Latest Publications

Share:

FedRAMP Announces New Approach to Assessing Security of Cloud Services Providers, Leveraging Commercial Practices and Tools

WHAT: FedRAMP has announced that it will be working on a new framework for authorization and assessment of cloud services for federal consumption, calling the initiative “FedRAMP 20X” (announcement here). In response to...more

DOD Mandates Use of Software Acquisition Pathway for Software Development Procurements

WHAT: Department of Defense (DOD) Secretary Pete Hegseth issued a memorandum titled “Directing Modern Software Acquisition to Maximize Lethality” that is intended to reform DOD’s procurement involving software development....more

FAR Council Unveils Long-Anticipated Rule for Controlled Unclassified Information

WHAT: The FAR Council published a proposed rule to incorporate the Controlled Unclassified Information (CUI) Program into the acquisition process and, in doing so, seeks to more clearly define government and contractor roles...more

Updates on Cybersecurity Requirements for Government Contractors

Part of the Biden Administration’s push to enhance U.S. cybersecurity capabilities has focused on imposing new requirements on government contractors. The 2023 National Cybersecurity Strategy suggested, for example, that...more

DOD Seeks Contractor Disclosures of Foreign Access to Software Source Code

WHAT: The U.S. Department of Defense (DOD) issued a proposed rule to implement Section 1655(a) and (c) of the National Defense Authorization Act (NDAA) for Fiscal Year (FY) 2019 (Pub. L. 115-232). The proposed rule would...more

DOD Crystalizes CMMC 2.0 Program Rule - UPDATED October 22, 2024.

WHAT: On October 15, 2024, the U.S. Department of Defense (DOD) published the final CMMC 2.0 Program rule. DOD’s final rule outlines the mechanisms that DOD will use to prescribe cybersecurity standards for safeguarding...more

DOD Crystalizes CMMC 2.0 Program Rule

WHAT: On October 15, 2024, the U.S. Department of Defense (DOD) will publish the final CMMC 2.0 Program rule. DOD’s final rule outlines the mechanisms that DOD will use to prescribe cybersecurity standards for safeguarding...more

DOD Issues Proposed Rule to Address Conflicts of Interest for Certain Consulting Services

Last week, the U.S. Department of Defense (DOD) published a proposed rule that would amend the Defense Federal Acquisition Regulation Supplement (DFARS) to implement a statutory prohibition on DOD awarding contracts with...more

Policy Patches: An Update on Software Security Regulation

So far, 2024 has been another very busy year for U.S. cybersecurity regulation. Among the top priorities has been software security, as we previewed early this year. Companies that sell software to the federal government or...more

Cybersecurity Updates: NIST Publishes SP 800-171 Revision 3. What Changed, and What Comes Next?

In May 2024, the National Institute of Standards and Technology (NIST) published Special Publication 800-171 Rev 3, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, and the accompanying...more

Not So Fast, NIST: DOD Issues Class Deviation to Retake Control Over What Cybersecurity Requirements Apply to its Contracts

WHAT: On May 2, 2024, the U.S. Department of Defense (DOD) issued a Defense Federal Acquisition Regulation Supplement (DFARS) class deviation related to the cybersecurity standards required for covered contractor information...more

What Does CISA’s Secure Software Development Form Mean for Contractors?

WHAT: The U.S. Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency (CISA) published the final version of its Secure Software Development Attestation Common Form (Common Form) and announced...more

DOD Publishes Video Overview of CMMC Program and Logistics

WHAT: On February 16, 2024, the U.S. Department of Defense (DOD) posted a 40-minute video overview of DOD’s proposed requirements for the Cybersecurity Maturity Model Certification (CMMC) program. The video is available here,...more

UPDATE: DOD Proposed Rule Solidifies Plans for CMMC 2.0 Program: Security Requirements, Assessments, Affirmations, and Some...

WHAT: The U.S. Department of Defense (DOD) has issued a proposed rule setting forth key requirements for its long-anticipated Cybersecurity Maturity Model Certification (CMMC) 2.0 program. The proposed rule primarily...more

DOD Proposed Rule Solidifies Plans for CMMC 2.0 Program: Security Requirements, Assessments, Affirmations, and Some Flow-Down...

WHAT: The U.S. Department of Defense (DOD) has issued a proposed rule setting forth the requirements for its long-anticipated Cybersecurity Maturity Model Certification 2.0 (CMMC) program. The proposed rule primarily...more

Update: FAR Council Proposes Pair of Major Cybersecurity Rules for Government Contracts

WHAT: As we previously reported here, on October 3, 2023, the Federal Acquisition Regulatory Council (FAR Council) proposed a pair of major cybersecurity rules intended to implement key parts of President Biden’s May 2021...more

FAR Council Proposes Pair of Major Cybersecurity Rules for Government Contracts

WHAT: The Federal Acquisition Regulatory Council (FAR Council) proposed a pair of major cybersecurity rules intended to implement key parts of President Biden’s May 2021 Executive Order No. 14028 on Improving the Nation’s...more

DHS Updates CUI Safeguarding and Incident Reporting Requirements for Contractors

On June 21, 2023, the U.S. Department of Homeland Security (DHS) issued a final rule that revises the Homeland Security Acquisition Regulation (HSAR) to implement security and privacy measures for contractors to safeguard...more

OMB Extends Timeline for Collection of Software Attestation Forms and Clarifies Scope of Requirement

On June 9, 2023, the Office of Management and Budget (OMB) issued a guidance memorandum, OMB M-23-16, that extends the timeline for agencies to begin collecting attestations for critical and non-critical software from...more

Federal Circuit Holds That the Air Force’s Unilateral Price Definitizations Were Not Government Claims

WHAT: On April 25, 2023, the United States Court of Appeals for the Federal Circuit issued a decision in Lockheed Martin Aeronautics Co. v. Secretary of the Air Force, No. 2022-1035, holding that the Contracting Officer’s...more

CISA Seeks Comments on New Security Attestation for Software Procurements

On April 27, 2023, the Cybersecurity and Infrastructure Security Agency (CISA) of the U.S. Department of Homeland Security (DHS) issued a Notice of Agency Information Collection Activities to solicit public comments on a...more

DOD Issues Final Rule Regarding Use of SPRS Assessments in Procurement

WHAT: The U.S. Department of Defense (DOD) issued a final rule that requires contracting officers to consider Supplier Performance Risk System (SPRS) risk assessments when evaluating contractors’ proposals and quotes and when...more

New York Ethics Commission Launches New Lobbying Training Program – Requires More People to be Trained

On January 18, the New York Commission on Ethics and Lobbying in Government (COELIG) launched a new online ethics training. Previously, only Individual Lobbyists were required to complete training. Now, all Individual...more

FAR Council Proposes to Create a New Standard of Contractor Responsibility: Requiring Contractors to Disclose Greenhouse Gas...

WHAT: The Federal Acquisition Regulatory Council (FAR Council) issued a proposed rule requiring certain contractors to make representations regarding greenhouse gas (GHG) emissions and climate-related financial risk,...more

Vermont Adopts a Statutory Code of Ethics: Something Old and Something New

On May 4, Vermont enacted its first statutory Code of Ethics. The Code will take effect July 1, 2022, and applies to all public servants[1] in Vermont. The Code identifies baseline ethics rules regarding gifts to public...more

28 Results
 / 
View per page
Page: of 2

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide