Home / Blog / Regulatory News

Regulatory News September 30, 2026 8 min read

Reading Between the Lines: What the DoW’s Latest DFARS Deviation Says About China

Sentinel Blue
Sentinel Blue 8 min read
Reading Between the Lines: What the DoW’s Latest DFARS Deviation Says About China

If you’re in the DIB, you’ve been waiting (with varying degrees of patience) for a CMMC Phase II update since July 2026. We feel your pain.

Earlier this month, we got something else entirely from the DoW: an 80-page memo on a class deviation implementing the Revolutionary FAR Overhaul for FAR Part 40 and DFARS Part 240.

The memo doesn’t tell us anything new about Phase II, since it carries forward the suspension announced in July, but it does offer some interesting information if you compare it against the previous class deviation: All but one of the changes in the new version directly involve China. (Specifically, Chinese military companies, Huawei semiconductors, and Da-Jiang Innovations.)

It’s clear from these changes that the DoW sees a clear and present threat in China, and that it intends to keep Chinese-linked companies and components out of the defense supply chain wherever it can. While we continue to wait for a CMMC Phase II announcement, let’s look a little more closely at why the DoW is currently preoccupied with China and how this might affect U.S. defense contractors moving forward.

What Changed in DFARS Part 240

The memo in question is Class Deviation 2026-O0025, Revision 3 (not to be confused with NIST SP 800-171 Revision 3, which we write about here), and it replaces Revision 2 from July 2026. The Revision 2 memo featured two main changes: It temporarily waived the 10 U.S.C. 4663 prohibition for Alibaba Group, and it gave contracting officers direction on suspending CMMC Phase II implementation.

Read on its own, Revision 3 looks like any other dense acquisition document… but it gets more interesting when you look at what was updated.

Of the seven key changes we found, only one of them, on page 18, has nothing to do with China. (It’s an update to provisions on personally identifiable information, PII.) Every other revision points to the same country.

Three separate passages address companies designated as Chinese military companies: pages 20–21, 53–54, and 65–66.

Two passages deal with semiconductors sourced from Huawei: pages 28–31 and 66–68.

One passage details new provisions on foreign-made drones, naming Da-Jiang Innovations (DJI) and China as well as Russia, Iran, and North Korea: pages 68–71.

What Changed Where
Chinese military companies Pages 20–21, 53–54, 65–66
Huawei semiconductors Pages 28–31, 66–68
Foreign-made drones (DJI, Russia, Iran, North Korea) Pages 68–71
Personally identifiable information Page 18

Taken together, these changes all push in the same direction: making it harder to do business with China. That wouldn’t be remarkable on its own, since restrictions on Chinese military companies have been building for years and already appeared in Revision 2. What stands out is that the DoW devoted six of the seven changes in Revision 3 to a single adversary.

For contractors, this is a clear signal. Doing business with Chinese military companies, or relying on Chinese-sourced semiconductors and drones in your supply chain, is getting harder, and the DoW is prioritizing those restrictions heavily.

Why the DoW Has China in Its Sights

The DoW’s focus on China isn’t surprising. Plenty of adversaries threaten U.S. interests, but China is the only one challenging us on every front at once: militarily, economically, technologically, and in cyberspace.

It’s also the adversary with the longest track record of targeting the defense industrial base directly, through years of intellectual property theft aimed at the companies that build America’s weapons systems. When the DoW looks at its supply chain, China is the name that comes up most often.

Dmitri Alperovitch, CrowdStrike co-founder and chair of a geopolitics think tank focused on China, made much the same case when he joined our CEO Andy Sauer on a recent episode of The Watchers podcast.

“I actually can’t believe that anyone would even argue that this is not a new Cold War, and one that is remarkably similar on almost every level to the first one.”

Dmitri AlperovitchCo-founder, CrowdStrike

He noted that, according to the FBI, the level of Chinese espionage against the U.S. far exceeds what the KGB managed during the Soviet era.

China’s cyber activity is changing.

For most of the past two decades, Chinese cyber operations were about stealing: trade secrets, defense designs, and intelligence. That’s still happening, but now China is also quietly positioning itself inside U.S. critical infrastructure and… just sitting there.

In his Watchers episode, Alperovitch gave examples of the two types of intrusions. He contrasted Salt Typhoon, the ongoing breach of U.S. telecommunications providers using conventional espionage tactics, with Volt Typhoon, an ongoing threat against small water utilities, electric utilities, and pipelines. Unlike Salt Typhoon, which is primarily about the theft of useful information, Volt Typhoon is believed to be preparation for future conflict, giving China access it can use to disrupt U.S. infrastructure before or during a conflict over Taiwan.

Salt Typhoon

An ongoing breach of U.S. telecommunications providers using conventional espionage tactics, primarily about the theft of useful information.

Volt Typhoon

An ongoing threat against small water utilities, electric utilities, and pipelines, believed to be preparation for future conflict over Taiwan.

Chinese supply chain dependence is a major vulnerability.

America’s dependence on China’s supply chain is likely another reason why Revision 3 is getting more restrictive about Chinese military companies, including Huawei semiconductors and DJI. Every Chinese component in the defense supply chain is a potential point of leverage, whether as a channel for compromise, a dependency China can threaten to cut off, or both.

Currently, U.S. reliance on China extends beyond critical minerals and pharmaceutical ingredients to basic components like capacitors and fasteners. The strategic risk, in Alperovitch’s view, is if China believes the U.S. is too dependent to risk a confrontation.

“We don’t want them to think, ‘Oh, we’re so dependent on them that we will never fight for Taiwan.'”

Dmitri AlperovitchCo-founder, CrowdStrike

His advice is to move critical supply chains out of China and use export controls to keep China reliant on U.S. and allied technology… which is exactly what the Revision 3 changes indicate.

Ultimately, Alperovitch believes a conflict can still be deterred, but only if China believes the U.S. is both militarily capable and economically willing to follow through. Tightening the defense supply chain is one way the DoW can make that case, and Revision 3 suggests it intends to.

How China’s AI Progress Has Raised the Stakes

Hacking and supply chains aren’t the only fronts where China is gaining ground. It’s also moving fast on AI, another reason the DoW has China squarely in its sights. AI tools are already reshaping military planning, intelligence collection, and cyber operations, and whichever country leads in AI will hold immense advantage.

Right now, China is making the most of its momentum. Companies like DeepSeek, Moonshot AI, and Z.ai are releasing impressive open-source models so that anyone can download, modify, and build on them. Meanwhile, much of the U.S. response to AI risk has focused on restricting American developers and users rather than on outpacing China.

Consider the guardrails on U.S. frontier models. They’re meant to keep dangerous capabilities out of the wrong hands, but they can also block legitimate offensive security research. As a result, some U.S. security researchers are turning to Chinese open models like GLM to do their work. In other words, safeguards designed to protect U.S. interests are pushing responsible American researchers toward foreign-built, foreign-controlled tools.

Legislation is heading the same way. The AI Kill Switch Act, introduced by Reps. Ted Lieu and Nathaniel Moran after the OpenAI/Hugging Face incident, would require AI companies to be able to throttle, suspend, or shut down their models upon DHS’s orders. The concern here is understandable, but the mandate only places new constraints on U.S. companies while doing nothing to slow China’s open-source development.

None of this means we should let AI development go unchecked. But it does mean that the U.S. needs to be smarter about where it applies pressure. The strongest lever we hold is our compute power: According to Alperovitch, the most advanced AI chips are designed in the U.S. and manufactured largely by allies. Tighter export controls on semiconductor technology will help keep China from becoming self-sufficient on this front.

This is likely the logic behind the Huawei provisions in Revision 3. At home, the priority should be enabling rather than restricting, with more consistent guardrails, programs that give researchers access to the tools they need, and support for a strong, secure open ecosystem of U.S.-built models.

We know that AI is already compressing the timeline of cyberattacks from hours to seconds, and defense contractors will need AI-enabled tools just to keep pace. The U.S. can’t afford to slow itself down while China speeds up, and Revision 3 suggests that the DoW is taking the competition seriously by keeping more Chinese technology out of critical systems.

Takeaways: What This Means for Defense Contractors

The DoW hasn’t given the DIB a CMMC Phase II update yet, but it did send a message about where its attention is centered. For defense contractors, this focus on China can be translated into some practical recommendations.

Know where your components come from, including semiconductors and drone technologies. Expect more scrutiny of suppliers with ties to Chinese military companies. And don’t mistake the Phase II pause for a pause on the threat. The same adversary driving these supply chain rules is the one CMMC was built to defend against.

We’ll soon be releasing a research report on who’s attacking the DIB, including China and other nation-state adversaries, so keep an eye out for more data soon.

In the meantime, we’ll keep doing what we always do: watching how new and ongoing threats develop, strengthening operational resilience for the DIB, and translating what it all means for the companies that support America’s warfighters.

Share: LinkedIn X / Twitter Email

Ready to get to work? So are we.

Our cyber adversaries aren't waiting and neither are we. Let's get the conversation started.

Contact Us Today