026, it is a good time for government contractors to reflect on their cybersecurity posture and the major shifts in federal data protection policy from 2025. Last year was more than just a year of evolution in the cybersecurity space—it was marked by long-anticipated regulatory milestones and an acceleration of federal enforcement
Government Contracts & Investigations Blog
Latest updates on Developments Affecting Government Contracts & Investigations
Blog Authors
Latest from Government Contracts & Investigations Blog
New Executive Order Bars “Underperforming” Defense Contractors from Stock Buybacks and Shareholder Dividends—What Contractors Need to Know Now
On January 7, 2026, President Trump issued a new executive order, “Prioritizing the Warfighter in Defense Contracting” (the “EO”), which states that “[a]fter years of misplaced priorities, traditional defense contractors have been incentivized to prioritize investor returns over the Nation’s warfighters.” The EO aims to realign these priorities by restricting defense contractors deemed…
Order Up – The First FASCSA Order Has Been Issued by ODNI
The wait is over – on September 18, 2025, almost 2 years after implementing the Interim Rule, the Office of the Director of National Intelligence (“ODNI”) issued a Federal Acquisition Supply Chain Security Act (“FASCSA”) order to remove and exclude products and services from Acronis AG, a Swiss cybersecurity and data protection company. Although the…
Don’t Fall Behind: The CMMC Final Rule to Update the DFARS is Here!
On September 10, 2025, the final rule to implement the Cybersecurity Maturity Model Certification (“CMMC”) program in the Defense Federal Acquisition Regulation Supplement (“DFARS”) was published with an effective date of November 10, 2025 (i.e., 60 days after publication). This is the trigger for the new CMMC clause to start appearing in solicitations and contracts.…
The Expanding Scope of FCA-Cybersecurity Liability
The inexorable expansion of the False Claims Act (“FCA”) to cover virtually all types of cybersecurity breaches and violations – to include allegedly poor practices and failure to fully adhere to security controls – continues. At one time, an organization might have thought that it was unlikely to face a potential FCA investigation and litigation…
Trump’s New Cybersecurity Executive Order: What Contractors Need to Know
On June 6, 2025, the Trump Administration released a new Executive Order (“EO”) on cybersecurity, Sustaining Select Efforts to Strengthen the Nation’s Cybersecurity and Amending Executive Order 13694 and Executive Order 14144.[1] The Executive Order itself will not impose new obligations on agencies; instead, it strikes, amends, and updates certain provisions in prior Executive…
All American AI: New OMB Memos Set Priorities for Federal AI Use and Acquisition
On April 3, 2025, OMB released two new memorandums on artificial intelligence (“AI”) as directed by Executive Order 14179, Removing Barriers to American Leadership in Artificial Intelligence. (As a reminder, President Trump issued Executive Order (EO) 14179 on January 23, 2025 after rescinding President Biden’s AI Executive Order (EO 14110)).…
FedRAMP 20x – Update on Significant Change Process and Assessment Scope Standards
Last month, the federal government announced a major overhaul of the Federal Risk and Authorization Management Program (“FedRAMP”) called “FedRAMP 20x” (we discussed the initiative here). FedRAMP 20x is moving forward fast – with new authorizations, community engagement efforts, standards documents, and the Phase One pilot program. (More information about the Phase One pilot…
The Squeeze is the Juice – Utilization of The False Claims Act in the DEI/Government Contracting Executive Order
Update: On February 22, Maryland District Court Judge Adam Abelson issued a Preliminary Injunction halting the rollout and enforcement of the several provisions in the EO. Relevant here, the PI prohibits the Federal Government from requiring any contractor or grantee to make any certification required by the EO; and prohibits the Federal Government from bringing any…
Looking Beyond FedRAMP – Lessons from the U.S. Treasury Cybersecurity Incident
In the ever-evolving world of cybersecurity, even organizations that meet stringent security standards can be victims of sophisticated cyberattacks. A notable example of this is the December 8, 2024 cybersecurity incident involving the U.S. Department of the Treasury and its third-party cloud service provider, BeyondTrust. This incident underscores some critical lessons for entities (both government…