Section 866 of the FY 2026 National Defense Authorization Act directs the Secretary of Defense to harmonize the cybersecurity requirements applicable to the defense industrial base and eliminate duplicative and inconsistent cybersecurity requirements, including reducing the number of requirements that are unique to a specific contract. The provision sets an initial harmonization-completion deadline of June 1, 2026, with the first congressional report due by the end of 2026 and annual reports thereafter. DoD has not publicly indicated whether it will meet the June 1 deadline.
The Problem Section 866 Is Meant to Fix
The proliferation of cybersecurity contract requirements in the DFARS is a product of the way federal cybersecurity policy has evolved since the early 2000s: each new statutory authority, IG report, or significant cyber incident has typically produced a new clause or reporting requirement layered on top of the existing framework without systematic coordination. The result is a contract compliance environment in which a defense contractor may simultaneously be subject to DFARS 252.204-7012's NIST 800-171 implementation requirement, one or more program-specific software assurance clauses, supply chain risk management provisions, and incident reporting timelines that don't always align with the 72-hour window in DFARS 7012. Contractors have long argued that the overlapping requirements create compliance confusion and unnecessarily increase compliance costs without producing meaningfully better security outcomes than a single well-designed framework would achieve. Section 866 is Congress's direct response to that concern.
CMMC as the Likely Consolidation Anchor
Public DoD statements and DFARS rulemaking commentary point toward CMMC becoming the primary compliance framework, with other cybersecurity clauses restructured as supplements to CMMC rather than standing as independent requirements. Under that approach, a contractor that has achieved CMMC Level 2 certification would be presumed to satisfy the core requirements of DFARS 252.204-7012 and related provisions, and additional program-specific clauses would reference CMMC-equivalent requirements rather than creating separate compliance tracks. How much of this DoD ultimately proposes — and whether it hits the June 1 deadline — will become clear once the harmonization plan itself is public.
What It Means for Contractors
Whatever the final architecture, the harmonization effort will shape the cybersecurity compliance landscape for defense contractors over the next several years.
- Contractors currently managing multiple overlapping cybersecurity compliance obligations on DoD contracts should document the compliance costs associated with each — time, personnel, and third-party assessment costs — since that record becomes useful once DoD solicits industry input on implementation.
- A CMMC-centric consolidation would accelerate the practical importance of CMMC Level 2 certification as a single compliance credential across the defense contracting base; companies behind on CMMC preparation should treat Section 866 as additional incentive to move up their certification timeline.
- Congress will receive DoD's harmonization report before any consolidated framework becomes effective; contractors that want to influence the outcome should engage their congressional delegations' defense policy staff and relevant industry associations during that review period.