CMMC Isn’t Your Only Cyber Compliance Problem.

A rulemaking-season rundown: even as the government preaches “harmonization,” defense and federal contractors are about to juggle at least five separate, overlapping cyber regulations. The through-line: CMMC gets blamed for everything, but the real driver is DFARS 7012 sitting untouched while newer rules pile on around it.

The five rules to watch:

1. FAR CUI rule — A government-wide framework extending DFARS-7012-style protection (800-171 Rev 3, FedRAMP, 72-hour reporting, flowdowns) to all agencies handling CUI. Ten years late; expected final by end of 2026 as part of the FAR overhaul. Upside: a standardized CUI-identification form could finally fix marking. Downside: it may create duplicate Rev 3 vs. Rev 2 baselines because of the CMMC suspension.

2. CIRCIA final rule — A broader cyber-incident-reporting regime; defense contractors are the single largest affected group. It can’t be cleanly harmonized with DFARS 7012 (not “substantially similar”), and CIRCIA doesn’t scope to CUI — it triggers on being critical infrastructure — so either CISA or DoD has to bend, or contractors face two reporting regimes. Expected possibly before the holidays.

3. DFARS 7012 “3.0” — The root problem nobody’s fixing. The revision (references to 800-172, terminology harmonization, international agreements) has been “in drafting” since 2023 with the internal deadline repeatedly slipped (now Oct 2026), zero visible progress. Because 7012 never even estimated implementation cost, CMMC unfairly absorbs the blame. Realistically not before end of 2027.

4. CMMC 3.0 — The DoD had a finished interim-final-rule (Rev 2→Rev 3 transition, ODP clarity, ~20% fewer companies affected) waiting on the CIO’s desk — with hard-won waivers, including from EO 14192’s ten-for-one deregulation mandate — and walked away from it to do the review. Any “significant change” now restarts rulemaking, and OIRA is unlikely to re-grant those waivers (that process took two years), risking ~24 months out of sync.

5. Post-quantum cryptography — A fifth, fully separate statutory track: congressional mandate (2022), $7B White House cost estimate (2024), DoD strategy folding PQC into CMMC (April 2026), and EO 14412 requiring a FAR rule mandating PQC-enabled FIPS by end of 2030. Likely a rule in early-to-mid 2027.

Bottom line: expect class deviations and CIO policy memos (fast, but no public comment) to patch the gaps — and between now and 2030, roughly half a dozen rules will hit contractors, almost certainly not perfectly harmonized.


Transcript

Jacob: All right, folks. It is September of 2026, and while the government talks a big game about harmonizing your cybersecurity requirements, chances are you’re going to have to juggle a lot of different regulations in the pretty near future. So, whether you are a defense contractor or just working federal contracts in general, here are five cyber regulations that you need to be aware of. That’s what we’re going to talk about today.

Jason — not so long ago, people used to ask us what we were going to talk about when the CMMC final rule came out at the end of 2024. Turns out, there’s more rulemaking going on in 2026 than there ever was before.

Jason: If anybody thinks that all we talk about is CMMC, they’ve never actually had a conversation with us at all — that’s the first thing. And the second thing is, I think it’s important for us to go outside of that vertical, for many particular reasons. And this one is case in point, because a lot of times our audience gets so hyperfocused on the requirements attached strictly with CMMC or DFARS’s requirements, that oftentimes they overlook what’s on the horizon from other government agencies — or even the same government agency — and it can lead to sticky problems for a lot of those contractors.

Jacob: Yeah. They don’t always line up. And there’s probably a case to be made — it’s too early to tell — that CMMC, if it had fewer question marks around it, as is the case in September of 2026, defense contractors might be more insulated from some of the other agency rulemaking we’re going to talk about today. But now that everything’s up in the air, everything is up in the air, if you will. And so there’s just a lot of stuff that could come your way, because you don’t have a solid, firm regulation sort of keeping everything at arm’s distance. But time will only tell as far as that goes. So let’s get into it. We’re talking about five different regulations here.

Let’s start with number one, the big one, the FAR CUI rule. So the summary of the FAR CUI rule in the government’s own words: The FAR CUI proposed rule would establish a government-wide contractual framework for protecting controlled unclassified information. The framework would use a standardized CUI form to identify applicable controlled unclassified information, and require contractors handling that CUI on non-federal systems to implement NIST SP 800-171 Revision 3 requirements, applicable CUI Specified requirements — like specific incident reporting requirements — and potentially even NIST SP 800-172 requirements, depending on the nature of the data you might handle pursuant to any given contract. That FAR CUI rule also establishes standardized 72-hour incident reporting requirements, cloud and FedRAMP requirements when you’re processing that CUI in the cloud, subcontractor flowdown requirements when you flow that controlled information to other non-federal systems and subcontractors, and disclosure of non-compliance, as well as plans of action and milestones, nonconformities, things like that.

The FAR CUI rule implements the National Archives and Records Administration controlled unclassified information program that was enacted under Executive Order 13556, which was signed all the way back in 2010. The NARA CUI program for the federal agencies didn’t come out as a final rule until 2016 — so, six years after the executive order, they finally got the rule for the agencies out there. So we had two of the things that we needed. The third part we were missing was implementing that guidance into contracts — the FAR CUI rule. So it’s about 10 years after we thought we were going to get the FAR CUI rule. But that’s why they’re doing the FAR CUI rule — that third piece they were missing of their three-part plan.

Jason: Yeah. So this is the rule that looks the most familiar to our audience, because it is the one that has all the meat and potatoes — or bones and muscle, whatever analogy you want to use — of what the DoD was going through with the CMMC program. It’s the protection of CUI in the cloud, it’s the protection on non-federal systems, it’s the incident reporting, all those things — because, as we know and as we saw throughout history, the DoD just moved a little bit faster, and now we’re at a snail’s pace, we’re slowed down, and things are catching up.

Jacob: Yeah, absolutely. So let’s talk about the timeline of where this rule was coming out. Like we said, we originally expected this rule in 2016. We’ve done, I think, 10 episodes on the FAR CUI rule from various angles and for various reasons — we’ll link a bunch of them down below if you’d like to know more context about the history of the rule, it’s actually quite interesting. But the proposed rule for the FAR CUI rule originally came out in January of 2025. Then the revolutionary FAR overhaul happened, and the government decided they were going to overhaul the entire Federal Acquisition Regulation — all of the parts of the FAR, all at the same time. So they took the proposed FAR CUI rule and included it in the series of proposed rules to overhaul the FAR, and we got that second proposed rule in June of 2026. And now we are expecting the final FAR CUI rule as part of the final FAR overhaul rulemaking tranches by the end of 2026. So I would expect it will be included in that rollup as a final rule, just like it was included in that rollup as a proposed rule, and that we will finally — 10 years later — see the FAR CUI final rule published by the end of 2026.

Jason: People first started talking about this — I thought it was fake, like it just would never show up. The FAR CUI rule. It’s like the goatman under the bridge or whatever. But you know what I mean — everybody was, even us, when we started talking about it. People were like, “Yeah, I’ve got these DoD requirements,” and we’re like, “Well, what about the FAR CUI rule?” And they’re like, “The what?”

Jacob: Yeah. And like you said, this will seem familiar to defense contractors, because it’s very similar to DFARS 7012. Technically, DFARS 7012 is a DoD placeholder while they were waiting for the FAR CUI rule to happen. They didn’t expect it was going to take 10 years — they thought it was going to take like one or two — but here we are. Anyways, let’s talk about why people should pay attention to this rule. The good news is that this potentially helps a lot with CUI identification and marking, via that standardized GSA form. This would be worth all the other nonsense, if just for a freaking form in your paperwork that says, “Yeah, there is CUI involved in this contract, and here are some examples of what it might be.” That’s wonderful. Bad news: this potentially will require duplicate baselines for protecting CUI, thanks to the DoD’s CMMC Phase 2 suspension and all the class deviation issues that have been raised. We just did a podcast episode on that exact issue, we’ll link it down below. So it’s a mixed bag here, but you should definitely pay attention to it, because it’s going to help in a lot of ways, and it could potentially make for a lot more work.

Jason: Just look at the evidence here. Can I nudge you over to the dark side just a little bit — and the belief that revolutionary FAR overhaul affects the rule that’s the baseline rule for the CMMC rule, and there’s going to be identification of CUI coming through? The CMMC rule was moving faster than the FAR CUI rule. It caught up. There are changes inside of it. Like I’ve said on previous episodes, Jacob, I think somebody saw the writing on this wall — the writing inside this rule — and was like, “Hold fast.” Or at least I hope so.

Jacob: Yeah. That’s a wonderful positive outlook that I do not share. I think the left hand isn’t talking to the right hand isn’t talking to the left hand.

Jason: All right, let’s share this positive outlook. Every single RFI response that’s been posted publicly that I’ve read is something to do with CUI marking and identifying CUI within a contract. And we know for a fact that the SF format this rule brings can help relieve some of those issues with CUI marking. Do you agree or disagree?

Jacob: I think we’re going to have to park that in theory. In theory. Hold on — I think we’re going to have to do a longer episode, because I will absolutely take too much time to explain it. Let us know in chat: do you want us to do an episode on whether we think the FAR CUI rule will help the RFI responses? Let us know.

Anyways, second rule here in the five: the CIRCIA final rule. So, quick summary. The CIRCIA rule would create a new cyber incident reporting regime for many defense contractors that is broader than the existing cybersecurity reporting regime in DFARS clause 252.204-7012 — different triggers for reporting, different contents required in the reporting, different system scopes involved in the reporting, different ransomware reporting requirements, different supplemental reporting requirements, two-year data preservation requirements, and so on. Quick timeline recap on the CIRCIA final rule: March of 2022, after everybody on the East Coast was waiting in line to get gas — you guys remember that — Congress passed the Cyber Incident Reporting for Critical Infrastructure Act. In September of 2022, there was an RFI. There were a bunch of listening sessions — sound familiar? In April of 2024, CISA released the proposed rule, and it was like 500 pages long. It was absolutely massive. Fun fact — we did episodes on this — the largest group of companies affected by the CIRCIA rule: defense contractors.

Jason: A lot of people don’t know that.

Jacob: A lot of people don’t know that. Anyways, fast forward to June of 2026 — another round of town hall listening sessions. And now here we are, awaiting the final rule. There’s a lot of congressional support by the authors of the CIRCIA bill to get this final rule out. We expect that rule will be out anytime between right now and the end of 2026. I would not be surprised if this is out before the holidays. They’ve been working on this for many years, there’s a lot of inertia behind it, a lot of congressional support behind it. They’ve done a ton of listening, and now we should see it here sometime soon.

Jason: Two separate portions — two separate eras of listening sessions. There’s probably 10 or 12 individual sessions that they actually held.

Jacob: Yeah.

Jason: And so this is a huge one. And the reason why is because — if anybody knows anything about the DIB, one of the things… you said defense contractors are heavily impacted by this, but if there’s one thing they struggle at more than implementing cybersecurity controls, it’s reporting cybersecurity incidents when they happen. Either they don’t report it out of reputational damage fears, or they don’t report it because they don’t know it’s happening, because they don’t have the infrastructure in place to even trigger a response. So this is going to be huge, because of the triggers attached to it — it means now even more incidents are going to go unreported. Even more incidents that should have been picked up and reported on for TTPs, or whatever it may be, are not going to be reported to the necessary bodies.

Jacob: Yeah. So that’s two things that are going to affect defense contractors that are not from the DoD, potentially by the end of the year. But just real quick, why you should pay attention to this: DFARS 7012 and CIRCIA, as written, cannot be clearly harmonized. That’s the word that everybody uses — harmonizing these regulations. These two cannot be clearly harmonized, because DFARS 7012 reporting requirements are not what they call “substantially similar” to the CIRCIA reporting requirements. As a result, CISA is either going to have to accept a much narrower amount of data and cyber incident reports according to DFARS 7012, or they will have to depend on the DoD to revise DFARS 7012 to match what CIRCIA wants. All of this has to happen while CISA and DoD are going to need to recognize that existing DoD reporting mechanisms have limited participation — those are all voluntary participation. They expanded voluntary participation in their information sharing and incident reporting rule back in 2024, but only a couple thousand companies actually participate. They’ve never actually given an update on how many. So it doesn’t really give CISA the visibility into the mandatory reporting requirements that the CIRCIA statute requires them to get. So, when we’ve asked DoD what the plan is, sometimes they said they don’t even know what CIRCIA is. So another one — like the FAR CUI rule — pay attention to this, because heads you’re wrong, tails you’ve got two different reporting requirements. We’ll just have to see how it plays out.

Jason: You said that either CISA has to accept and bend, or the DoD has to accept and bend and alter DFARS. There’s no instance where neither one of them bends, and both requirements sit in place for DIB contractors. That absolutely could happen.

Jacob: Yeah.

Jason: At one point in time where DIB contractors are struggling to do DFARS reporting requirements — which are much less of a burden, a magic word of the month — now CIRCIA is going to ask, because the DoD and CISA can’t come together.

Jacob: Yeah. CIRCIA does not care about CUI. They care about your existence as a critical infrastructure entity, and as a result there is no scoping for relevant systems. So DFARS 7012 is like a pinhole compared to what CIRCIA wants, which is why I don’t see them accepting DFARS 7012 as a substitute.

Jason: And realistically, if we look at this — I don’t want to beat the dead horse, but it’s laying there — the first two things we’ve covered, the FAR CUI rule and the CIRCIA final rule: if you look at the components, it’s exactly the same components DIB contractors have to abide by right now, but more stringent. Rev 3 as far as the implementation of controls, and incident reporting — which is much more, again, magic word, burden, much more overhead, many more people are going to have to track.

Jacob: Absolutely. Well, like we said, if CIRCIA wants to accept DFARS 7012 — I don’t think they will — or they could hope the DoD is going to update DFARS 7012 to match what CIRCIA would require. So let’s talk about number three: DFARS 7012 3.0, if you will. The DoD summary: their rule to revise DFARS 7012 for the first time since 2016 updates the “safeguarding covered defense information and cyber incident reporting” clause at DFARS 252.204-7012. The amendments and updates would include the incorporation of references to NIST Special Publication 800-172, harmonization of certain terminology like CUI, CDI, FedRAMP equivalency — all of these major hot-button issues that people blame on CMMC, they’re 7012 issues, they would have to get fixed via this rule — addressing international agreements (boy, boy oh boy, have we been waiting on that one for a while), and streamlining the vendor identification process, who knows what the heck that means — that’s just the generic summary they put in there.

Quick peek into the internal development life cycle of this rule: the DoD announced that they had started their internal drafting of the DFARS 7012 revision in October of 2023. The internal report about what that draft rule would look like was due in December of 2023, and they have subsequently extended their own internal deadline two weeks, three weeks at a time, consistently since then. As of last week, the internal deadline report has been extended to October of 2026. That is not a hard deadline — they’re just going to extend it again. There is zero indication that they have made any progress on drafting this 7012 3.0 rule at all. I haven’t heard anything about anyone in the Under Secretary for Acquisition and Sustainment — Mr. Duffy — that anyone in that office is working on this rule at all for the last three years. Almost all of the problems that people blame on CMMC — that everyone’s running around with their heads cut off doing reviews about — all trace back to the fact that 7012 hasn’t been updated in 10 years. We have no idea when the proposed rule might get published. There’s no indication that there’s any progress of the draft even being done. There’s almost certainly no chance we would see this by the end of this year. I think it’s a stretch to say we’d even see it by the end of next year.

Jason: You feel better? You got it all off?

Jacob: I feel great.

Jason: And then — I know people hate it, it’s all splitting hairs — but you can review CMMC as long as you want to; until you change 7012, you’re still going to have these problems. Maybe they’re out trying to streamline the rulemaking process — I don’t know what they’re trying to do, because nobody understands what “streamline the vendor identification” truthfully means. It’s just making it faster. I understand it’s provocative and flashy words. But this is something that’s been rumbling underneath for a while. It has nothing, again, to do with CMMC — it’s a modernization of something that hasn’t been touched in over a decade, that’s well overdue and needed, especially with all the changes to all the regulations around it that impact it, and even the body of people it impacts. It’s just outdated.

Jacob: Like, back in 2016 when they wrote the rule, they didn’t even estimate how much it would cost to implement 800-171. So all those costs that people are blaming on CMMC — part of the reason they get blamed on CMMC is because the DoD just never estimated how much it would cost to comply with this clause. If you want a belly button to press about whose fault it is for costing you money to comply with requirements, you’ve got to get DFARS 7012 updated to estimate a cost — because CMMC is going to say, “We don’t require you to implement anything. We’re just here to verify that you did implement it.” So why should you pay attention? If we see a change in DFARS 7012 — I don’t even think it’s going to happen until the end of 2027 at the earliest, based off what we’ve seen so far, unless something changes. Like and subscribe, because we’ll let you know if we see a change. But nothing’s changed in the last three years. That means everything else that orbits around DFARS 7012 — your self-scoring system, your requirements, your incident reporting, your assessments, your programs — all that other stuff will require constant monitoring, translation, memos, band-aids, updates, mappings, all that stuff everybody loves to do, will continue to have to happen, because DFARS 7012 will continue to be its old version. And all this other stuff — FAR, CIRCIA, CMMC, post-quantum crypto, blah blah blah — will have been updated, and 7012 will just be sitting there.

Jason: If there are places where gaps exist between what 7012 is from 10 years ago and all of these new regulations coming out, would something like a class deviation be issued that says, “This is the way to do it from here on out,” kind of like how they did with the revisions?

Jacob: Yeah, it’s going to be class deviations, it’s going to be policy memos from the DoD CIO. And those might be fast, and they might be like, “I’m not a regular appointee, I’m a cool appointee, because I’m doing memos, I’m not doing rulemaking” — except for the fact that you don’t get to put comments on their memos. You don’t get to make comments on class deviations. There’s no public involvement if you’re not doing rulemaking. Nobody likes rulemaking, but everybody wants to have their voice heard. So, pick your poison, everybody.

All right. Speaking of poison, number four: CMMC. CMMC 3.0. We’re going to do a combo here — CMMC 3.0 and DFARS clause 252.204-7021, which implements CMMC into contracts. So we had a preview of the rule the DoD did not publish, because they opted to do a review — long story, you’re probably aware, check out our previous episodes for more. The summary of the rule they were going to publish before the suspension, in their words: “This amendment defines a deadline and period for transition from the requirement to comply with NIST SP 800-171 Revision 2 to the requirement to comply with NIST SP 800-171 Revision 3. The changes include added specificity in the security requirements for organization-defined parameters, administrative edits, and clarifying content in multiple areas as necessary to effect the transition to 171 Rev 3.” And they go on to say: “This rule amendment is based on a more current estimate of the size of the defense industrial base. Overall, we estimate approximately 20% fewer total companies will be impacted by 32 CFR Part 170.” So the rule they didn’t go with was going to have a transition from 171 Rev 2 to 171 Rev 3, it was going to give us clarity by defining the organization-defined parameters, and it was going to affect 20% fewer companies than CMMC 2.0.

Jason: I know.

Jacob: And they didn’t go with that rule. They went with the review process. So now the question is, are they going to affect a larger number — 30% fewer companies, 40% fewer companies? Is the transition going to be different than what the rule was going to say? We don’t know, because we never saw this rule. But it sounds like what everybody was asking for — fewer companies, transition to updated requirements, more clarity, blah blah blah. I guess we’ll never know, because we never saw that one.

Jason: Yeah. Because if we would have seen the justification behind why they estimate 20% fewer companies were going to be impacted — “oh, we did this, now that takes out [X], we added this mechanism,” whatever it may be. What’s really important to see here is that it did the thing we’ve been talking about the entire episode: this rule harmonized at least the baseline for security implementations. And I think that would have been the most important thing — allowing some flexibility in the organization-defined parameters for some of those modernized things everybody’s harping on right now. Just basic, basic common sense here, right?

Jacob: Brilliantly put. Basic. Brilliant. Absolutely brilliant. So here’s the really brilliant part. Let’s talk about this timeline. Quick review: CMMC 1.0 came out in November of 2020. Very unpopular — election, big review, big sets of listening sessions, blah blah blah. In November of 2021, they announced they were going to do new rulemaking for CMMC 2.0. We didn’t see the proposed 2.0 rule until almost two years later, in December of 2023. Then the subsequent contract clause rule to take that idea and implement it in contracts — we got that proposed rule in August of 2024. We got the final program rule in October of 2024. And then we got the final contract clause rule in September of 2025, which kicked off Phase 1 of the CMMC phased rollout. Now, according to DoD’s own entry into what’s known as the unified agenda, that 3.0 rule we never saw was expected to be published in July of 2026. So we would have had a plan for transitioning to 171 Rev 3, a plan for affecting fewer companies, a plan for introducing clarity and definitions and things like that. And we wouldn’t have had an issue with the FAR CUI rule — maybe they could have focused on the CIRCIA problem. But now that they haven’t pursued that rule and they’ve opted to go with this suspension, all that other stuff is now back on the table.

So why should you pay attention? Everybody, listen to what I’m telling you here: this is the bureaucracy that is going to bite the review in the behind. DoD started drafting the CMMC 3.0 rule at the end of 2024. As soon as the 2.0 final rule was published, they started drafting the 3.0 rule, because they knew they had to transition to 171 Rev 3, define ODPs, all that other stuff. The 3.0 rule was expected in July of 2026 — so two years of time they spent on this 3.0 rule. The status of that 3.0 rule was what’s known as an interim final rule, meaning the rule would be published and then go into effect — you don’t have to wait to take public comments, and then spend a year adjudicating those comments, and then issue the final rule. So they fixed the timeline problem as far as being off with the FAR CUI rule requiring 171 Rev 3. More importantly, Executive Order 14192, known as “Unleashing Prosperity Through Deregulation” — this is the ten-for-one rule under the current administration: if you want to issue one regulation, you need to identify 10 regulations to repeal, otherwise you ain’t getting a regulation. Well, guess what? The DoD team, starting in 2024, got a waiver for Executive Order 14192. They got a waiver from OIRA to have an interim final rule. Those are both very difficult to get, which is why that process took two years to go through. But the DoD now says, “We’re not going with that rule.” So any program changes that result from the Phase 2 suspension that would be considered significant changes would require the rulemaking process to start all over again. They probably won’t get an interim final status, and who knows if they would get an Executive Order 14192 exemption. That last process took two years. So now you could potentially be out of baseline with the FAR CUI rule, CIRCIA, and 7012 for 24 months, as far as we know. Will they get out of the review and then just pick up the old rule and hope the waivers are still valid? We don’t know. Will they decide to do something different and need to go pursue new waivers, and we won’t know what’s going on for two years? Well, as of right now, in early September 2026, we don’t know. But you’d better pay attention, because there’s going to be a lot of stuff for you to spin in the air at the same time until they all get on the same page.

Jason: Yeah. At the time of this episode, the review from the task force is wrapping up, right? And the report’s being issued, and whatever comes of that report, they’re like, “This is the way to change it.” What you just said is that the way they have to change it is this arduous, burdensome government red-tape bureaucratic process. It’s just so funny that they’re like, “Well, there’s a Secretary of Defense strategy for reducing regulation.” And you’re like, “That’s great, you should reduce regulation.” The CMMC regulation had a waiver for the executive order that created that strategy.

Jacob: So they waived it. They waived it. So now if you want to change it, you’ve got to try to get that waiver again. And the team that had just gotten done with three-plus years of rulemaking went through another two-year process. Now you’ve got a whole new team of people. If you’re going to restart that process, it’s going to be a while.

Jason: Do you think people would question, like — this was so urgent that you had to get an interim final rule and an exemption for EO 14192, and now all of a sudden you want to change all of it and not go urgent? Exactly what happened in 2021.

Jacob: Everybody says, “Oh, the DoD said CMMC 2.0 was going to be done in 2023-2024, we didn’t get it until the end of 2025.” The reason they were telling everybody they’d be done in 2023 was they were expecting an interim final rule. But when they went back to OIRA after the review, OIRA was like, “It’s clearly not a national security emergency. You just went through a whole review process and changed everything. So you can go do rulemaking like everybody else.” Here, we got an interim final rule and another waiver for an entirely different executive order. And now the DoD says, “Well, actually, we’re going to go back and change our minds.” So they’re going to go back to OIRA and say, “We want waivers again.” History says that won’t work, and it’ll take them two or three years to implement the changes they want. But I don’t know, we’ll have to see. Maybe they crack the case. Like and subscribe, because we’re going to have to see.

Okay, number five here, wrapping up. Oh boy, we just did an episode on this one. Brave new world here, everybody: post-quantum cryptography requirements. Just a quick summary. Congress required the federal government to prepare for post-quantum crypto migration in 2022. The congressionally mandated 2024 White House report scoped the problem, analyzed the problem, and estimated the federal transition would cost like $7 billion, because a bunch of equipment and systems just can’t be upgraded to comply — so they’ve got to be ripped and replaced. DoD turned that direction into a defense-specific strategy in April of 2026, signed by the current DoD CIO, explicitly extending post-quantum crypto requirements and migration to the DIB, and including those in CMMC requirements — which we did a previous episode on. Then recently, in June of 2026, Executive Order 14412 accelerated the transition to post-quantum crypto by requiring a FAR rule that will require covered contractors — that’s you — to meet applicable post-quantum-crypto-enabled FIPS requirements by the end of 2030. We haven’t seen this rule, but it’s got a congressional mandate, it’s got an executive order behind it, so we’re going to see it probably pretty soon. Probably not the end of this year, but Q1 of next year, first half of next year — that’s 2027. They’ve got to get through the rulemaking process, and then they’ve got to have those requirements in contracts, ready for everybody to have, before the end of 2030. So it’s not a lot of time, as far as rulemaking goes. This is 100% going to affect defense contractors. The DoD CIO says it’s going to be included in CMMC, so maybe that’s going to be part of the review. I don’t know how that reduces cost and burden, but we’ll have to see how they exploit it. What do you think, man? This is a fifth completely separate statutory requirement that’s going to get flowed through rulemaking onto defense contractors.

Jason: I just — again, all signs point to Rev 3. FIPS validated — or the encryption requirement in Rev 3 — is a what? An ODP. Which means it is set by the issuing agency, that they define. So those ODPs were pulled too, right? Didn’t they pull the guidance on the ODPs they issue?

Jacob: Yeah, they removed it. I wonder why. To harmonize, to line things up.

Jason: Look, man, I think it would be wonderful if they came out and said, “We cut all the red tape and the burden, here’s your Rev 3 baseline, congratulations” — I hope it’s got post-quantum crypto requirements. I’ll translate into DoD-ese: “red tape and burden” means the assessments associated with it. There’s going to be some validation, but that’s not the way to get it — “let’s divert your attention to all this extra, high, flashy security that shows up in here.” I’m telling you.

Jacob: Well, there you go. We haven’t done a rulemaking update in quite a while. It is just after Labor Day, so we’re heading into peak rulemaking fun season. Between Labor Day and the holidays, essentially between now and the end of the year, you’ve got at least two things that are probably going to come out and affect defense contractors. Between Labor Day of 2026 and the end of 2030, there’s probably half a dozen things that will absolutely affect defense contractors. Will they be perfectly harmonized in such a way that you only have to pay attention to one thing at all? Probably not. But if you like and subscribe here, you only have to pay attention to a single YouTube channel to get all your information about rulemaking.

Jason: That is true. Hey, I just thought of that one.

Jacob: All right, so like and subscribe, and we’ll see you next week.

Jason: See you next week, folks.

[End of recording]

Contact

Speak With Our Team

Scroll to Top