- Planet Compliance
- Posts
- New NDAA Rules Expand Compliance Requirements for Defense Contractors
New NDAA Rules Expand Compliance Requirements for Defense Contractors

📝Editor’s Note
Compliance teams are dealing with a growing number of regulations that overlap across cybersecurity, supply chains, AI, and privacy. The organizations making the most progress are treating compliance as an ongoing business function rather than a series of annual audits.

📊Featured Analysis
New NDAA Rules Expand Compliance Requirements for Defense Contractors
A major change to the U.S. National Defense Authorization Act (NDAA) is reshaping how defense contractors manage supplier relationships. While Section 1260H itself does not prohibit U.S. companies from doing business with listed entities, it requires the Department of Defense (DoD) to identify companies believed to have ties to the Chinese military under China's military-civil fusion strategy.
The compliance landscape changed in June 2026, when Section 805 of the FY2024 NDAA took effect. The provision prevents the DoD from entering into, renewing, or extending contracts with companies listed under Section 1260H. The requirements will expand again in June 2027, when the restrictions will also apply to private contractors that source products or components from companies on the Section 1260H list.
These phased changes mean organizations supporting the DoD should begin mapping their supply chains now. Companies may need stronger supplier due diligence, better visibility into upstream sourcing, and continuous monitoring to identify exposure before the 2027 deadline.
Key takeaway: The biggest compliance challenge isn't just knowing whether a company appears on the Section 1260H list—it's identifying whether your supply chain depends on businesses that do.

✅ Best Practice Spotlight
Five Ways to Strengthen AI Governance
Define which AI tools employees are approved to use.
Create a review process for AI systems that handle sensitive or regulated data.
Document how AI-generated outputs are verified before use.
Review AI vendors for security, privacy, and regulatory compliance.
Update AI policies regularly as new laws and guidance emerge.

🛠️ Tool of the Week
Medical Coding Compliance Software
Medical coding compliance software helps healthcare organizations reduce billing errors, improve coding accuracy, and maintain compliance with evolving healthcare regulations. These platforms automate coding validation, identify documentation gaps, and support audit readiness while helping providers reduce denied claims.
What to look for:
✔️ Automated coding validation and error detection
✔️ ICD-10, CPT, and HCPCS code updates
✔️ Audit trails and compliance reporting
✔️ EHR and billing system integration
✔️ Analytics to identify coding trends and reimbursement risks
🌟 Leader Spotlight
GEICO Takes Action Against Alleged Insurance Fraud Network
GEICO has filed a lawsuit alleging that nine companies participated in a $3.3 million no-fault insurance fraud scheme involving staged or unnecessary medical treatments and fraudulent billing practices. According to the complaint, the network submitted claims that violated New York's no-fault insurance requirements, highlighting the ongoing challenge insurers face in detecting organized fraud. The case underscores the importance of robust claims monitoring, billing oversight, and investigative compliance programs. It also demonstrates how insurers are increasingly using legal action alongside analytics to combat sophisticated fraud networks.

📚 Recommended Reading
🗳️ Your Compliance Take

