Skip to main content
USTelecom — The Broadband Association
Sample profile — content is illustrative. Verify every name, date, and status against official sources before use.
Back to Agency Atlas
DoWHigh activityReview recommended · 2026-07-10

Department of War

Sets defense procurement and cybersecurity requirements that flow down to communications suppliers, including CMMC certification, the Section 1260H Chinese military companies list, and DFARS restrictions.

One-minute briefing

Agency snapshot

The DFARS final rule implementing CMMC became effective November 10, 2025, starting a three-year phased rollout in which contracting officers have discretion to include CMMC requirements before full mandatory compliance on November 11, 2028. Members in the defense supply chain should be advancing toward the certification level their contracts will require. Confirm specifics against the DoD CIO CMMC page.

3
Active initiatives
1
Upcoming deadlines
2
Priority topics
Most important thing right now

Determine the CMMC level your DoD contracts will require and begin (or complete) assessment during the phased-in window before November 2028.

Mandate & jurisdiction

What this agency does

CMMC and DFARS requirements flow down to communications suppliers and subcontractors, gating eligibility for defense work.

CMMC program

Requires certification of contractor cybersecurity maturity to handle FCI/CUI.

DFARS flow-downs

Imposes security and sourcing requirements down the supplier base.

1260H list

Identifies Chinese military companies, affecting contractor relationships and reputational risk.

Jurisdiction

  • Defense acquisition and DFARS requirements
  • Contractor cybersecurity (CMMC)
  • Section 1260H Chinese military companies list
Who should care

Government contracting, security/compliance, and procurement teams.

Operational

Security control implementation and assessment readiness.

Compliance

CMMC certification and DFARS clause obligations.

Procurement

Subcontractor flow-downs and 1260H-related sourcing decisions.

Initiatives & deadlines

What they are working on now

ImmediateEffectiveProcurement and contracting 2025-11-10

CMMC program (DFARS final rule)

The DFARS final rule implementing CMMC is effective November 10, 2025, beginning a three-year phased implementation. Contracting officers may include CMMC requirements in new solicitations (excluding COTS-only), with full mandatory compliance for applicable contracts on November 11, 2028.

MonitorRecently changedProcurement and contracting 2026-08-07

Section 1260H Chinese military companies list

DoW periodically updates the Section 1260H list identifying Chinese military companies. On August 7, 2026 a U.S. District Court granted a preliminary injunction barring DoW from enforcing the June 8 designation of WuXi AppTec, the first successful challenge to a 2026 listing and a template other designees will use; Alibaba's separate challenge remains pending. Practitioner sources place the Section 805 implementing rule at RIN 0750-AM09 (Phase 1); if it is not published before Q4 2026, expect a surge in waiver applications ahead of the June 30, 2027 indirect procurement prohibition. China's June 22 retaliation (10 U.S. firms added to its export control list; 46 barred from government procurement) shows the compliance burden now runs both ways.

MonitorRecently changedProcurement and contracting 2026-08-14

CMMC Reform Task Force RFI (closed Aug. 14, 2026)

The DoW CIO’s CMMC Reform Task Force RFI closed at 12:00 p.m. ET on August 14, 2026 — it is no longer an open deadline. The Task Force report to the DoW CIO is expected mid-September 2026, and the July 13, 2026 Phase 2 suspension remains the operative status while reform is pending.

Upcoming dates

  • 2026-08-14CMMC Reform Task Force RFI closed (12:00 p.m. ET)
  • 2028-11-11CMMC full mandatory compliance for applicable DoD contracts
Key decision-makers

Leadership to know

We focus on the roles whose decisions reach members, and why each one matters — not biographical trivia. Names are intentionally withheld until verified against an official source.

Pete Hegseth
Secretary of War

Why it mattersSets defense acquisition and cybersecurity priorities.

Review recommended
Kirsten Davies
Department of War Chief Information Officer

Why it mattersOwns the CMMC program and cybersecurity policy; confirmed December 2025 and has paused CMMC Phase 2 pending a program review.

Review recommended
Working Group analysis

What we are watching

Confidence: ConfirmedSupported by a primary official source on file.

What changed

  • CMMC DFARS final rule effective Nov 10, 2025; three-year phase-in began.

What we are watching

  • Assessor capacity and how quickly COs insert CMMC clauses.
  • 1260H list additions.

Member exposure

  • Certification cost/time for contractors and subs.
  • Sourcing decisions tied to 1260H.

Recommended preparation

  • Confirm required CMMC level; schedule assessment early.
  • Screen supplier base against 1260H.

Open questions

  • How fast will CMMC clauses appear in your specific contract vehicles?
Primary references

Sources & verification

Agency-level sources

This profile is a sample interface. Leadership names, dates, regulatory status, and figures must be confirmed against current official sources before any member distribution.