Cybersecurity Maturity Model Matures: DoD Adds New Requirements to Draft Cybersecurity Certification
Client Alert | 1 min read | 09.10.19
The Defense Department has released Revision 0.4 of its Cybersecurity Maturity Model Certification (CMMC) that, starting next year, independent auditors are to use to certify contractor compliance with DoD cybersecurity requirements. Revision 0.4 more than doubles the number of cybersecurity controls across the CMMC’s five maturity “Levels.” But the DoD emphasizes that it will further down-select these controls and that mature contractor processes may counteract gaps in the final controls’ implementation. In addition to NIST SP 800-171 (the default standard under DFARS 252.204-7012), Revision 0.4 now incorporates requirements from the NIST Cybersecurity Framework, ISO 27001, and CIS Critical Security Controls, as well as from “additional DIB inputs.” Notably missing is NIST SP 800-171B, which remains under review.
The DoD is requesting feedback on Revision 0.4 through September 25, 2019, and plans on releasing Revision 0.6 for comment in November 2019. The final CMMC is expected in January 2020.
Insights
Client Alert | 5 min read | 04.15.25
Is Section 230 Going to Change? The FTC, DOJ and FCC Signal Significant Change for Online Businesses
On April 3, 2025, the United States Department of Justice’ Antitrust Division hosted a forum on “Big-Tech Censorship” in which key Trump Administration Officials announced their desire to reform, or entirely overhaul, Section 230 of the Communications Decency Act. In March 2025, we wrote about the Federal Trade Commission’s (FTC) inquiry into “tech censorship” and its associated request for public comments from those who “may have been harmed by technology platforms that limited their ability to share ideas or affiliations freely and openly.” That RFI remains open, and its deadline is May 21, 2025.
Client Alert | 4 min read | 04.14.25
Client Alert | 4 min read | 04.10.25
Hikma and Amici Curiae Ask Supreme Court to Revisit Induced Infringement by Generic “Skinny Labels”
Client Alert | 1 min read | 04.09.25