Cybersecurity Updates at Department of Defense

The Department of Defense is intensifying efforts to build a resilient cyber workforce and update cybersecurity standards in response to evolving threats, particularly those involving AI and quantum computing. Key initiatives include expanding apprenticeship programs and integrating quantum-resistant cryptography into CMMC requirements, signaling significant shifts in defense contracting and compliance.

Market Analysis

The DoD cybersecurity landscape in 2026 is shaped by workforce development programs, regulatory updates, and strategic capability expansions:

Frequently Asked Questions

What are the key dates and requirements for the DoD Cyber Registered Apprenticeship Program in 2026?

The Cyber RAP opened applications on July 6, 2026, with a closing date of July 17, 2026. It offers a 12-month paid apprenticeship with competency-based training and industry certifications, targeting entry-level candidates without degree requirements. Training begins in fall 2026, providing a pathway to permanent DoD civilian cybersecurity roles.

How will the CIRCIA final rule affect cybersecurity reporting for defense contractors?

Starting September 2026, contractors in 16 critical infrastructure sectors must report significant cyber incidents within 72 hours and ransomware payments within 24 hours. This mandatory reporting replaces previous voluntary guidelines and requires contractors to update incident response and reporting processes to maintain compliance and contract eligibility.

What changes are expected in the Cybersecurity Maturity Model Certification (CMMC) related to Post-Quantum Cryptography?

The DoD's PQC Strategy requires integrating quantum-resistant algorithms into CMMC requirements by 2030, with full implementation by 2031. Contractors should begin evaluating their cryptographic systems and plan upgrades to meet these standards, as non-compliance could affect contract awards and renewals.

How might the creation of a dedicated DoD Cyber Force impact contracting opportunities?

The establishment of a Cyber Force will likely increase demand for specialized cyber training programs, advanced cyber defense technologies, and workforce sustainment services. Contractors should monitor acquisition forecasts for new solicitations aligned with cyber warfare capabilities and personnel development.

What should contractors know about updates to DFARS clauses related to cybersecurity?

DFARS clauses are being updated to align with new CMMC requirements and federal cybersecurity standards, including incident reporting and PQC integration. Contractors must proactively adjust security practices and compliance programs to meet these evolving requirements to remain eligible for DoD contracts.

Recent Signals

Air Force Addresses Cybersecurity Lockouts

Federal News

Air Force Addresses Cybersecurity Lockouts

🔒 Cybersecurity 🌐 Digital Infrastructure 🛡️ Defense & Military 💻 Information Technology

The U.S. Air Force is currently managing a widespread cybersecurity incident involving network lockouts affecting tens of thousands of devices across multiple bases and offices, including locations in Colorado, South Carolina, and Virginia. Triggered by the Department of the Air Force's Cyber Hygiene Initiative, these lockouts stem from software update compliance and anti-malware quarantine measures that have caused significant operational disruptions and system instability. The scale and persistence of this event have created urgent demand for specialized cybersecurity contractors and IT support services to assist in patch management, network restoration, and ongoing system stabilization efforts.

  • The Department of the Air Force and U.S. Air Force require contractors with expertise in cybersecurity patch management, network operations, and IT support to mitigate the impact of quarantine-induced lockouts.
  • Procurement professionals should anticipate increased contracting opportunities focused on cybersecurity solutions and system performance optimization at key Air Force locations such as Peterson (Colorado), Shaw (South Carolina), and Arlington (Virginia).
  • This situation underscores the critical importance of robust cyber hygiene programs balanced with operational continuity, highlighting a market need for innovative cybersecurity tools and responsive support services.
  • Contractors should evaluate capabilities to provide rapid incident response, endpoint security management, and scalable IT support to meet evolving Air Force requirements.

Federal News

DoD Closes Cyber Apprenticeship Applications Early

🔒 Cybersecurity 🛡️ Defense & Military

The Department of Defense (DoD) closed the application window early for its Cyber Registered Apprenticeship Program after receiving over 15,000 applications, demonstrating strong demand for federal cyber workforce development. This 12-month apprenticeship targets entry-level cyber roles such as defense analysts, infrastructure support specialists, and incident responders. The DoD plans to announce additional apprenticeship opportunities soon, continuing its emphasis on skill-based hiring to address cyber vacancies and expand the federal cyber talent pipeline.

  • The early closure signals high interest and competition for DoD cyber apprenticeship positions, indicating a robust market for cyber workforce training providers and contractors.
  • Procurement professionals should anticipate upcoming solicitations or contract opportunities related to cyber apprenticeship program expansion and associated training services.
  • Contractors specializing in cyber workforce development, training platforms, and apprenticeship program management may find increased demand as the DoD scales these initiatives.
  • This initiative reflects a strategic shift toward skill-based hiring in federal cyber roles, impacting future recruitment and contracting strategies within the cybersecurity domain.

Federal News

DoD Expands Cybersecurity and IoT Security Investments

🔒 Cybersecurity 🤖 Artificial Intelligence ☁️ Cloud Services 🛡️ Defense & Military 💻 Information Technology

The Department of Defense and related federal agencies are significantly increasing investments in cybersecurity and Internet of Things (IoT) security solutions to address rising cyber threats and protect critical infrastructure. The U.S. Military Cybersecurity market is projected to more than double from $16.5 billion in 2025 to $34.5 billion by 2035, driven by modernization efforts including zero-trust architectures, AI-enabled threat detection, and cloud security enhancements. Concurrently, the U.S. IoT Security Solutions market is expected to reach nearly $39 billion by 2030, fueled by 5G adoption and regulatory momentum. These developments highlight expanding procurement opportunities for defense contractors and cybersecurity vendors specializing in cloud-native security platforms, managed services, device identity, and compliance solutions.

  • Key agencies involved: U.S. Department of Defense (DoD), Cybersecurity and Infrastructure Security Agency (CISA), Federal Communications Commission (FCC), and National Institute of Standards and Technology (NIST) are central to driving requirements and standards.
  • Prime contractors: Lockheed Martin, Northrop Grumman, General Dynamics, Leidos, and Booz Allen Hamilton are actively expanding cybersecurity capabilities to meet evolving defense needs.
  • Market implications: Procurement professionals should anticipate increased demand for advanced cybersecurity solutions aligned with zero-trust and AI-enabled threat detection frameworks, as well as IoT security technologies supporting critical infrastructure protection.
  • Geographic focus: Regional defense hubs in Washington, D.C., Virginia, Texas, and California are focal points for modernization programs and contracting activity.
  • Actionable insight: Companies specializing in cloud security, managed cybersecurity services, and IoT device identity management should evaluate opportunities to engage with federal agencies and prime contractors as these markets grow rapidly through 2030 and beyond.

Federal News

SBA Supports Easing DoD Cybersecurity Rules

🔒 Cybersecurity 🛡️ Defense & Military

The Small Business Administration (SBA) Administrator Kelly Loeffler has publicly supported suspending certain cybersecurity assessment requirements for small defense contractors, aiming to reduce compliance burdens while maintaining national security standards. The Department of Defense (DoD) estimates that this regulatory easing could save over 38,000 small contractors nearly $6 billion annually. This initiative seeks to preserve innovation and sustain small business participation in the defense supply chain amid ongoing cybersecurity risks.

  • Why this matters: Procurement professionals should anticipate potential changes in cybersecurity compliance requirements for small defense contractors, which may affect contract eligibility and risk management.
  • Small businesses in the defense sector may benefit from reduced administrative costs, potentially increasing their competitiveness in DoD contracting opportunities.
  • Contracting officers and acquisition teams should evaluate how these changes impact cybersecurity risk assessments and contractor vetting processes.
  • Industry stakeholders should consider adjusting compliance strategies and support services to align with evolving DoD and SBA policies on cybersecurity for small contractors.

Federal News

UWM Advances Toward DoD Cybersecurity Certification

🔒 Cybersecurity 🛡️ Defense & Military 💻 Information Technology

The University of Wisconsin-Milwaukee (UWM) has achieved Level 1 Cybersecurity Maturity Model Certification (CMMC) and is actively progressing toward Level 2 certification by November 2026. This advancement enables UWM to qualify for more advanced Department of Defense (DoD) research projects and federal funding opportunities, fostering stronger collaborations with defense-related industries in southeastern Wisconsin. This development supports regional economic growth and innovation by expanding access to DoD contracts and research partnerships.

  • Why this matters: UWM's progress toward Level 2 CMMC certification opens new avenues for federal research funding and DoD contract eligibility, increasing opportunities for academic and industry partnerships.
  • Defense contractors and suppliers in Wisconsin should consider engaging with UWM to leverage emerging research collaborations enabled by enhanced cybersecurity compliance.
  • Procurement professionals should note the growing importance of CMMC certification for research institutions seeking DoD contracts, highlighting cybersecurity as a critical compliance factor.
  • Organizations aiming to participate in DoD research projects can benefit from aligning with certified academic partners like UWM to meet evolving cybersecurity requirements.
Department of War Pauses CMMC Level 2 Assessments

Federal News

Department of War Pauses CMMC Level 2 Assessments

🔒 Cybersecurity 🛡️ Defense & Military

The Department of War (DoW) has officially paused the Cybersecurity Maturity Model Certification (CMMC) Phase II third-party assessment requirement for Level 2 defense contractors, initiating a 60-day review of the validation program. This pause addresses the shortage of accredited assessors and aims to reassess the assessment framework to reduce burdens on small and medium businesses (SMBs) while maintaining all other cybersecurity requirements and self-assessments. Despite the pause, cybersecurity obligations remain in effect, and contractors are advised to strengthen governance frameworks, especially around AI and automated workflows accessing Controlled Unclassified Information (CUI), to ensure ongoing compliance and readiness for future verification processes.

  • Why this matters: The pause creates a temporary compliance relief window but signals potential revisions to the CMMC validation process that could impact future contract eligibility and cybersecurity requirements for Defense Industrial Base (DIB) contractors.
  • Procurement professionals should anticipate updates from the DoW and Cybersecurity Maturity Model Certification Accreditation Body (CyberAB) regarding revised assessment protocols and timelines.
  • Contractors, particularly SMBs, should use this period to enhance internal cybersecurity governance, focusing on unified controls for human and AI data access to mitigate compliance risks.
  • This development underscores the importance of maintaining robust cybersecurity programs despite assessment pauses to meet evolving DoW and DoD procurement standards.
DoD Launches Cyber Apprenticeship Program

Federal News

DoD Launches Cyber Apprenticeship Program

🔒 Cybersecurity 📋 Contracting Vehicles 🛡️ Defense & Military 💻 Information Technology

The Department of Defense has launched a 12-month paid Cyber Registered Apprenticeship Program (Cyber RAP) aimed at addressing critical cybersecurity workforce shortages by recruiting and training entry-level talent without requiring traditional degrees or prior experience. Applications opened on July 6, 2026, and close on July 17, 2026, with training scheduled to begin in fall 2026. This pilot program offers competency-based training, industry certifications, and an annual salary of $22,584, providing a pathway into permanent civilian cybersecurity roles within the DoD. The initiative represents a strategic shift toward skills-based hiring to rapidly build a capable cyber workforce supporting defense missions.

  • Why this matters: Procurement professionals should note the opening of this new apprenticeship opportunity that may influence future cybersecurity staffing and contracting needs within the DoD.
  • The program's focus on skills-based hiring without degree requirements signals evolving workforce development strategies that contractors and service providers can align with.
  • Organizations offering cybersecurity training, certification, and workforce development services may find partnership or subcontracting opportunities.
  • The July 17, 2026 application deadline is a critical milestone for interested candidates and agencies planning to integrate apprentices into their cyber teams starting fall 2026.

Federal News

DoD Advances Space-Based Solar Power Procurement

☁️ Cloud Services 🌐 Digital Infrastructure 🏛️ Physical Infrastructure 🛡️ Defense & Military 💻 Information Technology

The U.S. Department of Defense, led by the Air Force and Space Force, is actively advancing procurement and development of space-based solar power technologies to support military operations in contested and logistically challenging environments. Key contracts include a year-long study awarded to Overview Energy in May 2026 and Small Business Innovation Research grants to Star Catcher Industries in 2025. Additionally, a $40 million contract was awarded to Pulse for laser-based remote power systems supporting the Space Force. These efforts involve collaboration with Silicon Valley companies such as Meta and startups like Star Catcher Industries, reflecting growing public-private partnerships to accelerate innovation in power beaming satellites. Upcoming international defense events like NATO 2026 and the Farnborough Airshow are expected to further highlight these technologies.

  • Procurement professionals should note the increasing availability of contracts and grants focused on space-based energy solutions, including early-stage studies and technology development awards.
  • Industry stakeholders can leverage partnerships with established primes like Overview Energy and emerging startups to position for future solicitations.
  • The involvement of venture capital and tech giants indicates a competitive and innovative market landscape for space solar power systems.
  • Organizations should prepare for additional procurement opportunities as the DoD iterates on ground testing successes and moves toward operational deployment.
DoD Pauses CMMC Phase 2 Enforcement

Federal News

DoD Pauses CMMC Phase 2 Enforcement

🔒 Cybersecurity Regulatory Compliance 🛡️ Defense & Military 💻 Information Technology

The U.S. Department of Defense (DoD) has suspended enforcement of Phase 2 requirements under the Cybersecurity Maturity Model Certification (CMMC) 2.0 program, originally scheduled for November 10, 2026. This pause halts mandatory third-party cybersecurity assessments for defense contractors and initiates a 60-day review by a newly formed CMMC Reform Task Force, which will gather industry feedback and propose program adjustments. While Phase 1 self-assessments remain in effect, the freeze aims to reduce contractor attrition, lower compliance burdens on small and midsized businesses, and preserve innovation within the defense industrial base. Procurement professionals and contractors should note that cybersecurity compliance enforcement will continue through self-assessments, but third-party audits may be reinstated in a revised form. This development impacts over 120,000 small defense contractors and tribal enterprises, requiring adjustments in compliance strategies and contract risk management.

  • Why this matters: The pause creates uncertainty around cybersecurity certification enforcement, potentially increasing False Claims Act litigation risks for contractors due to unclear compliance expectations.
  • The review process offers an opportunity for industry stakeholders to influence future CMMC requirements and enforcement mechanisms.
  • Procurement teams should continue to require and verify Phase 1 self-assessments while preparing for possible reinstatement of third-party audits.
  • Small and midsized contractors may experience reduced immediate compliance costs but should remain vigilant for forthcoming changes affecting contract eligibility and cybersecurity obligations.
DOJ Settles Cybersecurity Violations with Huntsville Contractor

Federal News

DOJ Settles Cybersecurity Violations with Huntsville Contractor

🔒 Cybersecurity 🛡️ Defense & Military

The U.S. Department of Justice secured a settlement exceeding $500,000 with Huntsville-based defense contractor LOGZONE Inc. in 2026 for alleged violations of cybersecurity requirements under Department of the Navy contracts. The settlement resolves False Claims Act allegations related to non-compliance with NIST SP 800-171 standards, underscoring the government's intensified enforcement focus on cybersecurity compliance for contractors handling sensitive defense information. This case highlights the risks contractors face from discrepancies between self-assessed and government-assessed cybersecurity compliance scores, with enforcement coordinated by multiple federal agencies including the DOJ, Defense Contract Management Agency, and Naval Criminal Investigative Service.

  • Why this matters: Defense contractors must prioritize strict adherence to NIST SP 800-171 cybersecurity controls to avoid significant legal and financial penalties under the False Claims Act.
  • The enforcement action signals increased government scrutiny on cybersecurity compliance in Navy contracts, emphasizing the importance of accurate and verifiable self-assessments.
  • Procurement professionals should ensure contract requirements explicitly address cybersecurity standards and verification processes to mitigate risk.
  • Small and medium defense contractors should evaluate their cybersecurity programs urgently to align with federal requirements and reduce exposure to enforcement actions.

Explore Related Categories

More procurement intelligence by market category.