Photo of Kate GrowleyPhoto of Caitlyn WeeksPhoto of Dan WolffPhoto of Nkechi KanuPhoto of Jessica ChaoPhoto of Jacob Harrison

On March 12, 2025, the Government of Canada announced plans to launch the Canadian Program for Cyber Security Certification (CPCSC). CPCSC is a cybersecurity compliance verification program that aims to protect sensitive unclassified government information handled by Canadian government contractors and subcontractors within Canada’s defense sector. Canada will roll out CPCSC to contractors in four phases, with the first phase launching this month.

Continue Reading Canadian CMMC? Canada Proposes Cyber Compliance Regime for Canadian Defense Suppliers
Photo of Michael SamuelsPhoto of Jonathan M. Baker

On December 17, 2024, the Department of Defense (DOD) published a final rule amending the Defense Federal Acquisition Regulation Supplement (DFARS) to implement the data rights portions of the Small Business Innovation Research Program (SBIR) and Small Business Technology Transfer (STTR) Program Policy Directive, which itself was most recently amended in May 2023.  The changes from this final rule will be effective as of January 17, 2025. 

Continue Reading Final DOD Rule Codifies 20-Year SBIR Data Protection Period and Other SBIR Program Protections While Punting Potential Changes To Marking Requirements
Photo of Adelicia R. CliffePhoto of Alexandra Barbee-Garrett

On November 15, 2024, the Department of Defense (DoD) issued a Proposed Rule implementing Section 1655 of the John S. McCain National Defense Authorization Act (NDAA) for Fiscal Year (FY) 2019 (P.L. 115-232), over six years after Congress enacted the requirement. 

Continue Reading Six Years in the Making, DoD Releases Proposed Rule Requiring Disclosure of Foreign Review of Code for IT, Cybersecurity, Critical Infrastructure, and Weapons System Products and Services
Photo of Nkechi KanuPhoto of Brian Tully McLaughlinPhoto of Jessica ChaoPhoto of Jacob HarrisonPhoto of Jennie Wang VonCannonPhoto of Stephen M. Byers

On October 22, 2024, the Department of Justice (DOJ) announced that Pennsylvania State University (Penn State) will pay $1.25 million to resolve allegations that it violated the False Claims Act (FCA) by failing to comply with contractually mandated cybersecurity requirements by the Department of Defense (DoD) and National Aeronautics and Space Administration (NASA).  The announcement marks the most recent settlement under DOJ’s Civil Cyber-Fraud Initiative although, unlike prior settlements, there is no allegation of a cybersecurity incident or breach that was related to or caused by the contractor’s alleged noncompliance.

Continue Reading Allegations of a Litany of Lyin’: Penn State Settles Claims of Cybersecurity Noncompliance
Photo of Peter J. EyrePhoto of Adelicia R. CliffePhoto of Michael SamuelsPhoto of Jacob HarrisonPhoto of Christian CurranPhoto of Sarah BurgartPhoto of Allison Skager

As Crowell covered in a recent alert, the Department of Defense (DoD) on October 11, 2024 released a final rule (the “Final Program Rule”) formalizing the requirements, assessment processes, and related governance for its Cyber Maturity Model Certification Program (CMMC).

Continue Reading CMMC Final Rule Includes M&A Trigger for New Assessment
Photo of Peter J. Eyre

Cybersecurity, Health Information Technology

This week’s episode covers a False Claims Act whistleblower lawsuit involving failure to comply with federal cybersecurity requirements, a new CISA cyber incident reporting tool, and a proposed rule to implement an HHS-wide policy relating to health information technology, and is hosted by Peter Eyre. Crowell & Moring’s “Fastest 5 Minutes”

Photo of Nkechi KanuPhoto of Brian Tully McLaughlinPhoto of Jennie Wang VonCannonPhoto of Jessica Chao

On June 17, 2024, the Department of Justice (DOJ) announced a $11.3 million False Claims Act (FCA) settlement that touches on two key enforcement priorities:  the DOJ’s Civil Cyber-Fraud Initiative and pandemic-related fraud.  This settlement, the largest under the Civil Cyber-Fraud Initiative to date, resolved allegations that Guidehouse Inc. (Guidehouse) and its subcontractor, Nan McKay and Associates (Nan McKay), violated the FCA because they failed to conduct pre‑production cybersecurity testing on New York State’s Emergency Rental Assistance Program (ERAP) technology product before public launch, and that Guidehouse used an unapproved third-party data cloud software program to store personally identifiable information (PII).

Continue Reading Another One: It Pays to Consult the DOJ under the Civil Cyber Fraud Initiative
Photo of Peter J. EyrePhoto of M.Yuan Zhou
Cyber, Semiconductors, AI, False Claims Act

This week’s episode covers cybersecurity updates, a proposed rule regarding prohibition on semiconductors produced by certain Chinese manufacturers, DOL guidance entitled “Artificial Intelligence and Equal Employment Opportunity for Federal Contractors,” and two settlements under the civil False Claims Act, and is hosted by Peter Eyre and Yuan Zhou. Crowell

Photo of Nkechi KanuPhoto of Jacob Harrison

The Department of Defense (DoD) recently published a memorandum clarifying what it means for a cloud service provider (CSP) to be Federal Risk and Authorization Management Program (FedRAMP) Moderate baseline “equivalent” and meet incident reporting requirements under Defense Federal Acquisition Regulation Supplement (DFARS) Clause 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting (DFARS 7012). The memorandum states, in order to be considered FedRAMP equivalent going forward, CSPs must (1) be FedRAMP Moderate/High-Authorized, or (2) secure a third-party assessment confirming their compliance with all FedRAMP Moderate baseline security controls.

Continue Reading No Longer Cloudy: DoD Issues New Guidance on FedRAMP Moderate Equivalency Cloud Security Requirements
Photo of Peter J. EyrePhoto of Nkechi Kanu

CMMC

This special edition covers DoD’s proposed rule for the Cybersecurity Maturity Model Certification Program, and is hosted by Peter Eyre, Michael Gruden, and Nkechi Kanu. Crowell & Moring’s “Fastest 5 Minutes” is a biweekly podcast that provides a brief summary of significant government contracts legal and regulatory developments that no government contracts lawyer or