On March 12, 2025, the Government of Canada announced plans to launch the Canadian Program for Cyber Security Certification (CPCSC). CPCSC is a cybersecurity compliance verification program that aims to protect sensitive unclassified government information handled by Canadian government contractors and subcontractors within Canada’s defense sector. Canada will roll out CPCSC to contractors in four phases, with the first phase launching this month.
Continue Reading Canadian CMMC? Canada Proposes Cyber Compliance Regime for Canadian Defense SuppliersCybersecurity
Final DOD Rule Codifies 20-Year SBIR Data Protection Period and Other SBIR Program Protections While Punting Potential Changes To Marking Requirements

On December 17, 2024, the Department of Defense (DOD) published a final rule amending the Defense Federal Acquisition Regulation Supplement (DFARS) to implement the data rights portions of the Small Business Innovation Research Program (SBIR) and Small Business Technology Transfer (STTR) Program Policy Directive, which itself was most recently amended in May 2023. The changes from this final rule will be effective as of January 17, 2025.
Continue Reading Final DOD Rule Codifies 20-Year SBIR Data Protection Period and Other SBIR Program Protections While Punting Potential Changes To Marking RequirementsSix Years in the Making, DoD Releases Proposed Rule Requiring Disclosure of Foreign Review of Code for IT, Cybersecurity, Critical Infrastructure, and Weapons System Products and Services

On November 15, 2024, the Department of Defense (DoD) issued a Proposed Rule implementing Section 1655 of the John S. McCain National Defense Authorization Act (NDAA) for Fiscal Year (FY) 2019 (P.L. 115-232), over six years after Congress enacted the requirement.
Continue Reading Six Years in the Making, DoD Releases Proposed Rule Requiring Disclosure of Foreign Review of Code for IT, Cybersecurity, Critical Infrastructure, and Weapons System Products and ServicesAllegations of a Litany of Lyin’: Penn State Settles Claims of Cybersecurity Noncompliance





On October 22, 2024, the Department of Justice (DOJ) announced that Pennsylvania State University (Penn State) will pay $1.25 million to resolve allegations that it violated the False Claims Act (FCA) by failing to comply with contractually mandated cybersecurity requirements by the Department of Defense (DoD) and National Aeronautics and Space Administration (NASA). The announcement marks the most recent settlement under DOJ’s Civil Cyber-Fraud Initiative although, unlike prior settlements, there is no allegation of a cybersecurity incident or breach that was related to or caused by the contractor’s alleged noncompliance.
Continue Reading Allegations of a Litany of Lyin’: Penn State Settles Claims of Cybersecurity NoncomplianceCMMC Final Rule Includes M&A Trigger for New Assessment






As Crowell covered in a recent alert, the Department of Defense (DoD) on October 11, 2024 released a final rule (the “Final Program Rule”) formalizing the requirements, assessment processes, and related governance for its Cyber Maturity Model Certification Program (CMMC).
Continue Reading CMMC Final Rule Includes M&A Trigger for New AssessmentFastest 5 Minutes
Cybersecurity, Health Information Technology
This week’s episode covers a False Claims Act whistleblower lawsuit involving failure to comply with federal cybersecurity requirements, a new CISA cyber incident reporting tool, and a proposed rule to implement an HHS-wide policy relating to health information technology, and is hosted by Peter Eyre. Crowell & Moring’s “Fastest 5 Minutes”…
Another One: It Pays to Consult the DOJ under the Civil Cyber Fraud Initiative



On June 17, 2024, the Department of Justice (DOJ) announced a $11.3 million False Claims Act (FCA) settlement that touches on two key enforcement priorities: the DOJ’s Civil Cyber-Fraud Initiative and pandemic-related fraud. This settlement, the largest under the Civil Cyber-Fraud Initiative to date, resolved allegations that Guidehouse Inc. (Guidehouse) and its subcontractor, Nan McKay and Associates (Nan McKay), violated the FCA because they failed to conduct pre‑production cybersecurity testing on New York State’s Emergency Rental Assistance Program (ERAP) technology product before public launch, and that Guidehouse used an unapproved third-party data cloud software program to store personally identifiable information (PII).
Continue Reading Another One: It Pays to Consult the DOJ under the Civil Cyber Fraud InitiativeFastest 5 Minutes

Cyber, Semiconductors, AI, False Claims Act
This week’s episode covers cybersecurity updates, a proposed rule regarding prohibition on semiconductors produced by certain Chinese manufacturers, DOL guidance entitled “Artificial Intelligence and Equal Employment Opportunity for Federal Contractors,” and two settlements under the civil False Claims Act, and is hosted by Peter Eyre and Yuan Zhou. Crowell…
No Longer Cloudy: DoD Issues New Guidance on FedRAMP Moderate Equivalency Cloud Security Requirements

The Department of Defense (DoD) recently published a memorandum clarifying what it means for a cloud service provider (CSP) to be Federal Risk and Authorization Management Program (FedRAMP) Moderate baseline “equivalent” and meet incident reporting requirements under Defense Federal Acquisition Regulation Supplement (DFARS) Clause 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting (DFARS 7012). The memorandum states, in order to be considered FedRAMP equivalent going forward, CSPs must (1) be FedRAMP Moderate/High-Authorized, or (2) secure a third-party assessment confirming their compliance with all FedRAMP Moderate baseline security controls.
Continue Reading No Longer Cloudy: DoD Issues New Guidance on FedRAMP Moderate Equivalency Cloud Security RequirementsSpecial Edition of the Fastest 5 Minutes:

CMMC
This special edition covers DoD’s proposed rule for the Cybersecurity Maturity Model Certification Program, and is hosted by Peter Eyre, Michael Gruden, and Nkechi Kanu. Crowell & Moring’s “Fastest 5 Minutes” is a biweekly podcast that provides a brief summary of significant government contracts legal and regulatory developments that no government contracts lawyer or…


