The Federal Acquisition Regulatory Council published more than 1,000 pages of proposed rules in the Federal Register, launching the most sweeping overhaul of the Federal Acquisition Regulation in approximately 40 years. The package spans four rule packages targeting 20 FAR sections and proposes structural changes to the bid protest system, cybersecurity reporting requirements, drone procurement restrictions, and cloud security standards. The public comment period closes July 23, 2026.

Background

The FAR was last comprehensively restructured decades ago and has accumulated layers of supplements, clauses, and agency deviations that make it one of the most complex regulatory frameworks in the federal government. An April 2025 executive order directed the FAR Council — comprising the Department of Defense, General Services Administration, and NASA — to rewrite the regulation in plain language, return to statutory origins, and strip out requirements that lack a direct statutory basis.

The rulemaking packages cover Parts 1, 2, 3, 4, 5, 6, 7, 10, 18, 24, 26, 29, 33, 37, 39, 40, 41, 49, 52, and 53. Together they represent the first formal rulemaking step — proposed rules must go through notice-and-comment before any changes become final. The combined page count exceeds 1,000 across all four packages.

Key Provisions

Bid protest system: The most consequential structural change in the package moves primary bid protest authority from the Government Accountability Office to individual contracting agencies. The FAR Council frames this as "increasing confidence in agency protests" and enabling data capture at the agency level. Currently, vendors with losing bids most commonly file at GAO, where a four-month resolution timeline and automatic stay are well-established. Under the proposed framework, agencies would become the first forum for protest resolution, with GAO's role in the process substantially narrowed. Industry groups are expected to comment heavily; the current GAO process is widely used by contractors precisely because of its predictability and independence from the agency whose award is being challenged.

Cybersecurity incident reporting: Contractors would be required to report confirmed cyber incidents to the relevant agency within 72 hours of discovery. As a FAR clause it would extend the requirement government-wide, covering civilian agencies that currently have no uniform timeline. The proposed rules also establish a "do not buy" list targeting entities posing security risks.

Foreign-built drones: The proposed rules ban federal agencies from procuring drones manufactured by foreign entities. The rule targets supply chain risk in unmanned systems.

Cloud and controlled unclassified information: Agencies processing controlled unclassified information (CUI) in commercial cloud environments would be required to use at minimum the FedRAMP Moderate security baseline. This closes a compliance gap where agencies could store CUI in cloud environments certified only to FedRAMP Low.

Subcontractor restrictions: The proposed rules would prohibit agreements that restrict subcontractors from selling software or technical processes directly to the government. The provision is designed to preserve competition and prevent primes from contractually blocking subcontractors from pursuing government-direct relationships.

Commercial products and services: Agencies would be directed to acquire commercial products and services to the "maximum extent practicable." This provision would strengthen the existing preference for commercial item acquisition and reduce use of unique government specifications when commercial alternatives exist.

Contract announcement threshold: The dollar threshold triggering public contract award announcements would rise from $4.5 million to $5.5 million. The change reduces mandatory public disclosure for mid-range awards.

What It Means for Contractors

  • Comment by July 23, 2026. The 30-day comment window is short for a package of this size. Contractors with significant protest experience at GAO have the most immediate stake in the bid protest changes and should submit detailed comments. The primary Federal Register dockets are 2026-12559 and 2026-12560.
  • Review cyber incident response plans now. A 72-hour reporting requirement under a FAR clause would be enforceable on all federal contracts, not just defense. Contractors that have not yet built internal incident detection and escalation workflows should treat the proposed rule as a planning trigger, not a wait-and-see event.
  • Audit drone supply chains. If your company supplies unmanned systems or components to federal agencies, verify the country of manufacture for every hardware element. The rule as proposed bans procurement of foreign-built systems, meaning the restriction applies to the product itself regardless of who is reselling it.
  • Cloud and CUI compliance gap analysis. If you operate cloud environments hosting CUI for civilian agency customers at the FedRAMP Low baseline, a gap analysis against FedRAMP Moderate is warranted now. Remediation timelines for FedRAMP uplift can run many months, and final rules could carry short compliance windows.
  • Subcontract flow-down terms. Prime contractors should review teaming and subcontract agreements for language that restricts subcontractors from selling directly to the government. The proposed rule would make such restrictions a potential clause violation; primes should assess flow-down language before any rule becomes final.
  • Watch the commercial products preference. Companies selling to government through modified commercial terms or hybrid arrangements should assess whether a stronger commercial item preference opens new contract vehicle opportunities or, conversely, eliminates certain cost-type vehicles currently available to them.

What Comes Next

Proposed FAR rules do not take effect until a final rule is published — a process that typically takes six months to two years after the comment period closes, depending on public input volume and whether the FAR Council makes significant changes in response. The bid protest change will draw heavy comment from the contractor community and law firms specializing in protests. Even if the full package does not advance intact, individual provisions — especially the cybersecurity reporting timeline and the drone ban — may move faster as final rules because they align with existing statutory authority and active policy priorities. Contractors should monitor FAR case tracking for interim final rules that could take effect on shorter notice.

The plain-language rewrite of the FAR base text also has practical implications for contract administration. Clauses that have accumulated non-statutory language over decades may emerge from the rewrite with narrowed scope or altered interpretation, which could affect existing long-term contract vehicles at option exercise or modification. Legal counsel familiar with both the current FAR text and the proposed revisions should conduct a gap analysis against active contracts before any final rules publish.

Sources