Searches for DeepSeek NDAA DoD contractors guidance usually want one answer: if we run the model on our own hardware, are we still covered? Under Section 1532 of the FY2026 National Defense Authorization Act (Public Law 119-60, enacted December 18, 2025), the answer is yes. The statute bars a contractor from using AI developed by DeepSeek or High Flyer with respect to the performance of a contract with the Department of Defense, and the prohibition took effect January 17, 2026. It says nothing about how the model is deployed. If your company handles Controlled Unclassified Information (CUI) for DoD primes, this page separates what the statute requires from what commentary claims it requires.
Key takeaways
- Section 1532 of the FY2026 NDAA (Public Law 119-60) bars DeepSeek and High Flyer models on DoD contract work, effective January 17, 2026.
- The bar attaches to the model's developer, not the hosting arrangement: the statute never mentions cloud or self-hosted deployment, so a local install gets no pass.
- There is no local-model exemption in the enacted text, and there is no blanket country rule either: only DeepSeek, High Flyer, and entities High Flyer owns, funds, supports or holds at least a 20 percent stake in are named.
- CMMC (32 CFR Part 170) and NIST SP 800-171 contain no AI-origin rule. The restriction lives in the statute and in contract performance, not in the CMMC framework.
- Alibaba and Baidu joined the Section 1260H list on June 8, 2026, a designation Alibaba is contesting; the FY2027 bill (S. 4784, Section 1651) that would name more companies is pending, not law.
Each bullet is a decision point, and the second is the expensive one: a contractor that assumes the rule only reaches cloud APIs can keep a self-hosted instance running straight into the statute's plain text. The sections below take the statute first, then the CMMC question, then the replacement path.
What Section 1532 of the FY2026 NDAA Requires
Public Law 119-60 was enacted on December 18, 2025. Thirty days later, on January 17, 2026, the contractor prohibition in Section 1532(a)(3)(A) took effect. The operative sentence reads: "not later than 30 days after the date of enactment of this Act, no contractor may, during the period of performance of such contractor under a contract with the Department of Defense, use covered artificial intelligence with respect to the performance of a contract with the Department." The enrolled text is public at govinfo.gov, and it is worth reading yourself: it is shorter than most summaries of it.
The definition that decides everything
Section 1532(c)(2) defines "covered artificial intelligence" as AI developed by the Chinese company DeepSeek, or AI developed by High Flyer or an entity owned by, funded by, or supported by High Flyer, or an entity in which High Flyer directly or indirectly holds at least a 20 percent stake. That is the whole list. The definition runs on developer lineage, not on model capability, not on data handling, and not on country of origin as a general test. If the model traces back to DeepSeek or High Flyer, it is covered; if it does not, Section 1532 does not name it.
Section 1532 also defines a wider "covered artificial intelligence company" category: a producer on the Consolidated Screening List, a producer on the Section 1260H Chinese military companies list, an entity domiciled in a covered nation (China, Russia, Iran or North Korea, by cross-reference to 10 U.S.C. 4872(d)(2)), or an entity subject to unmitigated foreign ownership, control or influence by a covered nation. The contractor prohibition over that wider category, though, applies only if the Secretary of Defense issues separate guidance under Section 1532(a)(2), and the same subsection only asks the Secretary to "consider" issuing it. No public confirmation that this guidance has been issued exists as of this writing, so the wider category is a watch item, not a live prohibition.
The waiver valve and the internal mandate
Two other subsections matter in practice. First, Section 1532(b) allows case-by-case waivers for scientifically valid research; for evaluation, training, testing or other analysis needed for national security; for counterterrorism, counterintelligence or other operational military activities; and for mission-critical functions, with risk-mitigation steps required. A waiver is an affirmative government decision, not a self-declared exception, and none of the categories describes ordinary contract analytics. Second, Section 1532(a)(1) required the Secretary of Defense, within the same 30 days, to mandate the exclusion and removal of covered AI from the systems and devices of the Department of Defense itself. The government cleaned its own house on the same clock it set for yours.
Law-firm guidance converges on the practical duty. King & Spalding's FY2026 NDAA alert states that contractors "will need to audit its use of any covered AI." One university recipient of DoD funding, Harvard, published interim procedures in January 2026 that instruct contracting staff to collect signed attestations, identify covered individuals, and write the prohibition clause into subcontracts, and reads the restrictions as extending to contractor operations, systems, tools and workflows that directly or indirectly contribute to contract performance. The enacted text says "no contractor" and does not use the word subcontractor (our guide to how DoD subcontractors handle CUI covers flow-down generally); no DFARS clause implementing Section 1532 has been published. Treat flow-down as the direction of travel and confirm scope with counsel rather than assuming either way.
The Prohibition Follows the Model, Not the Deployment
Here is the reading that matters for your environment. The statute bars "use" of covered AI "with respect to the performance of a contract." It never mentions cloud, API, on-premises, downloaded weights, or any other deployment mode. Nothing in the enacted text creates an exemption for a locally hosted model, and nothing in it says the word "local" at all. The prohibition attaches to the developer of the model, so it follows the model wherever it runs: a DeepSeek API call on a DoD contract is covered, and a DeepSeek instance on a GPU server inside your own enclave used for that same contract is covered by the same words.
That is the plain text, and it is also how implementers read it. Federal policy had already moved this way before enactment: the U.S. Navy issued a memo on January 24, 2025 instructing personnel to refrain from using the DeepSeek model in any capacity, at work or at home, and DISA began blocking DeepSeek access on Pentagon IT networks on January 28, 2025. Those actions bind government personnel and networks rather than contractors directly, but they show the direction federal policy was already headed when Section 1532 turned that direction into contract law.
Why there is no local-model exemption
Three things people assume about self-hosting, checked against the statute. One: "we run it inside our accredited enclave" changes where the compute sits, not whose model it is. Two: "the weights are open, anyone can download them" describes the distribution method, not the developer, and the definition runs on the developer. Three: "we fine-tuned it, so it is our model now" changes the weights you run, but the base model was still developed by DeepSeek, the definition expressly includes successor AI developed by DeepSeek, and the enacted text contains no carve-out for modified versions, so treat a fine-tune as covered unless counsel concludes otherwise. Read those three together and the honest summary is this: the law does not distinguish between deployment modes, it does not exempt local use, and its plain text reaches any use in contract performance.
What self-hosting still fixes
None of this makes self-hosting pointless. A private deployment of a model outside the Section 1532 definition is exactly how you keep prompts, responses and CUI inside a boundary you control, which is what the CMMC and DFARS controls in the next section assess. The point of this section is narrower: self-hosting a named model is a legal problem that self-hosting does not solve, while self-hosting an unnamed model is a compliance control that works. Choose the model first, then the deployment.
Section 6604: A Separate Mandate for Intelligence Community Systems
The FY2026 NDAA adds a second restriction one section over. Section 6604, "Prohibition on Use of DeepSeek on Intelligence Community Systems," directs the Director of National Intelligence to develop standards and guidelines requiring removal of the DeepSeek application or any successor application or service from national security systems operated by an intelligence community element, by a contractor to an IC element, or by another entity acting on an IC element's behalf, with initial standards due within 60 days of enactment. It is application-focused, so it reads narrower than a weights ban, but it reaches IC contractors directly. If your work supports an IC element, Section 6604 applies to you even where Section 1532 does not.
What CMMC and NIST SP 800-171 Actually Say About AI Models
Nothing, and the absence is load-bearing. The CMMC program rule at 32 CFR Part 170 maps assessment levels to the NIST SP 800-171 series; it nowhere restricts AI models by country of origin and does not mention DeepSeek, Qwen or foreign AI at all. CMMC Level 2 is the 110 security requirements of NIST SP 800-171 organized into 14 domains, assessed for most contractors by a C3PAO. DFARS 252.204-7012 separately requires adequate security, defined as those same 110 controls, on every covered contractor information system, and requires a cloud provider handling covered defense information to meet the FedRAMP Moderate baseline or an equivalent. No clause in that stack names a model or a model-maker.
The control practitioners use to assess AI tools is requirement 3.1.20 of NIST SP 800-171, which asks you to verify and limit connections to and use of external systems. An AI tool, cloud or local, is assessed as an external system under that control: what it can reach, what it sends, and what you log. Feeding CUI into a Chinese-origin model would raise hard questions under your system security plan, but that is an assessment question about your boundary, not a named prohibition inside CMMC.
So the two obligations stack, and neither substitutes for the other, the same way CMMC and NIST SP 800-171 stack with each other. A CMMC certificate does not lift the Section 1532 prohibition, because the prohibition is statutory. Removing DeepSeek does not satisfy DFARS 252.204-7012, because the clause is about controls, not model lineage. The program is real and growing: Level 2 certifications grew from 773 in January 2026 to 1,391 in May 2026, and DoD's own scope estimate for CMMC is 220,966 entities. The DoD CIO announced a suspension of the Phase 2 certification deadline on July 13, 2026, but Phase 1 self-assessments remain in force and the DFARS clauses in your current contracts did not pause with it.
Qwen, GLM, Kimi and the Wider Field
The enacted statute names two developers. That is easy to overstate in both directions, so here is the precise position of every other Chinese-origin model family. Qwen (Alibaba), GLM (Zhipu), Kimi (Moonshot), MiniMax and the rest are not named in Section 1532, and no enacted federal rule reaches them by name. Alibaba and Baidu were added to the DoD Section 1260H "Chinese military companies" list on June 8, 2026, and a company on that list fits the Section 1532(c)(4) definition of a covered AI company, so some law firms read the contractor prohibition as already reaching their AI products. But the statutory trigger for that extension is the Secretary's Section 1532(a)(2) guidance, which has not been publicly confirmed as issued, and Alibaba is contesting its designation in court.
One pending bill would settle the question by name. The FY2027 NDAA Senate bill, S. 4784 as reported, carries Section 1651, which would amend Section 1532 to add Baidu, Zhipu AI, Moonshot AI, 01.AI, MiniMax, Alibaba and Tencent and make the guidance mandatory. The House passed its own FY2027 bill on July 22, 2026 without naming companies. Pending legislation is not law, and a contested list designation is not a prohibition either. Our position, stated plainly so you can copy the reasoning: a contractor should not deploy Qwen or any other 1260H-designated company's model for DoD work until counsel reviews the designation status, because the legal ground is moving under it. Models with no designation and no statutory name carry a different, lighter question: whether they belong inside your CUI boundary at all.
Replacing the Model: The Private AI Path
If Section 1532 reaches a model in your contract workflow, the fix is replacement, not deletion of the capability, and it is the core of our AI for defense contractors work. The open-weight field gives you several families that are not named in the statute: Gemma 4 from Google DeepMind, Llama 3.1 from Meta, Mistral, and Microsoft's Phi are all candidates we benchmark against a client's workload, and GPT-OSS is covered in the companion post later in this series. None of them traces to DeepSeek or High Flyer, so none fits the Section 1532(c)(2) definition. What fits your CUI boundary is a separate question, and it is answered with controls, not press releases.
The deployment method we run is a seven-stage sequence: define the data boundary (CUI, PHI, financial records and the frameworks that apply); run a paid scoping engagement that builds an MVP or prototype on your own data, often starting with a data ingestion project; size GPU hardware from what the prototype measured, because data volume changes the answer and a company ingesting 40 TB needs a different build than a smaller one; isolate the cluster on a segmented VLAN or full air gap; deploy open-weight models on an inference stack you control; layer role-based access control, encryption at rest and in transit, and audit logging mapped to framework controls; validate against those controls before production. The order matters: a replacement model gets sized after a paid scoping prototype on your data, never before it. The same boundary maps to CMMC Levels 1, 2 or 3, to HIPAA, and to DFARS 252.204-7012.
Sizing the hardware honestly
Hardware sizing has real numbers. A 7B parameter model runs on a single NVIDIA A100 or H100 GPU, and larger models require two to four GPUs. For compact, efficient models, Gemma 4 launched on March 31, 2026 and now spans E2B, E4B, 12B, 26B A4B (a mixture-of-experts model with 3.8B active parameters) and 31B Dense sizes, with a 128K token context window on E2B and E4B and 256K on the larger sizes. Google states that the unquantized bfloat16 weights fit on a single 80GB NVIDIA H100 GPU, and quantized versions run on consumer GPUs. Treat those as reference points: running a model also needs memory for the KV cache, which grows with context length, and the real build comes out of the scoping prototype on your data. The reference private AI cluster at the larger end uses GB10 Grace Blackwell nodes with 128 GB of unified memory each, clustered over a QSFP112 400G interconnect to pool 256 GB for bigger models, and single-box inference workstations sized around RTX 5090, RTX 6000 or H200 class GPUs.
Two licensing and provenance notes belong next to any model shortlist. Gemma 4 is released under the Apache 2.0 license, a commercially permissive license your procurement team already knows, which replaces the custom Gemma Terms of Use that covered earlier Gemma generations; still record the license and the exact weights you downloaded. And provenance cuts both ways: Gemma 4 is developed by Google DeepMind, a subsidiary of Alphabet, and it is not named in any enacted U.S. restriction on Chinese-developed AI. That is the accurate claim, and it is as far as it goes: no model file is "CMMC compliant" by itself, because CMMC scopes systems, not weights.
What the economics look like
Cost decides as many of these projects as compliance does. At 500,000 or more tokens per day, private deployment breaks even within 6 to 12 months, and at 5 million or more tokens daily the annual cost runs 60 to 80 percent below equivalent API spend. Below that volume, run your own arithmetic before buying hardware. The blueprint that walks through the eight hardening steps, from network isolation and secrets handling to prompt and access logging and egress control, is free on our site.
A 30-Day Sequence for the Compliance Lead
The statute has been in force since January 17, 2026, so this is remediation, not anticipation. Six steps, each tied to a sourced fact above:
- Inventory every AI model in use, commercial and self-hosted, and trace each one against the Section 1532(c)(2) definition: developer lineage back to DeepSeek or High Flyer, including entities at least 20 percent owned, funded or supported by High Flyer. King & Spalding's alert puts the same duty in one sentence: contractors will need to audit their use of any covered AI.
- Identify which contracts, task orders and workflows count as performance of a contract with the Department of Defense, and read "performance" the way the Harvard procedures do: broadly, including tools and workflows that indirectly contribute.
- Pull any named model out of DoD contract workflows now. Waivers under Section 1532(b) exist only for the narrow categories the statute lists, and they are government decisions, not internal ones.
- Check the rest of the field against the Section 1260H list and the pending Section 1651 of S. 4784, and route any 1260H-designated vendor's models to counsel before they touch DoD work.
- Map the replacement environment to the 110 security requirements of NIST SP 800-171 using the seven-stage method, with FIPS-validated cryptography protecting CUI; strong-but-unvalidated encryption does not meet the requirement as written.
- Document the result in your system security plan and POA&M so the evidence exists before anyone asks for it, and set a review cadence for the Section 1532(a)(2) guidance and the FY2027 bill, because the wider list is a when-question, not an if-question.
One more reason not to wait: Section 1532(a)(1) gave the Department itself only 30 days from enactment to require covered AI off its own systems and devices. That is the pace the statute signals downstream, and the audit expectation is already explicit in practitioner guidance.
How Petronella Technology Group, Inc. Fits
Petronella Technology Group, Inc. designs, builds and operates private AI clusters for regulated businesses end to end, and delivers the blueprint stack turnkey for defense industrial base teams. The company's own private AI cluster and 24/7 AI-plus-human hybrid threat analysis underpin its managed detection and response for DIB and healthcare clients that cannot send CUI or PHI to a public-cloud SOC: the AI never closes a ticket on its own, never touches production systems without human authorization, and every action is logged for CMMC and HIPAA audit. ComplianceArmor®, the company's compliance documentation platform, automates SSP authoring, POA&M tracking and evidence repository organization, which is where the inventory and removal record from the sequence above should live.
| Question | What the enacted text supports |
|---|---|
| DeepSeek API on a DoD contract | Covered by Section 1532(a)(3)(A) |
| Self-hosted DeepSeek weights on a DoD contract | Covered by the same words: the statute is silent on deployment mode |
| Research, testing or mission-critical use | Case-by-case waiver only, under Section 1532(b), with risk mitigation |
| Purely commercial, non-DoD work | Outside the statutory scope, though implementers read "performance" broadly |
| Qwen, GLM, Kimi and other Chinese-origin families | Not named in enacted law; 1260H designations contested; Section 1651 of S. 4784 pending |
| A CMMC Level 2 certificate | Does not lift the statutory prohibition, and model removal does not satisfy DFARS 252.204-7012 |
Petronella Technology Group, Inc. is a Cyber AB Registered Provider Organization, RPO #1449, offering CMMC consulting, and does not perform Level 2 assessments for clients it has prepared, because Cyber AB independence rules prohibit it. Every engineer assigned to a defense client holds the CMMC Registered Practitioner (CMMC-RP) credential. Craig Petronella, who founded the company in 2002 and has 30+ years of experience, holds CMMC-RP, CCNA, CWNE, an NC Licensed Digital Forensic Examiner license (#604180) and an MIT AI certificate. A readiness engagement typically runs 12 to 14 weeks for a mid-size contractor: discovery, gap analysis, remediation sprint, then C3PAO readiness handoff. The model replacement in this post slots into the remediation stage of that sequence rather than becoming a separate project.
Related reading
- CMMC Compliance: Gap Assessment, Levels 1 to 3
- CMMC Patient Portal Compliance Checklist for Secure Access
- What DoD Instruction Implements CUI? DoDI 5200.48
- CMMC Level 2 for Small Defense Contractors: Practical Guide
- Urgent DFARS Update: How to Keep Your DoD Contract
Frequently Asked Questions
Is DeepSeek barred for DoD contractors?
Yes, for contract work. Section 1532 of the FY2026 NDAA (Public Law 119-60) prohibits a contractor from using AI developed by DeepSeek or High Flyer with respect to the performance of a contract with the Department of Defense. The prohibition took effect January 17, 2026.
Does the FY2026 NDAA cover a locally hosted DeepSeek model?
The statute is silent on deployment mode. It bars use of the named models in contract performance, so a self-hosted copy falls under the same text as a cloud API call. There is no local-model exemption in the enacted text.
Does CMMC restrict AI models by country of origin?
No. The CMMC program rule (32 CFR Part 170) and NIST SP 800-171 contain no AI-origin rule. The restriction lives in the FY2026 NDAA statute and in contract performance, not in the CMMC framework.
Are Qwen, GLM or Kimi named in the enacted law?
No. Section 1532 names only DeepSeek and High Flyer, plus entities High Flyer owns, funds, supports or holds at least a 20 percent stake in. Alibaba and Baidu joined the Section 1260H list on June 8, 2026, a designation Alibaba is contesting, and the FY2027 bill (S. 4784, Section 1651) that would add more names is pending, not law.
What should a contractor do about a DeepSeek dependency first?
Inventory every AI tool against the Section 1532(c)(2) definition, including self-hosted installs, and pull any named model out of DoD contract workflows. Then map the replacement environment to the 110 security requirements of NIST SP 800-171.
Get the Model Question Off Your Contract Risk List
Series reading: why Gemma is the right local AI model for CMMC compliance covers the model we benchmark most often for CUI workloads, and the GPT-OSS companion post on regulated industries covers the other open-weight family worth testing. For the deployment side, start at the AI services hub, then private AI for data that cannot go to the cloud, the full private AI deployment method, and the free private AI blueprint with the eight hardening steps. For the compliance side, read CMMC Level 2 compliance and what counts as CUI and how to handle it. If you want the boundary monitored rather than just built, see managed detection and response for CUI and PHI workloads.
Petronella Technology Group, Inc. has secured regulated environments since 2002, remote-first across all 50 states. Call Penny at 919-348-4912 for a free 30-minute consultation with a CMMC Registered Practitioner, or use the contact form to have us review which AI models touch your DoD contract work.
Reference build sheets, a hardening checklist for open-weight model hosting and a data-sovereignty map for running AI on your own hardware.
Get the free guide