top of page

GovCon Tech Weekly — September 28, 2026

Rod Fontecilla
5 days ago
26 min read

GovCon Tech Weekly — September 28, 2026

Fiscal year 2026 closes on September 30, but the continuing resolution signed on September 2 moved the real funding and authorities cliff to December 11. The ten weeks between those two dates now carry a proposal deadline, a comment deadline, or a compliance gate on very nearly every business day — and the single largest change to contractor cost accounting in decades takes effect on Thursday.

A note on this edition

This is the first edition of GovCon Tech Weekly, so there is no prior week's brief to correct. That section begins next week and will lead the brief whenever it has content.

One correction is worth making anyway, because it is circulating widely and it is wrong. Numerous write-ups still list September 30, 2026 as the full-proposal deadline for DARPA's Quantum Benchmarking Initiative Topic (QBIT) Stage A solicitation, DARPA-PA-26-02-02. That date was accurate when DARPA announced the solicitation in March 2026, but the notice has since been modified three times and the current deadline is November 30, 2026 at 2:00 p.m. ET, per DARPA's own program page and the SAM.gov notice history. If your capture team has written off QBIT Stage A as closed, it is not. See item 7.

1. Cost accounting flips on October 1: the CAS threshold goes from $2.5M to $35M, and the Pentagon moves to GAAP

The OMB Cost Accounting Standards Board's final rule (91 FR 56056, doc. 2026-17901, RIN 0348-AB85), published September 1, 2026 and effective October 1, 2026, raises basic CAS applicability from $2.5 million to $35 million, full CAS coverage and the Disclosure Statement trigger from $50 million to $100 million, and agency-head waiver authority from $15 million to $100 million. The $7.5 million trigger-contract threshold is eliminated outright. The Board estimates roughly a 30% reduction in the number of entities subject to full CAS while retaining about 99% of dollar coverage. The rule also clarifies that for indefinite-delivery contracts, exemptions apply at the task/delivery-order level for multiple-award vehicles and at the contract level for single-award vehicles. A companion final rule (doc. 2026-17903) conforms CAS 407 to GAAP.

Running in parallel, Deputy Secretary of War Stephen Feinberg signed a memorandum titled "Fostering One Strong Industrial Base" on September 14, 2026, directing the department to make CAS the exception and GAAP the rule, with a dated implementation appendix: roughly October 14 to stop "shadow CAS" on exempt awards and nominate a CASB representative; October 29 to adopt a 15-business-day standard for commercial-item determinations; November 13 to submit CAS reform proposals to the CASB and publish commercial-aligned business-system criteria permitting independent accounting-firm GAAP certifications in lieu of government business-system reviews; December 13 to initiate DFARS profit-policy rulemaking; January 12, 2027 to reissue the Other Transactions Guide; and March 13, 2027 to structure advance market commitments.

So what. Re-run your CAS-coverage determination this week for every award you expect to receive on or after October 1 — a mid-tier firm with covered awards between $2.5 million and $35 million falls out of CAS entirely for new work, but legacy CAS-covered contracts keep their clauses, so you will be operating two regimes simultaneously and your disclosure statement still governs the old one. If you have been carrying CAS-driven indirect-rate structure or a Disclosure Statement purely to stay compliant, the economics of that changed on Thursday. On the DoW side, the November 13 business-system criteria are the item to watch: if independent GAAP certifications can substitute for DCMA business-system reviews, the compliance cost curve for defense work bends materially, and firms that price audit overhead into indirect rates should model that now rather than after competitors do. Forcing date: October 1, 2026.

2. The governmentwide contract landscape is being rebuilt mid-flight: SEWP V ends, NITAAC sunsets, Polaris is enjoined

Three things are converging at once. SEWP V's base ordering period ends September 30, 2026; SEWP VI — 2,100-plus awardees, a $20 billion ceiling, ordering from November 1, 2026 through October 2036 — goes live November 1, with its website available October 1. Two option periods (October 1, 2026–January 31, 2027 and February 1–April 30, 2027) are authorized in the contract, but we could not confirm that NASA has exercised the first, which is the difference between a clean handoff and a one-month ordering gap.

NITAAC is sunsetting all of its governmentwide acquisition contracts — CIO-SP3, CIO-SP3 Small Business and CIO-CS — after cancelling CIO-SP4 on a finding that it duplicated existing GSA and NASA vehicles (sources put the overlap at 90% or 93%). October 29, 2026 is the last day to award new orders, no order may extend past December 31, 2028, and the program's functions transition to GSA.

And Polaris, GSA's small business GWAC, is frozen. Judge Thompson M. Dietz of the U.S. Court of Federal Claims issued a sealed ruling on September 10, 2026 blocking further Polaris awards until GSA corrects prejudicial errors, finding unequal treatment: GSA refused to let protester OM Partners fix a clerical error while allowing another bidder to fix the same kind of error. OM Partners and DevTech prevailed; Assyst, GenceTek, BLJV and Rigil did not. The injunction reaches every award round beyond the initial 102 general small business awards made in January 2025, which means the SDVOSB, WOSB and HUBZone pools are on hold.

So what. If you hold a NITAAC seat, treat October 29 as a hard revenue date and go through your customers' unplaced requirements now — anything not awarded on that vehicle by then moves to a competition you may not be positioned for. If you hold SEWP V, close every open quote and get orders signed before the base period lapses on September 30 rather than betting on the option. And if your FY27 small-business pipeline assumed a Polaris socioeconomic pool award, replace that assumption this week: the realistic landing zones are GSA MAS, Alliant 3 and OASIS+, and capture teams that re-baseline vehicle strategy first will be the ones agencies can actually buy from in Q1. Forcing dates: September 30 and October 29, 2026.

3. Two of the largest federal IT competitions on the board both close in the first three weeks of October

DISA released the JWCC Unified Cloud Marketplace (UCM) Core solicitation on September 8, 2026: a full-and-open, multiple-award IDIQ with a ceiling of $21.6 billion over up to 10 years (five-year base plus a single five-year option), covering IaaS, PaaS and SaaS from Unclassified through TS/SCI at Impact Levels 2, 4, 5 and 6, and limited to U.S.-based hyperscale commercial cloud service providers. Proposals are due October 6, 2026 at 12:00 p.m. ET. Against the incumbent 2022 JWCC, DoD has obligated roughly $1 billion in order volume, with AWS at 55% ($564 million) and Microsoft at 28% ($291 million). The companion JWCC UCM Premier solicitation — which is where Tier 2 non-hyperscalers, ISVs, integrators and small businesses actually compete — is expected in Q1 CY2027 with awards in Q3 CY2027.

Separately, DHS has put NCCS 2.0 (solicitation 70RTAC26R00000007) on a punishing schedule. The Network Operations Security Center is consolidating fragmented component-level contracts into a single-award IDIQ covering network infrastructure, cloud and platform services, and cybersecurity operations, with a requirement that the solution incorporate agentic AI to automate low-level IT response. Phase 1 is pass/fail on facility clearance; Phase 2 covers prior experience, staffing and price. DHS says it will award without discussions. Final solicitation releases October 1, Phase 1 proposals are due October 6, advancement notifications go out October 9, Phase 2 proposals are due October 21, and award is anticipated in late November 2026. Reported ceiling figures conflict — see the uncertainty section.

In the background, DHS's Cumulus program signed Google Public Sector to a single-award IDIQ worth a potential $875.6 million over one base year plus four options, reported September 15 — the third of four planned awards after AWS (up to $2.6 billion, June 2026) and Oracle (up to $568 million, August 2026). Microsoft's was the last one outstanding against a September 30 target.

So what. For JWCC, the strategic decision for anyone who is not a U.S. hyperscaler is to stop spending on Core and start building the Premier teaming position now — Q1 2027 sounds distant, but hyperscaler partner slots on a vehicle of that size are allocated well before a draft RFP appears, and the 55/28 AWS/Microsoft obligation split is the baseline every teaming conversation should be priced against. For DHS NCCS 2.0, the five-day gap between solicitation release and Phase 1, and the fifteen-day gap to Phase 2, mean a team that is not already assembled with a facility clearance in hand is out; if you are an incumbent on a component contract being absorbed, this is binary, and you should know by October 1 whether you are bidding or negotiating a subcontract. Across both, the Cumulus pattern — large civilian agencies going direct to hyperscalers on single-award IDIQs and running a separate multiple-award competition for everyone else — is the structure to plan against, and that follow-on competition is the pipeline item worth tracking. Forcing dates: October 1, 6 and 21, 2026.

4. The FAR overhaul's second tranche lands: twelve more parts, comments due October 19 — and metered consumption becomes firm-fixed-price

The FAR Council published four proposed rules on September 18, 2026 under the Revolutionary FAR Overhaul, covering twelve FAR parts plus Part 52. Comments on all four are due October 19, 2026.

  • FAR Case 2026-003 (doc. 2026-19162) — Parts 8, 12, 13, 15, 38, 44, 51. Part 38 is removed entirely as duplicative of GSA regulations and Part 51 is folded into Part 8. Part 12 is restructured into presolicitation, solicitation-evaluation-award, and postaward phases. Part 15 emphasizes negotiation over "discussions," simplifies the definitions of deficiency and clarification, lets contracting officers accept late proposals at their discretion, and broadens competitive-range flexibility.

  • FAR Case 2026-006 (doc. 2026-19160, 91 FR 59476) — Parts 16, 17, 35. Implements section 1825 of the FY2026 NDAA by adding a new FAR 16.202-3 recognizing that supplies and services "capable of being metered and billed based on actual usage as fixed-price units" are acquired as a firm-fixed-price contract. It also authorizes on-ramps and off-ramps for multiple-award contracts, permits BPAs under multiple-award contracts, removes the general five-year duration limit in Part 17, and adds provisions for contract extension during an appropriations lapse.

  • FAR Case 2026-011 (doc. 2026-19159, 91 FR 59584) — Parts 9, 27, 47. Removes preaward surveys and contractor team arrangements from Part 9, replaces FAR subpart 27.4 with separate noncommercial and commercial data-rights subparts, sets SBIR/STTR data protection at a single 20-year non-extendable period, adds DEI-discrimination noncompliance as debarment/suspension grounds per EO 14398, and deletes 33 transportation clauses.

  • FAR Case 2026-010 (doc. 2026-19158) — Parts 14, 28, 36, 52. A companion Paperwork Reduction Act notice published September 23 (doc. 2026-19442) with comments due November 23.

Eight of twelve planned proposed rules have now published. No RFO final rule has issued — the binding text remains your contracting agency's own class deviation under OMB M-25-26, agency by agency. Separately, GSA published GSAR Case 2026-G501 (RIN 3090-AL13) on September 22, proposing to relocate Federal Supply Schedule ordering procedures out of FAR 8.4 and into GSAR Part 538, cutting the text from over 10,000 words to roughly 2,600; comments are due October 22, 2026.

So what. Two comment filings are worth real effort here, and they are not the obvious ones. The first is Part 27 data rights: if you sell AI, software or anything with fine-tuned models or derived artifacts, that subpart will determine who owns model outputs, training and tuning data, and derived weights — and it is far easier to shape now than to negotiate clause-by-clause later. The second is 16.202-3: codifying metered consumption as firm-fixed-price removes the main regulatory reason agencies buy cloud and SaaS as fixed-seat licenses, and the final text will govern how agencies can obligate against variable consumption — which matters enormously if your pricing model is usage- or token-based. Meanwhile, the Part 15 changes to late proposals and competitive range are a live proposal-strategy shift, and the GSAR 538 move means every Schedule compliance SOP, proposal boilerplate and training deck that cites FAR 8.4 will need rewriting. Note that a well-circulated industry newsletter lists October 18 for the FAR comments; the Federal Register says October 19 and governs, but October 18 is a Sunday, so treat Friday October 16 as your internal cutoff. Forcing dates: October 19 and October 22, 2026.

5. The $1 federal AI era ends September 30 — and VA starts writing the real checks

GSA's OneGov arrangement giving agencies ChatGPT for $1 per agency per year expires September 30, 2026. Its replacement, announced September 10 and effective October 1, is consumption-based: a 50% discount on token usage across ChatGPT models with no platform-access fee, no minimum order and no spend commitment, running 27 months through December 31, 2028, and available to federal executive, legislative and judicial agencies plus state, local and tribal governments through direct buy, resellers and cloud marketplaces on GSA MAS. GSA puts cumulative OneGov savings at roughly $1.7 billion, about $1.4 billion of it from AI tools, reaching some 3.5 million federal employees. Anthropic extended its $1-per-user Claude for Government deal by one month, to October 31, 2026. Google's Gemini OneGov deal was, as of mid-September reporting, the only one with no announced extension or replacement.

On the demand side, VA previewed a two-phase enterprise AI procurement on September 23: a first-party acquisition of core AI products and native vendor services, plus a separate three-year third-party services contract — likely firm-fixed-price tied to outcomes — covering requirements refinement, architecture, development, integration, testing, security and accessibility remediation, deployment and post-deployment iteration, deployed in six waves targeting 540,000 users. RFI responses are due October 7, 2026 at 10:00 a.m. ET, with the solicitation expected in October. VA separately selected Abridge and Knowtex on September 22 under a multi-award enterprise contract for AI-assisted clinical documentation with a $775.72 million ceiling over five years, task orders competed; ambient scribe is already live at more than 75 VA medical centers.

So what. The immediate operational risk is on your agency customers, and it is an Antideficiency Act problem before it is a technology problem: agencies that built workflows on a $1 license now face real, variable, unbudgeted obligations starting October 1, under a continuing resolution, with no spend ceiling in place. That is a services opportunity — token metering, consumption forecasting, chargeback, model routing, AI FinOps — and the agencies that will buy it are the ones whose usage spiked while it was free. Pull your customers' USAi and ChatGPT usage data this week and walk in with a number. If any of your solutions has a Gemini dependency, confirm vehicle continuity before September 30 rather than after. And the VA RFI on October 7 is the last low-cost chance to shape evaluation criteria and pricing structure on one of the largest civilian enterprise-AI services opportunities in the pipeline — the product/services split means you can compete without owning a frontier model, but firm-fixed-price tied to outcomes across 540,000 users is a meaningful risk transfer that deserves a comment. Forcing dates: September 30, October 1, October 7 and October 31, 2026.

6. A wave of edge-device zero-days puts agencies on three-day patch clocks — as DHS's IG says CISA cannot enforce its own directives

Citrix disclosed CVE-2026-88771 and CVE-2026-88772 in NetScaler ADC and NetScaler Gateway on September 27, 2026, both rated CVSS 9.5, both exploited as zero-days before disclosure. CVE-2026-88771 is an improper-input-validation flaw giving unauthenticated remote code execution against default configurations; CVE-2026-88772 is a memory buffer overflow reachable when DTLS is enabled, which is on by default for VPN virtual servers. Fixed builds are 14.1-73.37, 13.1-64.23, and 13.1-FIPS/13.1-NDcPP 13.1.37.279 and later. CISA added both to the KEV catalog and set a federal remediation deadline of September 30, 2026. Shadowserver counts roughly 23,000 internet-exposed NetScaler instances.

That follows a four-vendor wave added to KEV on September 22: CVE-2026-93952 in Arista's on-premises VeloCloud Orchestrator at CVSS 10.0 (remediation due September 25, now passed); CVE-2026-94127 in F5 BIG-IP APM at CVSS 9.8; and CVE-2026-85102 and CVE-2026-93616 in Check Point Security Gateway and Security Management, both CVSS 9.8. All four are perimeter or control-plane devices, where compromise is an administrative takeover of a network rather than a single host.

Separately, ShinyHunters compromised FBIJobs.gov, hosted on Oracle PeopleSoft, and claims to hold names, addresses, job titles, Social Security numbers and medical and psychiatric records on FBI personnel and applicants; the FBI issued an internal cyber security incident notice and the portal is offline. The vector is CVE-2026-35273, CVSS 9.8, an unauthenticated RCE in PeopleTools 8.61 and 8.62 patched out-of-band on June 10–11, 2026. Mandiant notified more than 100 organizations of mass exploitation and documented a WAF-evasion technique — requesting “/%50SEMHUB/” rather than “/PSEMHUB/”, which defeats WAF rules that match the literal path before URL-decoding.

The governing framework is BOD 26-04, "Prioritizing Security Updates Based on Risk," issued June 10, 2026, which replaced flat patch SLAs with risk tiers — three days for actively exploited, automatable flaws on internet-facing systems granting partial or full control, with forensic triage required where full control is possible. Agencies had until August 9 to update procedures; the remediation timelines themselves become operative December 7, 2026. And the DHS Inspector General reported on September 25–26 that 88 of 102 federal civilian agencies missed the June 20, 2025 deadline to implement CISA's Secure Cloud Business Applications directive, 40 missed the cloud tenant inventory deadline, and three-quarters remained non-compliant as of February 2026. The IG issued no recommendations, concluding that "CISA lacks the authority necessary to require full and timely implementation of Binding Operational Directives."

So what. Three concrete actions. First, inventory NetScaler ADC and Gateway across every environment you operate for a federal customer and patch or disconnect before Wednesday; expect emergency change windows to be pushed onto you rather than negotiated, and if any affected system processes covered defense information you have a 72-hour DFARS 252.204-7012 DIBNet clock the moment exploitation is suspected. Second, if you responded to the June PeopleSoft advisory with a WAF rule instead of a patch, you are still exposed and a virtual-patch-only response will not survive an incident review — patch PeopleTools 8.61/8.62 and hunt for web shells now. Third, read the IG report as a market signal rather than a compliance story: it is official confirmation that agencies cannot meet BOD deadlines with in-house capacity, and that the gap gets closed by procurement. Configuration hardening for M365 and Google Workspace, ScubaGear-style assessment tooling, continuous configuration monitoring and compromise assessment as a recurring service are all captive demand through FY27. Forcing dates: September 30 and December 7, 2026.

7. Quantum turns into a procurement calendar: $215M on the table by October 19, agency PQC plans due October 22

DOE's Office of Science issued DE-FOA-0003657, the Quantum Genesis Q Competition, on September 17, 2026 — up to $215 million across roughly ten expected awards, structured as a prize rather than a grant. Phase I pays fixed milestone awards of up to $1.5 million per awardee; Phase II is a $100 million general incentive pool for demonstrating a scientifically relevant quantum computer with at least 100 logical qubits, plus two $50 million bonus pools at 150 and 200 logical qubits. It is modality-agnostic and open to for-profit companies. Applications are due October 19, 2026. Critically, only $2.5 million is actually appropriated in FY2026 — the incentive pools are contingent on future appropriations. DOE simultaneously issued a $45 million Quantum HPC Validation and Verification Testbed lab call ($14 million in FY2026) to DOE national laboratories, hardware-agnostic, which will serve as the referee verifying vendor claims before incentive pools pay out. Note that the Quantum Genesis initiative was announced in late June 2026; what launched this month is its funding vehicle.

On the cryptography side, the clock that matters to every contractor is already running. EO 14412 (signed June 22, 2026) and OMB M-26-15 (signed by Director Russell T. Vought on June 24, 2026) require every agency to submit a PQC Migration Plan to OMB and ONCD within 120 days — approximately October 22, 2026. The memo mandates alignment to NIST IR 8547, cryptographic agility and automated cryptographic inventory, directs agencies to use CISA's PQC product-category guidance in requirements, and tells them to require vendor compliance with PQC readiness and crypto-agility provisions. EO 14412 separately directs the FAR Council to publish a proposed rule within 180 days — roughly December 19, 2026 — requiring contractors to comply with NIST FIPS 203, 204 and 205 by December 31, 2030, with CISA cryptographic-bill-of-materials guidance due around March 2027.

And, as flagged at the top: DARPA's QBIT Stage A full proposals under DARPA-PA-26-02-02 are now due November 30, 2026 at 2:00 p.m. ET, not September 30. QBI has evaluated 20 companies, advanced 11 to Stage B, and has two in Stage C via the US2QC pilot; Microsoft opened a 15,000-square-foot center at the University of Maryland Discovery District on September 22 that gives DARPA on-site access to its Majorana topological system for independent evaluation.

So what. Treat the PQC dates as the ones with teeth. The October 22 agency plans mean PQC language starts appearing in solicitations over the next two quarters, and the discriminator will be a contractor that can produce a real cryptographic inventory and a CBOM rather than a compliance narrative — start that inventory now, because it takes a quarter, not a sprint. The December 2026 proposed FAR rule is the most consequential forward item in this entire brief for the broad contractor base, because it converts PQC from agency policy into a flow-down clause with a hard 2030 date; plan the comment strategy in October, not December. On Quantum Genesis, the honest read for a client is that the $215 million headline is an appropriations bet — $2.5 million is real money and the rest is not yet — so position for Phase I milestone awards and the national-lab V&V buildout (which is near-term subcontract and staffing demand) rather than modeling revenue off the incentive pools. Forcing dates: October 19, October 22, November 30 and approximately December 19, 2026.

8. CMMC Phase 2 is still suspended and the reform report is overdue — but the liability never paused

DoD suspended CMMC Phase 2 on July 13, 2026 and stood up a CMMC Reform Task Force. Phase 2 would have made C3PAO third-party certification mandatory for Level 2 on new contracts starting November 10, 2026. The RFI window ran July 13 to August 14 and drew, per DoW CIO Kirsten Davies, over 1,100 responses and more than 10,000 pages, with events drawing over 3,000 attendees; Davies said "more than 50% of the respondents were in favor of us putting this on hold and seeking some level of reform," and that CMMC "was hitting small to medium-sized businesses really, really hard and inappropriately hard." The 60-day review closed September 11. As of September 28 the report has not been released, with official determinations expected no earlier than mid-October and at least one advisor warning of slippage into late 2026 or early 2027.

What has not changed is everything underneath. The 48 CFR/DFARS rule published September 10, 2025 and effective November 10, 2025 remains in force. DFARS 252.204-7021 stands as revised. DFARS 252.204-7012, NIST SP 800-171 Rev 2, SPRS scoring, annual affirmations and 72-hour DIBNet reporting all still apply. Class Deviation 2026-O0025 (Revision 3, reported September 3) carries the pause into current contract text and directs contracting officers to accept Level 1 and Level 2 self-assessments. And Honeywell Aerospace settled a False Claims Act case over NIST 800-171 non-compliance for $2,042,518 on September 1, 2026. GAO-26-107955 (March 12, 2026) found DoD never documented how it would mitigate insufficient C3PAO assessment capacity; DoD concurred and committed to documentation by December 31, 2026.

So what. The dangerous reading of the suspension is that remediation can wait, and the Honeywell settlement is the direct rebuttal: DoJ's civil cyber-fraud theory runs on SPRS score accuracy and 7012 compliance, neither of which was paused, and a contractor that stood down remediation in July while continuing to affirm a stale SPRS score is accumulating false-affirmation exposure with no certification deadline to discipline it. Re-validate your SPRS score against your actual current posture this quarter and document the basis. For the reform itself, Davies has signaled a pivot toward operational technology security and cyber resilience while saying assessment requirements "may remain in place" in some form — so the planning assumption should be that something certification-shaped returns, not that CMMC is gone. Watch the DPC class deviation page and 32 CFR Part 170 amendments; any Phase 2 restart requires new rulemaking or a further class deviation, which is your lead time. Forcing date: December 31, 2026 (GAO commitment); report release expected mid-October at the earliest.

9. D.C. Circuit upholds the Pentagon's supply-chain-risk designation of Anthropic — and the bar reaches contractors

Disclosure: Anthropic makes the model that wrote this brief. The record is reported as it stands, including the parts unfavorable to Anthropic.

On Friday, September 25, 2026, the U.S. Court of Appeals for the D.C. Circuit decided Anthropic PBC v. United States Department of War, No. 26-1049, upholding the Department's exclusion of Claude from its supply chain under the Federal Acquisition Supply Chain Security Act. The panel — Judges Gregory Katsas, Karen LeCraft Henderson and Neomi Rao — held that Anthropic's ability to enforce contractual restrictions on the model qualifies as a covered "supply chain risk," and that the Secretary's determination was neither arbitrary and capricious nor unconstitutional; Judge Henderson dissented. The opinion is explicit that covered procurement actions "include barring agency contracts with a particular supplier and subcontracts that use the supplier to perform work for the agency," and describes the CIO memo as having prohibited contractors from using Anthropic products in their work for the Department.

The designation was imposed in March 2026 after the Department sought, in February, to strike Anthropic's contract restrictions on domestic mass surveillance and fully autonomous weapons and replace them with an "all lawful use" term, which Anthropic refused. Anthropic won a partial victory in the Northern District of California in August 2026, where a court held one of the two statutory justifications unlawful; that split persists. Anthropic's statement: "We respectfully disagree with the court's decision. Another federal court has already held the government's parallel designation unlawful… We remain confident in our position and are considering all options, including further review." Operationally, Under Secretary of Defense for Research and Engineering Emil Michael said on September 11 that DoD is roughly 90% migrated off Anthropic across classified systems, targeting completion by end of September or October, with capacity shifting to OpenAI, xAI and Google plus eight unnamed companies. GenAI.mil, which the department says reached between 1.7 and 2 million users (sources differ — see uncertainty), hosts Google Gemini, OpenAI ChatGPT Mil and xAI Grok; Anthropic is not among them.

So what. If you perform DoD work, this is a compliance obligation and not a preference: audit your own tooling, your subcontractors' tooling and any delivered solution for Anthropic model dependencies, and treat Claude as unavailable for Department business until the designation is lifted. Civilian-agency use is unaffected, which means firms serving both will be running a split posture and should write that into their AI use policy explicitly rather than leaving it to individual judgment. The broader lesson is a diligence one: the Department used the supply-chain-risk mechanism against a domestic commercial vendor over a contract-terms dispute, and an appellate court let it stand — so designation risk now belongs in your vendor-selection criteria and in the representations you seek from AI suppliers. Finally, the migration itself is near-term displaced demand: classified workloads moving to three named providers and eight unnamed ones is teaming and recompete activity that is happening this quarter. Forcing date: DoD migration completion targeted end of September/October 2026; no appellate filing deadline announced.

10. The real cliff is December 11 — and the TMF window closes October 20

There is no shutdown risk on October 1. H.R. 6500, the Continuing Appropriations and Extensions Act, 2027 (P.L. 119-103), was signed September 2, 2026, funding the government through December 11, 2026 and deliberately pushing final FY2027 decisions past the November midterms. Zero of the twelve FY2027 appropriations bills have been enacted. Division B of that law extends three expiring authorities to the same December 11 date: Section 2011 amends the Cybersecurity Information Sharing Act of 2015 (6 U.S.C. 1510(a)), striking "September 30, 2026" and inserting "December 11, 2026"; Section 2014 does the same for the Technology Modernization Fund; and the Federal Cybersecurity Enhancement Act of 2015 is likewise extended.

The TMF 2026 Call for Proposals is open now, prioritizing legacy modernization and cybersecurity, permitting technology, and AI adoption in partnership with USAi. Initial Project Proposals are due October 20, 2026; later submissions "may be accepted" but are not guaranteed Board consideration before December 11 — the Board is explicitly working against its own authority expiration.

Two adjacent calendars belong here. FedRAMP has RFC-0033 (20x Phase 4 development tracks for Class D) and RFC-0034 open with comments closing October 9; full Class D requirements publish October 14, final requirements November 18, and the Phase 4 pilot is capped at 10 participants who must hold a CR26-compliant Class C Certification by December 1, 2026, with the application window December 1–4. FedRAMP states there will be "no extensions past the ending of the default grace period," with Rev5 applications closing June 11, 2027 and all CR26 grace periods expiring February 1, 2028. And SBA extended the comment period on its Small Business Size Standards proposed rule (RIN 3245-AI67), covering new standards for 338 industry groups and industries, from September 21 to November 20, 2026.

So what. The TMF deadline is the one to act on this week, because it is the only item here where three weeks of work changes an outcome: if any pipeline opportunity of yours depends on TMF financing, the agency's initial proposal has to be in by October 20, and after December 11 the Board may have no authority to approve anything. Help your customer write it. Second, price December 11 into your FY27 planning as a genuine lapse risk rather than a formality — a CISA 2015 lapse means contractor counsel typically shuts off voluntary threat-indicator sharing, which degrades DIB CS and JCDC feeds precisely while edge-device zero-days are landing weekly, so have a pre-drafted position on what you will and will not share absent reauthorization. Third, remember that a CR is not normal money: new starts are generally barred and agencies obligate at prior-year rates, so any FY27 IT modernization new start in your forecast is frozen until full-year bills pass or an anomaly is granted. And if you are a CSP that has not begun Class C certification, you cannot be in the first Class D cohort — that door closes December 1. Forcing dates: October 9, October 20, November 20, December 1 and December 11, 2026.

Dated actions, in order

  • Date — What · Who it binds

  • Sep 30, 2026 — FY2026 ends; expiring-year funds must be obligated · All

  • Sep 30, 2026 — SEWP V base ordering period ends (options authorized, exercise unconfirmed) · SEWP V holders

  • Sep 30, 2026 — CISA remediation deadline, Citrix CVE-2026-88771 / CVE-2026-88772 · FCEB agencies + their integrators

  • Sep 30, 2026 — OneGov $1 ChatGPT deal expires; Gemini deal expires absent extension · Agencies, resellers

  • Sep 30, 2026 — DHS target to finalize all four Cumulus hyperscaler awards (Microsoft outstanding) · DHS cloud market

  • Oct 1, 2026 — CAS thresholds effective: $35M basic / $100M full and Disclosure Statement · All contractors

  • Oct 1, 2026 — OpenAI OneGov consumption pricing begins (27 months, through Dec 31, 2028) · Agencies

  • Oct 1, 2026 — DHS NCCS 2.0 final solicitation release; SEWP VI website live · DHS bidders

  • Oct 6, 2026, 12:00 p.m. ET — JWCC UCM Core proposals due ($21.6B ceiling) · U.S. hyperscalers

  • Oct 6, 2026 — DHS NCCS 2.0 Phase 1 proposals due (facility clearance pass/fail) · DHS bidders

  • Oct 7, 2026, 10:00 a.m. ET — VA enterprise AI services RFI responses due · AI integrators

  • Oct 9, 2026 — FedRAMP RFC-0033 / RFC-0034 comments close; DHS Phase 2 notifications · CSPs; DHS bidders

  • ~Oct 14, 2026 — DoW 30-day mark: stop "shadow CAS" on exempt awards · Defense contractors

  • Oct 19, 2026 — Comments due, all four Sept 18 FAR Overhaul proposed rules · All contractors

  • Oct 19, 2026 — DOE Quantum Genesis Q Competition applications due (DE-FOA-0003657) · Quantum hardware firms

  • Oct 20, 2026 — TMF Initial Project Proposals due · Agencies + their integrators

  • Oct 21, 2026 — DHS NCCS 2.0 Phase 2 proposals due · DHS bidders

  • Oct 22, 2026 — Agency PQC Migration Plans due to OMB/ONCD (M-26-15, 120 days) · Agencies; flows to vendors

  • Oct 22, 2026 — GSAR Case 2026-G501 comments due (FSS ordering to GSAR 538) · Schedule holders

  • Oct 29, 2026 — Last day to award new orders on NITAAC GWACs · CIO-SP3 / CIO-CS holders

  • Oct 31, 2026 — Anthropic $1/user Claude OneGov deal expires · Agencies

  • Nov 1, 2026 — SEWP VI ordering begins ($20B ceiling, 2,100+ awardees) · SEWP VI holders

  • ~Nov 13, 2026 — DoW 60-day mark: commercial-aligned business-system criteria published · Defense contractors

  • Nov 18, 2026 — FedRAMP final Class D requirements · CSPs

  • Nov 20, 2026 — SBA size standards comments due (338 industries) · Small businesses

  • Nov 23, 2026 — FAR Case 2026-010 PRA information-collection comments due · All contractors

  • Nov 30, 2026, 2:00 p.m. ET — DARPA QBIT Stage A full proposals due (extended from Sep 30) · Quantum firms

  • Dec 1, 2026 — CR26-compliant FedRAMP Class C Certification required for Phase 4 pilot; window Dec 1-4 · CSPs

  • Dec 7, 2026 — BOD 26-04 risk-tiered remediation timelines become operative · FCEB agencies + integrators

  • Dec 11, 2026 — CR expires; TMF, CISA 2015 and Federal Cybersecurity Enhancement Act lapse · All

  • ~Dec 13, 2026 — DoW 90-day mark: DFARS profit-policy rulemaking initiated · Defense contractors

  • ~Dec 19, 2026 — FAR Council proposed PQC rule due (EO 14412, 180 days) · All contractors

  • Dec 30, 2026 — DARPA QBI 2026 and IV&V opportunity deadlines · Quantum firms

  • Dec 31, 2026 — DoD commitment to GAO: document C3PAO capacity mitigation · DIB

  • Dec 31, 2030 — FIPS 203/204/205 contractor compliance deadline (per EO 14412) · All contractors

Where this is uncertain

Items below are reported because they matter, but they are not settled. Treat them accordingly.

Sources conflict on the record.

  • DHS NCCS 2.0 ceiling. ExecutiveGov reports $626 million; Nextgov and Washington Technology published no ceiling; a separate aggregator describes it as "$100M+." We have not resolved this and have not used a figure in item 3.

  • GenAI.mil user count. Nextgov and Defense One (both September 23) report "more than 2 million users in one week," citing DoD Chief Digital and AI Officer Cameron Stanley. DefenseScoop, same day, reports 1.7 million total users with about 500,000 daily power users, citing Deputy Under Secretary James Mazol. The likeliest reconciliation is weekly-active versus registered, but no source states that. Do not quote a single number as authoritative.

  • Which directive authorizes the September 30 Citrix deadline. BleepingComputer attributes it to BOD 26-04; SecurityAffairs to BOD 22-01. Because BOD 26-04's remediation timelines do not take effect until December 7, BOD 22-01 is the more likely basis, but cisa.gov was returning 403 to automated retrieval and we could not confirm it. The deadline itself is confirmed by both.

  • The VA ambient-scribe ceiling. Nextgov reports $775.72 million over five years; an aggregator lists "$776M" and, separately, "$775M combined." Almost certainly the same vehicle described inconsistently. We have used $775.72M and could not locate the contract number.

  • Whether a revised Feinberg accounting memo issued. Breaking Defense ran a headline suggesting a follow-on memo tweaked the regime; Holland & Knight's September 25 alert states explicitly that no revised version was issued and the September 14 memo governs. Unresolved.

  • CIO-SP4 duplication finding. Reported as 90% (PilieroMazza) and 93% (Coalition for Government Procurement).

  • FAR comment deadline. The Coalition for Government Procurement's Friday Flash says October 18; the Federal Register says October 19 and governs. October 18 is a Sunday.

Single-sourced, and we could not corroborate.

  • DHS OIG report number OIG-26-30 and whether it released September 25 or 26 — one source for both, and two outlets covered the findings on September 24 without a number, which does not fit a September 26 release.

  • Class Deviation 2026-O0025 Revision 3 — the revision number, the September 3 date and the DFARS Part 240 / FAR Part 40 scope come from a single aggregator. Verify against the DPC class deviations page before relying on it.

  • Federal remediation due dates for CVE-2026-94127, CVE-2026-85102 and CVE-2026-93616. The September 22 KEV addition is corroborated; the per-CVE due dates are not. Only the Arista CVE's September 25 date is sourced.

  • Whether CVE-2026-35273 (PeopleSoft) is in the KEV catalog, and its due date. Unconfirmed. Patch regardless.

  • "No cost-share required" for DE-FOA-0003657 — reported by one newsletter, not confirmed against the FOA text.

  • TMF's current appropriation under the CR — reported as "approximately $5 million," not confirmed against a primary source.

Open questions we could not answer at all.

  • Whether NASA has exercised the SEWP V option period (October 1, 2026–January 31, 2027). This determines whether there is an ordering gap before SEWP VI's November 1 go-live, and it is the single most consequential open item for SEWP holders.

  • Whether the DHS–Microsoft Cumulus award closed during the reporting window.

  • Whether the Google Gemini OneGov deal was extended or replaced before September 30.

  • Whether JWCC UCM Core has been amended or its October 6 deadline extended. SAM.gov would not render to automated retrieval. A short-fuse extension would be the most consequential correction to this brief — verify on SAM.gov directly before relying on October 6.

  • Whether the CMMC Reform Task Force report has been delivered internally. No public release as of September 28.

  • GAO bid protest decisions from September 18–28. gao.gov returned HTTP 429 throughout; several late-September decisions appear on the recent-decisions listing (including B-424575, B-424537, B-424543, B-424616) but we could not read any of them or confirm subject matter. No IT-specific GAO protest decision from this window is reported here, which is a gap rather than a finding of none.

  • DoD daily contract announcements for September 22–25. war.gov returned 403; we could not screen them for cloud, AI or data-center awards.

  • National Quantum Initiative reauthorization. S.3597 cleared Senate Commerce and H.R. 8462 cleared House Science, both in April 2026. congress.gov is robots-blocked to automated retrieval and we could not confirm any September status. No movement is reported because none was found, not because none occurred.

Deliberately excluded. Several items circulating this week are real but fall outside the September 18–28 window and should not be presented as new: the CHIPS Act quantum equity awards finalized September 8; AWS's classified-region investment (November 2025); CISA's 2026 SBOM minimum elements (July 29, 2026); NIST SP 800-172r3 (May 2026); and a widely recirculated NIST quantum grant that actually dates to February 2026. We also found no new OMB AI memo, no new AI executive order, no new NIST AI standards release, no NSA CNSA 2.0 update, no new quantum export control action, and no CIRCIA final rule in this window — CISA had targeted September 2026 for CIRCIA and missed it; the Federal Register shows nothing newer than the August 14 Unified Agenda notice.

Adana Technologies — GovCon Tech Weekly. Compiled September 28, 2026 from primary agency sources where available and reputable trade press where not. Every date, dollar figure and identifier above was checked against the cited source; where that check failed, the item appears in "Where this is uncertain" rather than in the body. This brief is informational and is not legal, financial or contractual advice.

Copyright © 2024 Adana Technologies. All rights reserved. No part of this site, including images and text, may be reproduced, transmitted, or redistributed in any form or by any means without prior written permission from Adana Technologies.

bottom of page