In recent years, the U.S. federal government has taken significant interest in the cybersecurity compliance of its contractor base. In 2025 alone, the U.S. Department of Justice’s (DOJ) Civil Cyber-Fraud Initiative recovered more than $50 million across nine False Claims Act (FCA) cybersecurity fraud settlements, and it has secured almost 20 settlements since its launch in October 2021. Because most defendants facing FCA liability for alleged cybersecurity noncompliance enter into pre-litigation settlements, the last court decision in a cybersecurity FCA case was in 2022. However, earlier this month, on September 2, 2026, in United States ex rel. Pannek v. Archer Daniels Midland Co., No. 23-cv-15145, 2026 WL 2593317 (N.D. Ill. Sept. 2, 2026), Judge Sunil R. Harjani of the U.S. District Court for the Northern District of Illinois granted a motion to dismiss on materiality grounds and offered additional guidance on what a plaintiff must allege to adequately state an FCA cybersecurity claim.
Continue Reading In a First, District Court Dismisses FCA Cybersecurity Complaint for Lack of Materiality
Jacob Harrison
Jacob Harrison helps his clients navigate both domestic and international legal challenges.
Jake advises U.S. government contractors on internal investigations and state and federal regulatory compliance. His compliance practice focuses on counseling clients operating at the intersection of government contracts and cybersecurity, including for cybersecurity compliance reviews, risk assessments, and data breaches.
In his international practice, Jake represents foreign and domestic clients in Foreign Sovereign Immunities Act and Anti-Terrorism Act litigation. He also has experience advising clients involved in cross-border commercial arbitration proceedings.
During law school, Jake served as an associate editor of the Emory Law Journal and interned at the Supreme Court of Georgia and the Georgia House Democratic Caucus. Before attending law school, Jake worked in politics and state government.
New ISOO Guidance Directs Federal Agencies to Provide More CUI Guidance to Contractors
On September 2, 2026, the National Archives and Records Administration (NARA), through its Information Security Oversight Office (ISOO), released two new Notices on the topic of Controlled Unclassified Information (CUI): ISOO Notices 2026-07 and 2026-08.
Continue Reading New ISOO Guidance Directs Federal Agencies to Provide More CUI Guidance to ContractorsDepartment of War Immediately Suspends CMMC Phase II Requirements, Launches 60-Day Reform Review
The Department of War (DoW) is immediately suspending Cybersecurity Maturity Model Certification (CMMC) Phase II requirements, which had been scheduled to take effect on November 10, 2026.
Continue Reading Department of War Immediately Suspends CMMC Phase II Requirements, Launches 60-Day Reform ReviewTime for a Change: FedRAMP Fundamentally Revamps Program With Consolidated Rules for 2026
On June 25, 2026, the Federal Risk & Authorization Management Program (FedRAMP) launched its Consolidated Rules for 2026, marking a significant turning point in how the U.S. government administers security authorizations of private sector cloud offerings. The Consolidated Rules apply to all variants of the FedRAMP ecosystem, including legacy “Rev5” authorization holders, as well as future certifications under the new 20x program. Importantly, the Rules are intended in part to transition Rev5 authorizations over to 20x, with the Rev5 authorization status expected to terminate by the end of 2028.
Continue Reading Time for a Change: FedRAMP Fundamentally Revamps Program With Consolidated Rules for 2026National Security Memorandum Aims to Accelerate Deployment of AI and Streamline Procurement Aligned to Administration Policies
On June 5, 2026, President Trump issued National Security Presidential Memorandum (NSPM) 11 (NSPM-11) to accelerate AI adoption by the U.S. military and intelligence agencies. It directs updated AI management, acquisition, and use policies and seeks to compel AI companies to comply with Trump administration policies. It calls for expanded training and enhanced security in collaboration with the private sector and orders the “termination for default or for convenience” of government contracts with AI companies that wish to limit how the government uses their products. NSPM-11 could also herald a major change in autonomous warfighting policy by directing the update of the Pentagon’s primary directive on autonomous weapon systems.
Continue Reading National Security Memorandum Aims to Accelerate Deployment of AI and Streamline Procurement Aligned to Administration PoliciesFedRAMP Solicits Public Comment on Overhaul to Incident Communications Procedures
Introduction
The Federal Risk and Authorization Management Program (FedRAMP) continues to advance its modernization agenda. On April 8, 2026, FedRAMP released RFC-0031, Updated Incident Communications Procedures for public comment. This RFC proposes replacing the current FedRAMP Incident Communications Procedures (ICP) with what FedRAMP calls “a clear set of reporting requirements … established using a modern rules-based format.”
Below is a summary of key changes proposed in RFC-0031.
Continue Reading FedRAMP Solicits Public Comment on Overhaul to Incident Communications ProceduresAI for Government: 7 Days for Contractor Comments on GSA Proposed Contract Clause for AI Systems
On March 6, 2026, the General Services Administration (GSA) issued a significant proposed contract clause, GSAR 552.239-7001, Basic Safeguarding of Artificial Intelligence Systems (“Clause”), for inclusion in GSA Schedule solicitations and contracts for AI capabilities. The proposed clause would impose substantial new requirements related to AI sources, intellectual property rights, data use, change management, and performance standards. The Clause would also take precedence over any other contract terms (including commercial licensing terms) related to AI, including a Seller’s terms of sale and service to which the Government had previously agreed. GSA requests comments by March 20, 2026.
An analysis of the proposed clause follows below.
Continue Reading AI for Government: 7 Days for Contractor Comments on GSA Proposed Contract Clause for AI SystemsDHS Announces Virtual Town Halls on CIRCIA Final Rule
On February 13, 2026, the U.S. Department of Homeland Security (DHS) announced upcoming virtual town hall meetings scheduled for March 2026 regarding the implementation of the Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA). The meetings will allow industry stakeholders to provide input to DHS to refine the “scope and burden” of the forthcoming CIRCIA final rule.
Continue Reading DHS Announces Virtual Town Halls on CIRCIA Final RuleFedRAMP Proposes Updates to Authorization Process—Six New RFCs Released for Public Comment
What is FedRAMP?
The Federal Risk and Authorization Management Program (FedRAMP) is a government-wide initiative established to standardize the security assessment, authorization, and continuous monitoring of cloud products and services used by federal agencies. FedRAMP’s primary objective is to ensure that cloud service providers (CSPs) implement robust security controls to protect federal information in cloud environments. By leveraging a consistent framework for security assessment and authorization, FedRAMP is intended to reduce duplication of effort, cost, and time for both agencies and vendors.
Continue Reading FedRAMP Proposes Updates to Authorization Process—Six New RFCs Released for Public CommentCMMC for AI? Defense Policy Law Imposes AI Security Framework and Requirements on Contractors
In an important first, the yearly defense policy law, the National Defense Authorization Act (NDAA) for Fiscal Year 2026, directs the Department of Defense (DoD) to develop and implement a framework addressing the cybersecurity and physical security of artificial intelligence and machine learning technologies (AI/ML) acquired by the Pentagon.
Continue Reading CMMC for AI? Defense Policy Law Imposes AI Security Framework and Requirements on Contractors