ProductsIntelligenceLicensingAnalyst AccessPricingMethodologyContact
TECHNOLOGY, AI & COMPETITION

Defense Federal Acquisition Regulation Supplement

Technology and AI companies with Department of Defense contracts are navigating an accelerating series of DFARS rule changes that directly affect software supply chain security, AI system procurement, and data handling obligations. The Office of the Under Secretary of Defense for Acquisition and Sustainment, the Defense Contract Audit Agency, and the Defense Advanced Research Projects Agency each hold enforcement and contracting authority that touches how tech vendors price, disclose, and secure AI-enabled products sold to the federal government. Compliance teams are currently mapping DFARS 252.204-7012 cybersecurity clauses and the Cybersecurity Maturity Model Certification interim rule against their existing vendor and subcontractor agreements.

Watch

  • DFARS 252.204-7012 flowdown requirements for AI-integrated subcontractors
  • CMMC 2.0 final rule: Level 2 self-assessment deadlines for tech prime contractors
  • Defense Contract Audit Agency scrutiny of IR&D cost claims tied to AI R&D
  • Proposed DFARS rule on software bill of materials disclosure for DoD-facing SaaS products
  • Foreign ownership, control, or influence reviews affecting AI firm DoD eligibility

Recent material activity in Technology, AI & Competition

A selection of recent published briefs; this is not a complete archive.

  • Sep 25, 2026MATERIAL

    US CISA Cybersecurity release pending Cresthaven Analytics full analysis: KEV addition: CVE-2026-87902 — WordPress Core (WordPress Core Remote File Inclusion Vulnerability)

    US CISA Cybersecurity published a regulatory release titled 'KEV addition: CVE-2026-87902 — WordPress Core (WordPress Core Remote File Inclusion Vulnerability)'. Cresthaven Analytics' full intelligence brief is pending r…

    Read a full sample brief →
  • Sep 25, 2026MATERIAL

    CISA adds Microsoft SharePoint code injection flaw to Known Exploited Vulnerabilities catalog with federal remediation deadline of September 28 2026

    CISA added CVE-2026-65660, a code injection vulnerability in Microsoft SharePoint, to its Known Exploited Vulnerabilities catalog on September 25, 2026. The addition triggers mandatory remediation obligations for federal…

    Read a full sample brief →
  • Sep 25, 2026MATERIAL

    CISA adds MikroTik RouterOS behavioral-workflow vulnerability to Known Exploited Vulnerabilities catalog with federal remediation deadline of September 28 2026

    CISA added CVE-2026-67279, an improper enforcement of behavioral workflow vulnerability in MikroTik RouterOS, to its Known Exploited Vulnerabilities catalog on September 25, 2026. The vulnerability permits an unauthentic…

    Read a full sample brief →
  • Sep 25, 2026MATERIAL

    Canada Competition Bureau release pending Cresthaven Analytics full analysis: Competition Bureau to publish a call for information on pricing rules in retail grocery

    Canada Competition Bureau published a regulatory release titled 'Competition Bureau to publish a call for information on pricing rules in retail grocery'. Cresthaven Analytics' full intelligence brief is pending re-analy…

    Read a full sample brief →
  • Sep 25, 2026MATERIAL

    UK CMA Competition release pending Cresthaven Analytics full analysis: Macquarie Asset Management / Energy Assets Group merger inquiry

    UK CMA Competition published a regulatory release titled 'Macquarie Asset Management / Energy Assets Group merger inquiry'. Cresthaven Analytics' full intelligence brief is pending re-analysis; see the source link below …

    Read a full sample brief →
  • Sep 25, 2026MATERIAL

    CMA publishes interim market study update on early years education and childcare services in England

    The CMA published a market study update on September 25, 2026, covering evidence gathered since the study launched on July 1, 2026. The update sets out findings to date and signals how the CMA's analytical thinking is de…

    Read a full sample brief →
  • Sep 25, 2026MATERIAL

    China's SAMR publishes antitrust penalty decisions against two Chongqing municipal gas distributors for cartel conduct

    The State Administration for Market Regulation published administrative penalty decisions by the Chongqing Municipal Market Supervision and Administration Bureau against two piped-gas enterprises in Jiangjin District. Th…

    Read a full sample brief →
  • Sep 25, 2026MATERIAL

    China's SAMR publishes five administrative penalty decisions against Tibet concrete firms for cartel conduct

    The Tibet Autonomous Region Market Supervision and Administration Bureau concluded a monopoly-agreement investigation against five concrete enterprises, including Linzhi Lantian Concrete Co. Ltd. The investigation opened…

    Read a full sample brief →
  • Sep 24, 2026MATERIAL

    CISA adds Adobe Commerce and Magento authorization flaw to Known Exploited Vulnerabilities catalog with federal remediation deadline of September 27 2026

    CISA added CVE-2026-71362, an incorrect authorization vulnerability in Adobe Commerce and Magento, to its Known Exploited Vulnerabilities catalog on September 24, 2026. The vulnerability allows unauthenticated privilege …

    Read a full sample brief →
  • Sep 24, 2026MATERIAL

    CISA adds WSO2 path traversal vulnerability to Known Exploited Vulnerabilities catalog with federal remediation deadline of September 27, 2026

    CISA added CVE-2026-5430 to its Known Exploited Vulnerabilities catalog on September 24, 2026. The vulnerability is a path traversal flaw affecting WSO2 API Control Plane, API Manager, Traffic Manager, and Universal Gate…

    Read a full sample brief →