FAR & DFARS: Procurement Power
All Episodes
Federal Cyber Rules Are Splitting in Two

Federal Cyber Rules Are Splitting in Two

0:00|0:00

This episode breaks down the latest federal cybersecurity rule changes for contractors, from the shift to NIST SP 800-171 Revision 3 in civilian contracts to CMMC Level 2’s continued use of Revision 2 in defense work. It also covers the end of basic assessments, new breach reporting rules, key subcontractor flowdown issues, and the new form agencies must use to define CUI scope before demanding costly controls.

Show Notes


Chapter 1

The Rev 3 Collision and the End of Paper Compliance

Eric Marquette

If you sell a widget to NASA and the exact same widget to the Navy, you might assume your cybersecurity rulebook is, well, basically one single standard. But right now, you are legally staring down two completely contradictory rulebooks for the exact same laptop.

Paul Netopski

It is, uh, it is total regulatory whiplash. Firsthand testimony, not commentary here. On June twenty third, 2026, the FAR Council dropped their proposed overhaul for FAR Part 40. Under proposed clause 52.240 seven, any non federal system holding Controlled Unclassified Information must implement NIST SP 800 171 Revision 3. Period.

Eric Marquette

Okay, but the Pentagon is already doing CMMC Level 2.

Paul Netopski

Right! Under the Department of War's Class Deviation 2026 O0025, which took effect February first, defense acquisitions are explicitly tethered to Revision 2 under 32 CFR 170. So if you are a dual market supplier, you are governing the exact same enclave under Revision 2 and Revision 3 at the same time. The controls do not line up cleanly, the parameter requirements differ, and companies are caught in the crossfire.

Eric Marquette

Wait, so how does a small machine shop even bridge that?

Paul Netopski

They cannot, at least not without massive friction. And, and, and it gets sharper, because that same February class deviation quietly killed off the old paper game.

Eric Marquette

The old paper game?

Paul Netopski

DFARS 252.204 7019 is gone. Removed. And the replacement clause, DFARS 252.240 7997, completely deletes the term basic assessment. It does not exist anymore.

Eric Marquette

Hold on. Basic assessment was the self score you just uploaded to the supplier portal, right? You logged into SPRS, checked the boxes, entered a score of 110, and went back to work.

Paul Netopski

Exactly. Pure self attestation. Contractors treated their System Security Plan like an aspirational bucket list. 'We plan to have multi factor authentication on all remote access by next December, so let us just claim full credit today.' Well, the new clause only defines Medium and High assessments, both conducted by the government using NIST SP 800 171A procedures. Validation, not promises.

Eric Marquette

So if you put in a perfect 110 based on what you hoped to build...

Paul Netopski

The Department of Justice is actively pulling those SPRS records under the Civil Cyber Fraud Initiative. If your SSP says a control is implemented, but you cannot produce the continuous monitoring logs or access logs on day one of a review, that is no longer just a contracting dispute. That is a potential False Claims Act investigation.

Eric Marquette

That sounds terrifying for a business owner, but wait, wasn't there also a big change on breach reporting?

Paul Netopski

There was, and this part is actually welcome operational realism. The initial FAR proposal had an impossible eight hour notification window. FAR Part 40 thankfully harmonized it to seventy two hours across the board. Civilian incidents go to CISA, defense incidents go to DIBnet. But here is the critical provision tucked into DFARS Part 240: an explicit rule stating that a cyber incident that is reported by a contractor or subcontractor must not, by itself, be interpreted as evidence that the contractor failed to provide adequate security.

Eric Marquette

Wait, seriously? So reporting an incident is not an automatic confession of guilt?

Paul Netopski

Not on its own! The statutory text shields you from a contracting officer immediately terminating you for default just because an adversary got lucky against your perimeter. That is huge for encouraging real disclosure.

Chapter 2

The Flowdown Trap and the Standard Form XXX Shield

Eric Marquette

Now, let us talk about what happens down the chain, because if you are a subcontractor, say a heat treater or a bolt manufacturer, you are usually not dealing directly with the government. You are dealing with a tier one prime contractor dumping massive binders of clauses on your desk.

Paul Netopski

The flowdown epidemic. Prime contract managers have been practicing defensive over compliance for years. Instead of reviewing the purchase order to see if sensitive defense drawings are actually being shared, they just hit select all and push DFARS 252.204 7012 and CMMC Level 2 down to everyone.

Eric Marquette

Even if the vendor is literally stamping generic aluminum brackets?

Paul Netopski

Yes! I see machine shops quoted two hundred thousand dollars for dedicated sovereign cloud enclaves just to supply commercial bolts. Scope is being driven by the marking, not by the information. Someone upstream slaps a CUI banner on an email containing an off the shelf catalog part, and suddenly the machine shop is panicking about an upcoming third party audit.

Eric Marquette

Does the new FAR Part 40 rule give these suppliers any relief?

Paul Netopski

It actually offers two very solid technical carve outs. First, it explicitly excludes endpoints like laptops that connect via Virtual Desktop Infrastructure, provided the VDI is configured to prevent local storage, processing, or printing of CUI. The data stays in the secure virtual enclave; the laptop is just a glass window.

Eric Marquette

So you do not have to put the full NIST control stack onto every shop floor workstation.

Paul Netopski

Exactly. And second, it exempts general commercial communications networks that route traffic without inspecting the payload. That stops auditors from arguing that standard broadband links drag your entire network provider into scope.

Eric Marquette

And there is a new standardized document for this too, right? Something called Standard Form XXX?

Paul Netopski

Yes, SF XXX, which will get an official number once finalized. Under proposed FAR 52.240 six and seven, the requiring agency must fill out this form and attach it to the solicitation. It mandates that they explicitly identify what categories of CUI are involved, whether it lives in federal or non federal facilities, and whether enhanced NIST SP 800 172 controls apply.

Eric Marquette

So the government or the prime actually has to commit to what data is sensitive before awarding the job.

Paul Netopski

Precisely. It reverses the burden of proof. When a prime contractor hits you with a blanket CMMC Level 2 flowdown on a commercial task order, you do not just eat the cost. You push back and say, 'Show me Part C of the executed Standard Form XXX defining the CUI we will handle.' If they cannot produce it, they have no regulatory ground to demand a six figure security architecture. You manage the real risk, protect the data, and stop wasting capital on phantom scope.

Eric Marquette

Know the data, demand the form, and do not buy an enclave until you see it in writing. That is the play.