News & Analysis as of

Defense Contracts National Institute of Standards and Technology

BakerHostetler

CMMC Barrels Closer to Implementation with Latest Proposed Rule Establishing DFARS Contract Clauses

BakerHostetler on

Cybersecurity Maturity Model Certification (CMMC) is coming — and now appears to be coming faster than many defense contractors believed. In the latest signal of CMMC’s forward momentum, the Department of Defense (DoD) issued...more

PilieroMazza PLLC

Win or Lose: Using CMMC 2.0 Proposed Rule to Position Yourself for DOD Contracts

PilieroMazza PLLC on

The Cybersecurity Maturity Model Certification (CMMC) Program has been a headache for many defense contractors since the idea was first introduced in 2019. The program seeks to protect unclassified information, including...more

Skadden, Arps, Slate, Meagher & Flom LLP

How Defense Contractors Can Prepare Now for CMMC Implementation

The Department of Defense (DoD) is currently reviewing and adjudicating the public comments received in response to its proposed regulations implementing its Cybersecurity Maturity Model Certification 2.0 program (CMMC)....more

Wiley Rein LLP

Cybersecurity Updates: NIST Publishes SP 800-171 Revision 3. What Changed, and What Comes Next?

Wiley Rein LLP on

In May 2024, the National Institute of Standards and Technology (NIST) published Special Publication 800-171 Rev 3, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, and the accompanying...more

Dunlap Bennett & Ludwig PLLC

CMMC 2.0: Level One: A Self-Assessment

As we promised a trilogy in our earlier 2024 CMMC Blog – “Get Ahead of Compliance: The Proposed Rule for the Cybersecurity Maturity Model Certification (CMMC 2.0) Is Out!” – we continue our series with a discussion of each...more

Holland & Knight LLP

Foundational Cybersecurity Standards for Contractors Updated

Holland & Knight LLP on

The National Institute of Standards and Technology (NIST) released the third revision of its Special Publication (SP) 800-171, "Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations." This...more

Bass, Berry & Sims PLC

Department of Defense Issues Class Deviation Delaying Application of NIST SP 800-171, Revision 3

On May 2, the Department of Defense (DOD) issued a class deviation to DFARS 252.204-7012 “to provide industry time for a more deliberate transition upon the forthcoming release of [National Institute of Standards and...more

Robinson+Cole Data Privacy + Security Insider

U.S. Government Intervenes in Case Alleging Unauthorized Disclosure of CUI

The U.S. government recently intervened in a False Claims Act qui tam case against Georgia Tech Research Corporation, Georgia Institute of Technology, and Georgia Tech Research Institute for violations of NIST 800-171 for...more

McCarter & English Blog: Government Contracts...

DoD’s Proposed CMMC Rule: Groundhog Day… or a Final Rule in the Works?

On December 26, 2023, the Department of Defense (“DoD”) belatedly gifted defense contractors and subcontractors a Proposed Rule on the Cybersecurity Maturity Model Certification (“CMMC”) Program. DoD also released eight CMMC...more

Goodwin

CMMC 2.0: Defense Contractors Get Ready

Goodwin on

The US Department of Defense (DoD) has issued a proposed rule to implement its long-awaited Cybersecurity Maturity Model Certification program (CMMC 2.0). This proposed rule — released on December 26, 2023, and published in...more

Bass, Berry & Sims PLC

Department of Defense Publishes Long-Awaited CMMC Proposed Rule

On December 26, the Department of Defense (DoD) published its long-awaited Cybersecurity Maturity Model Certification (CMMC) Program proposed rule, which places comprehensive cybersecurity and information security...more

Venable LLP

The New CMMC Rule: FAQs for Federal Contractors and Subcontractors

Venable LLP on

The Department of Defense (DoD) delivered its proposed Cybersecurity Maturity Model Certification Program rule (CMMC) the day after Christmas this year, including several related guidance documents (listed here). The proposed...more

Orrick, Herrington & Sutcliffe LLP

The False Claims Act in Cybersecurity Enforcement: Unsealed Complaint Signals Growing Use

A recently unsealed False Claims Act qui tam complaint against Penn State is the latest in line with DOJ’s Civil Cyber-Fraud Initiative. The case is United States ex rel. Matthew Decker v. Pennsylvania State University,...more

Holland & Knight LLP

Podcast - Third-Party Assessments and NIST SP 800-171

Holland & Knight LLP on

In this episode of "Regulatory Phishing," Eric Crusius is joined by Tom Tollerton, a partner with FORVIS, a Certified Third-Party Assessment Organization (C3PAO). In this episode, Eric and Tom discuss the role of the C3PAO in...more

Holland & Knight LLP

Third-Party Assessments and NIST SP 800-171

Holland & Knight LLP on

In this episode of "Regulatory Phishing," Eric Crusius is joined by Tom Tollerton, a partner with FORVIS, a Certified Third-Party Assessment Organization (C3PAO). In this episode, Eric and Tom discuss the role of the C3PAO in...more

Holland & Knight LLP

Third-Party Cybersecurity Assessments Potentially Coming Soon to Department of Defense

Holland & Knight LLP on

Contractors that do business with the U.S. Department of Defense (DoD) and handle Controlled Unclassified Information (CUI) have been awaiting the issuance of a rule implementing the Cybersecurity Maturity Model Certification...more

Whitcomb Selinsky, PC

CMMC Program Enhances DOD Contractors’ Cybersecurity

Whitcomb Selinsky, PC on

The Cybersecurity Maturity Model Certification (CMMC) program, first announced in 2019 by the Department of Defense (DoD), aims to enhance the cybersecurity profile of DoD contractors. The original iteration of DoD’s...more

Whitcomb Selinsky, PC

Cyber Security-Covered Defense Information

Whitcomb Selinsky, PC on

The Department of Defense recently released new guidance regarding cybersecurity regulations for all defense contractors. A new clause in the Defense Federal Acquisition Regulations Supplement, added on Sept. 17, 2017, DFARS...more

Holland & Knight LLP

CMMC 2.0 Simplifies Requirements But Raises Risks for Government Contractors

Holland & Knight LLP on

With the announcement of a revamped Cybersecurity Maturity Model Certification (known as CMMC 2.0),1 for the third time in five years, the U.S. Department of Defense (DOD) announced new, comprehensive cybersecurity standards...more

Miles & Stockbridge P.C.

CMMC 2.0: DoD Scales Back Certification and Streamlines Cybersecurity Requirements for Defense Contractors

Miles & Stockbridge P.C. on

On November 4, 2021, the U.S. Department of Defense (DoD) Office of the Under Secretary of Defense for Acquisition and Sustainment (OUSD(A&S)) announced Version 2.0 of the highly publicized Cybersecurity Maturity Model...more

Sheppard Mullin Richter & Hampton LLP

Updates Announced to Department of Defense Cybersecurity Certification Program

The Department of Defense (DOD) recently announced several changes to its Cybersecurity Maturity Model Certification program. The program applies to those who serve as contractors and suppliers to the DOD. As described in our...more

NAVEX

CMMC Is Coming: How Government Contractors Can Prepare

NAVEX on

People like to say that cybersecurity threats are constantly evolving. So perhaps it’s fitting that cybersecurity compliance is undergoing a significant evolution of its own this year, too. That evolution is the arrival of...more

Wilson Sonsini Goodrich & Rosati

Interim Rule Introduces New Cybersecurity Assessment Requirements for Defense Contractors, Provides Initial Details on CMMC

On September 29, 2020, the Department of Defense (DoD) issued an interim rule amending the Defense Federal Acquisition Regulation Supplement (DFARS) to create new assessment and certification requirements for DoD contractors....more

Tucker Arensberg, P.C.

Defense Contractors Are Required To Implement Cybersecurity Measures In Order To Do Business with the Federal Government

Tucker Arensberg, P.C. on

The Defense Federal Acquisition Regulation Supplement (“DFARS”) 252.204-7008 and 252.204-7012 require defense contractors who possess, store or transmit “covered defense information” to comply with the security requirements...more

King & Spalding

DoD Releases Version 1.0 of the Cybersecurity Maturity Model Certification Framework

King & Spalding on

On January 31, 2020, the Department of Defense (DoD) released the latest version (Version 1.0) of its Cybersecurity Maturity Model Certification (CMMC) framework, setting forth future cybersecurity requirements for thousands...more

38 Results
 / 
View per page
Page: of 2

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide