On June 12, 2026, President Trump signed National Security Presidential Memorandum 12 (NSPM-12), which establishes a new cybersecurity governance framework for National Security Systems (NSS). This framework applies to federal agencies that own or operate NSS, which includes any contractors that operate NSS on behalf of a federal agency.
Key takeaways for government contractors that own or operate NSS include that:
- All NSS must meet or exceed the National Institute of Standards and Technology cybersecurity standards, unless the Committee on National Security Systems (CNSS) provides otherwise.
- The Director of the National Security Agency (NSA) may issue “emergency directives” that instruct federal agencies to protect NSS from threats, vulnerabilities, and risks. Government contractors that own or operate NSS must comply with any such directives.
- Over the next 120 days, CNSS will issue updated NSS configuration standards, incident reporting formats, and cryptographic requirements.
NSPM-12 Applies to Contractors Operating NSS
NSPM-12 applies to federal agencies that own or operate NSS, which includes any contractors that own or operate NSS on behalf of a federal agency. NSS has a relatively broad definition that encompasses systems that process classified information, involve intelligence activities, involve command and control of military forces, or are critical to the direct fulfillment of military or intelligence missions. See 44 U.S.C. § 3552. Common types of NSS include cloud service providers, managed security service providers, and systems integrators.
What NSPM-12 Does
NSPM-12 re-establishes the CNSS as the principal governance body for NSS cybersecurity, and re-designates the Director of the NSA as the National Manager for NSS. Among other things, the Director of the NSA may issue binding emergency directives to any federal agency including directives requiring immediate operational changes to covered systems. The memorandum harmonizes NSS requirements with Executive Order 14306 (June 6, 2025), establishing NIST cybersecurity standards as a mandatory baseline for all NSS unless the CNSS provides otherwise.
Key Compliance Deadlines
NSPM-12 establishes an aggressive implementation timeline that will generate new regulatory requirements in rapid succession:
- Within 30 days (by July 12, 2026), the CNSS must revise CNSS Directive 900, updating the governing and operating procedures for the committee. Contractors should monitor these revisions closely, as they will define the procedural framework for all subsequent CNSS activity.
- Within 60 days (by August 11, 2026), agencies must update their incident response policies to incorporate new NSS-specific reporting standards, once the National Manager publishes recommended thresholds. Cloud service providers accredited to host NSS must prepare to submit configuration baselines to the CNSS within 120 days. Critically, agencies and their contractors operating NSS on their behalf must maintain and annually update a formal inventory of all NSS owned or operated and make those inventories available to the National Manager.
- Within 90 days (by September 10, 2026), the CNSS will complete a comprehensive review of all existing CNSS policies, directives, and instructions, with rescissions and harmonization to follow. The CNSS will also issue guidance on cloud security requirements for NSS at the Secret, Top Secret, TS/SCI, and SAP classification levels directly affecting any contractor providing cloud-based services to the intelligence community or Department of Defense.
What This Means for Defense Contractors
Any company that owns, operates, or provides services to a system meeting the NSS definition must review its existing cybersecurity posture now. The most immediate obligations are contractual and operational: existing government contracts will need to be reviewed for cybersecurity clauses that may require updating to reflect new CNSS directives; incident response plans must be revised to align with forthcoming reporting thresholds; and NSS inventory requirements must be satisfied as an ongoing compliance matter.
The National Manager’s emergency directive authority is particularly significant. Under NSPM-12, NSA can issue a directive to any agency including civilian agencies requiring immediate action with respect to an NSS, including systems “used or operated by another entity on behalf of an agency.” This means a directive can flow directly to a contractor operating an NSS under a government contract, requiring operational changes on short notice with no requirement for the contractor's consent.
The memorandum also strengthens accountability mechanisms. The CNSS may request government-wide assessments of NSS cybersecurity posture, including performance metrics and compliance results, and CNSS findings may be reported to Congress and the Council of Inspectors General on Integrity and Efficiency. Contractors with deficient cybersecurity postures risk contract non-compliance findings, adverse past performance assessments, and potential False Claims Act exposure where cybersecurity certifications are incorporated into contract representations.
Cloud Providers and Cross-Domain Solutions
Companies providing cloud services to the federal government at classified levels face discrete obligations under NSPM-12. Within 120 days, cloud service providers accredited to host NSS must submit configuration baselines and security specifications to the CNSS, which will evaluate them against NSS requirements. Providers operating at TS/SCI and SAP classification levels should begin preparing those baseline submissions now and should expect the CNSS cloud security report due within 90 days, to define new accreditation standards that could affect existing FedRAMP authorizations.
The memorandum also establishes NSA as the principal advisor to NSS owners and operators on cross-domain solutions, the hardware and software products that allow data to move between systems operating at different classification levels. Contractors providing or integrating cross-domain solutions should anticipate updated standards and a revised CNSS-approved products list.
How WBD Can Help
Womble Bond Dickinson’s International Trade and National Security Practice attorneys advise defense contractors, intelligence community support companies, and federal agencies on the full spectrum of NSS compliance obligations. Our team has deep experience with CNSS policy frameworks, NSA technical security requirements, contracting structures, and the intersection of cybersecurity obligations with government contracts law. We also advise clients on cybersecurity compliance and related False Claims Act and government contracts enforcement risk.
Specific services include: NSS inventory audits and classification assessments; NIST cybersecurity compliance, contract clause review and modification for CNSS directive compliance; incident response policy drafting and updating; cloud accreditation and FedRAMP-to-NSS gap analysis; and counsel on National Manager emergency directive response.

/Passle/6878183c1547331efeed13be/SearchServiceImages/2026-08-06-14-12-11-890-6a74963bf96ff179f854a7d0.jpg)
/Passle/6878183c1547331efeed13be/SearchServiceImages/2026-08-03-17-36-32-417-6a70d1a0b949cf9a2cde52c5.jpg)
/Passle/6878183c1547331efeed13be/SearchServiceImages/2026-07-27-15-27-13-095-6a6778d12f7f4abc62410a19.jpg)