News & Analysis as of

FedRAMP

Morrison & Foerster LLP - Government...

Without Fanfare or Opportunity for Public Comment, GSA Changes Cybersecurity Requirements for Contractors

In a recent update to internal procedural guidance, the General Services Administration (GSA) has established a new framework of security requirements and privacy controls for contractor information systems that process,...more

Sheppard Mullin Richter & Hampton LLP

GSA Signals Enhanced Focus on Contractor Cybersecurity Practices: What You Need to Know About GSA’s New CUI Guide

On January 5, 2026, the General Services Administration (“GSA”) issued an updated version of its policy guidance document for contractors on protecting Controlled Unclassified Information (“CUI”). This document, titled IT...more

Husch Blackwell LLP

GSA Joins the CUI Compliance Movement: What Non-Defense Contractors Need to Know

Husch Blackwell LLP on

Key point: Historically, civilian‑agency contractors who handled Controlled Unclassified Information (CUI) enjoyed an informal compliance environment, with a requirement to adhere to NIST SP 800‑171 often framed as...more

Sheppard Mullin Richter & Hampton LLP

What a Year! Cybersecurity Recap and 2026 Forecast for Government Contractors

As we welcome 2026, it is a good time for government contractors to reflect on their cybersecurity posture and the major shifts in federal data protection policy from 2025. Last year was more than just a year of evolution in...more

Blank Rome LLP

GSA Issues New Framework for Protecting CUI in Contractor Systems

Blank Rome LLP on

Last month the General Services Administration’s (“GSA”) Office of the Chief Information Security Officer (“OCISO”) issued CIO-IT Security-21-112 Rev. 1, a procedural guide governing how Controlled Unclassified Information...more

Wiley Rein LLP

FedRAMP Issues Final Proposed Changes to Cloud Authorization Process, Seeks Comments from Industry

Wiley Rein LLP on

WHAT: The FedRAMP Program Management Office (PMO) has released a “final set” of proposed changes to the FedRAMP process for authorizing and assessing the security of cloud services for federal consumption. The final proposed...more

Mintz - Health Care Viewpoints

Cybersecurity-Related Enforcement Under the False Claims Act in 2025: New Settlements, Same Lessons — EnforceMintz

In 2025, Department of Justice (DOJ)’s Civil Cyber-Fraud Initiative drove major False Claims Act (FCA) settlements involving defense contractors, research institutions, and health care companies—highlighting the need for...more

Wilson Sonsini Goodrich & Rosati

DOJ Indicts Former Senior Manager of Federal Contractor over Alleged Misrepresentations Concerning FedRAMP/DoD Cybersecurity...

On December 10, 2025, the U.S. Department of Justice (DOJ) announced that Danielle Hillmer, a former senior manager at a government contractor, was indicted for falsely claiming that her employer had implemented required...more

Parker Poe Adams & Bernstein LLP

DOJ Ramps Up Cybersecurity Enforcement Pressure With Criminal Charges Against Employee of Federal Contractor

The U.S. Department of Justice continues an increasingly aggressive approach to enforcing cybersecurity requirements applicable to federal contractors and subcontractors, as we previously highlighted in a November client...more

Foley & Lardner LLP

DOJ Charges Former Executive in Criminal Case Alleging Cybersecurity Compliance Fraud

Foley & Lardner LLP on

A recent indictment underscores the U.S. Department of Justice (“DOJ”)’s focus on cybersecurity compliance in federal contracting and DOJ’s willingness to escalate enforcement beyond the civil False Claims Act (see Foley’s...more

Herbert Smith Freehills Kramer

Target Acquired: DOJ Strikes at Defense Contractors Over Cybersecurity Compliance and Pricing Issues

The U.S. Department of Defense (DOD) obligates about half a trillion dollars a year to private contractors for everything from high-end weapons and data systems to basic goods and services like fuel, shipping, food, and...more

Wiley Rein LLP

President Trump’s Cyber Mandate: Analysis of Executive Order on Strengthening U.S. Cybersecurity

Wiley Rein LLP on

President Trump issued a cybersecurity Executive Order, “Sustaining Select Efforts to Strengthen the Nation’s Cybersecurity” (Trump EO), along with a corresponding Fact Sheet on June 6, 2025. The Trump EO clears some of the...more

Morrison & Foerster LLP

Trump Issues Executive Order on Cybersecurity Rolling Back Some Prior Policies and Introducing New Ones

Last week, the Trump administration made its priorities clear for the nation’s cybersecurity posture in the form of the newly issued executive order entitled “Sustaining Select Efforts to Strengthen the Nation’s Cybersecurity...more

Jenner & Block

Client Alert: White House Narrows and Refocuses Biden Executive Order on Strengthening Federal Cybersecurity

Jenner & Block on

On June 6, 2025, President Donald J. Trump signed a new executive order on “Sustaining Select Efforts to Strengthen the Nation’s Cybersecurity and Amending Executive Order 13694 and Executive Order 14144” (“Trump Cyber EO”),...more

Sheppard Mullin Richter & Hampton LLP

FedRAMP 20x – Update on Significant Change Process and Assessment Scope Standards

Last month, the federal government announced a major overhaul of the Federal Risk and Authorization Management Program (“FedRAMP”) called “FedRAMP 20x”. FedRAMP 20x is moving forward fast – with new authorizations, community...more

Cohen Seglias Pallas Greenhall & Furman PC

Cybersecurity Enforcement: The More Things Change, The More They Stay the Same

Despite a change in administrations, the government’s vigilance and enforcement of cybersecurity requirements have not missed a beat. On March 14, 2025, MORSECORP, Inc. of Cambridge, MA resolved allegations that it had...more

Davis Wright Tremaine LLP

FedRAMP 20x Initiative Promises Major Changes for Federal Cloud Service Providers

Major changes are coming again to the Federal Risk and Authorization Management Program ("FedRAMP"), the federal government's cybersecurity authorization program for cloud service providers ("CSPs")....more

Fox Rothschild LLP

Government Contractors Beware: Failure to Comply with DOD Cybersecurity Requirements Can Trigger Civil FCA Liability

Fox Rothschild LLP on

The Department of Justice (DOJ) recently reached a $4.6 million civil False Claims Act (FCA) settlement with MORSECORP, Inc. (MORSE) arising out of allegations that the company failed to comply with Department of Defense...more

Saul Ewing LLP

Cybersecurity Failures Lead to False Claims Act Case Against Government Contractor

Saul Ewing LLP on

In a striking move at the end of March, the U.S. Department of Justice (“DOJ”) announced a $4.6 million settlement with MORSE Corp Inc. (“MORSE”), a defense contractor based in Cambridge, Massachusetts, for falsely certifying...more

Ice Miller

As the Department of Justice Affirms and Advances Its Cyber-Fraud Initiative, Government Contractors Should Take Steps to Ensure...

Ice Miller on

While some areas of white-collar enforcement have been deprioritized by the Trump Administration, the Department of Justice (DOJ) remains committed to its Civil Cyber-Fraud Initiative as demonstrated by two recent False...more

Latham & Watkins LLP

Week 12 in Review: Defense Industry Enhancements, Tariffs, and Regulatory Shifts in Energy and Environment 

Latham & Watkins LLP on

Last week, President Trump signed over 10 executive orders related to efforts to strengthen America’s defense industry, bolster coal production and electric grid management, and roll back other regulations it views as...more

Latham & Watkins LLP

GSA Announces Initiative to Revamp FedRAMP to Further Administration’s Priority of Promoting Government Efficiency

Latham & Watkins LLP on

FedRAMP 20x aims to increase efficiency through automation and removal of hurdles to FedRAMP authorization....more

Holland & Knight LLP

GSA Announces Overhaul of FedRAMP with Emphasis on Industry Input and Automation

Holland & Knight LLP on

The U.S. General Services Administration (GSA) recently announced plans to develop the Federal Risk and Authorization Management Program (FedRAMP) 20x – a new approach to the government-wide program for the security...more

Sheppard Mullin Richter & Hampton LLP

FedRAMP 20x – Major Overhaul Announced to Streamline the Security Authorization Process for Government Cloud Offerings

On March 24, 2025, the Federal Risk and Authorization Management Program (“FedRAMP”) announced a major overhaul of the program, which is being called “FedRAMP 20x.” The FedRAMP 20x announcement stated there are no immediate...more

Cozen O'Connor

FedRAMP Update – New Approach(es) to Authorization on the Way

Cozen O'Connor on

On Monday, March 24, 2025, the General Services Administration (GSA) launched FedRAMP 20x, as an effort to automate parts of the program and create collaboration with the industry to improve authorization process for cloud...more

67 Results
 / 
View per page
Page: of 3

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide