News & Analysis as of

Controlled Unclassified Information (CUI) National Institute of Standards and Technology

Akin Gump Strauss Hauer & Feld LLP

Surprise! GSA Releases New Cybersecurity Requirements

Civilian-agency contractors will now be required to evaluate the security of information technology systems that process, store or transmit Controlled Unclassified Information (CUI) as the Government Services Administration...more

Morrison & Foerster LLP - Government...

Without Fanfare or Opportunity for Public Comment, GSA Changes Cybersecurity Requirements for Contractors

In a recent update to internal procedural guidance, the General Services Administration (GSA) has established a new framework of security requirements and privacy controls for contractor information systems that process,...more

Sheppard Mullin Richter & Hampton LLP

GSA Signals Enhanced Focus on Contractor Cybersecurity Practices: What You Need to Know About GSA’s New CUI Guide

On January 5, 2026, the General Services Administration (“GSA”) issued an updated version of its policy guidance document for contractors on protecting Controlled Unclassified Information (“CUI”). This document, titled IT...more

Husch Blackwell LLP

GSA Joins the CUI Compliance Movement: What Non-Defense Contractors Need to Know

Husch Blackwell LLP on

Key point: Historically, civilian‑agency contractors who handled Controlled Unclassified Information (CUI) enjoyed an informal compliance environment, with a requirement to adhere to NIST SP 800‑171 often framed as...more

Blank Rome LLP

GSA Issues New Framework for Protecting CUI in Contractor Systems

Blank Rome LLP on

Last month the General Services Administration’s (“GSA”) Office of the Chief Information Security Officer (“OCISO”) issued CIO-IT Security-21-112 Rev. 1, a procedural guide governing how Controlled Unclassified Information...more

Holland & Knight LLP

CMMC Affirmation Trap: FCA Exposure for Defense Contractors and Acquirers

Holland & Knight LLP on

Defense contractors subject to Cybersecurity Maturity Model Certification (CMMC) compliance under government contracts will be subject to False Claims Act (FCA) liability risks going forward. The CMMC program went live on...more

Wiley Rein LLP

Updates to NIST Cybersecurity Guidance May Impact Government Contractors

Wiley Rein LLP on

November 2025 has been a busy month for cybersecurity rules affecting government contractors. The long-awaited Cybersecurity Maturity Model Certification (CMMC) Program went into effect on November 10. We are now seeing the...more

Holland & Knight LLP

CMMC Regulations: Key Questions and Answers for Defense Contractors

Holland & Knight LLP on

On Nov. 10, 2025, the long-awaited final rule amending the Defense Federal Acquisition Regulation Supplement (DFARS) to implement the Cybersecurity Maturity Model Certification (CMMC) program became effective. This rule,...more

Alston & Bird

CMMC Brings New Era of Cybersecurity Compliance for Defense Contractors

Alston & Bird on

Our Privacy, Cyber & Data Strategy Team breaks down the Department of Defense’s finalized Cybersecurity Maturity Model Certification (CMMC) rule, which establishes a tiered compliance framework that will soon be mandatory for...more

Dickinson Wright

Preparing for CMMC: Navigating DoD’s New Cybersecurity Rules

Dickinson Wright on

After half a decade of development and review, the U.S. Department of Defense (DoD) will implement contracting regulations, effective November 10, 2025, making the Cybersecurity Maturity Model Certification (CMMC) Program a...more

Hogan Lovells

Recent developments in FCA cybersecurity enforcement for government contractors

Hogan Lovells on

The U.S. Department of Justice (“DOJ”) has kept busy in pursuing cybersecurity-related fraud in government contracts resulting in seven settlements. These settlements illustrate the continuing need for contractors to...more

Ice Miller

Cybersecurity is Now Foundational to Doing Business with the Department of Defense

Ice Miller on

Notwithstanding Executive Orders to reduce federal rules affecting industry in effect today, the Department of Defense (DOD) recently enacted new regulations by finalizing the Cybersecurity Maturity Model Certification (CMMC)...more

Troutman Pepper Locke

What to Expect When the New CMMC Final Rule Hits Defense Acquisitions on November 10

Troutman Pepper Locke on

On September 10, the U.S. Department of Defense (DOD) posted its final rule implementing the Cybersecurity Maturity Model Certification (CMMC) program for defense acquisitions. This new rule (acquisition rule) updates the...more

Cozen O'Connor

This Is Not a Drill: Cybersecurity Maturity Model Certification Goes into Effect on November 10, 2025

Cozen O'Connor on

The wait is finally over, and U.S. Department of Defense (DoD) contractors need to be prepared. On September 10, 2025, DoD posted a final rule that will officially make Cybersecurity Maturity Model Certification (CMMC) a...more

Ogletree, Deakins, Nash, Smoak & Stewart,...

DoD Finalizes Cybersecurity Maturity Model Certification Rule: What Defense Contractors Need to Know

On September 10, 2025, the U.S. Department of Defense (DoD) published a final rule that will shake up cybersecurity compliance for DoD contractors. The new rule formally incorporates the Cybersecurity Maturity Model...more

Parker Poe Adams & Bernstein LLP

Department of Defense Issues Final Rule Implementing Contractual Requirements Related to Cybersecurity

The U.S. Department of Defense (DOD) issued a final rule this month that fundamentally changes eligibility for DOD procurement by tying contract awards directly to cybersecurity readiness....more

Wiley Rein LLP

Additional Analysis on DOD’s Final Rule for the Cybersecurity Maturity Model Certification Program

Wiley Rein LLP on

WHAT: The U.S. Department of Defense (DOD) this month published the second of two final rules needed to begin phasing in the long-awaited Cybersecurity Maturity Model Certification (CMMC) Program. This final rule amends the...more

Venable LLP

The Cybersecurity Maturity Model Certification Is Finally Here - Is Your Organization Ready?

Venable LLP on

The Department of Defense (DoD) recently finalized a new rule, to be codified at Defense Federal Acquisition Regulation Supplement (DFARS) 252.204-7021 (contract clause) and 252.204-7025 (solicitation provision), which will...more

BakerHostetler

Ready or Not, CMMC Is Here: DoD Issues Final Rule Establishing Contract Clauses Implementing CMMC Program

BakerHostetler on

The wait is over. Five years after the Department of Defense (DoD) first introduced the Cybersecurity Maturing Model Certification (CMMC) program, the companion Final Rule was published in the Federal Register on Sept. 10....more

Schwabe, Williamson & Wyatt PC

DoD Issues Final Rule Implementing CMMC Requirements in DFARS

The Department of Defense (DoD) has issued its highly anticipated final rule amending the Defense Federal Acquisition Regulation Supplement (DFARS) to incorporate contractual requirements for the Cybersecurity Maturity Model...more

Fisher Phillips

New Cybersecurity Standards Will Impact Defense Contractors in November: 5 Steps to Ensure CMMC Compliance

Fisher Phillips on

Starting November 10, federal contractors that perform work with the Department of Defense will need to ensure they comply with a new cybersecurity framework. The Department of Defense (DoD) just amended the Defense Federal...more

Sheppard Mullin Richter & Hampton LLP

The Expanding Scope of FCA-Cybersecurity Liability

The inexorable expansion of the False Claims Act (“FCA”) to cover virtually all types of cybersecurity breaches and violations – to include allegedly poor practices and failure to fully adhere to security controls –...more

Offit Kurman

Non-Compliance with CMMC Could Put Your DoD Contracts at Risk

Offit Kurman on

This past month, the Department of Defense sent the final rule for the new Cybersecurity Maturity Model Certification (CMMC) program under the Federal Acquisition Regulation to the Office of Information and Regulatory Affairs...more

Blank Rome LLP

Beyond the Balance Sheet: The Continued Importance of Cybersecurity in M&A

Blank Rome LLP on

In our August 1 post, we discussed how companies that acquire government contractors can inherit the False Claims Act (“FCA”) exposure based on their targets’ cybersecurity violations. Now, the Department of Justice (“DOJ”)...more

Holland & Knight LLP

DoD Publishes Organization-Defined Parameters for NIST SP 800-171 Rev. 3

Holland & Knight LLP on

The U.S. Department of Defense (DoD) recently issued a memorandum signaling that defense contractors soon will be required to comply with new cybersecurity compliance requirements. The memorandum establishes...more

155 Results
 / 
View per page
Page: of 7

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide