BLOG POST

Morgan Lewis Government Contractor Guidebook

YOUR GUIDE TO THE ISSUES THAT MATTER TO GOVERNMENT CONTRACTORS

Cybersecurity Rules, GSA Fraud Referrals, and the Army’s Janus Program

Recent government contracting developments include a potential milestone for governmentwide contractor cyber incident reporting requirements, the General Services Administration’s (GSA’s) identification of more than $13 billion in suspected procurement fraud, and the Army’s selection of contractors and installations for its Janus nuclear microreactor program.

FAR Council Signals Near-Term Final Rule on Contractor Cyber Incident Reporting

The Office of Federal Procurement Policy, US Department of Defense, GSA, and NASA recently published their latest regulatory agenda, placing FAR Case 2021-017, Cyber Threat and Incident Reporting and Information Sharing, in the final rule stage with a target publication date of September 2026.

According to the agenda, the rule is intended to require certain federal contractors to report cyber incidents and offerors to represent that previously submitted incident reports are current, accurate, and complete. Although the September date is an estimate and the final text has not yet been published, the agenda signals that the governmentwide rulemaking is approaching a significant milestone after several years of development.

The proposed rule contemplated substantial new compliance obligations, including an initial incident report within eight hours, updates every 72 hours, preservation of affected systems and data, software bills of materials, cooperation with government investigations, and flowdown requirements. It also proposed coverage extending to contracts involving information and communications technology, including certain commercial products and commercially available off-the-shelf items.

The final rule may differ from those proposals, making the forthcoming text particularly important for contractors to review. In the meantime, the rulemaking aligns with civilian and defense agencies’ continued emphasis on cybersecurity compliance and cyber incident reporting.

Although Cybersecurity Maturity Model Certification (CMMC) Level 2 certifications have been paused, underlying cybersecurity obligations remain in place, including requirements applicable to contractors handling controlled unclassified information under provisions such as Defense Federal Acquisition Regulation Supplement 252.204-7012. Cybersecurity compliance also remains an area of False Claims Act (FCA) enforcement attention.

GSA Announces $13 Billion in Suspected Procurement Fraud Referrals

GSA recently announced that it has identified more than $13 billion in suspected fraud involving federal contractors since March. According to the agency, it used governmentwide procurement data, public reporting, and inspector general information to identify potential misconduct.

GSA said its review encompasses COVID-19 spending, Section 8(a) program integrity, contractor eligibility, bid rigging, cybersecurity false claims, bribery, and other procurement integrity risks. The agency is referring suspected matters to inspectors general and the US Department of Justice. GSA did not identify the contractors or contracts involved or provide details regarding the number of investigations included in the reported total.

The announcement reflects a broader shift toward centralized, data-driven contractor oversight. Independent reporting suggests that some matters included in the $13 billion figure may predate the current initiative, meaning the total should not be viewed as a determination of liability, actual government losses, or completed recoveries.

Nevertheless, the announcement signals increased use of government data and analytical tools to identify potential fraud. Contractors should anticipate continued scrutiny of eligibility representations, ownership structures, pricing and invoicing practices, subcontracting arrangements, cybersecurity certifications, and performance reporting.

Army Launches Janus Microreactor Program at Five Installations

The Army recently announced agreements worth up to a combined $2.2 billion with five companies to develop and operate nuclear microreactors at five Army installations under the Janus Program.

The projects will use Other Transactions Authority and milestone-based payments, with contractors owning, building, and operating the reactors while the Army oversees safety, security, and mission requirements. The five projects pair contractors with installations in North Carolina, Kentucky, Texas, Georgia, and New York.

The program is intended to provide dependable power for critical missions when the commercial grid is disrupted. The Army hopes the initiative will support deployment of more than 20 reactors across military installations and is targeting September 30, 2028, for the first operational Army-regulated reactor.

Beyond opportunities for reactor developers, the program may create work for contractors supporting site preparation, construction, cybersecurity, physical security, fuel logistics, permitting, environmental review, and long-term operations.

Because the program relies on milestone-based payments and significant private investment, participants should closely consider project governance, financing arrangements, risk allocation, data rights, and performance requirements at the outset.

Looking Ahead

These latest developments illustrate two parallel trends for companies doing business with the federal government: (1) increasingly sophisticated oversight of contractor cybersecurity and potential fraud and (2) continued use of nontraditional acquisition and financing structures to advance national security priorities. Contractors should monitor the forthcoming cyber incident reporting rule and evolving data-driven enforcement efforts while companies in the nuclear energy and related sectors assess potential opportunities arising from the Army’s broader push for energy resilience.