Agenda
Flip through our conference brochure and discover what’s new this year.
Download Brochure
Pre-Conference Primer
September 28, 2026
Pre-Conference Registration and Continental Breakfast
Close of Pre-Conference Primer
Day 1 — Main Conference
September 29, 2026
Registration
Networking Break
FOCI EXPANSION
Examining DCSA’s Expanded Scope Under Incoming 847 Revisions: How the Impact Will Affect Classified and Unclassified Contracts Mean in Practice

Curtis H. Chappell, ISP®Vice President, SecurityThales Defense & Security, Inc.

Richard RayFSOEutelsat Network Solutions

John O’LoughlinPartnerWeil
Prepare for DCSA reviews to include contracts of approximately $5 million or more—covering both classified and unclassified awards, as well as pre-award stages. Previously, FOCI was limited to contractors and subcontractors performing classified work. The proposed shift is expected to increase disclosure and oversight expectations. This session will address Section 847 applicability, thresholds, and reporting requirements.
- Examining the timeline and current status of implementing the revisions (expected rollout)
- How this implementation will work legally
- Determining the applicability to uncleared vs. cleared companies
- Expansion of FOCI requirements to foreign-owned entities
- Best practices for preparing for the what if’s and uncertainties in the adoption process
- Determining whether something qualifies as a commercial product or commercial service in accordance with FAR 2.101, and the related questions about beneficial ownership once that determination is made
- Anticipating when will DCSA will develop new templates specifically tailored to mitigating FOCI risks unrelated to classified contracts
The New Reporting Requirements for Contractors in Unclassified Environments: Under the Expanded Scope of SF-328

Matthew BarbeDirector of SecurityHanwha Defense USA, Inc.

Jason GarkeyChief Security OfficerMomentus

Andrew K. McAllisterPartnerHolland & Knight LLP
Previously limited to cleared government contractors, the expanded SF-328 form will now also apply to certain contractors operating in unclassified environments, depending on the contract type. It is expected to require more expansive disclosures, giving DCSA deeper insight when evaluating an entity’s foreign relationships. This interactive session will include completing mock forms and interactive discussions.
- Navigating expanded ownership reporting requirements challenges
- Sharing best practices for form completion
- Clarifying how much information is required to complete the form, beyond standard legal and financial disclosures
- Determining when the new form must be used beyond initial submissions, such as during FOCI reviews, ownership changes, and renewals
- Identifying what FSOs need to know to meet reporting requirements

Jennifer BrownVice President, Federal SecurityHP
Outside Director
WSP USA

Curtis H. Chappell, ISP®Vice President, SecurityThales Defense & Security, Inc.

Norm PashoianSenior Industrial Security AdvisorWhite & Case LLP
Back by popular demand! Delegates are invited to break out into smaller group discussion tables to trade experiences and lessons learned. Facilitators will guide the conversation to identify the latest best practices. Delegates are encouraged to choose their preferred table topic, and to move between tables during the discussion.
- Workforce capacity: Pressure to grow cleared talent pool and board/oversight participation to meet expanded compliance demands
- Affiliate coordination: Need for proactive engagement with foreign parents to balance compliance, oversight, and operational efficiency
- SSA, Proxies and Other Agreements- Considerations and Processes of when to restructure
- Export/import compliance: Tariffs, ITAR, and cross-border controls require stronger coordination with corporate parents and robust policies
- Vendor flow-down requirements: Compliance obligations cascade to suppliers (especially manufacturing), affecting profitability and participation in the DIB
- Annual Reporting: Best Practices in Compiling an Effective AICR (Annual Implementation & Compliance Report)
Close of Day 1
Networking Cocktail
Day 2 — Main Conference
September 30, 2026
Registration and Continental Breakfast
Co-Chairs’ Opening Remarks
A Day in the Life Series: Parent Companies and Lesson for Optimizing FOCI Mitigation: Real-Life Success Stories

Julien ApollonGeneral CounselSafran Defense & Space

Anthony FadelGeneral Counsel & SecretaryST Engineering North America

Teresa AmundsonAssistant GC and Chief Compliance OfficerAirbus Space and Defense

Norm PashoianSenior Industrial Security AdvisorWhite & Case LLP
Some parent organizations take a “sign-and-forget” approach, resulting in limited ongoing compliance awareness, while others become overly involved. This session will explore how to achieve the right balance for effective affiliate coordination, including:
- Examining the importance of proactive engagement with foreign parent entities to align compliance, oversight, and operational efficiency
- Applying strategies for overcoming cultural and governance challenges
- Analyzing the implications of FOCI mitigation arrangements on a cleared subsidiary’s business operations
- Determining how parent and affiliate organizations should interact with Outside Directors or Proxy Holders, as well as the cleared subsidiary’s executive leadership
- Approaches to balancing group-level business objectives, strategies, and procedures with FOCI mitigation requirements
Uncovering Hidden Supply Chain and FOCI Risks: Unpacking the Implications of the Anthropic Designation and Vendor Attestation Challenges

Johnathan RudyAssistant General Counsel, CybersecurityGEICO

Margaret CassidyFounder & Managing AttorneyCassidy Law PLLC
Supply chain visibility is becoming more demanding as regulatory expectations expand, requiring organizations to track product origin, components (including software), and attestations—adding significant industry burden and increasing the need to understand evolving legislation and compliance obligations. These challenges are underscored by recent developments, including the early March 2026 designation of Anthropic as a supply chain risk by the U.S. Department of War—a notable first for a U.S.-based company, which had been typically reserved for foreign firms with potential ties to adversaries. The designation followed the company’s refusal to permit unrestricted military use of its AI model and signals a potential shift in how supply chain risk determinations may be applied, raising questions about future enforcement actions, contractor expectations, and the governance of approved technologies.
In this session:
- Navigating vendor attestation challenges
- Assessing and managing software supply chain risks
- Monitoring suppliers and evaluating overall supply chain security and resilience
- Sorting which FOCI companies, non-FOCI companies, public trust contracts and third-party contractors require enhanced scrutiny
- Anthropic issue: supply chain risk designation and implications—how litigation will be resolved and the impacts
- Navigating the employment of foreign nationals contractually
Networking Break

Jill M. McCluneU.S. General CounselAvon Protection/ Team Wendy

B.J. AltvaterAttorneyCleary GottliebFormer Intelligence Oversight Officer and Policy Analyst at the U.S. Department of Homeland Security
- Integrating FOCI into the Committee on Foreign Investment in the United States (CFIUS) review process, and the risks of transaction delays
- Comparing how CFIUS involvement affects DCSA timelines
- Assessing key provisions of Foreign Investment Risk Review Modernization Act of 2018 (FIRRMA)
- Understanding how FOCI integrates into the Committee on Foreign Investment in the United States review process, and the risks of transaction delays
- Identifying and addressing FOCI issues during due diligence and within transaction documents
- Analyzing the effects of FIRRMA on companies at different stages of FOCI mitigation and CFIUS approval
- Developing strategies to manage FOCI and CFIUS processes in tandem
- Establishing best practices for coordinating with government stakeholders, transaction parties, and outside counsel

Jennifer BrownVice President, Federal SecurityHP
Outside Director
WSP USA

Robert RixmannChief Security OfficerLeonardo DRS, Inc.
- Prepare the critical documentation, governance records, and supporting materials needed to demonstrate compliance and streamline the DCSA Security Review process
- Conduct proactive compliance checks to identify and remediate potential gaps before review activities begin • Leverage Outside Directors and Proxy Holders effectively to reinforce oversight, governance integrity, and FOCI mitigation compliance
- Understand the most common review deficiencies and operational pitfalls that can delay approvals or increase scrutiny
- Apply proven best practices to improve review outcomes, strengthen security posture, and enhance long-term regulatory readiness and stakeholder confidence
Networking Lunch
A Day in the Life Series: Best Practices for Enhancing General Counsel, FSO Teamwork and More Cross-Functional Teamwork

Tom BrewerVice President, Security and ComplianceTAD PGS, Inc.

Dennis KallelisChief Security OfficerIDEMIA Identity & Security

Andrew LotwinSenior Vice President of FederalISI Defense

Matthew MadaloSenior Vice President – General Counsel, Chief Compliance Officer and Corporate SecretarySiemens Government Technologies
As part of the General Counsel risk focus, building a strong, integrated partnership between the GC and FSO is key to maintaining oversight across security, personnel, and compliance. Together, they drive disciplined monitoring of clearances, formalize procedures, and ensure effective onboarding and training. Establishing consistent processes and cadences—especially for employee offboarding—paired with vigilant facility clearance management, creates a resilient framework. Close coordination with stakeholders and alignment with HR ensures policies are executed seamlessly, risks are minimized, and both functions reinforce one another.
- Continue monitoring and managing personnel clearances
- Establish and document standard operating procedures
- Strengthen onboarding and training programs
- Define clear processes and regular cadences for employee offboarding
- Maintain and support facility clearance requirements in coordination with the FSO
- Collaborate with stakeholders and align closely with HR policies and workflows
- Forming a cohesive, high-functioning team—where legal, security, and HR intersect to proactively manage risk and enable compliant, efficient operations.
CMMC Implementation, Your Network and Cyber Controls and ECPs: Navigating New Complexities of Secure CUI Enclave Expansion

Ric HelthallOutside DirectorShiver Security Systems

Richard WakemanChief Security Architect- Defense Industrial BaseMicrosoft
The Cybersecurity Maturity Model Certification (CMMC) has a phased implementation which started November 2025, the program mores strictly controls how Controlled Unclassified Information is safeguarded which impacts FOCI mitigation, new contracts, third-parties, parent companies and cloud providers.
- Building and managing CUI enclaves and enclaves within enclaves
- What FSOs and other key stakeholders need to know
- Safeguarding the relationship of a foreign entity and the mitigated entity, delineating access to network controls and cyber controls, and updating your company’s Electronic Communication Plans (ECP)
- Aligning CMMC with FOCI
- Access control, IAM, and firewalls
- Challenges with security and data control of affiliates and suppliers
Networking Break
Modernizing FOCI Framework

Dr. Deanna CaputoChief Scientist for Insider Threat ResearchMITRE

Lisa HimesOf CounselRogers Joseph O'Donnell PC
Security can be a force multiplier—enhancing integrity and resilience while enabling cost-effective, competitive, and fast delivery of solutions to the warfighter without compromise.
- Improve end-to-end timelines from initial review through clearance and contract initiation
- Focus on aligning policies based on real-world implementation
- Align cloud oversight and zero trust principles with contractor realities, emphasizing identity and data enforcement layers.
- Digitize clearance workflows and status tracking, automate form validation, enforce consistent metadata and markings, and integrate threat telemetry under clear governance.
- Modernizing the FOCI Framework to better reflect current risks and operational needs
The Evolving Roles of Outside Directors and Proxy Holders in Balancing Parent and Shareholder Priorities

Brian E. KaveneyPartnerArmstrong Teasdale LLP

Ben RichardsonChief Commercial OfficerGambit
- Navigating the role of an outside director when a FOCI-mitigated company holds a clearance for contract purposes but does not perform classified work
- Balancing the priorities of the parent company with those of shareholders
- Determining what information must be reported to the government security committee
- Documenting government security committee meetings and demonstrating compliance with NISPOM
