Air Force Cracks Down on Non-Compliant Computers and Software
The Air Force's 688th Cyberspace Operations Wing is actively enforcing the Department of Defense's Comply to Connect (C2C) framework by quarantining non-compliant hardware and software on Air Force and Space Force networks.…
Cabrillo Club
Editorial Team · August 1, 2026 · 4 min read
Cabrillo Club Insights
Air Force Cracks Down on Non-Compliant Computers and Software
Also in this intelligence package
TL;DR
The Air Force's 688th Cyberspace Operations Wing is actively enforcing the Department of Defense's Comply to Connect (C2C) framework by quarantining non-compliant hardware and software on Air Force and Space Force networks. This enforcement is part of the DoD (Department of Defense)'s Zero Trust push tied to the 2021 executive order, which requires 91 specific DoD cybersecurity initiatives to be in place by the end of fiscal 2027. Contractors with systems or devices that connect to Air Force or Space Force networks risk quarantine and loss of access if their hardware or software does not meet DoD cybersecurity standards. Immediate implications: contractors must validate inventory, attestations, and security posture now; remediation or risk of operational disruption is real and active. Failure to act will likely interrupt mission connectivity and could block performance on affected task orders and networked services.
Key Points
- What happened: The 688th Cyberspace Operations Wing is enforcing DoD's Comply to Connect (C2C) by quarantining non-compliant hardware and software on Air Force and Space Force networks.
- Who is affected: NAICS 541512, 541513, 541519, 541330, 334111, 334118, 517311, 518210, 541511, 541715; agencies: DOD, Air Force, Space Force, 688th Cyberspace Operations Wing; market segments: Cybersecurity, IT Services, Defense, Network Security, Hardware Manufacturing, Software Development, Cloud Services, Managed IT Services, Systems Integration, Endpoint Security.
- Timeline: Active enforcement now; 91 DoD cybersecurity initiatives required by the end of fiscal 2027 per the 2021 executive order.
- What contractors should do NOW: Immediately inventory and map all hardware and software that connect to Air Force/Space Force networks, validate compliance against DoD standards and Comply to Connect requirements (including listed compliance regimes), isolate or remediate non-compliant assets, update documentation and attestation, and notify contracting officers and program offices of any anticipated outages.
Who Is Affected
- Specific NAICS codes, agencies, and contract vehicles listed in segmentation: NAICS 541512, 541513, 541519, 541330, 334111, 334118, 517311, 518210, 541511, 541715.
- Agencies: DOD, Air Force, Space Force, 688th Cyberspace Operations Wing.
- Contract vehicles: SEWP, NITAAC CIO-SP4, CHESS, ITES-SW2, OASIS+, Alliant 3.
- Compliance regimes called out in segmentation: CMMC (Cybersecurity Maturity Model Certification), NIST 800-171 (NIST Special Publication 800-171), NIST 800-53, Zero Trust Architecture, Comply to Connect (C2C), DoD Cybersecurity Framework, Executive Order 14028, DFARS (Defense Federal Acquisition Regulation Supplement) 252.204-7012, DFARS 252.204-7021.
Frequently Asked Questions
Q: Will contractors be quarantined from Air Force and Space Force networks?
A: The Air Force is actively quarantining non-compliant hardware and software on Air Force and Space Force networks. Contractors with non-compliant systems connected to those networks face quarantine and loss of access.
Q: Which cybersecurity standards should contractors validate against?
A: Contractors should validate against DoD cybersecurity standards referenced by the enforcement — including Comply to Connect (C2C) and the DoD Zero Trust initiatives — and the compliance regimes listed in segmentation (CMMC, NIST 800-171, NIST 800-53, DFARS clauses, etc.). Prioritize C2C attestation and Zero Trust alignment.
Stop missing federal opportunities
Signals matches SAM.gov opportunities to your NAICS codes, tracks regulatory changes, and alerts you before competitors.
Start Free Trialor try our free Intelligence Dashboard→
Q: What immediate coordination should contractors expect?
A: Expect operational notifications from network owners and the 688th Cyberspace Operations Wing regarding quarantine actions. Contractors should be prepared to provide inventory, attestation, and remediation plans; specific coordination procedures are pending source review for local network policies.
Definitions
- Comply to Connect (C2C): A DoD-aligned framework to verify endpoint and system compliance before granting network access; non-compliant assets may be quarantined.
- Zero Trust: An architectural approach and security posture emphasizing continuous verification, least privilege access, and assuming network compromise.
Intelligence Response
- Cabrillo Signals War Room — Already detected this event and delivered this briefing. Continuously monitors regulatory changes, contract vehicles, and policy shifts relevant to DoD network enforcement actions.
- Cabrillo Signals Match Engine — Rescores opportunity pipelines and capture priorities where enforcement shifts risk or opens windows for compliant offers.
- Cabrillo Signals Intelligence Hub — Tracks the affected agencies, NAICS codes, and contract vehicles; saved searches will alert when follow-on solicitations or policy releases appear on SAM.gov (System for Award Management).
- Proposal Studio (Proposal OS) and Proposal Studio Workflow Tracker — Use Proposal OS to generate compliance matrices and remediation narratives; use Workflow Tracker to route compliance approvals and maintain audit-ready documentation.
Who to notify:
- CIO/CISO — to coordinate technical remediation and attestations.
- Capture/BD lead — to reassess bids and schedules tied to affected networks.
- Program Manager/Contracting Officer Representative — to report potential outages or inability to meet deliverables.
- Network Operations / Security Engineering — to execute the technical isolation/remediation plan.
First 48-hour playbook:
Stop missing federal opportunities
Signals matches SAM.gov opportunities to your NAICS codes, tracks regulatory changes, and alerts you before competitors.
Start Free Trialor try our free Intelligence Dashboard→
- Hour 0-4: Convene incident stand-up with CIO/CISO, Program Manager, Capture lead; declare systems that connect to Air Force/Space Force networks. Pull existing C2C/Zero Trust attestation artifacts.
- Hour 4-12: Run an accelerated inventory sweep of endpoints and software that access those networks. Flag items with expired or missing attestations and produce a prioritized remediation list.
- Hour 12-24: Begin remediation for high-risk items (patching, configuration changes, removing unauthorized software, or isolating hardware). Prepare evidence packages for network owners (logs, attestations, remediation timelines).
- Hour 24-48: Submit attestation/remediation status to contracting officer/program office; configure continuous monitoring and saved searches in Cabrillo Signals Intelligence Hub for follow-up notices. Activate Proposal Studio templates to capture any contractual impacts and update capture strategy via Cabrillo Signals Match Engine.
Relevant Cabrillo resources and guides: Secure Operations Guide (/insights/secure-operations-guide); see related reads CMMC Compliance Guide (/insights/cmmc-compliance-guide) and CUI (Controlled Unclassified Information)-Safe CRM Guide (/insights/cui-safe-crm-guide).
Stop missing federal opportunities
Signals matches SAM.gov opportunities to your NAICS codes, tracks regulatory changes, and alerts you before competitors.
Start Free Trialor try our free Intelligence Dashboard→

Cabrillo Club
Editorial Team
Cabrillo Club is a defense technology company building AI-powered tools for government contractors. Our editorial team combines deep expertise in CMMC compliance, federal acquisition, and secure AI infrastructure to produce actionable guidance for the defense industrial base.