DoD Previews New Third-Party Cyber Certification Requirements
Client Alert | 1 min read | 06.17.19
The Department of Defense is moving closer to a third-party certification to ensure compliance with its standard cybersecurity requirements – what is being called the “Cybersecurity Maturity Model Certification” (CMMC). While still in the early stages of development, the CMMC would likely require all contractors subject to DFARS 252.204-7012 to obtain a certification issued by an independent third party stating that the contractor has sufficiently implemented its required cybersecurity controls. Holding this certification would be a “go/no-go” condition to compete for relevant DoD work. Although NIST SP 800-171 is the default cybersecurity standard currently required under -7012, DoD is also exploring the creation of a new standard that would govern the certification. DoD is projecting that the CMMC will start appearing in solicitations as early as Fall 2020, but much work remains to be done – including potential revisions to -7012 – and will no doubt be informed by extensive industry engagement.
Insights
Client Alert | 2 min read | 02.19.25
District Court Grants Temporary Reprieve to USAID Implementing Partners
On February 13, 2025, Judge Amir Ali of the U.S. District Court for the District of Columbia issued a temporary restraining order in two combined cases—one filed by U.S. Agency for International Development (USAID) contractors, a second by USAID grant recipients—challenging Executive Order 14169, “Reevaluating and Realigning United States Foreign Aid,” which paused almost all foreign assistance funding.
Client Alert | 7 min read | 02.19.25
Trump Administration Seeks Input from Public on National Artificial Intelligence Action Plan
Client Alert | 3 min read | 02.18.25
California’s New AI Bill To Require Copyright Disclosure of Training Data
Client Alert | 4 min read | 02.18.25