State & Local Event

Industry Advances Third-Party Risk Management

πŸ”’ Cybersecurity πŸ’» Information Technology

The 2026 Q2 Symposium highlights the growing emphasis on modernizing Third-Party Risk Management (TPRM) frameworks to effectively reduce organizational vulnerabilities within complex vendor and supply chain ecosystems, including emerging risks from AI and Operational Technology (OT) environments. This virtual event provides procurement professionals and contractors with actionable strategies to enhance governance, increase risk visibility, and implement mitigation techniques that address multi-tier supplier risks without vendor influence.

  • Procurement teams should prioritize integrating advanced TPRM practices to manage risks beyond direct vendors, encompassing partners’ extended networks.
  • Organizations can leverage insights from the symposium to strengthen contractual requirements and oversight mechanisms related to third-party cybersecurity and operational risks.
  • This focus on TPRM modernization signals increased demand for solutions and services that provide comprehensive risk assessment, continuous monitoring, and mitigation capabilities across complex supply chains.
  • Contractors offering expertise in AI and OT risk management may find new opportunities as agencies seek to address vulnerabilities in these emerging technology domains.

Realizing your org is only as secure as your least secure partner - or partners’ partners - leaves teams struggling to address the root risks effectively.

— Ryan Leirvik

Locations

Sources

Federal News

Anthropic Advances AI Cryptanalysis Capabilities

πŸ”’ Cybersecurity πŸ€– Artificial Intelligence πŸ›‘οΈ Defense & Military πŸ’» Information Technology

Anthropic's AI model Claude Mythos Preview has successfully identified a critical structural flaw in the post-quantum cryptographic candidate HAWK within 60 hours, a problem that human experts had been unable to solve over two years. Additionally, the AI developed a novel attack method that accelerates cryptanalysis of a reduced-round AES variant by 200 to 800 times. These breakthroughs demonstrate the transformative potential of AI-assisted cryptanalysis for cryptographic standards evaluation and cybersecurity resilience. Government agencies and contractors involved in cryptographic research, cybersecurity, and AI integration should consider the implications for security planning, standards development, and procurement strategies.

  • Why this matters: AI-driven cryptanalysis can rapidly uncover vulnerabilities in cryptographic algorithms, impacting the evaluation and adoption of post-quantum cryptographic standards.
  • Agencies like NIST may need to reassess cryptographic candidate resilience and accelerate AI integration in security research and testing.
  • Contractors specializing in cybersecurity and cryptographic solutions should evaluate AI capabilities to enhance threat detection and algorithm validation.
  • This development signals increased demand for AI-powered security tools and expertise in government procurement related to cryptography and cybersecurity.

Sources

Federal News

OMB Highlights AI Cybersecurity Compliance Challenges

πŸ”’ Cybersecurity πŸ€– Artificial Intelligence πŸ’» Information Technology 🚨 Public Safety

The Office of Management and Budget (OMB) has identified that existing compliance frameworks continue to slow the deployment of AI-powered cybersecurity defenses across federal agencies, despite the increasing urgency driven by rapid cyber threats and AI-enabled attacks. Recent U.S. Executive Orders further emphasize the need for secure AI and quantum computing deployment frameworks, introducing new governance tools such as AI risk registers and updated cybersecurity standards. These developments signal heightened regulatory expectations and expanded collaboration opportunities for contractors specializing in AI risk management and cybersecurity solutions.

  • Federal agencies face ongoing compliance-related delays in adopting AI cybersecurity technologies, underscoring the need for streamlined procurement and risk management processes.
  • Contractors with expertise in AI governance, risk assessment, and cybersecurity frameworks aligned with NIST and Executive Order mandates are positioned to support federal modernization efforts.
  • Procurement professionals should anticipate evolving requirements that integrate AI-specific security controls and quantum computing considerations into cybersecurity acquisitions.
  • Organizations can leverage these policy shifts to develop offerings that address both foundational cybersecurity practices and emerging AI risk management needs, particularly in key federal hubs such as Washington, D.C., California, Texas, and Virginia.

Sources

Federal News

White House Proposes Federal AI Regulation Framework

πŸ€– Artificial Intelligence πŸ”’ Cybersecurity πŸ’» Information Technology

The White House has introduced a National Policy Framework for Artificial Intelligence aimed at establishing a unified federal regulatory standard to replace the current fragmented state-level AI laws. This initiative, supported by Executive Order 14409, prioritizes enhanced cybersecurity measures for advanced AI systems and seeks to sustain U.S. leadership in AI technology. However, formal adoption depends on Congressional legislation, which remains pending. The framework also highlights unresolved challenges around regulating open-source AI, signaling ongoing complexities for developers and procurement officials.

  • Why this matters: Federal agencies and contractors should anticipate a shift toward standardized AI compliance requirements once legislation is enacted, impacting procurement specifications and contract terms.
  • The emphasis on cybersecurity for AI systems indicates increased demand for secure AI development, integration, and monitoring services.
  • Organizations involved in AI technology development or deployment should prepare for potential federal mandates that could supersede state regulations, affecting product design and risk management.
  • Procurement professionals should track Congressional actions closely to align acquisition strategies with forthcoming federal AI policies and standards.

Sources

Federal News

VA Addresses FISMA Audit Deficiencies

πŸ”’ Cybersecurity βœ… Regulatory Compliance πŸ₯ Healthcare πŸ’» Information Technology

The Department of Veterans Affairs (VA) failed its fiscal year 2025 Federal Information Security Modernization Act (FISMA) audit, with multiple cybersecurity deficiencies identified including vulnerability management and identity controls. Despite the audit findings and 19 formal recommendations from the independent auditor CliftonLarsonAllen LLP, the VA disputes the report's conclusions, citing ongoing cybersecurity improvements and current measures already implemented. The agency has outlined ambitious cybersecurity goals for fiscal years 2026-2029, signaling continued investment in strengthening its IT security posture and compliance efforts.

  • Why this matters: Procurement professionals should anticipate increased VA demand for cybersecurity solutions and services aimed at addressing FISMA compliance gaps, particularly in vulnerability management and identity control systems.
  • The VA's disagreement with the audit findings suggests potential shifts in procurement priorities as the agency balances remediation efforts with existing cybersecurity initiatives.
  • Contractors specializing in federal cybersecurity frameworks and compliance should evaluate opportunities to support the VA's multi-year cybersecurity enhancement plans.
  • Organizations should consider the implications of the VA's cybersecurity posture on contract requirements, risk assessments, and future IT acquisitions.

Sources

Federal News

AI Companies Intensify Washington Lobbying

βœ… Regulatory Compliance πŸ”’ Cybersecurity πŸ“œ Policy πŸ’» Information Technology πŸ›‘οΈ Defense & Military

AI industry leaders including OpenAI, Anthropic, and Meta have significantly increased lobbying expenditures in Washington, D.C., spending a combined $109 million in 2025 and $41 million in the first half of 2026. Their efforts focus on shaping federal AI safety standards, cybersecurity policies, export controls, and defense procurement regulations. OpenAI and Anthropic are actively engaging with the Pentagon and Congress to influence AI-related defense contracts and regulatory frameworks, while advocating for federal preemption over state-level AI regulations. This surge in lobbying activity signals a strategic push by AI companies to secure favorable government investment and contract opportunities amid evolving national security and technology policy landscapes.

  • Why this matters: Procurement professionals should anticipate increased federal investment and contracting opportunities in AI technologies, influenced by industry lobbying on defense and cybersecurity requirements.
  • Agencies may see evolving AI procurement policies emphasizing safety, supply chain risk management, and export controls, affecting vendor eligibility and contract terms.
  • Contractors should evaluate how federal preemption efforts might standardize AI compliance requirements across states, impacting proposal strategies.
  • Organizations involved in AI infrastructure and defense applications can leverage this environment to align offerings with emerging government priorities and regulatory expectations.

Sources

Federal News

Department of War Pauses CMMC Phase 2 Implementation

πŸ”’ Cybersecurity πŸ›‘οΈ Defense & Military

The Department of War (DOW) has officially suspended Phase 2 of the Cybersecurity Maturity Model Certification (CMMC) program, delaying the mandatory third-party cybersecurity audits for defense contractors that were scheduled to begin in November 2026. This pause initiates a 60-day review and public comment period aimed at reassessing the program's structure and its compliance impact, especially on small and medium-sized businesses. Meanwhile, Phase 1 self-assessment requirements and existing cybersecurity standards remain in effect, allowing contractors to continue meeting baseline cybersecurity obligations without the immediate burden of third-party audits.

  • Why this matters: Defense contractors should adjust compliance planning to reflect the delayed enforcement of Phase 2 audits, avoiding premature expenditures on third-party certifications.
  • Small and medium-sized businesses in the defense supply chain may benefit from the extended timeline to prepare for future requirements.
  • Procurement professionals should update contract language and compliance monitoring to align with the current status of CMMC requirements.
  • Organizations can engage in the public feedback process to influence potential revisions to the CMMC program design.

Sources

Federal News

Healthcare Sector Strengthens AI Cybersecurity Governance

πŸ”’ Cybersecurity βœ… Regulatory Compliance πŸ₯ Healthcare πŸ’» Information Technology

Federal and healthcare industry leaders are emphasizing the urgent need for robust governance frameworks and enforceable cybersecurity standards to protect AI systems and patient data in healthcare. Dr. Leeda Rashid of the FDA Digital Health Center of Excellence advocates for comprehensive federal oversight covering the entire AI lifecycle, while experts from NIST and the Coalition for Healthcare AI highlight risk-based governance, vendor oversight, and integrated monitoring as critical to scaling AI adoption securely.

  • Healthcare procurement professionals should anticipate increased demand for cybersecurity and regulatory compliance solutions tailored to AI healthcare applications.
  • Agencies like FDA, NIST, and HHS are likely to develop or enforce standards that contractors must meet, creating opportunities for vendors specializing in AI risk management and governance tools.
  • Organizations involved in healthcare IT procurement should prioritize vendors with expertise in AI lifecycle security and ethical use frameworks.
  • This focus on governance indicates a growing market for services that ensure clinical safety, data integrity, and compliance with emerging federal cybersecurity mandates.

Sources

State & Local News

Los Angeles Installs Energy-Efficient AC Units

πŸ›οΈ Physical Infrastructure βœ… Regulatory Compliance πŸ—οΈ Construction & Infrastructure ⚑ Energy & Utilities

Los Angeles city officials have initiated the installation of 1,066 energy-efficient air conditioning units across public housing properties managed by the Housing Authority of the City of Los Angeles (HACLA) as part of the Heat Mitigation Home Improvement Program (HMHIP). This effort, announced on July 27, 2026, is supported by over $4 million in federal Community Project funding secured by Congresswoman Maxine Waters and involves collaboration with the Los Angeles Department of Water and Power (LADWP). The initiative aims to enhance heat resilience, reduce energy costs, and improve health outcomes for vulnerable residents in facilities such as Nickerson Gardens, Imperial Courts, Gonzaque Village, and Jordan Downs.

  • Procurement professionals should note the integration of federal funding with local agency partnerships, highlighting opportunities for contractors specializing in energy-efficient HVAC systems and public housing upgrades.
  • The program underscores growing municipal commitments to climate adaptation and environmental justice, signaling increased demand for sustainable building improvements.
  • Vendors with expertise in affordable, energy-efficient cooling solutions may find emerging opportunities in similar urban climate resilience projects.
  • Agencies and contractors should consider the importance of cross-agency coordination, as demonstrated by HACLA and LADWP collaboration, for successful implementation of large-scale housing improvement programs.

Sources

State & Local News

Maryland Advances FSK Bridge Rebuild

πŸ›οΈ Physical Infrastructure πŸ—οΈ Construction & Infrastructure

The State of Maryland, led by Governor Wes Moore and supported by key federal and state legislators, is advancing the Francis Scott Key Bridge rebuild project, a critical infrastructure initiative aimed at restoring a vital transportation corridor for regional and national commerce. The project, which began pre-construction activities in January 2025, is a collaborative effort involving the Maryland Transportation Authority and the U.S. Department of Transportation, emphasizing safety, efficiency, and cost-effectiveness.

  • The rebuild contract encompasses engineering, construction, and platform development, representing a significant infrastructure investment in Maryland.
  • Federal and state partnerships highlight the importance of coordinated funding and oversight, with involvement from congressional leaders including chairs of relevant Senate and House committees.
  • Procurement professionals should note ongoing opportunities related to construction and engineering services under this project, with potential for subcontracting and supply chain participation.
  • The project's progress signals continued federal infrastructure support, making it relevant for contractors specializing in large-scale bridge and transportation infrastructure projects in the Mid-Atlantic region.

Sources

State & Local News

Maryland Awards NourishMD Grants to Expand Food Access

πŸ’° Grants & Funding πŸ›οΈ Physical Infrastructure πŸ₯ Healthcare πŸ—οΈ Construction & Infrastructure

In July 2026, the State of Maryland awarded nearly $3.65 million in NourishMD grants to 44 organizations aimed at expanding fresh food access in food deserts across 18 counties. This program, supported by both state and federal funding, targets retail outlets with capital needs to improve availability of nutritious foods, prioritizing businesses that accept federal nutrition benefits. The initiative focuses on reducing food insecurity and strengthening local food economies, particularly in rural and underserved communities within Maryland.

  • The Maryland Department of Housing and Community Development (DHCD), Department of Agriculture, and Department of Health are key agencies administering the grants.
  • Procurement professionals should note the emphasis on supporting retail outlets that accept federal nutrition benefits, indicating opportunities for vendors aligned with federal nutrition programs.
  • Businesses and contractors serving rural and underserved Maryland communities may find increased demand for infrastructure and service improvements funded through these grants.
  • This initiative reflects a growing state-level focus on addressing food insecurity through targeted capital investments, signaling potential future procurement opportunities in public health and community development sectors.

Sources