Recent developments in government contracting highlight significant changes affecting cybersecurity compliance, defense industry consolidation, contract disputes, and federal grant conditions. The latest updates include the Department of War’s decision to delay implementation of the next phase of the Cybersecurity Maturity Model Certification program, continued Department of Justice scrutiny of mergers in the defense industrial base, an Armed Services Board of Contract Appeals ruling on the public availability of Board decisions, and a federal court injunction blocking enforcement of certain DEI-related grant conditions.
DOW Delays CMMC Phase II and Pauses Future Certification Rollout
As discussed in our recent LawFlash, the Department of War has suspended implementation of CMMC Phase II and all subsequent phases, postponing the November 2026 rollout of third-party cybersecurity assessment requirements for covered contractors. The department also established a task force to conduct a 60-day review and issued a request for information seeking industry feedback on ways to reduce the cost and administrative burden associated with CMMC compliance.
The CMMC program was designed to implement increasingly rigorous cybersecurity requirements for defense contractors through a phased rollout. Phase II would have introduced a significant new obligation by requiring many contractors to obtain assessments from Certified Third-Party Assessment Organizations before becoming eligible for certain contract awards.
The department’s announcement pauses that transition, leaving the underlying cybersecurity requirements in place while, at least for now, continuing to rely on contractor self-assessments.
For contractors, the delay provides additional time before third-party certification requirements take effect, but it should not be viewed as a relaxation of cybersecurity expectations. The department appears focused on reassessing implementation and compliance costs rather than abandoning the broader CMMC framework. Contractors that process controlled unclassified information or support sensitive defense programs should continue preparing for eventual certification requirements while monitoring the department’s review process.
DOJ Challenge Ends Defense Supplier Acquisition
The Department of Justice recently announced that TransDigm Group abandoned its proposed $960 million acquisition of Stellant Systems after the department informed the parties it intended to challenge the transaction.
According to DOJ, both companies manufacture and repair defense and industrial components used by the US Navy and Air Force, and the proposed merger would have combined two important suppliers serving military customers. The department stated that it will continue to “rigorously investigate and challenge mergers that create monopolies and harm competition.”
For government contractors, the matter serves as a reminder that transactions affecting the defense industrial base remain subject to close antitrust scrutiny, particularly where they involve a limited number of qualified suppliers. It also reflects the government’s sustained focus on supply chain resilience as an important consideration in evaluating competition within national security–related markets.
ASBCA Holds Decisions Cannot Be Kept Confidential Through Settlement
The Armed Services Board of Contract Appeals recently held that it must publish its decision in a construction dispute involving a $524 million contract between KiewitPhelps and the US Army Corps of Engineers despite the parties’ settlement agreement providing that the opinion would not be published.
The Board reached this conclusion notwithstanding a confidentiality order, a joint request by the parties to suppress the decision, and the fact that nonpublication was a material component of the settlement.
The ruling reinforces the limited ability of contractors to shield ASBCA decisions from public disclosure, even where both parties favor confidentiality and have resolved the underlying dispute.
For contractors, the decision may impact strategic considerations when selecting a forum for resolving contract disputes. While the Boards of Contract Appeals have often been viewed as attractive alternatives to Article III courts, the inability to maintain confidentiality over significant Board decisions may alter that analysis in certain cases.
Federal Court Blocks Enforcement of Certain DEI-Related Grant Conditions
On July 9, the US District Court for the Northern District of California granted a preliminary injunction preventing the Department of Homeland Security, Department of the Interior, and DOJ from enforcing certain DEI- and immigration-related grant conditions against several California cities while litigation proceeds.
The challenged conditions arose from executive orders addressing DEI, immigration, and related antidiscrimination policies. DOJ has previously indicated that it intends to enforce certain grant certifications under the False Claims Act.
The court concluded that the government’s definitions of DEI- and immigration-related activities were sufficiently vague such that grant recipients could face FCA exposure based on reasonable but ultimately incorrect interpretations of ambiguous compliance requirements. On that basis, the court issued a preliminary injunction prohibiting enforcement of the challenged conditions against the plaintiffs.
While the injunction currently applies only to the plaintiff entities and their subrecipients, the decision represents one of the most significant judicial examinations to date of the administration’s efforts to implement broader DEI policy objectives through federal funding conditions.
For organizations receiving federal funds, the ruling highlights continued legal uncertainty surrounding these requirements and suggests that courts may closely scrutinize attempts to impose broad policy objectives through grant certifications where agencies have not clearly defined compliance expectations.
Looking Ahead
These latest developments demonstrate that regulatory priorities continue to evolve across cybersecurity, antitrust enforcement, contract dispute resolution, and federal grant administration.
Contractors should continue monitoring changes to CMMC implementation, anticipate ongoing scrutiny of defense-sector transactions, account for the public nature of ASBCA decisions when evaluating litigation strategy, and closely follow litigation affecting evolving grant conditions and compliance obligations.