All Articles
Compliance & Risk

Compliance & Risk Articles

Regulatory guidance, compliance frameworks, and risk mitigation.

1012 articles

Blog post hero image
Compliance & Risk

Interior Department finding momentum with modernization

The Department of Interior is executing a comprehensive modernization of its contracting and procurement infrastructure, deploying robotic process automation (RPA) and evaluating generative AI and blockchain technologies for acquisition workflows. Following an IG audit that identified $40 million in misclassified IT purchases across FY2022-2024, DOI is centralizing IT infrastructure and tightening FITARA compliance controls. Contractors serving DOI—particularly those in IT modernization, cloud services, and emerging tech—should anticipate stricter procurement classification reviews, updated technical requirements in upcoming solicitations, and potential consolidation of contract vehicles as the agency standardizes its technology stack.

Cabrillo Club·February 18, 2026
Blog post hero image
Compliance & Risk

FAA, DOD data silos were partly to blame for last year’s DCA crash

The NTSB's final report on the DCA midair collision reveals systemic data-sharing and safety management failures across FAA and DOD, with specific recommendations for improved data analysis and inter-agency information sharing. The findings highlight deficiencies in Army helicopter flight safety data monitoring and FAA's risk assessment processes, which may drive new data management and safety compliance requirements for defense contractors. Contractors supporting aviation operations, particularly those working with FAA and DOD on safety systems and data analytics, should anticipate enhanced oversight and potential new requirements for safety data collection and sharing protocols.

Cabrillo Club·February 18, 2026
Blog post hero image
Compliance & Risk

FAA, DOD data silos were partly to blame for last year’s DCA crash

The NTSB's final report on the DCA midair collision reveals systemic data-sharing and safety management failures across FAA and DOD, with specific recommendations for improved data analysis and inter-agency information sharing. The findings highlight deficiencies in Army helicopter flight safety data monitoring and FAA's risk assessment processes, which may drive new data management and safety compliance requirements for defense contractors. Contractors supporting aviation operations, particularly those working with FAA and DOD on safety systems and data analytics, should anticipate enhanced oversight and potential new requirements for safety data collection and sharing protocols.

Cabrillo Club·February 18, 2026
Blog post hero image
Compliance & Risk

FAA, DOD data silos were partly to blame for last year’s DCA crash

The NTSB's final report on the DCA midair collision identifies systemic failures in data sharing and safety management between FAA and DOD, with specific emphasis on incompatible safety reporting systems and inadequate risk assessment processes. The FAA's Aviation Safety Information Analysis and Sharing (ASIAS) program had zero integration with Army Safety Management systems, creating dangerous blind spots. Contractors supporting aviation safety systems, data analytics, and inter-agency information sharing should anticipate new compliance requirements for safety data collection, enhanced oversight protocols, and mandated cross-agency data integration standards—particularly those holding OASIS+, ASTRO, and GSA Schedule 70 vehicles supporting FAA and DOD aviation programs.

Cabrillo Club·February 18, 2026
Blog post hero image
Compliance & Risk

Australia prepares for next batch of ‘Ghost Bat’ warplane buddy drones

Australia's Royal Australian Air Force has ordered seven additional MQ-28A Ghost Bat collaborative combat aircraft from Boeing Defence Australia in a third tranche worth AUS$754 million (US$534 million). This brings the total fleet to 18 aircraft across three blocks, with plans for 10 operational units by 2028 as part of Australia's long-range deterrence strategy. The program demonstrates international defense collaboration and potential export opportunities for U.S. defense contractors working with allied nations on unmanned combat systems.

Cabrillo Club·February 17, 2026
Blog post hero image
Compliance & Risk

Australia prepares for next batch of ‘Ghost Bat’ warplane buddy drones

Australia's Royal Australian Air Force has ordered seven additional MQ-28A Ghost Bat collaborative combat aircraft from Boeing Defence Australia in a third tranche worth AUS$754 million (US$534 million). This brings the total fleet to 18 aircraft across three blocks, with plans for 10 operational units by 2028 as part of Australia's long-range deterrence strategy. The program demonstrates international defense collaboration and potential export opportunities for U.S. defense contractors working with allied nations on unmanned combat systems.

Cabrillo Club·February 17, 2026
Blog post hero image
Compliance & Risk

Australia prepares for next batch of ‘Ghost Bat’ warplane buddy drones

Australia's Royal Australian Air Force has contracted Boeing Defence Australia for seven additional MQ-28A Ghost Bat collaborative combat aircraft in a AUS$754 million (US$534 million) third tranche, bringing the total fleet to 18 units with 10 operational aircraft planned by 2028. This expansion signals accelerating international demand for unmanned collaborative combat systems and validates the CCA concept as a cornerstone of allied long-range deterrence strategies. U.S. defense contractors with capabilities in autonomous systems, AI-enabled mission planning, sensor fusion, and secure datalink technologies should immediately assess positioning for Foreign Military Sales (FMS) and Direct Commercial Sales (DCS) opportunities as allied nations replicate Australia's CCA integration model.

Cabrillo Club·February 17, 2026
Blog post hero image
Compliance & Risk

Federal Register: Federal Acquisition Regulation: Prohibition on Certain Semiconductor Products and Services

OFPP, DoD, GSA, and NASA (collectively referred to as the Federal Acquisition Regulatory Council, or FAR Council) are proposing to amend the Federal Acquisition Regulation (FAR) to partially implement a section of the James M. Inhofe National Defense Authorization Act for Fiscal Year 2023 which prohibits executive agencies from procuring or obtaining certain products and services that include covered semiconductor products or services effective December 23, 2027.

Cabrillo Club·February 17, 2026
Blog post hero image
Compliance & Risk

Federal Register: Federal Acquisition Regulation: Prohibition on Certain Semiconductor Products and Services

OFPP, DoD, GSA, and NASA (collectively referred to as the Federal Acquisition Regulatory Council, or FAR Council) are proposing to amend the Federal Acquisition Regulation (FAR) to partially implement a section of the James M. Inhofe National Defense Authorization Act for Fiscal Year 2023 which prohibits executive agencies from procuring or obtaining certain products and services that include covered semiconductor products or services effective December 23, 2027.

Cabrillo Club·February 17, 2026
Blog post hero image
Compliance & Risk

Federal Register: Federal Acquisition Regulation: Prohibition on Certain Semiconductor Products and Services

The FAR Council is proposing amendments to prohibit federal agencies from procuring products or services containing covered semiconductor products or services, effective December 23, 2027. This implements Section 5949 of the FY2023 NDAA and will fundamentally reshape supply chain compliance requirements across the entire federal contracting base. Contractors must immediately audit their semiconductor supply chains, identify covered products, and prepare mitigation strategies before the 2027 deadline. This is not optional—non-compliance will result in contract ineligibility across all executive agencies.

Cabrillo Club·February 17, 2026
Blog post hero image
Compliance & Risk

Federal Register: Posting of Informational Video: Cybersecurity Maturity Model Certification (CMMC) Program

The Office of the Department of Defense Chief Information Officer (DoD CIO) has released an informational video to provide the public with an overview of the proposed rule for DoD's updated Cybersecurity Maturity Model Certification (CMMC) Program, which was published in the Federal Register on December 26, 2023 for public comment. The proposed rule establishes requirements for a comprehensive and scalable assessment mechanism to ensure defense contractors and subcontractors have, as part of the CMMC Program, implemented required existing security requirements for Federal Contract Information and Controlled Unclassified Information (CUI) and adds new CUI security requirements for certain priority programs. This document announces that a video file containing an overview briefing of the CMMC proposed rule, presented by leadership and staff from the Office of the DoD Deputy CIO for Cybersecurity, was posted on the internet on February 14, 2024.

Cabrillo Club·February 17, 2026
Blog post hero image
Compliance & Risk

Federal Register: Posting of Informational Video: Cybersecurity Maturity Model Certification (CMMC) Program

The Office of the Department of Defense Chief Information Officer (DoD CIO) has released an informational video to provide the public with an overview of the proposed rule for DoD's updated Cybersecurity Maturity Model Certification (CMMC) Program, which was published in the Federal Register on December 26, 2023 for public comment. The proposed rule establishes requirements for a comprehensive and scalable assessment mechanism to ensure defense contractors and subcontractors have, as part of the CMMC Program, implemented required existing security requirements for Federal Contract Information and Controlled Unclassified Information (CUI) and adds new CUI security requirements for certain priority programs. This document announces that a video file containing an overview briefing of the CMMC proposed rule, presented by leadership and staff from the Office of the DoD Deputy CIO for Cybersecurity, was posted on the internet on February 14, 2024.

Cabrillo Club·February 17, 2026
Blog post hero image
Compliance & Risk

Federal Register: Posting of Informational Video: Cybersecurity Maturity Model Certification (CMMC) Program

The DoD Chief Information Officer has published an official informational video briefing on the CMMC 2.0 proposed rule, originally released for public comment on December 26, 2023. This video, presented by the Office of the Deputy CIO for Cybersecurity, provides authoritative guidance on the comprehensive assessment framework that will govern how defense contractors and subcontractors must implement security controls for Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). The proposed rule introduces a scalable, three-tiered certification model with new CUI security requirements for priority programs—signaling that CMMC enforcement is transitioning from 'proposed' to 'imminent operational reality.'

Cabrillo Club·February 17, 2026
Blog post hero image
Compliance & Risk

Federal Register: Cybersecurity Maturity Model Certification (CMMC) Program

With this final rule, DoD establishes the Cybersecurity Maturity Model Certification (CMMC) Program in order to verify contractors have implemented required security measures necessary to safeguard Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). The mechanisms discussed in this rule will allow the Department to confirm a defense contractor or subcontractor has implemented the security requirements for a specified CMMC level and is maintaining that status (meaning level and assessment type) across the contract period of performance. This rule will be updated as needed, using the appropriate rulemaking process, to address evolving cybersecurity standards, requirements, threats, and other relevant changes.

Cabrillo Club·February 17, 2026
Blog post hero image
Compliance & Risk

Federal Register: Cybersecurity Maturity Model Certification (CMMC) Program

With this final rule, DoD establishes the Cybersecurity Maturity Model Certification (CMMC) Program in order to verify contractors have implemented required security measures necessary to safeguard Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). The mechanisms discussed in this rule will allow the Department to confirm a defense contractor or subcontractor has implemented the security requirements for a specified CMMC level and is maintaining that status (meaning level and assessment type) across the contract period of performance. This rule will be updated as needed, using the appropriate rulemaking process, to address evolving cybersecurity standards, requirements, threats, and other relevant changes.

Cabrillo Club·February 17, 2026
Blog post hero image
Compliance & Risk

Federal Register: Cybersecurity Maturity Model Certification (CMMC) Program

The Department of Defense has published the final rule establishing the Cybersecurity Maturity Model Certification (CMMC) Program in the Federal Register, making cybersecurity certification a mandatory contract requirement for defense contractors handling Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). This rule operationalizes verification mechanisms that will require contractors to demonstrate—and maintain—specific CMMC levels throughout contract performance periods. Every defense contractor must immediately assess their current cybersecurity posture, determine required CMMC levels for existing and pipeline opportunities, and initiate certification pathways or risk disqualification from DoD solicitations.

Cabrillo Club·February 17, 2026
Blog post hero image
Compliance & Risk

Federal Register: National Industrial Security Program

This final rule removes the DoD's regulations on the National Industrial Security Program (NISP) regarding industrial security procedures and practices related to foreign ownership, control, or influence (FOCI) for U.S. Government activities. The interim final rule currently in effect is duplicative and obsolete. The Director of the National Archives and Records Administration's (NARA) Information Security Oversight Office (ISOO) is responsible for implementing and monitoring Executive Branch implementation of the NISP, and DoD's rule duplicates an amendment to the NARA rule on the same subject.

Cabrillo Club·February 17, 2026
Blog post hero image
Compliance & Risk

Federal Register: National Industrial Security Program

This final rule removes the DoD's regulations on the National Industrial Security Program (NISP) regarding industrial security procedures and practices related to foreign ownership, control, or influence (FOCI) for U.S. Government activities. The interim final rule currently in effect is duplicative and obsolete. The Director of the National Archives and Records Administration's (NARA) Information Security Oversight Office (ISOO) is responsible for implementing and monitoring Executive Branch implementation of the NISP, and DoD's rule duplicates an amendment to the NARA rule on the same subject.

Cabrillo Club·February 17, 2026
Blog post hero image
Compliance & Risk

Federal Register: National Industrial Security Program

The Department of Defense is removing its duplicative National Industrial Security Program (NISP) regulations governing Foreign Ownership, Control, or Influence (FOCI) procedures for cleared contractors. This final rule eliminates DoD's redundant oversight in favor of centralized administration by NARA's Information Security Oversight Office (ISOO), which already maintains authoritative NISP regulations. Cleared contractors operating under facility security clearances (FCLs) must now reference ISOO's 32 CFR Part 2004 as the sole regulatory authority for FOCI mitigation instruments, ownership reporting, and industrial security procedures. This consolidation does not change substantive FOCI requirements but eliminates regulatory duplication that has created compliance confusion.

Cabrillo Club·February 17, 2026
Blog post hero image
Compliance & Risk

Federal Register: National Industrial Security Program Operating Manual (NISPOM); Amendment

DoD is proposing amendments to the National Industrial Security Program Operating Manual (NISPOM) based on public comments received on a final rule published on December 21, 2020. The proposed amendments address implementation guidance and costs for the Security Executive Agent Directive (SEAD) 3, clarifications on procedures for the protection and reproduction of classified information, controlled unclassified information (CUI), National Interest Determination (NID) requirements for cleared contractors operating under a Special Security Agreement for Foreign Ownership, Control or Influence, and eligibility determinations for personnel security clearance processes and requirements.

Cabrillo Club·February 17, 2026
Blog post hero image
Compliance & Risk

Federal Register: National Industrial Security Program Operating Manual (NISPOM); Amendment

DoD is proposing amendments to the National Industrial Security Program Operating Manual (NISPOM) based on public comments received on a final rule published on December 21, 2020. The proposed amendments address implementation guidance and costs for the Security Executive Agent Directive (SEAD) 3, clarifications on procedures for the protection and reproduction of classified information, controlled unclassified information (CUI), National Interest Determination (NID) requirements for cleared contractors operating under a Special Security Agreement for Foreign Ownership, Control or Influence, and eligibility determinations for personnel security clearance processes and requirements.

Cabrillo Club·February 17, 2026
Blog post hero image
Compliance & Risk

Federal Register: National Industrial Security Program Operating Manual (NISPOM); Amendment

DoD has published proposed amendments to the National Industrial Security Program Operating Manual (NISPOM) addressing critical implementation gaps from the December 2020 final rule. These changes directly impact cleared contractors' handling of classified information, CUI protocols, Foreign Ownership Control or Influence (FOCI) mitigation under Special Security Agreements, and personnel security clearance eligibility determinations. Contractors holding Facility Clearances (FCLs) must prepare for revised compliance requirements across information security, FOCI mitigation, and personnel vetting processes. This is a HIGH severity event requiring immediate review by FSOs, Compliance Officers, and Capture leadership.

Cabrillo Club·February 17, 2026
War Room intelligence briefing hero image
Compliance & Risk

US Air Force needs 500 next-gen fighters, bombers to beat China, think tank says

The Mitchell Institute for Aerospace Studies recommends the U.S. Air Force procure at least 500 next-generation aircraft (300 F-47 fighters and 200 B-21 bombers) to counter China, significantly exceeding current plans of 185 F-47s and 100 B-21s. This policy recommendation could drive major procurement increases for Boeing's F-47 program and Northrop Grumman's B-21 Raider program. While currently a think tank recommendation rather than official policy, such influential defense policy papers often shape congressional budget decisions and DoD acquisition strategies.

Cabrillo Club·February 16, 2026
War Room intelligence briefing hero image
Compliance & Risk

US Air Force needs 500 next-gen fighters, bombers to beat China, think tank says

The Mitchell Institute for Aerospace Studies recommends the U.S. Air Force procure at least 500 next-generation aircraft (300 F-47 fighters and 200 B-21 bombers) to counter China, significantly exceeding current plans of 185 F-47s and 100 B-21s. This policy recommendation could drive major procurement increases for Boeing's F-47 program and Northrop Grumman's B-21 Raider program. While currently a think tank recommendation rather than official policy, such influential defense policy papers often shape congressional budget decisions and DoD acquisition strategies.

Cabrillo Club·February 16, 2026