1. Home
  2. |Insights
  3. |No Post-Thanksgiving Break for Cyber – DoD and NIST Publish New Guidance

No Post-Thanksgiving Break for Cyber – DoD and NIST Publish New Guidance

Client Alert | 1 min read | 12.01.17

Both the Department of Defense and National Institute of Standards & Technology (NIST) have put pen to paper and provided new information for contractors looking to comply with DFARS 252.204-7012 and its accompanying cybersecurity requirements under NIST Special Publication (SP) 800-171.  Earlier this week, the DoD posted guidance explaining that contractors can still use system security plans (SSPs) under the original version of NIST SP 800-171 to “document implementation” under the DFARS Clause, despite that version not including SSPs as a security control requirement.  Separately, NIST published a draft of NIST SP 800-171A, Assessing Security Requirements for Controlled Unclassified Information, providing guidance to both contractors and their customers regarding how to conduct assessments under NIST SP 800-171.  Importantly, the draft is open to comment through December 27, 2017, providing contractors with a unique opportunity to weigh in on how their customers may ultimately judge compliance with the DFARS Clause’s security requirements.


Contacts

Insights

Client Alert | 3 min read | 02.11.26

Clicking All the Right Boxes: FTC Moves to Revive “Click-to-Cancel” Rule Following Eighth Circuit Vacatur

On July 8, 2025, the U.S. Court of Appeals for the Eighth Circuit vacated the Federal Trade Commission’s (FTC) Rule Concerning Subscriptions and Other Negative Option Plans, commonly known as the “Click-to-Cancel” rule. As detailed in a previous client alert, the rule was intended to regulate negative option plans[1]— such as subscriptions and automatic renewals — by imposing stringent requirements on businesses, including streamlined cancellation processes and enhanced disclosure obligations. The Eighth Circuit vacated the Click-to-Cancel rule because it found that the FTC had failed to comply with mandatory procedural requirements. As a result, the rule is no longer in effect, and businesses are not currently subject to its mandates....