Insights

Professional
Practice
Industry
Region
Trending Topics
Location
Type

Sort by:

Firm News 16 results

Firm News | 8 min read | 08.15.24

The Best Lawyers in America 2025 Recognizes 42 Crowell & Moring Attorneys, Three Selected as Lawyer of the Year

Washington – August 15, 2024: The 2025 edition of The Best Lawyers in America® has recognized 42 Crowell & Moring lawyers as "Best Lawyers" and 29 lawyers as “Ones to Watch.”
...

Firm News | 4 min read | 06.24.24

Crowell Earns Top Rankings from Legal 500 United States 2024

Washington – June 24, 2024: Crowell & Moring has been recommended in eight practice areas in the 17th edition of the Legal 500 United States. In addition, partner Daniel Forman, co-chair of the firm’s Government Contracts Group, has been named to the Legal 500’s “Hall of Fame” for Government Contracts.
...

Firm News | 4 min read | 06.04.24

ArmorText and Crowell & Moring Release New Open Source Cybersecurity Tabletop Exercises

MCLEAN, Va., June 4, 2024 - ArmorText, which safeguards communication for organizations worldwide, and the international law firm of Crowell & Moring LLP today released an update to their tabletop exercise guide, making new exercise scenarios publicly available under a Creative Commons license. The new Cyber Resilience: Incident Response Tabletop Exercises Q2 2024 addresses urgent challenges facing executives, including disruptive attacks by increasingly sophisticated criminal actors with well-publicized recent examples, as well as increasingly complex regulatory obligations.
...

Client Alerts 175 results

Client Alert | 2 min read | 03.31.25

Canadian CMMC? Canada Proposes Cyber Compliance Regime for Canadian Defense Suppliers

On March 12, 2025, the Government of Canada announced plans to launch the Canadian Program for Cyber Security Certification (CPCSC). CPCSC is a cybersecurity compliance verification program that aims to protect sensitive unclassified government information handled by Canadian government contractors and subcontractors within Canada’s defense sector. Canada will roll out CPCSC to contractors in four phases, with the first phase launching this month.
...

Client Alert | 3 min read | 03.26.25

FedRAMP 20x: Proposed Framework Aims To Increase Automation and Efficiency

On March 24, 2025, the Federal Risk and Authorization Management Program (FedRAMP) unveiled “FedRAMP 20x,” a proposal to make FedRAMP more efficient by automating FedRAMP security assessments and continuous monitoring, simplifying required technical controls, and leaning on industry to provide tooling and solutions to support automation. 
...

Client Alert | 5 min read | 03.10.25

SEC Shifts Enforcement Focus With Launch of Cyber and Emerging Technologies Unit

On February 20, 2025, the Securities and Exchange Commission (SEC) announced the formation of the Cyber and Emerging Technologies Unit, known as “CETU,” which will replace the Crypto Assets and Cyber Unit (“CACU”).
...

Press Coverage 49 results

Press Coverage | 11.09.23

SEC/SolarWinds Legal Analysis w/Evan Wolff (podcast)

The Cyber Ranch Podcast

Publications 33 results

Publication | 01.28.25

Changes to Critical Infrastructure Requirements

In 2025, owners and operators of critical infrastructure will have new security and information sharing obligations to consider under the National Security Memorandum 22 (“NSM-22” or the “Memorandum”). NSM- 22 replaces the Obama-era Presidential Policy Directive 21: Critical Infrastructure Security and Resilience (PPD-21).
...

Publication | 01.28.25

Preparing for CMMC in 2025

After years of anticipation and a series of delays, implementation of the U.S. Department of Defense’s Cyber Maturity Model Certification Program (CMMC) is rapidly approaching. Though CMMC is not expected to enter into effect until early-to- mid 2025, DOD contactors can start taking steps now to ensure a smooth transition into this new regulatory era.
...

Publication | 05.14.24

Critical Infrastructure: Updating the 2013 NIPP and other Risk Mitigation Actions

Privacy and Cybersecurity Outlook: The 2024 Landscape
Protecting critical infrastructure is paramount to today’s digital age. Critical infrastructure includes physical and virtual systems essential for the functioning of our society, economy, and national security. Such a definition may include power grids, communication networks, and financial institutions, among other networks that heavily rely on interconnected computer systems. These systems are also considered critical infrastructure, as they are used to protect critical cybersecurity infrastructure. 
...

Events 50 results

Event | 05.19.25 - 05.22.25

Law-Tech Connect and XPONENTIAL 2025

Join Crowell at Law-Tech Connect and AUVSI XPONENTIAL in Houston, where industry experts focus on how changes in technology, policy, safety, and society are shaping the uncrewed systems and robotics industry. Co-located at XPONENTIAL, Law-Tech Connect is designed to connect and inform all those involved in uncrewed and autonomous systems in a one-day session focused on the intersection between technology and legal issues.

Event | 04.10.25, 8:00 AM EDT - 1:00 PM EDT

Crowell's CMMC Day

You are invited to attend Crowell's CMMC Day, an in-person event dedicated to exploring the complexities of CMMC implementation and associated legal risks. This event will feature a series of insightful conversations with industry experts on topics such as prepping for assessments, risk management, and the government and private sector’s perspectives on CMMC. 

Event | 11.19.24, 8:00 AM EST - 9:30 AM EST

CMMC Finalized: How to Prepare & Achieve Certification

Crowell is honored to host Ms. Stacy Bostjanick, the Defense Department’s CMMC Program Director, who will be joined live by Crowell attorneys Evan Wolff and Michael Gruden for an engaging fireside chat.

Webinars 27 results

Webinar | 01.27.25, 10:00 AM EST - 10:45 AM EST

Cyber For All: A FAR CUI Proposed Rule Webinar

The FAR Council recently released a proposed rule (the “FAR CUI Rule”) that would amend the FAR to implement federal government-wide Controlled Unclassified Information (CUI) cybersecurity, training, and incident reporting requirements for government contractors and subcontractors.  

Webinar | 05.15.24, 1:00 PM EDT - 2:00 PM EDT

NIST SP 800-171 Transitions to Revision 3: What to Know

As the National Institute for Standards and Technology (NIST) prepares to release its highly anticipated Revision 3 to the security standard required by CMMC and current DoD contracts alike, join Crowell attorneys Evan Wolff and Michael Gruden in a robust discussion with one of the key architects of Revision 3, NIST’s own Senior Computer Scientist, Victoria Pillitteri.

Webinar | 02.14.24, 1:00 PM EST - 2:00 PM EST

CMMC 2.0: Legal, Assessor, and Threat Intelligence Perspectives

Members of Crowell’s Privacy & Cybersecurity practice and panelists from Coalfire and Mandiant will discuss the highly anticipated proposed rule for the Cybersecurity Maturity Model Certification Program (CMMC) issued by the Department of Defense (DOD) in December.

Blog Posts 17 results

Blog Post | 02.10.20

Energy Cybersecurity Act of 2019

Crowell & Moring's Data Law Insights

Blog Post | 08.20.19

Privacy & Cybersecurity – New York Enacts the SHIELD Act

Crowell & Moring's International Trade Law

Podcasts 19 results

Podcast | 02.15.22

Byte-Sized Q&A: What Should Contractors Know About the Cybersecurity Provisions Included In, and Left Out Of, the National Defense Authorization Act

Crowell & Moring’s “Byte-Sized Q&A” podcast takes the complex world of government contracts cybersecurity and breaks it down into byte-sized pieces.  In this episode, Evan Wolff and Chris Hebdon discuss the notable cybersecurity provisions and omissions in the National Defense Authorization Act (NDAA) for Fiscal Year 2022.
...

Podcast | 01.19.22

Byte-Sized Q&A: What is CISA and Why is it Important to Government Contractors?

Crowell & Moring’s “Byte-Sized Q&A” podcast takes the complex world of government contracts cybersecurity and breaks it down into byte-sized pieces. In this episode of Byte Sized Q&A, Evan Wolff and Michael Gruden discuss the Cybersecurity Infrastructure Security Agency (CISA) and why it is important for contractors to take note of CISA’s actions.
...

Podcast | 12.03.21

Byte-Sized Q&A: What’s not in CMMC 2.0?

Crowell & Moring’s “Byte-Sized Q&A” podcast takes the complex world of government contracts cybersecurity and breaks it down into byte-sized pieces. In this episode, hosts Evan Wolff and Kate Growley talk through some key elements that are no longer expected under CMMC 2.0.
...