NDAA FY2026 Section 1513: CMMC Is Coming for Your AI Stack

NDAA FY2026 Section 1513 extends CMMC-style security requirements to DoD AI systems — and the framework is being built right now.

By Containment.ai Research  ·  Published August 3, 2026  ·  Product status: Trust page →
One control plane, three moments of risk. The same deterministic discipline governs three boundaries: the human prompt (AI Chat Firewall, between an employee and the AI provider), the agent action (Agent Governance, between an agent and a tool or system), and the mission boundary (Mission Authorization Gateway, between an AI system and an edge, domain, or OT environment). All three run intercept, canonicalize, evaluate, enforce, audit.
FIG. A — ONE ENFORCEMENT LAYER, THREE MOMENTS OF RISKCONTAINMENT.AI

For defense contractors already wrestling with CMMC, there is a new variable: your AI and machine learning systems are next.

The National Defense Authorization Act for Fiscal Year 2026 (P.L. 119-60) — signed into law on December 18, 2025 — includes Section 1513, which establishes physical and cybersecurity procurement requirements for covered DoD AI and machine-learning systems. The provision directs the Department of Defense to develop a comprehensive, risk-based framework for AI and machine learning cybersecurity and to incorporate that framework into the Defense Federal Acquisition Regulation Supplement (DFARS) and the Cybersecurity Maturity Model Certification program.

In plain terms: CMMC is being extended to AI.

What Section 1513 Actually Requires

The statute covers AI/ML acquired by DoD and all associated components — source code, model weights, and the methods, algorithms, data, and software used to develop the AI/ML. Contractors developing, deploying, storing, or hosting AI/ML for DoD fall within the framework's reach.

The framework must be implemented as "an extension or augmentation" of existing DoD cybersecurity frameworks, including CMMC. It will apply stringent security requirements aligned with protections for national security systems, with a specific focus on highly capable AI systems that may be of highest interest to cyber threat actors.

A key milestone has already passed: the Department owed Congress a status report on the framework's implementation plan by June 16, 2026 — 180 days after enactment. The framework is not a distant prospect; it is being built now.

Why This Is Different From Previous CMMC Guidance

CMMC Phase 1 began on November 10, 2025. Defense contractors have spent the past two years gearing up for it. But CMMC was built to verify that contractors can safeguard sensitive information — federal contract information (FCI) and controlled unclassified information (CUI) — in nonfederal systems. It was not built for AI systems.

The difference matters. An AI boundary is not a network boundary. A model weight is not a document. An inference call is not a file transfer. The access control and audit-trail requirements for a production LLM or autonomous decision system are fundamentally different from those for a SharePoint folder.

Section 1513 acknowledges this gap and fills it with a mandate: contractors must demonstrate that they govern their AI stack with the same rigor they apply to their cybersecurity posture.

The Compliance Pattern Defense Contractors Need

What does "governing your AI stack" look like in practice under a CMMC-adjacent framework? The signal from the statute is clear: lifecycle security, activity logging, traceability, protections against model tampering, and controls over data leakage.

Those requirements map directly to what a deterministic AI boundary control layer provides:

  • Intercept — every inference call is caught before it leaves the boundary
  • Policy evaluation — each call is evaluated against a defined governance policy (classification, content, behavioral constraints)
  • Enforce — non-compliant calls are blocked, clamped, or routed to a human reviewer
  • Record — a signed, tamper-evident receipt is generated for every decision

This is not a logging addon bolted onto an existing LLM deployment. It is the governance layer that makes an AI system auditable — the kind of evidence trail a CMMC assessor or a contracting officer reviewing DFARS clauses will eventually require.

What Contractors Should Be Doing Now

Section 1513 does not yet have a published implementation deadline, but the trajectory is familiar. CMMC began with a provision in the FY2020 NDAA and took years to finalize — yet many contractors still found themselves unprepared. The smart move is to act before the DFARS clause lands.

Specifically:

  1. Inventory your AI/ML surface. Identify every system that develops, deploys, stores, or processes AI/ML outputs for a DoD program. Model weights, inference endpoints, fine-tuning pipelines — all of it.

  2. Map your boundary. Understand where data flows from human operators to AI systems and back. Where are inference calls made? Who authorizes them? What happens if an AI system produces an unsafe or out-of-policy output?

  3. Implement deterministic controls. Probabilistic guardrails — content filters, instruction-following, RLHF-based safety training — are not auditable. They do not produce a compliance artifact. Deterministic enforcement at the boundary does.

  4. Generate the audit trail. The CMMC assessment model is built around evidence. AI governance needs the same evidentiary foundation: a signed receipt per enforcement decision, a policy version number, and a human-reviewable log.

The June 16 Signal

The status report DoD owed Congress by June 16, 2026 is not a compliance deadline for contractors — it is a forcing function for the Department itself. The implementation plan it describes will become the blueprint for what DFARS AI clauses eventually require.

Contractors who instrument their AI boundary while the framework is still being drafted will be in a materially better position than those who wait for the clause. The compliance clock is not reset when the DFARS is amended — it has been running since December 18, 2025.


Containment.AI builds the Mission Authorization Gateway — a deterministic, non-bypassable enforcement layer for AI systems operating in safety- and security-critical environments. Every inference call is intercepted, policy-evaluated, enforced, and logged with a signed receipt. Learn how it works →

READY TO CLOSE THE GAP?
Deterministic AI governance for regulated and mission environments.
Request a 30-minute Boundary Review → Apply to the Design Partner Program → Keep controlled data out of public AI →