
Second Batch of Revolutionary FAR Overhaul Clears OMB
The FAR Council's second batch of Revolutionary FAR Overhaul (RFO) rules cleared Office of Management and Budget review on August 28, 2026. The four proposed rules are expected to publish in the Federal Register in the coming weeks. Publication opens a public comment period, which ran 30 days for the first batch.
This article covers what the second batch changes, which FAR parts matter most if you bid on defense work, what happens next, and why none of it changes your CMMC obligations.
The FAR overhaul does not touch CMMC
The RFO rewrites the Federal Acquisition Regulation (the FAR). CMMC is not in the FAR. It is defined in two places the overhaul is not rewriting:
- 32 CFR Part 170, the Department of Defense rule that sets the CMMC levels and assessment requirements.
- DFARS clauses 252.204-7021 and 252.204-7025, the contract clauses that put CMMC requirements into DoD solicitations and awards. These are part of the Defense FAR Supplement, a separate DoD rulebook that this rulemaking does not cover.
Both come from Section 1648 of the FY2020 National Defense Authorization Act, which directed DoD to build a cybersecurity certification program. The RFO removes requirements that are not backed by a law or executive order. CMMC is backed by a law, so the RFO does not reach it.
The RFO does touch one cybersecurity clause at the FAR level. The basic safeguarding clause for federal contract information, formerly FAR 52.204-21, was given a new number. The requirements themselves did not change. Your obligations to protect federal contract information and controlled unclassified information, including the NIST 800-171 requirements in DFARS 252.204-7012, are the same as before.
The CMMC Phase 2 suspension is a separate action with its own process. The task force's recommendations are expected in late September or early October. Those recommendations will shape how CMMC assessments work. The FAR overhaul will not.
Recommended reading
CMMC News 2026: Every Program Update, Rule Change & Enforcement Action
Why operational technology is driving the CIO's thinking and potential reform
Davies framed information security as a baseline obligation and OT security as the harder problem. Protecting federal data is already a regulatory requirement. The part she described as underserved is the resilience and readiness of manufacturing operations: the controllers, workstations, and production systems that determine whether a supplier can actually deliver on their contracts.
Davies came to the role from industry, including a stint as deputy global chief information security officer at Siemens, and she reaches for manufacturing examples rather than data-breach ones. At DIBX, she walked through a short history of cyber-physical attacks:
- Stuxnet attack against programmable logic controllers that controlled the spinning in the Iranian uranium centrifuges.
- a steel mill where a cyberattack drove furnace conditions to the point of causing physical injuries to employees nearby
- bridge controllers in Amsterdam manipulated to raise spans that should have stayed down
The current example is closer to home. Since late July 2026, water and wastewater utilities in at least seven states have reported incidents to the FBI, with activity that degraded operations through pressure loss and flooding. The FBI and EPA public service announcement named internet-facing Rockwell Automation/Allen-Bradley MicroLogix PLCs as the targeted devices. Subsequent reporting put the number of affected states at a dozen or more, with some utilities losing remote control and reverting to manual operation.
The relevance to a defense supplier is not the water sector itself. It is the attack pattern: internet-exposed controllers, weak or reused credentials, and flat networks where a foothold in one place reaches machinery in another. Most small and mid-sized manufacturers in the Defense Industrial Base run some version of that environment.
“These are the threats that are top of mind for me, coming from manufacturing, and top of mind for you all, because you make things for our warfighters,” she said.
The goal of reform is figuring out how to address these very real cybersecurity risks but “still drive market share, revenue generation, and competition… in a safe and resilient way.”
What's included in Batch 2 of the FAR overhaul
The second batch covers 16 FAR parts across four proposed rules. All four were cleared "Consistent with Change" on August 28:
- FAR Case 2026-003 (RIN 9000-AO88): Parts 8, 12, 13, 15, 38, 44, 51
- FAR Case 2026-006 (RIN 9000-AO91): Parts 16, 17, 35
- FAR Case 2026-010 (RIN 9000-AO83): Parts 14, 28, 36
- FAR Case 2026-011 (RIN 9000-AO84): Parts 9, 27, 47
Batch 1, published June 23, 2026, covered 20 parts in four rules. Later batches will cover the rest, including small business (Part 19), labor (Part 22), Buy American (Part 25), and cost accounting standards (Parts 30 and 31).
Recommended reading
Government Cyber Attacks: 10+ Examples, Trends & Tips for Prevention
Why these rules matter when agencies already use the new text
Nothing changes day to day when these proposed rules publish. Since mid-2025, federal agencies have been using the RFO text through class deviations, which are written approvals that let an agency follow different rules than the FAR requires. Contracting officers are already working from the same text the proposed rules contain.
What the proposed rules change is how permanent that text is. A class deviation is temporary and can be changed by the agency at any time. A proposed rule is the first step in making the new text part of the FAR itself. After the comment period closes, the FAR Council reads the comments, revises the text, sends the final rule back to OMB for review, and publishes it with an effective date. The FAR Council has not published a date for final rules. Based on how long rulemaking usually takes, expect months, not weeks, after comments close.
The comment period is the only point in this process where contractors can formally object or ask for changes. Once a rule is final, the text becomes the regulation.
The rewritten FAR keeps only the requirements that come from a law or executive order. Guidance, best practices, and step-by-step procedures move out of the regulation and into buying guides on acquisition.gov. The buying guides are not binding. Contracting officers can follow them or not.
The result is a shorter FAR and more decisions left to the contracting officer. For a small or mid-size contractor, that means fewer regulatory requirements to satisfy when you respond to a solicitation. It also means fewer rules you can cite if you believe an agency ran a competition or negotiation unfairly. You can file a protest over a violated regulation. You cannot file one over an ignored buying guide.
How Batch 2 affects how you bid on contracts
Six parts in this batch shape competitive bidding and contract terms for defense contractors:
- Part 15, Contracting by Negotiation. Covers competitive proposals: how agencies evaluate offers, hold discussions with bidders, and pick a winner. If you respond to RFPs, this part sets the rules of the competition and your grounds for protest.
- Part 16, Types of Contracts. Defines fixed-price, cost-reimbursement, and incentive contracts, plus contracts where the government orders work over time without committing to a set amount up front. The contract type determines how much financial risk you carry and how you get paid.
- Parts 12 and 13, Commercial Products and Services, and Simplified Acquisition Procedures. Cover the faster purchasing paths agencies use for commercial items and lower-dollar buys. Many small contractors win most of their work through these two parts.
- Part 9, Contractor Qualifications. Sets the standards an agency uses to decide whether a contractor is eligible for award, including the checks on financial capacity, past performance, and integrity. Also covers debarment and suspension, and the special qualification requirements that can limit who is allowed to compete for certain work.
- Part 27, Patents, Data, and Copyrights. Covers who owns technical data and software developed under a contract. If your business depends on keeping rights to what you build, read this one closely.
- Part 44, Subcontracting Policies and Procedures. Covers when you need government approval to subcontract and which contract requirements a prime must pass down to its subcontractors. If you are a subcontractor, this part determines which clauses land in your subcontract.
The class deviation text for each of these parts is on acquisition.gov now and shows the direction the proposed rules will take. Reading it before the Federal Register version publishes gives you a head start on the comment period.
Timeline: what happens and when
Batch 2 has passed OMB review, the last step before publication. The steps after that follow the standard rulemaking process, and the FAR Council has not announced dates for any of them.
Coming weeks: The four Batch 2 rules publish in the Federal Register. Earlier RFO rules published within a few weeks of clearing OMB.
Comment period: Batch 1 rules allowed 30 days. Expect the same. Comments are submitted through regulations.gov under the FAR case number.
After comments close: The FAR Council reviews comments and prepares final rules, which go through OMB review again before publishing. No date has been announced.
When final rules take effect: The rewritten text becomes the FAR and the class deviations end.
What defense contractors should prioritize next
None of these steps require action today. But the comment period will open with little notice and close in 30 days, and the preparation you do before publication determines whether you can use that window. Three things to do now:
- Read the deviation text for the parts you rely on. Parts 15, 16, 12, 13, 9, 27, and 44 are on acquisition.gov. Compare them against your proposal templates, your standard subcontract terms, and your data rights positions.
- Decide whether to comment, and draft it early. If a provision being removed from the FAR protects your business, a specific comment that explains how you rely on it and what the removal costs you carries more weight than a general objection. Draft it before publication so you can file early in the window.
- Keep CMMC on its current track. Your CMMC level, assessment type, and deadline are set by 32 CFR Part 170, DFARS 252.204-7021, and the outcome of the Phase 2 task force. This rulemaking changes none of them.
We’ll cover Batch 2 publication, the comment deadline, and the CMMC task force recommendations as they happen. Follow the cmmc.com newsroom for updates.