Government Contractor Insurance

Mission-Critical Coverage. Strategic Discipline.

The way government contractor insurance is bought and sold is fundamentally broken. Brokers follow the same playbook — check the FAR boxes, shop three carriers, present the lowest quote, and move on. PFTN was built to be the opposite of that. We understand federal contract requirements, walk your facilities, and engineer a risk strategy that actually moves the needle.

15+
Years of Strategic Advisory
98%
Client Retention Rate
100+
Carrier Relationships
All 50
States Licensed & Active

The FAR Compliance Grind Is Broken

The Compliance Checkbox

Too many government contractors fall into the trap of treating insurance like a compliance checkbox — expecting better results from the same FAR-minimum approach. Your broker confirms the required coverages, submits a certificate, and moves on. 45-55% of initial COI submissions get rejected by contracting officers. For first-time contractors, that number is 75%. The math doesn't lie: claims won't magically drop. Premiums won't naturally improve. Not unless you change the approach and improve the strategy.

A Renewed Mindset

Our 4-Step Strategic Process gives government contractors what the traditional model never does: leverage. We start months before your renewal by understanding your contract structure, your facility operations, and your regulatory environment — then build a risk profile that carriers actually compete for. By the time the market sees your program, you're in the strongest position possible. We help you take back control from the insurance market, close compliance gaps, and boost financial performance — intentionally and strategically.

Coverage Built for Federal Complexity

We don't sell policies. We improve how you manage risk — and the financial outcomes that follow. Every government contract carries unique insurance requirements that most brokers aren't equipped to navigate.

General Liability & Umbrella

FAR 52.228-5 mandates $500K+ per occurrence for work on government installations. We structure GL and umbrella programs with proper additional insured endorsements, waiver of subrogation, and primary/noncontributory language that contracting officers require.

Workers' Compensation & DBA

Federal and state statutory coverage plus Defense Base Act requirements for overseas contract work. PFTN helps control costs through loss control, safety programs, and experience modification management — critical for maintaining competitive bid positioning.

Nuclear & Radiological Liability

Specialized coverage for contractors at DOE, NNSA, and NRC-regulated facilities. We navigate the interplay between Price-Anderson indemnification and commercial liability, ensuring you're protected for both nuclear incidents and non-covered exposures.

Cyber Liability & CMMC

Contractors handling CUI, classified data, or operating under DFARS cybersecurity requirements face escalating cyber exposure. We build cyber programs that cover breach response, regulatory defense, and notification costs aligned with CMMC certification requirements.

Pollution & Environmental Liability

Standard CGL policies contain absolute pollution exclusions — leaving contractors exposed during environmental remediation, hazmat handling, and work at contaminated federal sites. Contractors Pollution Liability fills this critical gap that most brokers overlook entirely.

Professional Liability / E&O

Technical services, engineering, consulting, and project management contracts carry professional liability exposure on every deliverable. We structure programs that protect your firm from errors, omissions, and inadequate performance claims — not just a CGL endorsement that leaves dangerous gaps.

Federal Contractor Specialists

Whether you're a small technical services firm or a large prime contractor, government contractors need risk strategies tailored to their contract type, clearance level, and regulatory environment — not a commercial policy with a few FAR endorsements bolted on.

DOE & Nuclear Facility Contractors

Technical support, environmental remediation, facility management, and security operations at DOE sites including Oak Ridge, Y-12, ORNL, Savannah River, Hanford, and Los Alamos. We understand radiological exposure, Price-Anderson indemnification, OSHA/NRC dual jurisdiction, and the unique insurance challenges of the nuclear contractor ecosystem.

Defense & Intelligence Contractors

DFARS compliance, classified information handling, CMMC cybersecurity requirements, and performance bonding for DoD and intelligence community contracts. We structure programs that account for security clearance implications, FAR/DFAR insurance mandates, and the specialized liability that defense work demands.

Professional & Technical Services

Engineering, IT, consulting, environmental science, and technical support firms operating under IDIQ, cost-plus, FFP, and task order contracts. We build programs that scale with your contract portfolio — from your first small business set-aside through large multi-agency prime contracts.

Purchase with Purpose, Not Habit

The industry standard gives you 90 days to renew. That's not a strategy. We take a longer view — building a process that puts you ahead of the market and delivers cost and coverage outcomes most government contractors don't know are possible.

1. Strategic Discovery

We start by understanding your contract portfolio, growth trajectory, and risk tolerance — not just your current policy deck. We review your FAR/DFAR requirements, examine your facility operations, and map every exposure before quoting anything.

2. Risk Assessment

We identify current and future risks that could impact your contracts and your bottom line. We use a systematic, quantifiable approach to surface the risk issues most brokers never look for — from pollution exclusions to cyber liability gaps to Price-Anderson blind spots.

3. Solution Design

We build an integrated insurance and risk management strategy — not a one-size-fits-all policy package. Every solution is tailored to your contract type, your regulatory environment, and your growth plans.

4. Ongoing Optimization

We monitor, adjust, and evolve your protection strategy. Your contract portfolio changes — new agencies, new facilities, new clearance requirements — and your insurance should too. We continuously track your risk profile, claims trends, and market conditions.

From the first engagement with PFTN, we will educate, consult, and help you find strategic opportunities to impact your business. The shift starts with one conversation.

The Risks That Keep Government Contractors Up at Night

Most risk hides in plain sight. The traditional marketplace subjects the buyer to reactive service crammed into a 90-day renewal window, leaving you with low leverage and no control. PFTN illuminates what others overlook — and structures a strategy that actually moves the needle on these exposures before they become claims.

Your Insurance Should Work as Hard as Your Mission

The Traditional Approach

Coverage Approach
Checking the FAR boxes and shopping on price. The process rewards speed and volume — not strategy and outcomes. Coverage is whatever meets the minimum contract requirement.
Compliance Management
You submit a certificate, it gets rejected, you resubmit with corrections. Your broker handles administrative follow-up. No one asks whether the coverage actually protects you.
Renewal Process
Annual call with three quotes and a decision — no strategy discussion. The same 90-day grind, year after year, wondering why nothing improves.

The PFTN Approach

Coverage Approach
Custom program design based on contract analysis, facility audits, and regulatory requirements. Every solution tailored to your contract portfolio, your clearance level, and your growth trajectory.
Compliance Management
We ensure your certificates are compliant before submission — proper endorsements, correct limits, and all required FAR language. Zero rejected COIs, zero contracting officer callbacks.
Renewal Process
Strategic review that begins months before expiration. We build a risk profile carriers compete for — so by the time the market sees your program, you're in the strongest position possible.
"In over 15 years of working with hundreds of organizations, I've never sat down with a company that was already buying insurance strategically. But the few that break that cycle don't just save money — they transform their entire organization. Strategic insurance buying isn't just a cost decision. It's a cultural shift."
Ryan Mefford — President, Risk Advisor

The Tools to Take Control

Most risk hides in plain sight. The PFTN platform puts a full suite of tools at your fingertips — designed to illuminate what is otherwise overlooked. Training events, predictive modeling, compliance resources, risk assessment tools, and 24/7 access to everything you need to stay ahead of risk.

PFTN Torch

Shine a light on hidden risk through comprehensive assessments that uncover gaps in your coverage before they become costly surprises.

PFTN Benchmark

Project, track, and manage your experience modification rate with data-driven strategies that directly impact your workers' compensation costs.

PFTN Advocate

Personal claims management by our dedicated claims manager — from first report through resolution, we advocate on your behalf.

PFTN Equip

Thought leadership workshops, lunch & learns, and executive briefings designed to keep your team ahead of emerging risks and industry trends.

PFTN Portal

Secure, 24/7 access to your full insurance program — desktop or mobile. Every document, every policy, always at your fingertips.

PFTN Vault

A private resource library built for your team — HR tools, compliance guides, safety programs, and learning systems in one place.

The Future of Federal Risk Placement

Most government contractors renew on autopilot, repeating the same process year after year and wondering why nothing improves. The truth is, the traditional approach to federal contractor insurance wasn't designed to acknowledge growth or improving outcomes. It is designed to repeat the cycle with as little change or friction as possible at all points of the distribution channel.

The future of risk placement doesn't belong to contractors who shop harder. It belongs to contractors who stop renewing on autopilot and start doing the work between renewals that actually moves the needle. When a contractor commits to that kind of discipline, the market responds. Insurance stops being a compliance cost you manage and starts becoming a position of strength.

These tools exist to help you get there. They're not a value add. They are the strategy.

Carrying the Light Forward

Tim Keller wrote that "to be the light means to illuminate what is true." These briefings exist to do exactly that — to shine a light on what the insurance industry would rather keep in the dark.

Property

Builders Risk Insurance on Federal Construction Contracts in 2026

A federal construction contract dictates the builders risk terms, names the government's interest, and leaves the gaps that bite — faulty-workmanship exclusions, flood sublimits, and soft-cost limits set before 2026 material costs moved.

Read More →
Professional Liability

Professional Liability and Errors and Omissions Coverage for Government Contractors in 2026

General liability covers the physical harms. For the growing share of federal work that is services — IT, consulting, engineering, program management — the core exposure is the economic loss a professional error causes, and that is exactly what a standard program leaves uncovered.

Read More →
Transactional Risk

Representations and Warranties Insurance for Government Contractor Mergers and Acquisitions in 2026

Representations and warranties insurance shifts a seller’s indemnity risk onto an insurer, freeing escrow and enabling cleaner exits. In government contractor deals, the reps that carry that risk are the regulatory ones — and diligence is what makes the deal insurable.

Read More →
Overseas Security Risk

Kidnap, Ransom, and Political Risk Coverage for Overseas Government Contractors in 2026

The Defense Base Act covers an injured worker overseas — but not a kidnapping, a forced evacuation, or a government that seizes the project. How kidnap, ransom, and political risk coverage answer the exposures a federal contractor carries the moment it operates abroad, and why duty of care makes them a board-level question in 2026.

Read More →
Aviation / UAS

Unmanned Aircraft Systems Liability Insurance for Federal Drone Contractors in 2026

The commercial general liability policy every contractor carries excludes unmanned aircraft — and since 2015 the ISO endorsements have said so in writing. As Part 108 and the Blue UAS list pull federal work into the air, how to build a drone program where compliance and coverage stay two separate obligations.

Read More →
Product Liability

The Government Contractor Defense and Product Liability Exposure for Defense Manufacturers in 2026

Building to the government's drawings feels like borrowing its liability shield — but the Boyle defense is narrower than most contractors assume, and 2026 case law has narrowed it further. Why product liability coverage still carries the exposure the defense cannot.

Read More →
Cyber / DFARS

DFARS 252.204-7012 Cyber Incident Reporting and First-Party Breach Costs in 2026

Defense contractors treat cybersecurity as a compliance project — NIST 800-171, the CMMC assessment. But when a breach hits, the governing clause is DFARS 252.204-7012, and its 72-hour reporting deadline starts the moment an incident is discovered. Whether a cyber policy’s first-party coverage actually funds that obligation is a separate question entirely.

Read More →
Crime / Fidelity

Commercial Crime and Fidelity Bond Requirements for 2026 Government Contractors

A government contractor can be CMMC-ready and DCAA-clean and still lose six figures to a wire it authorized. How commercial crime and fidelity coverage answer employee theft and third-party fraud — and where the 2026 social-engineering sublimit quietly leaves the loss on your books.

Read More →
Environmental Liability

Contractor's Pollution Liability and PFAS Exposure for Federal Environmental Contractors in 2026

In 2026, PFAS moved to the center of federal environmental contracting. The CERCLA designation, the spread of PFAS exclusions in pollution coverage, indemnity in cleanup contracts, and the governance a contractor needs before bidding the work.

Read More →
Surety & FAR

Miller Act Payment and Performance Bonds for Federal Construction Contractors in 2026

On federal construction, the unpaid subcontractor cannot lien the property — the Miller Act bond is what replaces the lien. What the statute requires, the payment-bond deadlines that quietly disqualify the unwary, and how the 2026 surety market and the fixed-price shift reshape the bond conversation.

Read More →
FAR / Contract Risk

Government-Furnished Property and Contractor Risk of Loss Under FAR 52.245-1 in 2026

FAR 52.245-1 generally relieves contractors of liability for government-furnished property — but the exceptions, the DCMA-reviewed property system, and the reach into insurance proceeds are where the exposure hides. How risk of loss is allocated, and how to insure the gap in 2026.

Read More →
Management Liability

Employment Practices Liability Insurance for Government Contractors in 2026

Federal contracting stacks employment-law exposure — prevailing-wage rules, whistleblower overlap, and funding-driven layoffs — on top of ordinary workforce risk. This briefing surfaces what Employment Practices Liability Insurance covers, where it stops, and how contractors should structure it for 2026.

Read More →
Crisis Management

The Fourth Funding Cliff: Preparing Your Coverage for September 30

Two competing CRs, no Senate spending bills, a September 30 deadline — how GovCon owners keep coverage, cash flow, and compliance intact through a lapse.

Read More →
Liability Management

SAFETY Act Certification and Liability Protection for Government Contractors in 2026

The SAFETY Act can cap a contractor's terrorism liability at the insurance DHS requires. Understanding Designation, Certification, and that required amount is how you structure CGL and excess coverage with intention in 2026.

Read More →
Management Liability

Directors and Officers Liability and False Claims Act Exposure for Government Contractors in 2026

False Claims Act recoveries hit a record $6.8 billion in FY2025. How the FCA exposes government contractors and their officers, why directors and officers coverage responds, and the exclusions and notice provisions a govcon program has to get right.

Read More →
Professional Liability

Errors and Omissions Coverage for Government IT Services Contractors in 2026

For a government IT contractor, cyber liability and technology errors and omissions coverage answer two different failures. This briefing examines what E&O actually covers, how it interacts with cyber and FAR flow-down indemnity, and why the fine print of the professional-services definition decides whether a claim is paid.

Read More →
Advisory

PEO Co-Employment, Certificates, and Coverage Gaps for Government Contractors in 2026

The PEO pitch of turnkey payroll, benefits, and workers compensation is built for a general small business, not a federal contractor. This briefing surfaces the coverage, co-employment, certificate, and cost-accounting gaps, and how an independent broker closes them.

Read More →
Workers Compensation

Defense Base Act Insurance Requirements for Overseas Contract Performance in 2026

Overseas government work carries a workers' compensation exposure many contractors underwrite by accident. The Defense Base Act reaches every prime, every subcontractor, and every employee abroad, and the gaps hide in the subcontractor chain you did not verify.

Read More →
Cyber / Compliance

The Software Bill of Materials Mandate Is Here — Just Not the One Everyone Expected

OMB rescinded the uniform secure-software attestation requirement on January 23, 2026, replacing the CISA Common Form with a risk-based approach in which each federal agency develops its own SBOM and attestation requirements. The headline read it as deregulatory. The contracting reality is the opposite. The SBOM mandate is now distributed across every awarding agency rather than centralized at OMB.

Read More →
DCAA Compliance

The DCAA Timekeeping Audit That Started Last Quarter

The DCAA labor floor check is the most discreet audit in federal contracting. The auditor walks the office at an undisclosed time, asks four or five employees what they are working on, what charge code they are billing to, and how they entered yesterday's time. The audit lasts twenty minutes. The findings shape the indirect rates the contractor will negotiate for the next three years. Q1 2026 was a heavy floor-check quarter.

Read More →
Government Contractor Risk

CMMC Flow-Down Is Now a Prime Contractor Liability Problem

Phase 2 enforcement begins November 10. Boeing, Lockheed, RTX are already conditioning awards on Level 2. Only ~1.4% of the affected supplier base is certified. The CMMC story was sold as a supplier problem. It is about to become a prime problem.

Read More →
FAR Compliance

The 45% Rejection Rate No One Talks About

Nearly half of all certificate of insurance submissions to contracting officers get rejected on the first pass. For first-time government contractors, that number climbs to 75%. The cost isn't just administrative rework — it's delayed contract execution, stalled revenue, and a reputation with your CO that starts in the wrong place. The fix isn't harder. It's just intentional.

Read More →
Nuclear Liability

What Price-Anderson Doesn't Cover

The Price-Anderson Act indemnifies DOE contractors up to $16.6 billion per nuclear incident. It sounds comprehensive — until you realize it only covers nuclear events. Professional liability claims, cyber breaches, pollution incidents, and everyday operational exposures? Those are entirely on you. Most brokers conflate Price-Anderson protection with comprehensive coverage. The gap between the two is where contractors get hurt.

Read More →
Cyber Risk

CMMC Compliance Is Not Cyber Insurance

Too many government contractors believe that meeting CMMC cybersecurity requirements eliminates their need for cyber liability insurance. It doesn't. CMMC is a set of technical security controls. Cyber insurance covers the financial consequences when those controls fail — breach response, notification, regulatory defense, and third-party claims. They're different tools solving different problems, and confusing them is one of the most expensive mistakes a contractor can make.

Read More →
The Commodity Trap

Good Enough

The insurance industry has become a race to the bottom — cheaper quotes, faster binding, less thinking. But when the work is reduced to transactions, something gets lost: the meaning. When you build an agency that treats advisory work as craft, you attract people who want to do meaningful work, not just process transactions. And the light gets brighter.

Read More →
Environmental Risk

The Pollution Exclusion That Killed a Contractor

Every standard CGL policy contains an absolute pollution exclusion. Every one. For contractors performing environmental remediation at federal sites — handling hazmat, working in contaminated soil, managing legacy waste — that exclusion is a loaded gun. Contractors Pollution Liability isn't optional coverage. It's the only thing standing between your firm and an uninsured environmental claim that can end your business.

Read More →
Risk as Culture

When Insurance Becomes a Discipline

A captive insurance company puts the insured in the driver's seat — and that changes everything. When your company funds its own first layer of risk, every person in the building has skin in the game. The real case for a captive isn't financial. It's cultural. And for government contractors managing complex, multi-year exposures, it's a strategic advantage most firms never consider.

Read More →
Nuclear Liability

The Three Layers of Nuclear Liability No One Explains

Price-Anderson's $16.6 billion sounds like a single wall of protection. It isn't. It's a three-layer system — primary insurance, retrospective premiums, and federal backstop — each with different triggers, different timelines, and different implications for the contractor standing in the middle. Most brokers can't explain how these layers interact. That's a problem when the claim hits.

Read More →
FAR Compliance

FAR 52.228: The Insurance Clauses Your Broker Should Know by Heart

The Federal Acquisition Regulation contains a dozen insurance clauses that govern what coverage you must carry, how it must be structured, and what endorsements the contracting officer will require. FAR 52.228-3 through 52.228-16 aren't suggestions — they're contractual requirements that flow down to every subcontractor. If your broker can't recite them, they're guessing with your compliance.

Read More →
View all briefings →

Government Contractor Insurance FAQs

What insurance does a government contractor need? +

Government contractors must carry workers' compensation, general liability ($500K+ per occurrence), and automobile liability per FAR 52.228-5. Depending on the contract, you may also need professional liability, pollution liability, cyber liability, Defense Base Act coverage, and surety bonds. The specific requirements depend on your contract type, the agency, and the facility where work is performed. PFTN builds FAR-compliant programs tailored to your exact contract requirements — not a generic commercial package with a few endorsements added.

What is FAR 52.228-5 and how does it affect my insurance? +

FAR 52.228-5 governs insurance requirements for work on government installations. It mandates specific coverage types, minimum limits, and endorsements including waiver of subrogation, additional insured status for the government agency, primary and noncontributory language, and 30-day cancellation notice to the Contracting Officer. Non-compliance can result in contract termination, and most brokers don't fully understand the nuances of these requirements.

What is Price-Anderson and do I still need commercial insurance? +

The Price-Anderson Nuclear Industries Indemnity Act provides federal indemnification for DOE nuclear facility contractors, currently capped at $16.6 billion per incident. While this covers nuclear incidents — including personal injury, property damage, and evacuation costs — contractors still need commercial coverage for non-nuclear claims, professional liability, cyber exposure, pollution incidents, and other exposures outside the scope of Price-Anderson indemnification. Few brokers understand where Price-Anderson ends and your commercial exposure begins.

Why do government contractor COI submissions get rejected? +

45-55% of initial certificate of insurance submissions are rejected by contracting officers — and the rate jumps to 75% for first-time contractors. Common failures include missing waiver of subrogation endorsements, incorrect additional insured language, inadequate cancellation notice provisions, missing primary and noncontributory endorsements, and policy limits below contract minimums. These rejections delay contract execution and cost contractors an estimated $25,000+ annually in administrative rework and premium increases.

Do I need cyber liability insurance for government contracts? +

Yes — and it's increasingly critical. Contractors handling Controlled Unclassified Information (CUI) or classified data face significant cyber exposure. DFARS cybersecurity requirements and CMMC certification mandate specific security controls, but compliance alone doesn't protect you from the financial consequences of a breach. Cyber liability insurance covers breach response costs, notification expenses, regulatory defense, and third-party claims. It's a separate requirement from CMMC compliance — and most brokers conflate the two.

What is pollution liability and why do I need it at federal sites? +

Standard CGL policies contain absolute pollution exclusions that leave contractors completely exposed during environmental remediation, hazmat handling, and work at contaminated federal sites. Contractors Pollution Liability (CPL) fills this gap, covering third-party bodily injury, property damage, defense costs, and cleanup expenses from pollution incidents on federal property. If you're performing any work at DOE environmental cleanup sites, legacy contamination facilities, or installations with known environmental history, CPL isn't optional — it's essential.

Your Mission Starts Here

Tell us about your operations and your contract portfolio. From the first conversation, we will educate, consult, and help you find strategic opportunities to impact your business. A relationship built on honest counsel — not sales quotas.

Property
October 2026

Builders Risk Insurance on Federal Construction Contracts in 2026

Builders risk is the coverage federal contractors treat as an afterthought — a line on a certificate — right up until a fire or water loss turns a half-built facility into an open claim. On commercial work the exposure is familiar. On federal work it is governed by a different hand, and that hand is the contract itself.

Start with where the obligation originates. Under FAR 52.236-7, the contractor "shall also be responsible for all materials delivered and work performed until completion and acceptance of the entire work." That single sentence places the risk of loss squarely on the builder until the government signs for the project — not on the government, and not on the day the last subcontractor leaves. FAR Part 28.3 adds that although the government is "not ordinarily concerned with the contractor's insurance coverage" on a fixed-price job, in special circumstances — work on a government installation, government property in play — the agency may specify requirements, and FAR 52.228-5 then obliges the contractor to "provide and maintain... at least the kinds and minimum amounts of insurance required in the Schedule." The Corps of Engineers, GSA, and the installation commands layer their own supplements on top. The requirement is not something the carrier dictates. It is something the solicitation dictates, and the carrier must be made to match.

That distinction drives who gets named. A well-built builders risk policy carries a broad omnibus-insured clause — owner, general contractor, and subcontractors of every tier insured on one form, sparing you the thicket of additional-insured endorsements. On federal work the government's interest must be written in as well, as an insured or loss payee depending on the clause and agency supplement. A certificate that names the right parties while the policy behind it does not is not protection — it is paper.

Then come the exclusions that bite, and they bite hardest where contractors assume they are covered. Builders risk is all-risk property coverage: it answers for direct physical loss from fire, wind, theft, vandalism, and collapse unless something is specifically excluded. What is specifically excluded is the work itself. The cost of making good faulty workmanship, defective material, or flawed design is carved out, and the only question that matters is how far that carve-out reaches. This is the ground the LEG and DE clauses contest. LEG 1 excludes the defect entirely; LEG 2 pays for resulting damage but not the cost of the original defective element; LEG 3 reaches furthest, covering damaged property while excluding the cost of improving the deficient work. The distinction is not academic — a federal court called the LEG 3 wording "egregiously ambiguous" and "bordering incomprehensible," so a claim can turn on language few contractors read before binding. Flood and earthquake are rarely excluded outright but capped by sublimits far below full project value — a quiet ceiling on a federal site in a seismic zone or floodplain. And the losses that leave no debris — soft costs, delay-in-completion, loss of use — are extensions you must buy on purpose. When a covered loss pushes a federal completion date past its deadline, the liquidated-damages and financing exposure is real — but the policy answers for it only if someone asked it to.

Now layer in 2026. Tariff-driven material inflation has moved the number builders risk is supposed to track. AGC data through January 2026 shows aluminum mill shapes up 33% year over year, steel mill products up roughly 21% — some lines as much as 50% — and copper and brass up nearly 16%, with overall construction costs projected to rise about 8% and steel-intensive projects 15% to 25%. A policy written to completed value at bid is a policy written to yesterday's prices. On a $10 million project, material inflation of 8% to 15% can leave you $800,000 to $1.5 million short of the limit you need — a gap uncovered, almost always, at the claim. Carriers are answering with demands for updated appraisals and tighter agreed-value terms. The discipline is to revisit valuation mid-project, not at renewal.

Two programs, two philosophies. A project-specific policy is built for one job, with limits, term, and extensions matched to that contract — the right instrument for a large or long-duration federal build. A blanket or reporting-form program covers an ongoing book of smaller projects under one master policy, reported as they start, and leans on the contractor to report accurately and stay inside the per-project cap. Neither stands alone. Builders risk must be coordinated with the government-furnished property on site, which the clauses treat differently from the work itself, and with the GC's other coverages — general liability, the subcontractors' policies, the owner's program — so a single loss does not fall into the seam between two forms.

None of this is cause for alarm. It is cause for ownership. At Peoples First Tennessee, we work federal builders risk through our 4-Step Strategic Process — Strategic Discovery to read the solicitation and surface what the agency requires, Risk Assessment to measure your limits and named parties against the contract and against today's material costs, Solution Design to build the project-specific or blanket program that fits, and Ongoing Optimization to revisit valuation before inflation turns adequate coverage into a shortfall. The discipline is to carry the torch into the policy language before the loss, not after.

Sources: FAR 52.236-7 Permits and Responsibilities (Cornell Law); FAR 52.228-5 Insurance—Work on a Government Installation (Acquisition.gov); FAR 28.306 Insurance under fixed-price contracts (Acquisition.gov); When Federal Contracts Meet Insurance Coverage, Part 1 (National Law Review); Builders Risk Insurance: A Solution for Complex Construction Projects (NASBP); LEG3: A Turning Point for Construction Insurance? (Howden); Builder's Risk Insurance Coverages and Exclusions (The Hartford); How Tariffs Ripple Into Construction Costs and Insurance (Grit Insurance / AGC data)

— Ryan Mefford, President & Risk Advisor

Professional Liability
October 2026

Professional Liability and Errors and Omissions Coverage for Government Contractors in 2026

The complete-looking program has a quiet gap. A government contractor carries general liability, workers' compensation, and — if the contract requires it — cyber and crime coverage. The program looks finished. Then a contracting officer alleges that a deliverable was defective, that advice was wrong, that a design or a software build failed to perform, and the contractor discovers that the one exposure most tied to what it actually sells is the one its program does not address. Professional liability is the quiet gap in a great many federal contractor insurance programs in 2026.

Where general liability stops. The gap is structural, not accidental. A commercial general liability policy covers bodily injury and property damage — the physical harms. It expressly does not cover the economic loss that flows from a professional error: the report that was wrong, the system that did not work, the engineering judgment that missed. For a contractor whose product is physical, that may not matter. For the large and growing share of federal work that is services — IT and software, consulting, engineering, program management, architecture and engineering, environmental and technical services — the core exposure is precisely the economic loss that general liability excludes. The more a contractor sells expertise rather than objects, the larger the uninsured gap.

The defense that is not as broad as it sounds. Many contractors assume the government contractor defense fills this space. It is worth understanding why it does not. The doctrine, established by the Supreme Court in Boyle v. United Technologies in 1988, can shield a contractor from certain state-law tort claims when it built to precise government specifications, the product conformed to those specifications, and the contractor warned of known dangers. It is a real protection, but a narrow one. It applies mainly to design-defect tort claims on products built to government specs; it does not answer a professional negligence claim on a services contract, a breach-of-contract allegation that a deliverable failed to meet requirements, or a dispute over professional judgment where the contractor — not the government — owned the design. Treating the government contractor defense as a substitute for professional liability coverage is a category error.

What professional liability actually answers. Professional liability — errors and omissions — responds to claims arising from the performance of professional services: negligent acts, errors, or omissions in the work the contractor was hired to perform. For a federal services contractor, it is the coverage matched to the actual risk. And it is increasingly not optional as a contractual matter. Federal rules require professional liability for architect-engineer contracts, and a growing number of solicitations across IT, consulting, and technical services now specify professional liability limits as a condition of award. A contractor without the coverage is not only exposed; it may be ineligible to bid.

The coverage has to be read for the features that federal work demands. Technology services contractors need a policy that integrates professional liability with cyber and technology errors and omissions, because a single failed deliverable can trigger both at once. Contractors performing a mix of services need coverage broad enough to follow the actual scope of work rather than a narrow professional-services definition that leaves part of the book uncovered. And because professional liability is written claims-made, continuity of coverage and the retroactive date matter as much as the limit — a lapse can leave years of completed work unprotected.

There is a procurement dimension contractors miss. In federal procurement, the insurance program is part of the firm's responsibility determination — the government's judgment that a contractor is capable of performing. A contractor that carries the right professional liability limits presents as a mature, fully covered firm. A contractor scrambling to add coverage after award, or discovering mid-performance that a claim falls in the gap, presents as the opposite. The program is not just protection; it is part of how the firm is evaluated.

This is the discipline PFTN brings to a government contractor's program. Strategic Discovery maps what the contractor actually sells and where the professional exposure genuinely lives, service line by service line. Risk Assessment tests the current program against the real claims — the defective deliverable, the failed system, the contested judgment — and against what each target solicitation requires. Solution Design structures professional liability alongside cyber, technology errors and omissions, and the general program so the coverages work together rather than leaving seams. Ongoing Optimization keeps the program aligned as the contract portfolio and the solicitation requirements evolve. A federal contractor is hired for its judgment and its expertise. The coverage that answers a claim against that judgment should be the center of the program, not the afterthought.

Sources: Business Benefits Group — Professional Liability and the Government Contractor Defense; FEDS Protection — Federal Contractor Professional Liability Insurance; Moody Insurance Worldwide — How Professional Liability Insurance Protects Federal Contractors; Moody Insurance Worldwide — Insurance for Government Contractors: What to Look For in a Program; CIS Solutions — Types of Insurance Every Government Contractor Should Have; Sahouri Insurance — Specific Insurance Requirements for Government Contractors

— Ryan Mefford, President & Risk Advisor

Overseas Security Risk
September 2026

Kidnap, Ransom, and Political Risk Coverage for Overseas Government Contractors in 2026

The Defense Base Act tells a federal contractor how an injured worker overseas is covered. It says nothing about the worker who is taken. For a company performing U.S.-funded work abroad — construction, logistics, IT, security, or humanitarian services — the Defense Base Act answers workers’ compensation for injury and death, and it is mandatory under FAR 52.228-3. But it is exactly that: workers’ compensation for the employee. It does not answer a kidnapping, a forced evacuation, or a host government that seizes the equipment mid-contract. The contractor that treats the DBA as its “overseas coverage” has mistaken one line for the whole category.

Two very different families of risk sit in that gap. The first is security risk to people — kidnap, ransom, extortion, wrongful detention, and the chaos of an evacuation. The second is political risk to assets and contracts — a government expropriating property, blocking currency, or repudiating the agreement the contractor was hired to perform. Neither is exotic for a firm operating in the regions where U.S.-funded work concentrates, and neither is covered by the DBA, the general liability policy, or the property program written for domestic operations.

The market for the first family has grown precisely because the exposure has. The global kidnap-and-ransom insurance market was valued at roughly $2.32 billion in 2024 and is projected to reach $4.7 billion by 2034, a 7.3 percent annual growth rate; the U.S. segment alone runs near $0.88 billion and is expected to grow at about 6.1 percent, with North America accounting for more than 42 percent of the global market. The drivers named by market analysts are the ones a government contractor recognizes immediately — rising geopolitical instability, the expansion of transnational organized crime, and mounting duty-of-care obligations toward personnel deployed to higher-risk regions in Africa, Latin America, and South Asia.

What kidnap-and-ransom coverage actually funds is broader than its name. It reimburses ransom payments, but its more valuable component is the response — access to a specialist crisis-management firm that negotiates on the company’s behalf, coordinates with authorities, and manages the family and the media. It reaches extortion, wrongful detention, hijacking, and, in many forms, the cost of evacuating personnel when a situation deteriorates. For a contractor sending employees into an unstable environment on the government’s behalf, that response capability is the difference between a managed incident and an improvised catastrophe.

Political risk insurance answers the second family — the exposures that attach to capital and contracts rather than people. It responds to expropriation, confiscation, and nationalization of assets; to currency inconvertibility and transfer restrictions that trap revenue in-country; to political violence that damages property; and, in the forms most relevant to a service contractor, to contract frustration and the wrongful calling of performance guarantees when a sovereign counterparty defaults or a project is cancelled by government action. The Lloyd’s market and specialist brokers write these coverages for precisely the environments where federal work and political instability overlap.

The timing gives the question new weight. The One Big Beautiful Bill Act, signed in July 2025, pushed the FY2026 defense budget past one trillion dollars — a 13 percent increase — and directed more than $200 billion through new loans, grants, and other transaction authority, alongside expanded funding for security and infrastructure work. More federal dollars flowing to overseas and border-adjacent projects means more contractors, and more subcontractors, deploying people and assets into exposed environments. The mission is growing; the risk profile is growing with it.

Underneath the coverage sits a legal obligation that has moved from the security office to the boardroom: duty of care. An employer that sends personnel into a known-hazardous environment owes them a defensible standard of protection, and failure to meet it is both a liability exposure and a reputational one. Kidnap-and-ransom and political risk programs are not merely balance-sheet protection; they are the documented evidence that an organization took its duty of care seriously before an incident, not after. For a government contractor whose reputation with its agency customer is its most valuable asset, that record matters.

This is the terrain our 4-Step Strategic Process is built to map. Strategic Discovery inventories every country of performance and every deployed employee, asset, and contract at risk. Risk Assessment measures those exposures against what the DBA, general liability, and property programs actually cover — and, more to the point, what they do not. Solution Design structures kidnap-and-ransom and political risk coverage to the specific jurisdictions and contracts in play, and confirms the DBA placement is compliant rather than assumed. Ongoing Optimization keeps the program current as the country list, the threat environment, and the contract portfolio shift. The Defense Base Act is the floor of a contractor’s overseas program, not its ceiling — and the exposures above it are the ones that end companies rather than merely cost them.

Sources: Market.us — Kidnap & Ransom Insurance Market (2024–2034); WTW — The Impact of the One Big Beautiful Bill Act and the Defense Base Act on Government Contracting; Marsh McLennan Agency — Defense Base Act Insurance; NFP — Trade Credit, Political Risk, Kidnap & Ransom; Lloyd’s — Political Risk (Crystal Risk Guidance); Global Underwriters — Government Contractors Coverage.

— Ryan Mefford, President & Risk Advisor

FAR Compliance
March 2026

The 45% Rejection Rate No One Talks About

Here is a number the insurance industry doesn't advertise: 45-55% of all certificate of insurance submissions to federal contracting officers are rejected on the first pass. For first-time government contractors, that number climbs to 75%.

Think about what that means. You've won the contract. You've mobilized your team. You've committed resources, signed subcontractors, and started planning the work. And then everything stalls — because your insurance certificate doesn't meet the contracting officer's requirements.

The cost isn't just the rework. It's delayed contract execution. Stalled revenue. A reputation with your CO that starts in the wrong place. And in some cases, it's the difference between keeping a contract and losing it before the work even begins.

The failures are almost always the same. Missing waiver of subrogation endorsements. Incorrect additional insured language — naming the wrong entity or using the wrong form. Inadequate cancellation notice provisions that don't meet the 30-day requirement. Missing primary and noncontributory endorsements. Policy limits that fall below the contract minimums specified in FAR 52.228-5.

These aren't exotic requirements. They're standard FAR clauses that have been in place for decades. And yet brokers continue to submit non-compliant certificates because they treat government contractor insurance like commercial insurance with a few extra boxes to check.

It isn't harder to get this right. It's just intentional. It requires a broker who reads the contract before placing the coverage. Who understands the difference between FAR 52.228-3 and FAR 52.228-5. Who knows that a waiver of subrogation on workers' compensation requires a specific endorsement — not just an additional insured notation. Who structures the certificate before submission, not after the rejection.

At PFTN, we don't submit certificates that get rejected. Not because we have some secret knowledge — but because we do the work upfront that most brokers skip. We read the contract. We match every insurance requirement to a specific policy provision. We verify endorsements before binding. And we build the certificate around the CO's requirements, not around what's convenient for the carrier.

The 45% rejection rate isn't a market condition. It's a choice. And it's one your firm doesn't have to make.

— PFTN Risk Management
Nuclear Liability
March 2026

What Price-Anderson Doesn't Cover

If you're a contractor at a DOE facility, you've probably heard the phrase "Price-Anderson covers that" more times than you can count. It's become a kind of magic incantation in the nuclear contractor world — a belief that the federal government's indemnification program eliminates the need to think seriously about insurance.

It doesn't. And the gap between what Price-Anderson actually covers and what contractors assume it covers is where firms get hurt.

The Price-Anderson Nuclear Industries Indemnity Act was enacted in 1957 to ensure that the public would be compensated in the event of a nuclear incident at a DOE facility. It provides federal indemnification currently capped at $16.6 billion per incident. That's an enormous number, and it covers an enormous scope — personal injury, property damage, evacuation costs, claims investigation, and settlement expenses arising from a nuclear event.

But here's what it doesn't cover: everything else.

Professional liability claims — when your engineering deliverable contains an error that causes project delays or rework — that's not a nuclear incident. Price-Anderson doesn't apply. Cyber breaches — when a threat actor compromises your systems and exfiltrates Controlled Unclassified Information — that's not a nuclear incident either. Pollution events that don't involve radioactive materials? Not covered. Workplace injuries from non-nuclear hazards? Your workers' compensation policy handles those, not Price-Anderson.

The distinction matters because DOE contractors face a uniquely complex risk environment. You're operating at facilities with radiological hazards, environmental contamination, classified information, sophisticated cyber threats, and high-consequence professional obligations — all at the same time. Price-Anderson addresses one dimension of that exposure. Your commercial insurance program needs to address everything else.

And yet most brokers treat DOE contractors like any other commercial account. They confirm that Price-Anderson indemnification exists, check the box, and move on to shopping your GL and workers' comp on price. They don't ask about your professional liability exposure on technical deliverables. They don't examine whether your pollution coverage extends to non-radiological contamination at legacy sites. They don't structure cyber programs around DFARS requirements and CUI handling obligations.

The result is a coverage program with a $16.6 billion nuclear indemnification sitting on top of a foundation full of gaps. It's like putting a titanium roof on a house with no walls.

At PFTN, we understand where Price-Anderson ends and your commercial exposure begins. We map every non-nuclear risk in your operation — professional liability, cyber, pollution, auto, workers' comp, umbrella — and build a program that actually protects the contractor, not just the public.

Because the $16.6 billion doesn't help you when the claim isn't nuclear.

— PFTN Risk Management
Cyber Risk
March 2026

CMMC Compliance Is Not Cyber Insurance

There is a dangerous conflation happening in the government contracting world right now: the belief that achieving CMMC certification eliminates the need for cyber liability insurance. It's wrong, and it's expensive to learn that the hard way.

CMMC — the Cybersecurity Maturity Model Certification — is a set of technical security controls. It tells you what safeguards to put in place: multi-factor authentication, encryption, access controls, incident response procedures, audit logging. These are important. They reduce your likelihood of a breach. They are, in many cases, contractually required.

But they are not insurance. They don't pay for anything when something goes wrong.

When a breach occurs — and breaches occur to compliant organizations regularly — the costs cascade fast. Forensic investigation to determine the scope and origin. Legal counsel specializing in government data breach notification requirements. Notification to affected individuals and agencies. Credit monitoring services. Regulatory defense when the contracting officer asks why Controlled Unclassified Information ended up where it shouldn't be. Business interruption while your systems are offline and your contracts are suspended pending investigation.

CMMC doesn't cover any of that. Cyber liability insurance does.

Think of it this way: CMMC is the lock on the door. Cyber insurance is the policy that pays to rebuild the house after someone picks the lock. Both matter. Neither replaces the other.

The problem is compounded by the fact that most insurance brokers don't understand CMMC well enough to explain the distinction. They see "cybersecurity requirement" in the contract and assume the client's IT team has it handled. They don't ask what level of CMMC certification is required. They don't examine whether the cyber policy's coverage triggers align with the types of incidents most likely to affect a government contractor handling CUI. They don't verify that the policy covers regulatory defense costs specific to federal data breach obligations.

And so the contractor ends up with two things that don't talk to each other: a CMMC certification that reduces risk, and a generic cyber policy that wasn't designed for government data exposure.

At PFTN, we build cyber programs specifically for government contractors. We understand the difference between CMMC Level 1 and Level 2 requirements. We know which policy forms cover federal regulatory defense and which don't. We structure coverage triggers around the actual threat landscape that DOE, DoD, and intelligence community contractors face — not a generic small business cyber template.

Compliance is the floor. Insurance is the safety net. You need both, and you need them built to work together.

— PFTN Risk Management
The Commodity Trap
February 2026

Good Enough

The insurance industry has become a race to the bottom. Cheaper quotes. Faster binding. Less thinking. The brokers who win are the ones who process the most volume with the least friction. And the clients? They get what the system is optimized to produce: good enough.

Good enough coverage. Good enough service. Good enough until it isn't — until a claim lands and the gaps reveal themselves, and everyone discovers that "good enough" was actually "not nearly enough."

This is the commodity trap, and it affects government contractors more acutely than almost any other segment. Federal contracts carry insurance requirements that are more complex, more specific, and more consequential than standard commercial obligations. FAR clauses. DFAR supplements. Facility-specific endorsements. Agency-specific limits. The margin for error is razor thin, and the cost of getting it wrong isn't just a denied claim — it's a terminated contract.

And yet the industry treats government contractor insurance the same way it treats everything else: shop it on price, bind it fast, and move on to the next account.

When the work is reduced to transactions, something gets lost. The meaning. The care. The recognition that behind every policy is a business with employees and families and missions that depend on getting this right.

When you build an agency that treats advisory work as craft — that sees every risk assessment as a chance to protect something worth protecting — you attract people who want to do meaningful work. Not just process transactions. Not just check boxes. But actually think about whether the coverage matches the exposure, whether the endorsements match the contract, whether the program serves the client or just satisfies the minimum.

And the light gets brighter.

PFTN was built on the conviction that "good enough" is the enemy of "actually protected." We don't process government contractor insurance. We engineer it. And we believe the difference between those two words is the difference between a firm that survives a claim and one that doesn't.

— PFTN Risk Management
Environmental Risk
March 2026

The Pollution Exclusion That Killed a Contractor

Every standard Commercial General Liability policy in the United States contains an absolute pollution exclusion. Every single one. It's been standard since 1986, and it means exactly what it says: if a claim arises from the discharge, dispersal, seepage, migration, or release of pollutants, your CGL policy does not respond.

For most businesses, this exclusion is an academic concern. For government contractors performing work at federal sites — especially DOE environmental cleanup facilities, legacy contamination sites, and installations with decades of industrial history — it is an existential threat.

Consider the work. Environmental remediation contractors handle hazardous materials daily. They excavate contaminated soil. They manage asbestos abatement. They transport and dispose of regulated waste. They work in and around structures with known environmental contamination stretching back to the Manhattan Project. Every day on the job is a day spent handling materials that trigger the pollution exclusion.

Now consider what happens when something goes wrong. A containment failure during soil remediation releases contaminants into a neighboring water supply. A worker is exposed to hazardous dust that wasn't properly controlled. A transport vehicle is involved in an accident that releases regulated materials onto a public roadway.

The contractor calls their broker. The broker calls the carrier. The carrier points to the pollution exclusion. Claim denied.

The defense costs alone can reach seven figures. The liability — bodily injury, property damage, cleanup expenses, regulatory fines — can reach eight. And the contractor, who believed their CGL policy would protect them, discovers that the most fundamental risk in their operation was never covered at all.

This is not a hypothetical. This happens. It happens because brokers don't understand the work their clients perform, and they don't examine whether the coverage matches the exposure. They see "general liability" on the FAR requirement list, they place a standard CGL policy, and they move on.

Contractors Pollution Liability — CPL — exists specifically to fill this gap. It covers third-party bodily injury and property damage from pollution events. It covers defense costs. It covers cleanup expenses. It can be structured to cover both sudden and gradual pollution events, and it can be combined with professional liability to create comprehensive environmental coverage for firms performing technical services at contaminated sites.

If your firm performs any work at DOE environmental cleanup sites, legacy contamination facilities, or installations with known environmental history, CPL isn't optional coverage. It's the only thing standing between your firm and an uninsured claim that can end your business.

The pollution exclusion in your CGL policy isn't a technicality. It's a wall. And most brokers never tell you it's there.

— PFTN Risk Management
Risk as Culture
March 2026

When Insurance Becomes a Discipline

A captive insurance company puts the insured in the driver's seat. That's the standard elevator pitch, and it's true as far as it goes. But it doesn't go far enough — because the real transformation isn't financial. It's cultural.

When your company funds its own first layer of risk, every person in the building has skin in the game. The safety manager isn't filling out forms for the carrier's benefit — they're protecting the company's own capital. The project manager isn't managing risk because the contract requires it — they're managing risk because every claim comes directly out of the captive that their company owns.

That shift in mindset changes everything. It changes how people think about jobsite safety. It changes how they review contracts. It changes how they manage subcontractors and how they respond to incidents. The risk isn't abstract anymore. It's personal.

For government contractors, this matters more than most. The federal contracting environment is built on compliance — layers of regulations, oversight mechanisms, and reporting requirements designed to ensure minimum standards are met. But compliance is a floor, not a ceiling. The contractors who thrive don't just meet the minimum. They build a culture where risk management is a discipline, not a checklist.

A captive structure reinforces that discipline. When your experience modification rate directly affects your captive's profitability — and that profitability flows back to your firm — the incentive to prevent losses becomes visceral. When your claims history determines your captive dividends rather than your carrier's quarterly earnings, the feedback loop tightens. You see the results of your risk management in your own financial statements, not in a carrier's annual report.

PFTN was the first firm in the Tennessee marketplace to introduce captive insurance solutions. We've designed and implemented every structure — group captives, cell captives, single-parent programs — for organizations across the spectrum, including firms operating in the federal contracting space.

The real case for a captive isn't the premium savings or the investment income or the underwriting profit. It's the culture it creates. When your company owns its risk, your people own it too. And that ownership is what separates contractors who manage risk from contractors who merely insure against it.

— PFTN Risk Management
Nuclear Liability
March 2026

The Three Layers of Nuclear Liability No One Explains

Every DOE contractor has heard the number: $16.6 billion. That's the current per-incident liability cap under the Price-Anderson Nuclear Industries Indemnity Act, most recently reauthorized through 2065. It's a staggering figure — designed to reassure the public that nuclear incidents will be compensated and to give contractors the confidence to perform work that no private insurer would fully underwrite.

But $16.6 billion is not a single pool of money sitting in a vault. It's a three-layer system, and the mechanics of how those layers work — who pays, when, and under what conditions — matter enormously to the contractor caught in the middle of a claim.

Layer One: Primary Insurance

For commercial nuclear power plants licensed by the NRC, the first layer is a mandatory primary insurance policy of $450 million, purchased from American Nuclear Insurers (ANI). This is real, private-market insurance with premiums, policy terms, and claims procedures.

For DOE contractors, this layer works differently. DOE contractors typically don't purchase private nuclear liability insurance at all. Instead, the DOE itself provides indemnification through the contract — essentially stepping into the role that ANI plays for commercial operators. The DOE indemnification agreement covers the contractor's full liability for nuclear incidents arising from contractual activities. There is no premium. There is no deductible. The government absorbs the cost.

This is the layer most contractors understand, and it's the one that creates the false sense of total protection.

Layer Two: Retrospective Premiums

For commercial operators, if a nuclear incident exhausts the $450 million primary layer, the second layer kicks in: retrospective premium assessments levied against every licensed nuclear power reactor in the United States. Each reactor operator can be assessed up to approximately $121 million per reactor per incident, with annual installments capped at $19 million per reactor. With 93 licensed reactors, this pool generates roughly $11.25 billion in additional capacity.

DOE contractors are not part of this retrospective assessment pool. Their incidents are funded through government appropriation, not through industry mutual assessment. But the mechanics matter because they reveal an important truth: the system was designed with the understanding that nuclear incidents can overwhelm any single insurance source. The pooling mechanism exists precisely because the risk is too large for individual entities to bear.

Layer Three: The Federal Backstop

If the combined primary insurance and retrospective premium pool are insufficient — which would require damages exceeding approximately $16.6 billion from a single incident — the statute requires the President to submit a plan to Congress for additional compensation. This is not automatic. It requires legislative action. Congress must appropriate the funds.

For DOE contractors, the federal backstop is more direct. The DOE's indemnification agreement covers the contractor up to the full statutory cap. Beyond that, the same Congressional action requirement applies. But the critical point is this: between the DOE indemnification agreement and the statutory cap, the contractor is fully protected for nuclear incident liability.

Where Contractors Get Confused

The confusion isn't about whether Price-Anderson provides protection. It does — and it's extraordinarily broad. The omnibus coverage provision extends indemnification to the prime contractor, all subcontractors at any tier, suppliers, transporters, and essentially any person who may be legally liable for a nuclear incident arising from DOE contractual activities. A 2025 Federal Circuit ruling in Cotter Corp. v. United States confirmed this expansive interpretation, holding that even downstream purchasers of radioactive material can qualify for indemnification.

The confusion is about boundaries. Specifically:

Workers' compensation is expressly excluded. If your employee suffers an occupational injury — even from radiation exposure — their workers' compensation claim is not indemnified by Price-Anderson. That's your workers' comp policy. Period. The statute explicitly carved out state and federal workers' compensation acts from the definition of "public liability."

On-site property damage is excluded. If a nuclear release damages the facility itself — your equipment, your temporary structures, your materials — Price-Anderson does not cover that loss. You need property insurance, and that property policy almost certainly contains a nuclear hazard exclusion. This creates a gap that requires careful structuring.

Non-nuclear incidents are not covered. A fall from scaffolding. A vehicle accident on the access road. An electrical fire in the maintenance building that has nothing to do with radioactive materials. These are standard operational risks that require standard commercial insurance. Price-Anderson doesn't touch them.

The Combined Claim Problem

Here's where it gets genuinely complicated. Consider a scenario where a radioactive release at a DOE facility causes direct radiation exposure (Price-Anderson), triggers an evacuation that results in a vehicle accident (general liability), causes thyroid damage in employees (workers' compensation), and contaminates adjacent commercial property (potentially both Price-Anderson and property/pollution).

That single event generates claims that split across multiple coverage paths. The radiation exposure flows to Price-Anderson indemnification. The vehicle accident flows to your commercial general liability policy. The employee thyroid damage flows to workers' compensation. The off-site property contamination requires analysis — if it's radiological, Price-Anderson may apply for third-party claims; if it's mixed contamination, you may need both Price-Anderson and your pollution liability policy.

And here's the coverage trap: your standard CGL policy contains a nuclear hazard exclusion. Your pollution policy excludes radioactive materials. If a claim has concurrent nuclear and non-nuclear causation, which policy responds? Without explicit coordination language — "this coverage is in addition to and not in lieu of indemnification under the Price-Anderson Act" — your commercial carrier may deny the claim on the theory that Price-Anderson is the proper coverage path. And DOE may decline indemnification on the theory that the non-nuclear component is not a nuclear incident.

The contractor falls into the gap between two systems that each assumes the other is covering the loss.

What This Means for Your Insurance Program

Price-Anderson is not your insurance program. It's one component of your risk management architecture — an extraordinary one, but a limited one. Your commercial insurance stack needs to be built around the specific exclusions and boundaries of Price-Anderson, not as a redundant layer on top of it.

That means workers' compensation structured for radiological workplace exposure. General liability with endorsements that coordinate with — not conflict with — DOE indemnification. Professional liability with tail coverage adequate for the decades-long latency of nuclear-related claims. Pollution coverage that explicitly addresses the boundary between radioactive and non-radioactive contamination at legacy sites.

At PFTN, we build insurance programs that start where Price-Anderson ends. We map every non-nuclear exposure, structure every endorsement for federal contract compliance, and coordinate every policy with the indemnification framework your DOE contract provides. Because the $16.6 billion protects the public. Your commercial program is what protects the contractor.

— PFTN Risk Management
FAR Compliance
March 2026

FAR 52.228: The Insurance Clauses Your Broker Should Know by Heart

The Federal Acquisition Regulation is not light reading. It's 53 parts, thousands of clauses, and an endless maze of cross-references. But buried in Part 28 — "Bonds and Insurance" — and Part 52.228 is a set of clauses that directly govern what insurance a government contractor must carry, how it must be structured, and what happens when it isn't.

If your broker can't walk you through these clauses without looking them up, they're not a government contractor specialist. They're a generalist guessing at federal requirements. And guessing is how certificates get rejected, contracts get delayed, and compliance becomes a recurring crisis instead of a baseline condition.

Here are the clauses that matter most — and what each one actually requires.

FAR 52.228-3: Workers' Compensation Insurance (Defense Base Act)

This clause requires contractors performing work outside the United States to carry workers' compensation insurance under the Defense Base Act (DBA). The DBA extends the Longshore and Harbor Workers' Compensation Act to cover employees working on military bases, public works contracts, and federally funded projects overseas.

The critical detail: DBA coverage is not standard workers' compensation. It's a federal program with its own benefit structure, reporting requirements (Form LS-202 within 10 days of injury), and dispute resolution through the Department of Labor's Office of Workers' Compensation Programs. Many domestic workers' comp carriers either don't offer DBA coverage or offer it as a poorly understood endorsement. If your contractor performs any work at overseas installations — including temporary assignments — this clause applies, and your policy must specifically provide DBA coverage.

FAR 52.228-5: Insurance — Work on a Government Installation

This is the foundational insurance clause for contractors performing work on government property. It establishes minimum coverage requirements that the contracting officer can adjust upward based on the nature of the work.

The baseline minimums under FAR 52.228-5:

Workers' compensation: As required by applicable federal and state workers' compensation and occupational disease statutes. For work subject to the Longshore and Harbor Workers' Compensation Act, coverage must meet that Act's requirements.

Employer's liability: $100,000 minimum, unless the state of performance has a higher requirement.

Bodily injury liability: $500,000 per occurrence.

Property damage liability: $500,000 per occurrence — covering both contractor operations and completed operations.

Automobile liability: $200,000 per person / $500,000 per occurrence for bodily injury, $20,000 per occurrence for property damage.

These are minimums. Contracting officers routinely require higher limits — $1 million or $2 million per occurrence for GL, $1 million combined single limit for auto — and the solicitation or contract will specify any increased requirements. The mistake brokers make is treating these as the actual requirements rather than the floor.

FAR 52.228-7: Insurance — Liability to Third Persons

This clause applies primarily to cost-reimbursement contracts and requires the contractor to maintain insurance coverage for liabilities to third persons arising out of contract performance. It's broader than 52.228-5 in scope because it addresses the reimbursability of insurance costs under cost-type contracts.

The clause requires: general liability insurance, automobile liability, and aircraft public and passenger liability (where applicable). But the real significance is in the cost allowability provisions. Under cost-reimbursement contracts, insurance premiums that comply with FAR 31.205-19 are allowable costs — meaning the government reimburses the contractor for insurance that meets these requirements. This creates both an obligation and an opportunity: the contractor must carry adequate coverage, but the cost of that coverage is a reimbursable contract expense.

The catch is FAR 31.205-19's limitations. Self-insurance is allowable only if it's more economical than purchased coverage. Insurance against defects in the contractor's own work is not allowable. And rates must be "reasonable" — which gives the contracting officer latitude to challenge premiums that appear inflated.

FAR 52.228-8: Liability and Insurance — Leased Motor Vehicles

A narrow but frequently triggered clause. When contractors lease motor vehicles for use in government contract performance, this clause requires specific insurance provisions: the contractor must maintain adequate liability insurance, include a waiver of subrogation against the government, provide 30-day cancellation notice, and accept liability for negligence-caused damage to the leased vehicle.

The detail that trips up most brokers: the waiver of subrogation must specifically name the United States Government. A generic waiver of subrogation endorsement naming the "certificate holder" is often insufficient. The endorsement must be explicit.

The Endorsement Requirements That Kill Certificates

Beyond the specific FAR clauses, government contracts typically require a set of policy endorsements that most commercial insurance programs don't include by default. These endorsements are where the 45% certificate rejection rate originates.

Additional Insured — United States of America. The government must be named as an additional insured on the contractor's general liability and auto liability policies. This isn't a simple certificate notation — it requires an actual policy endorsement (CG 20 10, CG 20 37, or equivalent). Many carriers use restrictive additional insured forms that limit coverage to "ongoing operations" but exclude "completed operations." For government contracts, both must be covered.

Waiver of Subrogation. The contractor's insurer must waive its right to subrogate against the government and any other additional insureds. This requires endorsements on CGL (CG 24 04), workers' compensation (WC 00 03 13), and auto liability. Without waiver of subrogation on workers' compensation — which is a separate endorsement from the additional insured — the carrier retains the right to pursue the government for recovery of claim payments. Contracting officers know this and will reject certificates that don't include it.

Primary and Non-contributory. The contractor's coverage must be primary to — and not seek contribution from — any insurance the government may maintain. This endorsement (CG 20 01 or policy language) ensures the contractor's insurance responds first. Without it, the contractor's carrier may argue that the government's own liability coverage should share in the loss, creating a dispute that delays claims resolution.

Cancellation Notice. A minimum 30 days' written notice to the contracting officer before any cancellation or material change in coverage. Standard ACORD certificates now include only a "best efforts" cancellation notice — which is legally meaningless. The endorsement must be added to the policy itself, not just noted on the certificate.

DFARS Supplements: Defense Contractors Face Additional Requirements

Contractors working under Department of Defense contracts face additional requirements under the Defense Federal Acquisition Regulation Supplement (DFARS). DFARS 252.228 series clauses add requirements for aircraft liability insurance, war-hazard protection, and nuclear incident indemnification specific to DoD operations.

For contractors at DOE facilities performing defense-related work — which includes most Oak Ridge operations — both FAR and DFARS requirements may apply simultaneously. The insurance program must satisfy both sets of requirements, and the certificate must demonstrate compliance with each applicable clause.

Cost Allowability: FAR 31.205-19

For cost-reimbursement contractors, insurance costs are allowable under FAR 31.205-19 if the coverage is required by the contract, required by law, or necessary for the contractor's operations. Premiums must be at rates not exceeding those generally available to the contractor. Self-insurance programs are allowable but must be approved by the contracting officer and must be more economical than purchased insurance.

The practical implication: DOE contractors on cost-plus contracts should carry the right insurance — not the cheapest insurance. The cost is reimbursable, and the protection is real. Cutting corners on insurance to reduce reimbursable costs is a false economy that saves the government pennies and exposes the contractor to dollars in uninsured liability.

The PFTN Approach

At PFTN, we don't submit certificates and hope they pass. We read the contract first — every FAR clause, every DFARS supplement, every special provision in the solicitation. We match each insurance requirement to a specific policy endorsement. We verify endorsement language before binding. And we build the certificate as a compliance document, not an afterthought.

The FAR insurance clauses aren't complicated. They're specific. And specificity is something most brokers avoid because it requires actually understanding the regulatory framework. We don't avoid it. We live in it.

— PFTN Risk Management
Government Contractor Risk
Ryan Mefford, President & Risk Advisor · May 2026

CMMC Flow-Down Is Now a Prime Contractor Liability Problem

The CMMC enforcement conversation has spent the last three years inside the subcontractor community. Small and mid-sized defense suppliers, trying to figure out the cost, the timeline, the gap, and the path to Level 2 certification. That conversation was always going to bend.

November 10, 2026, is when it bends.

That is the start of CMMC Phase 2. Mandatory C3PAO-assessed Level 2 certification on all new defense contracts involving Controlled Unclassified Information. Organizations not certified when a Phase 2 solicitation appears cannot compete for the award. Boeing, Lockheed Martin, RTX, and several other large primes are no longer waiting for the formal deadline — they are already conditioning new subcontract awards on Level 2 readiness and walking away from suppliers who cannot show a credible certification path.

That is a procurement story. It is also a prime contractor liability story, and the second story is the one most prime contractors have not absorbed yet.

The False Claims Act exposure runs in two directions. A prime contractor that passes CUI to a subcontractor it knows or should know is not CMMC-compliant — and continues collecting government payments on a contract that requires supply-chain compliance — has potential FCA exposure on the prime's own invoices. Not the sub's. The prime's. The DOJ's cyber-related FCA recoveries hit $52 million in FY 2025 and have tripled in each of the last two years.

The flow-down requirement is not symmetric. Subcontractors must comply with CMMC requirements in the same way as the prime, with the exception of sharing CMMC Unique Identifier data with the contracting officer. That asymmetry creates an operational responsibility for the prime that the prime cannot delegate. The prime determines the appropriate CMMC level for each subcontractor. The prime documents the determination. The prime monitors the certification status. The prime accepts the contractual and statutory consequence if the subcontractor fails to maintain that status during performance.

The supplier base is largely uncertified. Roughly 76,598 contractors and subcontractors need CMMC Level 2 certification under the rule. As of early 2026, only about 1,042 had completed Level 2. That is 1.4 percent of the affected population, against a Phase 2 deadline six months away. The math does not work. Primes are already absorbing the implication.

The insurance program is not built for this. Standard cyber liability policies typically do not respond to FCA matters — they are written for first-party breach, third-party privacy liability, business interruption, and ransomware extortion, not for affirmative misrepresentation claims under the FCA. Most D&O forms exclude FCA matters or carve them out behind significant retentions. Professional liability for government contractors varies wildly by carrier on FCA response. The contractor that walks into a 2026 renewal with the same submission file as 2024 is paying for a coverage gap on every line.

The cyber underwriter is now asking the prime two new questions. What is your supply-chain CMMC verification process. What is your written policy on CUI flow-down to subcontractors that have not completed Level 2 certification. The submission that does not have written answers gets either a coverage gap or a premium increase. Sometimes both.

The CMMC rule was always going to push compliance cost down into the supply chain. What the rule also pushed — and what most primes have not yet internalized — is the compliance verification responsibility back up into the prime. The prime is now the certification cop, the documentation custodian, and the FCA defendant of first instance. The supplier is the certification candidate. The two roles have very different risk profiles, and they need very different insurance conversations.

PFTN's 4-Step Strategic Process for federal contractors starts with Strategic Discovery: contract portfolio, agency mix, prime versus subcontractor role distribution, supply-chain depth, CUI scope, CMMC level required by active contract, SPRS attestation history, and the documented flow-down protocol. Risk Assessment quantifies cyber form FCA exclusion language, D&O form FCA exclusion language, professional liability response on attestation accuracy, and the gap between the firm's CMMC documentation and the renewal application narrative. Solution Design pairs the certifications with the policy forms so the actual claim type the DOJ is bringing has somewhere to land.

The CMMC rule was sold to primes as a supplier problem. November 10 is when it becomes a prime problem.

The mission starts months before the deadline — and never on autopilot.

— Ryan Mefford, President & Risk Advisor · PFTN Risk Management
Cyber / Compliance
April 20, 2026

The Software Bill of Materials Mandate Is Here — Just Not the One Everyone Expected

The Software Bill of Materials story that most federal contractors prepared for in 2025 is not the story that landed in 2026. The Office of Management and Budget rescinded the uniform secure-software attestation requirement on January 23, 2026 — replacing the one-size-fits-all CISA Common Form with a risk-based approach in which each federal agency develops its own SBOM and software-attestation requirements.

The headline read the rescission as a deregulatory move. The contracting reality is the opposite. The SBOM mandate is now distributed across every awarding agency rather than centralized at OMB — which means the contractor's SBOM and attestation obligation depends on which agency, which contract vehicle, and which scope of work the contractor is executing.

OMB Memorandum M-26-05 replaced the Biden-administration Memorandum M-22-18. The CISA Common Form attestation that federal agencies had been required to obtain from software producers is no longer mandatory. Agencies may still use the Common Form. Agencies may also develop their own risk-based approach. Agencies may still require an SBOM.

A contractor running on DoD task orders is going to see one SBOM expectation. A contractor running on civilian agency vehicles is going to see another. A contractor delivering software for cleared-environment use is going to see a third — driven by NIST SP 800-218 and the Secure Software Development Framework references that the cleared community has not relaxed.

DOJ's Civil Cyber-Fraud Initiative remains active. Settlements under cybersecurity-related FCA cases continue to land. The OMB rescission does not insulate a contractor from FCA exposure. If a contract requires an SBOM or a secure-software attestation, and the contractor delivers one without the actual underlying secure-development practices in place, the FCA exposure is the same as it was under the prior Common Form posture.

CMMC Phase 2 enforcement still begins November 10, 2026. Contractors delivering software in support of DoD requirements still have to satisfy the CMMC Level 2 control inventory. The OMB rescission does not relieve the CMMC posture.

The contractor's cyber insurance underwriter used to be able to ask one question — "Are you compliant with the CISA Common Form attestation requirement?" — and use the answer to score the SBOM exposure. The 2026 underwriting question is more granular — which agencies, which contract vehicles, which task orders, which software components, which attestation requirements does your portfolio carry?

PFTN's govcon approach treats the SBOM file the way the contracting officer treats it. Strategic Discovery starts with the contract vehicle inventory, the agency mix, the software-development practices, and the supplier flow-down posture. Risk Assessment quantifies the agency-by-agency requirement set and the FCA exposure inside cybersecurity representations the contractor has already made. Solution Design pairs the cyber tower with practice management liability and the surety program.

The SBOM mandate is here. It just is not the one everyone expected. The shift starts with one conversation — and preferably before the next contract modification lands.

— Ryan Mefford, President & Risk Advisor

DCAA Compliance
April 6, 2026

The DCAA Timekeeping Audit That Started Last Quarter

The DCAA labor floor check is the most discreet audit in federal contracting. The auditor walks the office at an undisclosed time, asks four or five employees what they are working on right now, what charge code they are billing to, and how they entered yesterday's time. The audit lasts twenty minutes. The findings shape the indirect rates the contractor will negotiate for the next three years.

Q1 2026 was a heavy floor-check quarter. DCAA's audit guidance for 2026 explicitly elevates labor floor checks, total time accounting verification, and audit-trail completeness on the contractor's timekeeping system. The contractors who walked into Q1 with a documented labor charging policy and an enforceable approval workflow are the contractors who passed without finding.

Total Time Accounting requires that every hour an employee works gets recorded — direct and indirect, billable and overhead, training and PTO and uncompensated overtime. Labor cost cannot be allocated correctly to a federal contract if the contractor does not capture every hour the employee actually worked. Labor mischarging is the FCA exposure the agency is most actively pursuing.

Daily time entry is the audit anchor. A timesheet submitted weekly, biweekly, or at the end of the pay period fails the DCAA daily-entry standard — because the auditor cannot test whether the employee actually entered time on the day the work was performed. The 2026 floor check explicitly asks the employee when they entered yesterday's time and whether they remember the charge code without checking notes.

DCAA expects the timekeeping system to preserve a complete record — who entered each time entry, when, what was changed, who approved the change, and what supporting documentation accompanied the correction. A contractor with a hand-edited spreadsheet timekeeping system in 2026 is a contractor the auditor is going to score as a control deficiency.

The auditor's twenty-minute walk of the office is not actually about catching a fraudulent timecard. It is about testing whether the supervisor review the contractor's policy claims to perform — actually happens. The supervisor who cannot describe what the employee is working on this week is a supervisor whose review the auditor reads as ceremonial.

Timekeeping records must be retained for at least three years after the final contract payment. The contractor whose record retention is tied to a timekeeping platform's data export schedule — and not to the contract closeout calendar — is going to discover the gap during a post-award DCMA audit, not during a floor check.

PFTN's govcon approach treats the DCAA file the way the auditor treats it. Strategic Discovery starts with the timekeeping system, the charge code library, the labor cost allocation model, and the indirect rate posture. Risk Assessment quantifies the FCA exposure inside the labor charging history. Solution Design pairs the practice management liability and the surety program with the labor compliance posture — because a floor-check finding is also an insurance event.

The DCAA auditor who walked the office in Q1 already wrote the finding. The shift starts with one conversation — and preferably before the next floor check.

— Ryan Mefford, President & Risk Advisor

Crime / Fidelity
September 10, 2026

Commercial Crime and Fidelity Bond Requirements for 2026 Government Contractors

Government contractors spend enormous discipline on the compliance frontier — CMMC assessments, DCAA-ready timekeeping, FAR flow-downs, the cybersecurity controls that protect controlled unclassified information. That attention is earned; the requirements are real. But while the firm fortifies the network perimeter, the oldest loss in business is still walking out the back door: money leaving through an employee who steals it, or through a finance clerk who wires it to a fraudster posing as a vendor. A contractor can be cyber-hardened and audit-clean and still absorb a six-figure loss on a transaction it authorized itself.

Commercial crime insurance is the line built for exactly that loss, and it answers two faces of the same problem. IRMI calls crime coverage “the other property policy” — it protects money, securities, and property from theft rather than from fire or wind. One half covers employee dishonesty: the embezzlement, the fraudulent payroll, the diverted progress billing. The other covers third-party crime: theft, forgery, computer fraud, and funds-transfer fraud committed from outside. Beazley’s claims leadership describes a market where the two now run in parity — roughly half of commercial crime losses originate with employees and half with outside actors. A program that guards one and ignores the other is only half a program.

The contractor’s operating profile is precisely what fraudsters study. Payroll for a distributed workforce, subcontractor and supplier payments, progress billings and milestone draws, reimbursements for government-furnished property — large sums moving on predictable schedules, often across multiple job sites with thin back-office staffing. The numbers behind the external threat are stark. The FBI’s Internet Crime Complaint Center reports that business email compromise produced more than $55.4 billion in exposed losses across 305,033 incidents between October 2013 and December 2023, with U.S. victims accounting for $20.1 billion and global losses climbing nine percent in a single year. BEC is not a fringe scam — it is the most lucrative fraud scheme the Bureau tracks.

Here is the gap that catches contractors who believe they are covered. When an employee is deceived into wiring funds to a fraudster, the loss is social engineering — and the two policies a contractor is most likely to hold both treat it as an exception. Cyber policies frequently exclude voluntary-parting fraud, reasoning that no system was breached; crime policies cover it only by specific endorsement. Business Insurance reports that adding social engineering coverage typically raises a crime premium by 25 to 50 percent, and even then the protection is usually sublimited — $100,000, $250,000, or perhaps $500,000 sitting behind a policy whose headline limit reads $1 million. Two or three fraudulent transfers in a month can clear six figures, and the loss is absorbed long before the sublimit is reached. Full-limit social-engineering coverage exists, but only for the contractor who asks for it and documents the controls to earn it.

The fidelity side carries its own mandates. A blanket fidelity bond and employee-dishonesty coverage are standard answers to internal theft, and for contractors they are frequently not optional — teaming agreements and prime-subcontractor terms routinely require them, and federal law imposes a separate fidelity-bond obligation on anyone who handles employee-benefit-plan assets under ERISA. The question is rarely whether a contractor needs the coverage; it is whether the limits and the definitions match how the business actually moves money.

The enforcement climate has raised the stakes on the controls behind the coverage. The Department of Justice stood up a National Fraud Enforcement Division on April 7, 2026, scaling toward roughly 500 attorneys and staff by late August and naming six procurement-fraud priorities — defective pricing, bid rigging, self-dealing, bribery, product substitution, and billing fraud. Its March 2026 voluntary-self-disclosure policy rewards the contractor who detects a problem internally and reports it. The through-line is unmistakable: the financial controls regulators now expect — segregation of duties, documented approvals, reconciliation — are the same controls that surface an embezzlement before it compounds. Crime insurance is what responds when those controls are defeated anyway, and a clean control environment is what earns the broader terms at renewal.

This is the work of PFTN’s 4-Step Strategic Process. Strategic Discovery traces how money actually moves through the contract — payroll, vendor payments, draws, and the people authorized to release funds. Risk Assessment measures the crime and fidelity limits against that reality and, critically, reads the social-engineering sublimit and the boundary between the crime and cyber policies. Solution Design coordinates the two so fraudulent-transfer loss lands on a policy that answers it at a limit sized to the exposure, not a token sublimit. Ongoing Optimization keeps the coverage aligned as contracts scale and the back office changes.

A contractor that has invested years in compliance discipline should extend that same discipline to the dollars themselves. Illuminating where the crime policy ends, where the cyber policy declines, and where a sublimit quietly shifts the loss back onto the balance sheet turns an overlooked exposure into deliberate control of the firm’s own money.

Sources: IRMI — Crime Insurance: The Other Property Policy; IRMI — Commercial Crime Policy (CR); IRMI — Employee Dishonesty Coverage; IRMI — Blanket Fidelity Bond; Business Insurance — Demand for Social Engineering Fraud Coverage on the Rise; FBI IC3 — Business Email Compromise: The $55 Billion Scam; National Law Review — DOJ Fraud Division’s New Enforcement Priorities: What Government Contractors Need to Know

— Ryan Mefford, President & Risk Advisor

Cyber / DFARS
September 14, 2026

DFARS 252.204-7012 Cyber Incident Reporting and First-Party Breach Costs in 2026

Defense contractors have spent years treating cybersecurity as a compliance project — NIST SP 800-171 controls, the CMMC assessment, the System Security Plan and its plan of action. That work matters, but it answers a different question than the one a breach actually poses. When a contractor’s network is compromised in 2026, the governing clause is not a maturity model — it is DFARS 252.204-7012, and it imposes obligations that begin the moment an incident is discovered, obligations most contractors have never rehearsed and that their insurance may or may not fund.

Start with what the clause requires. DFARS 252.204-7012 obligates a contractor handling covered defense information to safeguard it under NIST SP 800-171 and, critically, to rapidly report any cyber incident that affects that information or the contractor’s ability to perform — within 72 hours of discovery — to the Department of Defense through the DIBNet portal. Reporting requires a DoD-approved medium assurance certificate obtained in advance; a contractor scrambling to register one during an active incident has already lost hours it does not have. The clause also requires the contractor to preserve images of affected systems for at least 90 days, to submit malicious software to the DoD Cyber Crime Center, and to flow the same requirements down to subcontractors.

The 72-hour clock is where the exposure becomes concrete. Seventy-two hours is a narrow window in which a contractor must detect the incident, scope which covered defense information was affected, engage forensic help, and file a substantive report — while continuing to perform the contract. A firm without a rehearsed incident-response plan discovers, mid-crisis, that the obligation runs on the government’s clock, not on the pace at which its IT staff can investigate. Meeting the deadline is itself a cost, and it is one that lands before anyone has quantified the damage.

This is where the insurance question diverges from the compliance question, and where many defense contractors carry a false sense of security. A cyber liability policy is built around two halves. Third-party coverage answers claims brought by others. First-party coverage answers the insured’s own breach-response costs — forensic investigation, legal counsel, notification, credit monitoring, public relations, and business interruption. It is the first-party side that funds exactly the work DFARS 252.204-7012 forces a contractor to perform on a 72-hour deadline, and it is the first-party side that thin or generic policies most often underinsure.

The alignment between the clause and the policy is rarely examined until it fails. A cyber policy may impose its own notification deadline to the carrier that sits awkwardly against the 72-hour DoD requirement. It may sublimit forensic costs below what a defense-grade investigation actually runs. It may scope regulatory response narrowly enough that a DoD reporting obligation falls outside it. And it may not contemplate the cost of preserving system images for 90 days or the specialized counsel a covered-defense-information incident demands. A contractor that bought cyber coverage to check a box can hold a policy that does not answer the specific obligations its contracts impose.

The flow-down provision multiplies the problem down the supply chain. A prime that must ensure its subcontractors carry the clause — and can actually meet it — inherits the subcontractors’ unpreparedness as its own risk. A subcontractor breach that affects covered defense information becomes the prime’s reporting problem and, potentially, its performance problem. Reading the flow-down as a contract-management and insurance question, not only a compliance one, is what keeps a sub’s incident from becoming the prime’s uncovered loss.

This is the work of PFTN’s 4-Step Strategic Process. Strategic Discovery establishes what covered defense information the contractor actually handles, where it lives, and what its contracts and flow-downs require. Risk Assessment reads the cyber policy against DFARS 252.204-7012 line by line — the notification timing, the first-party sublimits, the regulatory-response language, the image-preservation and forensic costs — and surfaces the gaps before an incident tests them. Solution Design negotiates coverage that funds the 72-hour obligation and aligns the carrier’s conditions with the DoD’s. Ongoing Optimization revisits both as the DFARS and CMMC frameworks evolve and the contractor’s data footprint changes.

Compliance frameworks are written for the calm before an incident; DFARS 252.204-7012 is written for the 72 hours after one. A defense contractor that has satisfied its controls but never mapped its insurance to the reporting clause is prepared for the audit and unprepared for the breach. Illuminating that distinction — and building coverage that funds the obligation the clause actually imposes — is what turns a cyber incident from a contract-threatening event into a managed one.

Sources: eCFR — 48 CFR 252.204-7012: Safeguarding Covered Defense Information and Cyber Incident Reporting; Acquisition.gov — DFARS 252.204-7012; Summit 7 — DFARS 7012; CyberSaint — DFARS 252.204-7012: What You Need to Know; The Defense Compliance Report — DFARS 7012 Incident Reporting: 72-Hour DoD Checklist; Legal Information Institute (Cornell) — 48 CFR 252.204-7012

— Ryan Mefford, President & Risk Advisor

Product Liability
September 2026

The Government Contractor Defense and Product Liability Exposure for Defense Manufacturers in 2026

For a company that machines airframe components, molds body-armor plates, or assembles electronics for a federal supply schedule, the reasoning often runs like this — we build to the government's drawings, so the government's liability shield is ours. That assumption has always been narrower than contractors hope, and 2026 has drawn the boundary in sharper lines. The government contractor defense is real, it is powerful, and it is not a stand-in for a product liability program.

The defense traces to Boyle v. United Technologies Corp., 487 U.S. 500 (1988) — a case that reached the Supreme Court after a Marine helicopter pilot could not escape a downed aircraft because a design flaw blocked his emergency hatch. The Court held that state tort law can be displaced when it conflicts with the federal government's discretionary procurement choices. But the Court did not hand manufacturers blanket immunity. It built a three-part test, and each element carries its own ownership: the United States approved reasonably precise specifications; the equipment conformed to those specifications; and the supplier warned the United States of dangers known to the supplier but not to the government.

Read those elements closely and the strategic point surfaces. The defense protects a contractor for building what the government told it to build — not for what the contractor decided on its own. Reasonably precise specifications mean the government exercised discretion over the design; a rubber-stamp of the contractor's own drawings does not qualify. Conformance must be provable, which is a documentation challenge before it is a legal one. And the duty to warn is affirmative — a hidden hazard the contractor knew about but never disclosed can collapse the entire defense.

The line between mil-spec and commercial-item work is where many manufacturers miscalculate. When the government dictates a detailed design, the defense stands at its strongest. When a contractor supplies a commercial-item or COTS product — the same pump, connector, or coating it sells to private buyers — the government has approved little, the discretion is the contractor's, and the shield thins to nearly nothing. Dual-use products occupy the uncomfortable middle. A component engineered to a Defense Department drawing may qualify; the same part pulled from a commercial catalog and dropped into a defense platform likely will not.

Service and performance contractors sit under the same light. Boyle was a procurement case about equipment built to specification, and the Defense Department itself has cautioned that the doctrine does not extend cleanly to nonprocurement performance work. That distinction was underscored this spring. In Hencely v. Fluor Corp., decided April 22, 2026, the Supreme Court ruled 6-3 that federal law did not preempt an injured Army specialist's state negligence claims against a military contractor whose employee carried out a 2016 suicide bombing at Bagram Airfield. The Court narrowed the protection to situations where a contractor is sued precisely for accomplishing what the federal government requested. Because Fluor's conduct was neither ordered nor authorized — and ran contrary to instructions — no shield applied.

Months earlier, in GEO Group v. Menocal (February 2026), the Court clarified that the related Yearsley defense is a merits defense rather than an immunity from suit — meaning contractors can no longer exit early through interlocutory appeal and must instead run through discovery and trial. The direction is consistent: the courts are illuminating the edges of these doctrines, not widening them.

Set those developments beside the casualty market and the fiduciary case for a real program becomes plain. Nuclear verdicts rose 40.7% in 2025, and product liability alone produced 29 such verdicts totaling roughly $12 billion, according to Marathon Strategies research. The median top-tier U.S. casualty verdict reached $98 million in 2024, and Aon projects general liability rates climbing as much as 9% in early 2026. A defense that resolves — if it resolves — only after years of litigation does not fund defense costs along the way, does not answer the commercial-item claim it never reached, and does not protect the additional insureds your prime demanded.

So the discipline is layered, not singular. Product liability and completed-operations limits — the coverage that responds for a finished product after it leaves your control — carry the litigation the defense cannot dispose of on a short timeline. Indemnification clauses in prime and subcontract flow-downs deserve line-by-line review, because a hold-harmless you signed can leverage away the very protection Boyle offers. Vendors' and additional-insured discipline — knowing who owes defense to whom, and confirming it on paper before a loss — determines whether a claim lands on your tower or someone else's. And your specification and warning records are not filing-cabinet clutter; they are the evidence that decides whether elements one through three of Boyle are even available to you.

This is the work our 4-Step Strategic Process is built to do. Strategic Discovery maps where your products sit on the mil-spec-to-commercial spectrum and where the defense realistically reaches. Risk Assessment uncovers the hidden gaps — the dual-use SKU, the unreviewed indemnity, the certificate that never arrived. Solution Design structures product liability and completed-operations limits around what the defense will not carry. Ongoing Optimization keeps that structure current as the case law and your contract flow-downs continue to move. The government contractor defense is a genuine asset. Treated as one layer of a strategy, it protects you; treated as the whole strategy, it becomes an exposure of its own.

Sources: Faegre Drinker Biddle & Reath — Supreme Court Decides Hencely v. Fluor Corp. et al.; Wiley Rein LLP — Immunities and Defenses for Government Contractors, Part 1: Tort Claims; Federal News Network — A Supreme Court Case Could Redefine Contractor Liability in Combat Zones; Congressional Research Service — Are State Tort Claims Against Military Contractors Preempted? (LSB11364); The Contractor's Perspective — The Government Contractor Defense: 10 Things Contractors Need to Know; Insurance Journal — Nuclear Verdicts Go Boom, Increase 40.7% in 2025; Aon — 2026 P&C Outlook: Navigating Volatility, Unlocking Growth; Insureon — What Is Products-Completed Operations in Business Insurance?

— Ryan Mefford, President & Risk Advisor

Aviation / UAS
September 21, 2026

Unmanned Aircraft Systems Liability Insurance for Federal Drone Contractors in 2026

A commercial insurance program is built on the aircraft exclusion. Nearly every general liability policy a government contractor carries excludes bodily injury and property damage arising out of the ownership, maintenance, or use of any aircraft — and since 2015, the Insurance Services Office has confirmed in writing that an unmanned aircraft is an aircraft for that purpose. When a contractor flies a drone over a federal installation, an infrastructure corridor, or a disaster site, the standard commercial general liability policy does not merely question the claim. It excludes it entirely.

That gap has moved from a technicality to a live exposure, because federal work is pulling contractors into the air on purpose. In June 2025, Executive Order 14307, “Unleashing American Drone Dominance,” directed the FAA to accelerate the rule that governs routine flight beyond the operator’s visual line of sight. The agency published its proposed Part 108 that August and reopened the comment period in January 2026, with a final rule expected this year. Part 108 is the framework that lets a contractor fly a bridge inspection, a pipeline patrol, or a perimeter-security orbit without a case-by-case waiver — which means the agencies buying those services will expect the flights, and the contracts will require the coverage.

The coverage requirement is where the discipline begins. Drone liability is not a rider you assume is buried somewhere in the file — it is a decision you make on purpose. The ISO endorsements make the choice explicit. Form CG 21 09 strips unmanned aircraft out of the liability policy altogether; CG 21 10 removes only the bodily-injury and property-damage side while leaving personal and advertising injury in place. To put coverage back, an underwriter uses CG 24 50, “Limited Coverage For Designated Unmanned Aircraft,” which schedules each airframe by description — and a drone not listed on that schedule is a drone not covered. A contractor who buys a new airframe mid-performance, or subcontracts the flying to a firm with its own uninsured fleet, has surfaced an exposure the certificate of insurance will never reveal.

The federal layer adds a second discipline that has nothing to do with insurance and everything to do with eligibility. The FY2020 NDAA’s Section 848 and the American Security Drone Act bar federal agencies — and the contractors flying on their behalf — from procuring or operating drones built with covered foreign components. The Defense Innovation Unit’s Blue UAS list is the government’s answer: a roster of cleared airframes a contractor is permitted to buy and fly on federal work. The exposure here is subtle. A contractor can hold a flawless aviation liability policy and still sit in breach of contract — and outside coverage for the resulting claim — because the aircraft itself was never eligible for the mission. Compliance and coverage are two separate obligations, and a program that satisfies one while ignoring the other is only half a program.

What a well-built drone program actually requires is a small set of intentional decisions. A hull-and-liability aviation policy — not a general liability endorsement alone — is the instrument that carries the exposure, because it is written for the way drones actually fail: the airframe lost, the third party injured, the payload data compromised, the ground damage from a fly-away. Limits should be set to the contract, not to habit, and every airframe should appear on the schedule before it appears in the air. Where flying is subcontracted, the prime should verify the subcontractor’s aviation coverage and Blue UAS eligibility with the same rigor it applies to its own — because a flow-down clause transfers the obligation, not the risk. The certificate that names the agency as additional insured is the last step, not the first.

This is the work of a broker who reads the contract before quoting the policy, and it maps to the way we run every engagement at Peoples First Tennessee. Strategic Discovery surfaces what a contractor is actually flying, and for whom. Risk Assessment measures the gap between the aircraft exclusion in the current program and the coverage the federal contract demands. Solution Design builds the aviation and eligibility structure to close it — scheduled airframes, contract-matched limits, verified subcontractors. Ongoing Optimization keeps the schedule current as the fleet, the missions, and Part 108 itself continue to change.

The drone is no longer a novelty on the federal contract — increasingly, it is the deliverable. The contractors who treat its insurance as an afterthought will discover the exclusion at the worst possible moment. The ones who treat it as a design problem will own the airspace, and the coverage, on their own terms.

Sources: Federal Register — Executive Order 14307, “Unleashing American Drone Dominance” (June 11, 2025); Federal Register — Normalizing Unmanned Aircraft Systems Beyond Visual Line of Sight Operations; Reopening of Comment Period (Jan. 28, 2026); DLA Piper — FAA’s Proposed Part 108 BVLOS Rule: Industry Response and Key Concerns; ISO Form CG 21 09, Exclusion — Unmanned Aircraft; ISO Form CG 24 50, Limited Coverage For Designated Unmanned Aircraft; Defense Innovation Unit — Blue UAS Policy / FY2020 NDAA Section 848.

— Ryan Mefford, President & Risk Advisor

Transactional Risk
September 2026

Representations and Warranties Insurance for Government Contractor Mergers and Acquisitions in 2026

Every government contractor eventually confronts the same question — not whether the company will change hands, but how. A sale, a strategic acquisition, a private-equity roll-up: the deal environment heading into 2026 is active, and defense and government-services businesses sit near the center of it. Sponsors are consolidating fragmented set-aside shops into platforms, strategics are buying capability and clearances rather than building them, and owners who spent a decade winning contracts are now weighing what an exit actually looks like. The appetite is real. So is the friction — because a government contract is not an ordinary asset, and diligence on one is not an ordinary exercise.

That friction is where representations and warranties insurance earns its place. In a purchase agreement, the seller makes reps — assertions about the business, its compliance, its contracts — and the buyer relies on them. When a rep turns out to be untrue, the buyer suffers a loss, and traditionally the seller made that loss good through indemnification backed by escrow. RWI rewrites that arrangement. Instead of the seller standing behind the reps, an insurer does. The buyer files a claim against the policy rather than clawing back proceeds, escrow shrinks or disappears, and the seller walks away with a cleaner exit — capital freed at closing rather than held hostage for years. The risk does not vanish; it moves — from the parties to the balance sheet of a carrier whose business is pricing it.

For most middle-market deals the structure has settled into a recognizable shape. Limits commonly run around ten percent of enterprise value; retention — the buyer’s out-of-pocket layer before coverage responds — has compressed to roughly half a percent to one percent of enterprise value, dropping further after the first year. Rate on line sits near two-and-a-half to three percent of the limit, with all-in cost landing closer to three-and-a-half to four percent once fees are counted, plus an underwriting fee typically in the twenty-five-to-thirty-five-thousand-dollar range. Policies survive three years for general reps and six for fundamentals. And the party paying has shifted: buyers now cover the premium in the large majority of deals, a reversal from a few years ago. Capacity is abundant, pricing is soft, and — for owners weighing a transaction — that combination is worth understanding before the term sheet, not after.

Where govcon deals diverge is in the reps that carry the risk. An underwriter pricing a generic manufacturer worries about financial statements and material contracts. An underwriter pricing a government contractor worries about a regulatory architecture that can quietly hollow out the value being purchased. Small-business size status is the sharpest example — a private-equity acquisition triggers SBA affiliation analysis under 13 CFR 121.103, and a target that thrives in set-aside competition can lose eligibility the moment it joins a sponsor’s portfolio, trading a protected lane for full-and-open competition it may not survive. Organizational conflicts of interest, dormant in a standalone company, surface across a multi-portfolio sponsor. Cybersecurity and CMMC readiness matter not only as a compliance cost but as a fraud exposure — an inaccurate self-assessment against NIST SP 800-171 is a False Claims Act problem, not a paperwork one. Add FAR and DFARS compliance, CAS, Service Contract Act wage obligations, security clearances and FOCI where foreign capital sits in the fund, and novation mechanics under FAR 42.1205, and the diligence surface widens considerably.

The False Claims Act deserves particular attention, because it is where hidden liability becomes acquired liability. Successor exposure is not theoretical — recent settlements have reached acquiring entities for pre-acquisition conduct, and even sponsor-level involvement in compliance decisions has drawn enforcement. That is precisely why underwriters scrutinize regulatory compliance so heavily, and precisely where exclusions tend to land: known issues surfaced in diligence, fraud and FCA matters, and forward-looking projections generally fall outside coverage. RWI is not a wager on problems you already see — it protects against the breach nobody found, not the one everyone did.

Which reframes the entire exercise. The instinct is to treat RWI as a product to buy. The discipline is to recognize it as the reward for diligence done well — the more rigorously counsel and advisors illuminate size status, cyber posture, and FCA exposure, the broader the coverage and the tighter the price. A thin diligence file does not just weaken the deal; it narrows what the policy will insure. Insurability and quality of preparation are, in practice, the same thing.

That discipline is the work we do. Our four-step process — Strategic Discovery, Risk Assessment, Solution Design, and Ongoing Optimization — is built to surface the regulatory exposures that shape a transaction before they shape its price, then structure the coverage around them and steward it through the survival period. For an owner contemplating a sale, an acquirer building a platform, or a sponsor assembling a roll-up, the goal is the same: a deal that is not merely done, but durable.

Sources: Gallagher — Who Pays the RWI Premium and Retention in 2026? A Look at Evolving Market Norms; Beancount.io — Representations and Warranties Insurance in Middle-Market M&A (2026); CRC Group — Representations + Warranties Insurance: Why 2026 May Be the Moment to Act; King & Spalding — DLA Contractor Acquisitions: A Regulatory Diligence Guide for PE Buyers; Holland & Knight — CMMC Affirmation Trap: FCA Exposure for Defense Contractors and Acquirers; Crowell & Moring LLP — Representations and Warranty Insurance in Transactions Involving Government Contractors; Kennedys — Negotiating transaction documents in 2026: Evolving dynamics with representation & warranty insurance

— Ryan Mefford, President & Risk Advisor