Comment on FR Doc # 2026-12559
Anonymous AnonymousSupportOther
Summary: The commenter provides five specific technical recommendations for updating the Federal Acquisition Regulation (FAR). These include clarifying applicability, correcting terminology regarding Contracting Officer responsibilities, adding definitions for commercialization and computer programs, updating records retention citations, and incorporating due diligence requirements for foreign risk and cybersecurity.
1. Recommendation: FAR 1.101 says that the FAR is applicable to all acquisitions and all executive agencies. Please be more specific as to applicability.
Rationale: GSA and DHS issue CSO awards using Title 41 of the U.S.C., which are not required to be subject to the FAR (but can be subject to it like DoW CSOs are subject to the System). Additionally, OTs are not applicable to the FAR. For example, the authorities for DoW OTs are at 10 U.S.C. 4021, 4023, and 4023 are under Subtitle A, Part V – Acquisition. Further, all executive agencies, as defined at 5 U.S.C. 105, are not subject to the FAR.
2. Recommendation: Change FAR 1.404(a)(3)(i) to “Contracting officers may not designate…” Additionally, change “assign” to “designate” so that it reads, “Contracting officers may designate the COR…”
Rationale: FAR 1.404(a)(3)(i) says that COs may not delegate responsibilities to a COR that are delegated to a CAO under 42.202; however, FAR 1.404(a)(1) says that CORs are designated, not delegated. The same rationale about consistent usage of the word "designate" should be applied to the word “assign” to be consistent.
3. Recommendation: Add definitions at FAR 2.101 as follows:
a. “Commercialization (as related to the Small Business Innovation Research and Small Business Technology programs in accordance with 15 U.S.C. 638) means – (1) The process of developing products, processes, technologies, or services; or (2) The production and delivery (whether by the originating party or by others) of products, processes, technologies, or services for sale to or use by the Federal Government or commercial markets.”
b. “Computer program means a set of instructions, rules, or routines recorded in a form that is capable of causing a computer to perform a specific operation or series of operations.”
Rationale: The definition of “computer software” includes computer program, so the addition of a definition of “computer program” would be helpful in FAR 2.101, as well as FAR part 27 clauses. With the addition of SBIR/STTR requirements into the FAR, inclusion of these definitions would help promote the use of Phase III contracts. Additionally, the definitions reflect those used in 15 U.S.C. 638 and the SBIR/STTR Policy Directive.
4. Recommendation: In FAR 4.310, the records retention period in Table 4-3, number (8) should be updated to reflect FAR 52.227-20 or other SBIR/STTR data rights clause.
Rationale: First, FAR clause 52.227-30 is an incorrect citation. The FAR clause is FAR 52.227-20. Second, the SBIR/STTR Policy Directive includes a sample SBIR/STTR data rights clause in paragraph (5)(d)(3) of Appendix I, which some agencies have used in lieu of FAR 52.227-20 because of the incorrect protection period and directions in the clause that do not say that language can be “substantially the same as”.
5. Recommendation: Include requirements and create a provision and clause from 15 U.S.C. 638 in FAR part 40 related to due diligence/foreign risk evaluation, which includes a cybersecurity component and also concerns foreign ownership, control, and influence or beneficial ownership risk.
Rationale: 15 U.S.C. 638 includes a requirement for Federal agencies required by 15 U.S.C. 638(f) to establish an SBIR and/or STTR program to establish and implement a due diligence program to assess security risks presented by small business concerns. This program includes the assessment of cybersecurity practices of a small business concern, among other risks. The agency programs must assess awards and proposals, as applicable, and agencies are prohibited from making an award under certain circumstances (see 15 U.S.C. 638(g)(16) and (o)(20)). Further, during the performance of a contract, changes to disclosures, material misstatements, and changes to ownership, entity structure, or other substantial change in circumstances that pose a risk to national security may result in a termination and a requirement for the small business to repay all amounts received if there was a risk to national security.
Inclusion of a provision discussing the inability to award and a clause enforcing compliance with submitting disclosures during performance and repayment of funding received if a change to a disclosures during contract administration causes a risk to national security should be created.