Opportunity

Federal Register #9000AO34

Regulatory agenda for FAR rulemaking on cyber threat reporting, organizational conflicts of interest, and supply chain software security

Buyer

Department of Defense/General Services Administration/National Aeronautics and Space Administration (FAR)

Posted

August 14, 2026

Identifier

9000AO34

This regulatory agenda outlines upcoming Federal Acquisition Regulation (FAR) rulemaking actions affecting federal procurement processes: - Government buyers involved: - Office of Federal Procurement Policy (OFPP) within the Office of Management and Budget (OMB) - Department of Defense (DoD) - General Services Administration (GSA) - National Aeronautics and Space Administration (NASA) - No OEMs or vendors are named; the agenda is focused on regulatory changes, not product or service procurement. - Key rulemaking actions: - FAR Case 2021017: Will require certain contractors to report cyber incidents and facilitate information sharing between the Government and providers, based on recommendations from OMB and the Department of Homeland Security under Executive Order 14028. - FAR Case 2023006: Will update guidance and clauses to prevent organizational conflicts of interest in federal acquisition, requiring contractors to disclose relevant information and adhere to professional standards. - FAR Case 2023002: Addressed supply chain software security but was withdrawn following updated OMB direction. - No products, part numbers, or quantities are requested; the agenda is informational and regulatory in nature. - Notable requirements: - Enhanced cyber threat reporting obligations for contractors - Stricter organizational conflict of interest disclosures - Supply chain software security rule withdrawn per new guidance - The agenda impacts acquisition procedures and contractor compliance, but does not involve direct procurement.

Description

This rule authorizes agencies to increase sharing of information about cyber threats and incidents between the Government and certain providers. It requires certain contractors to report cyber incidents to the Federal Government to facilitate effective incident response and remediation. Offerors must represent that they have submitted all security incident reports accurately and completely. The rule is issued pursuant to recommendations from the Office of Management and Budget and the Department of Homeland Security under Executive Order 14028 titled Improving the Nation's Cybersecurity.

View original listing