Surviving the Policy Pendulum
A Resilience Framework for Government Contractors Facing Administration-Driven Regulatory Change
For government contractors (GovCons), regulatory change is no longer an occasional disruption but a permanent operating condition. This pattern has repeated across the Obama, Trump (45), Biden, and Trump (47) administrations. Each transition has brought new priorities, policy directives, and compliance expectations that reshape how agencies award, oversee, and manage contracts. While the specifics of each administration differ, the need for organizations to adapt quickly and confidently remains constant.
The GovCons that consistently succeed are not those that react fastest to each new requirement. They are the organizations that have built resilient governance, compliance, and operational processes that can accommodate change without sacrificing performance. Rather than viewing every policy shift as a new challenge to overcome, leading organizations treat regulatory volatility as a strategic business reality.
This article presents a practical framework for doing just that. It explains how to distinguish enduring compliance obligations from short-term policy changes and outlines a four-pillar resilience model that helps leadership teams strengthen decision-making, reduce disruption, and remain competitive regardless of how the regulatory environment evolves.
Which Compliance Requirements Are Actually Durable?
Not all regulatory change carries the same risk of reversal. The single most useful distinction for a GovCon compliance officer to make is between requirements that are codified in statute (durable) and requirements that exist only through Executive Order, proposed rule, or class deviation (volatile, and reversible by the next administration without congressional involvement).
| Policy Area | Mechanism | Durability | Reversal Risk |
|---|---|---|---|
| GHG Disclosure (FAR 23.5) | Proposed Rule / Executive Order | Low | Withdrawn before the change in administration took effect. |
| NDAA-set CAS & TINA Thresholds | Statute (FY 2026 NDAA) | High | Requires new legislation to reverse. |
| Revolutionary FAR Overhaul Reforms ( FAR 23.5 Eliminated ) | Class Deviation | Low–Medium | Can be rescinded administratively without Congressional action. |
| DEI Certification Requirements | Executive Order (EO 14398) | Low–Medium | Can be rescinded by a future Executive Order. |
| FAR Subpart 31.2 Cost Principles | Codified FAR Text | High | Unaffected by the Revolutionary FAR Overhaul; changing them would require formal rulemaking. |
The Greenhouse Gas (GHG) disclosure proposal is the clearest cautionary example. The Biden Administration’s proposed rule, published November 14, 2022 (87 FR 68312) under Executive Order 14030—Climate-Related Financial Risk, would have required mid-sized contractors ($7.5M–$50M) to disclose Scope 1 and 2 emissions, and large contractors (over $50M) to disclose Scope 1, 2, and 3 emissions and set science-based targets. Because the rule was never codified into statute, it was withdrawn a week before the Trump 47 inauguration, and FAR Subpart 23.5 was eliminated entirely under the Revolutionary FAR Overhaul. Contractors who had already built emissions-tracking infrastructure in anticipation of the rule did not waste that investment. By contrast, contractors who waited to comply until the rule was finalized never had to comply at all, but they also never built a durable capability for the version of this rule that eventually returns.
Quick-Reference Resilience Checklist
Organizations that can answer "Yes" to most of these questions are generally better positioned to navigate future procurement policy changes.
-
✓We can distinguish, in writing, which of our compliance obligations are codified versus administratively reversible.
-
✓We hold a balanced contract portfolio across contract types, agencies, and (where applicable) civilian and defense customers.
-
✓We maintain a dedicated financial reserve for regulatory transition costs.
-
✓Our compliance systems are designed to satisfy the strictest plausible near-future standard—not just today's minimum requirement.
-
✓Legal has reviewed our DEI, SBA 8(a) Business Development Program, and CAS/TINA exposure under current thresholds and certification requirements.
-
✓We conduct a recurring annual regulatory review rather than reacting after each Executive Order or FAR revision.
-
✓Our FY 2028–2029 strategic plan includes at least one "administration flips" scenario with corresponding budget and compliance implications.
The Current Environment (2025–2026): Five Shifts in Motion
The framework above is not theoretical. It responds directly to five concurrent developments reshaping GovCon compliance right now.
- SBA 8(a) Program Scrutiny. SBA requested three years of financial records from 4,300 firms; roughly 15% refused, triggering termination proceedings against 628 firms. A proposed rule regarding 8(a) eligibility would also remove the rebuttable presumption of social disadvantage for certain designated groups, though entity-owned small businesses (tribal, Alaska Native Corporations, Native Hawaiian Organizations, and Community Development Corporations) are unaffected.
- Elimination of DEI Requirements. EO 14398 (March 31, 2026) requires contractors to certify they do not engage in protected-class-based preferential treatment across hiring, promotion, training, and vendor selection, at every subcontractor tier. Noncompliance risk has shifted from an employment-law issue into a False Claims Act and qui tam exposure issue.
- The Revolutionary FAR Overhaul (RFO). A roughly 25% reduction in FAR volume and elimination of about 2,700 acquisition mandates, aimed at faster procurement and reduced burden. Core cost-reimbursable compliance is untouched: FAR 52.216-7, incurred cost submissions, indirect rate reviews, DCAA oversight, and the 52 cost principles under FAR Part 31 all remain in force. Government contractors must still follow FAR Subpart 15.4 for cost/price proposals, and the proposed rule (RFO) makes only cosmetic changes. Certified Cost or Pricing Data requirements and Table 15.2 proposal format remain unchanged, while estimating system language is trimmed (though requirements persist) and profit policy subsections are partially, not fully, removed.
- The FY 2026 NDAA. Authorizes $900.6B for Department of War activities and codifies several reforms so they survive future administrations. Key provisions (defense contracts only): a Best Value standard for defense Multiple Award Schedule orders; the TINA cost-or-pricing threshold raised from $2.5M to $10M and decoupled from CAS minimum coverage; CAS thresholds raised (Modified-CAS minimum now $35M, Full CAS now $100M); a bid-protest reform withholding up to 5% of payment on meritless US Government Accountability Office (GAO) protests; and a Nontraditional Defense Contractor exemption from FAR Part 31.2 cost principles and certified cost-or-pricing data for firms without a full year of Full CAS coverage. Separately, Small Business Innovation Research (SBIR)/Small Business Technology Transfer (STTR) was reauthorized through September 30, 2031, via the Small Business Innovation and Economic Security Act (S.3971), signed April 13, 2026.
- DCAA Capacity Strain. Federal workforce reductions have shrunk DCAA staffing from approximately 4,800 to 3,900, with further agency-wide reductions rumored ahead of an October 1, 2026 deadline. Office consolidations, relocations, and pending updates to audit programs (including changes to the Incurred Cost Electronically Model (ICE) workbook schedules) mean contractors should expect continued uncertainty in audit timing and consistency, independent of any FAR or NDAA change.
How GRF Can Help
The policy pendulum is unlikely to slow down, and responding to one Executive Order at a time is not a sustainable strategy. Organizations that succeed over the long term are those that build resilient governance, compliance, and operational capabilities that can adapt as regulations and priorities evolve.
At GRF CPAs & Advisors, we help government contractors move beyond reactive compliance. Our professionals work with organizations to develop durable-versus-volatile compliance frameworks, strengthen governance processes, build financial resilience, and implement systems that support ongoing DCAA and FAR readiness. We also advise clients on cybersecurity, internal controls, enterprise risk management, tax strategy, transaction advisory, joint ventures, and mergers and acquisitions. For some organizations, that may include evaluating whether a strategic acquisition or other exit strategy is the best path to achieving long-term growth and stability.
Regardless of where your organization is in its lifecycle, the objective is the same: build an operating model that can withstand regulatory change, support informed decision-making, and position the business to compete with confidence in any administration.
Contact
Learn more about GRF’s Government Contracting practice and advisory services at www.grfcpa.com.