The Revolutionary FAR Overhaul (RFO) finally has moved into formal rulemaking, and it comes with a few surprises. The FAR Council completed the first phase of the RFO in September 2025, publishing model deviations to the FAR that agencies then had to adopt by issuing their own deviations and guidance. We digested the changes, organized by FAR part, here.
To begin making the FAR changes official, the FAR Council published four proposed rules[1] on June 23, 2026, covering Parts 1, 2, 3, 4, 5, 6, 7, 10, 18, 24, 26, 29, 33, 37, 39, 40, 41, 49, and 53. For the most part, the proposed rules adhere closely to the 2025 deviations. However, there are a few meaningful changes to watch, including an updated Controlled Unclassified Information (CUI) rule in Part 40 and an abbreviated timeline for Terminations for Convenience in Part 49. Stay tuned for our forthcoming, in-depth analysis of the proposed CUI rule.
Below we have highlighted the more substantial changes between the proposed rules and the 2025 RFO deviations. Public comments on the proposed rules are due by July 23, 2026—30 days from publication.
Part 5: The proposed rule shifts commercial acquisition references to FAR Part 12 and revises certain presolicitation and award announcement and posting requirements. The proposed rule clarifies that, even when relying on national security authority, agencies must post a presolicitation notice unless the notice would reveal sensitive information. Additionally, contracting officers may but are no longer required to publicly announce awards over $5.5 million.
Part 6: The most significant change to FAR Part 6 is a dramatic relaxation of the justification and approval thresholds for “other than full and open competition” awards for DOD, NASA, and the Coast Guard. For example, the proposed rule increases the contracting officer self-certification ceiling from $900,000 to $10 million and the senior procurement executive threshold from $150 million to $500 million. It also expands sole-source flexibility by making the list of qualifying circumstances under Section 6.103-1 non-exhaustive, adding agency standardization programs as a new basis, and permitting sole-source consideration of unsolicited proposals that do not meet traditional “unique and innovative” research criteria. This means defense and space agencies can approve high-dollar sole-source contracts at lower organizational levels, reducing oversight for high-value non-competitive awards.
Part 7: A notable change from the FAR Part 7 RFO deviation is the addition of FAR 7.201 Market Research Requirements. FAR 7.201(f) establishes a hierarchy for the government to follow when beginning the acquisition cycle that prioritizes commercial products and services. Procurement officials must now first look to existing governmentwide contracts for commercial solutions to satisfy the agency’s requirements and, if none exist, must consider whether the agency can modify its requirements to fit available governmentwide solutions. An agency must next look to commercial products or services or consider modifying the agency’s needs to meet existing commercial products or services. Only if the agency’s needs cannot be met through the above steps should it solicit a non-commercial solution, referred to as a “nondevelopmental item.” This hierarchy aligns with the Administration’s policy focus on commercial solutions.
Part 33: The proposed rule adds new procedures for agency-level bid protests and ostensibly seeks to make agency-level protests more attractive and informative to protestors. The proposed rule would require agencies to give protestors a redacted copy of the final technical evaluation of their proposals. Currently, protestors are only entitled to a redacted copy of the source selection decision.
Part 39: Changes to FAR Part 39 include the addition of the National Initiative for Cybersecurity Education (NICE) Cybersecurity Framework, now defined at FAR 39.002 in the proposed rule. The NICE Cybersecurity Framework was developed by the National Institute of Standards and Technology (NIST) to standardize cybersecurity workforce tasks, knowledge, skills, and work roles. Agencies would utilize the NICE Framework when evaluating the competence of contractors in solicitations for information technology services.
Part 40: The proposed rule significantly updates FAR Part 40, which covers information security and supply chain security. In addition to including a “do not buy” list prohibiting certain products and sources from the federal supply chain, the proposed rulemaking adds several FAR provisions implementing the executive branch’s CUI program. The updated FAR Part 40 and new FAR Part 52 solicitation provisions and contract clauses will have a significant impact on contractors who handle CUI as part of contract performance. The proposed CUI requirements, first introduced in a January 2025 rulemaking, will require contractors who adhere to security controls established by the NIST report cyber-incidents within 72 hours of discovery. The proposed rule also introduces a new Standard Form dictating whether and how contractors will be obligated to safeguard CUI. While these requirements sound like the DOD’s Cybersecurity Maturity Model Certification (CMMC) program, the proposed FAR requirements differ in several significant ways, which we will explore in a later blog dedicated to the topic.
Part 49: The proposed rule makes significant changes to the termination process in FAR Part 49 that were missing from the initial RFO deviation. Contractors should take note that the proposed rule would significantly reduce deadlines associated with a termination for convenience. After notice of a termination for convenience, contractors would have only 90 days (down from one year) to submit a termination settlement proposal and 60 days to request an extension of that deadline. In addition, contractors would have 60 days (down from 120 days) to submit an inventory disposal schedule, and 30 days to request an extension. The proposed rule would also replace mandatory audits of settlement proposals triggered by certified cost/pricing data thresholds with a discretionary risk-based approach based on the individual Termination Contracting Officer’s evaluation.
The Fox team will continue to monitor the rulemaking process.
[1] The four proposed rules are available at 91 Fed. Reg. 37550, 37698, 37676, and 37636.