What Are the Current Conflict-of-Interest Rules in Federal Contracting in 2026?
FAR Subpart 9.5 still controls OCI risk in 2026: disclose, avoid, or mitigate conflicts before award. DoD adds DFARS 209.571 for major defense programs.
Gov Contract Finder
•7 min read
What Are the Current Conflict-of-Interest Rules in Federal Contracting and Who Does It Affect?
What are the current conflict-of-interest rules in federal contracting?
GSAFAR
According to GSA and FAR Subpart 9.5, the current rules require contracting officers to identify, evaluate, and address organizational and consultant conflicts of interest before award. The main OCI categories are biased ground rules, impaired objectivity, and unequal access to nonpublic information. These rules apply to all federal contractors, including small businesses and large integrators.
According to GSA guidelines, contractors must treat OCI as a pre-award compliance issue, not a paperwork formality. FAR Subpart 9.5 requires contracting officers to avoid, neutralize, or mitigate significant potential conflicts before award, and that review starts as soon as a firm enters the competition. The three most common OCI categories remain biased ground rules, impaired objectivity, and unequal access to information. In practice, this means a company that writes requirements, evaluates competing offers, or sees source-selection data may need a written mitigation plan, personnel recusal, segregated teams, and controlled document access. SBA certifications such as 8(a), HUBZone, WOSB, VOSB, and SDVOSB do not remove OCI exposure. The current standard is simple: identify the conflict early, document the risk, and fix it before award, not after the agency has already built its source-selection record around your proposal.
Per FAR 9.500 and DFARS 209.571, the OCI framework is broader than ethics rules alone because it governs how contractors can participate in a procurement, not just how employees behave. According to GAO, weak visibility into outside affiliations can create hidden risk, especially where consultants, advisers, or affiliated firms work across sensitive programs. That is why the rules focus on roles and relationships: who drafted the statement of work, who advises the government on requirements, who evaluates competitors, and who can see pricing or technical solutions. DoD adds a more aggressive layer for major defense acquisition programs under DFARS 209.571, where the acquisition team may restrict scope, impose organizational separation, or exclude a conflicted firm from certain tasks. The 2026 FAR Council agenda still shows OCI reform as an active rulemaking topic, which means contractors should expect more scrutiny, not less, over the next award cycle.
Under OMB Circular A-123, agencies are expected to maintain internal controls, and that pressure is showing up in OCI reviews as more contracting officers ask for org charts, proposal-team rosters, employee certifications, and subcontractor disclosures before award. For cloud and cyber work, FedRAMP authorization and CMMC compliance are separate gates; neither one cures an OCI problem by itself. A company can be fully authorized for secure cloud hosting and still be barred from a task if it helped define the requirement or will later evaluate the same vendor. DHS, NASA, VA, and civilian agencies each apply their own acquisition supplements, but the central question is the same: does the contractor have a defensible wall between conflicting duties? Contractors that can answer with contemporaneous records, named reviewers, and clear reporting chains usually have a much stronger OCI position than firms relying on verbal assurances or generic firewalls.
How do contractors comply with the current conflict-of-interest rules?
GSAFARDoDDFARS
According to GSA and FAR Subpart 9.5, contractors comply by disclosing potential OCIs in the proposal, screening employees and affiliates, separating conflicting teams, and submitting a mitigation plan before award. DoD bidders should add DFARS 209.571 controls for major defense programs. Update disclosures immediately when ownership, staffing, or advisory roles change.
How Do Federal Conflict-of-Interest Controls Work in Practice?
According to GSA guidelines, the fastest way to reduce OCI risk is to build a written matrix before you bid. List every current or recent contract, advisory assignment, subcontract, and teaming arrangement that touches the same program office, competitor, requirement, or evaluation team. Then classify each relationship under FAR Subpart 9.5: biased ground rules, impaired objectivity, or unequal access to information. Contracting officers usually want to see who drafted requirements, who will evaluate deliverables, who can access pricing, and who can see technical solutions. If there is overlap, prepare a mitigation package that includes recusal, separate reporting chains, locked data rooms, nondisclosure agreements, and periodic certifications from affected staff. For primes and large integrators, the package should also cover parent companies, affiliates, and proposed teammates. The key is speed. The closer you get to proposal submission, the less likely the agency is to accept a late fix, especially if the source-selection record is already moving.
Per FAR 9.505 and agency supplements, some conflicts can be mitigated, but that decision belongs to the contracting officer, not the contractor. Small businesses should not assume size status offsets OCI exposure; SBA certification helps with set-asides, not ethics or source-selection rules. If a subcontractor is conflicted, prime contractors should flow the disclosure requirement down to the team and verify compliance before award. For DoD work, DFARS 209.571 can make the review stricter on major defense acquisition programs, especially when a firm has helped draft requirements or support independent cost estimates. For cloud and data contracts, FedRAMP and CMMC evidence can support operational separation, but they do not replace the OCI memo. Agencies want contemporaneous records, not verbal promises, and they expect contractors to prove independence with documents, not slogans.
1
Step 1: Map relationships in 10 business days
Per FAR 9.500 and 9.505, inventory every advisory, technical, pricing, and oversight role that touches the same program office, competitor, or requirement.
2
Step 2: Classify the OCI type before proposal submission
Use the FAR 9.5 categories: biased ground rules, impaired objectivity, and unequal access to information, then assign a risk level for each one.
3
Step 3: Build a written mitigation plan within 5 business days of finding overlap
Add recusal, separate reporting, locked folders, NDAs, and staff certifications so the contracting officer can review a complete package before award.
4
Step 4: Flow down disclosures to teammates and subcontractors within 48 hours
For DoD work, align subcontractor screening with DFARS 209.571 and document the review in the proposal file and teaming agreement.
5
Step 5: Re-certify after every staffing or ownership change
Update OCI disclosures immediately when key personnel, affiliates, or advisory roles change, and re-issue the certification before any option exercise or task order.
Important OCI Warning
A firewall memo alone does not satisfy OCI review. Agencies expect named personnel, separate reporting lines, and a written mitigation plan before award. If the same employee helped write the statement of work and later evaluates offerors, the conflict is usually much harder to defend.
"Contracting officers shall avoid, neutralize, or mitigate significant potential conflicts of interest before contract award."
The Challenge
Needed to bid a $6.5M DHS data-modernization task in 2026 after one subcontractor had helped support requirements development on the prior bridge contract.
Outcome
Won the $6.5M task order, 17% under the incumbent's revised price, after the contracting officer accepted the mitigation package.
What happens if contractors do not comply with OCI rules?
GSAGAODoDDFARS
According to GSA and GAO, noncompliance can lead to proposal rejection, exclusion from the competition, contract termination, a negative responsibility finding, or a protest sustain. For DoD programs, DFARS 209.571 can also force task reallocation or organizational separation. The risk starts before award and can continue through option exercises and modifications.
What Are the Best Practices for Reducing OCI Risk in 2026?
According to GSA guidelines, the best performers treat OCI like a bid gate, not a legal afterthought. They run a 100% relationship check on employees, affiliates, and teammates before proposal release, then keep a dated OCI matrix in the file throughout performance. For a mid-size procurement, that usually means identifying every advisory, evaluation, and requirements-writing role in the first 30 days of capture. Contractors should also require monthly certifications from key personnel and immediate re-screening when ownership, staffing, or subcontracting changes. If the opportunity is in DoD, the team should overlay DFARS 209.571 controls on top of the FAR review so the defense package matches the agency’s stricter expectations. For civilian agencies, this same discipline helps with DHS, NASA, and VA awards because source-selection teams want proof that the contractor understands the boundary between support and oversight. Clean records win faster decisions.
Per OMB A-123 and FAR Subpart 9.5, the strongest OCI programs use three layers of control: prevention, detection, and documentation. Prevention means screening before the bid is final. Detection means a recurring review of personnel, subcontractors, and affiliates for new conflicts. Documentation means keeping a complete record of the mitigation plan, every certification, every change notice, and every contracting officer communication. Contractors should also train capture managers and proposal managers to spot red flags early, especially on repeat buys where a firm has already supported the customer in another capacity. If a company provides advisory support on one procurement and then wants to bid the resulting implementation work, the OCI issue should be evaluated immediately, not at the debrief stage. That discipline matters more in 2026 because procurement teams are increasingly focused on defensibility. A well-documented OCI file can shorten award review by weeks, while a weak file can trigger questions that stall the procurement for months.
Deadline: disclose every potential OCI at least 10 business days before proposal submission under FAR 9.504.
Budget: plan $25,000-$150,000 for legal review, screening walls, and employee certifications on a mid-size mitigation package.
Action: re-verify 100% of key personnel and affiliates within 5 business days of any staffing or ownership change.
Risk: one unresolved conflict can block award, terminate performance, or trigger a protest at any time before option exercise.
Sources & Citations
1. FAR 9.500 Scope of Subpart[Link ↗](government site)
2. FAR Subpart 9.5 - Organizational and Consultant Conflicts of Interest[Link ↗](government site)
3. DFARS 209.571 Organizational conflicts of interest in major defense acquisition programs[Link ↗](government site)