On December 26, 2023, the Department of Defense (DoD) released the highly anticipated proposed rule for the Cybersecurity Maturity Model Certification Program (CMMC), a cybersecurity regulatory program that will likely impact most of the government contractor community. Every contractor who handles sensitive data such as Controlled Unclassified Information (CUI) or Federal Contract Information (FCI) during DoD contract performance will be covered by this regulation. While the CMMC program builds upon the security requirements included in Defense Federal Acquisition Regulation Supplement (DFARS) clause 252.204-7012, CMMC will bring greater scrutiny to contractors’ cybersecurity compliance and potentially greater consequences for failure to comply in the era of the Department of Justice’s Civil Cyber Fraud Initiative and False Claims Act litigation. If finalized as proposed, the rule will significantly impact the CMMC regime, notably by requiring senior company officials to complete an affirmation for every CMMC level self-assessed or certified, thus increasing legal compliance risks.
Continue Reading DoD’s New Year Resolution: A Cybersecurity Maturity Model Certification Program (CMMC) Proposed RuleCybersecurity
Fastest 5 Minutes: False Claims Act, Cybersecurity

This week’s episode covers two notable False Claims Act settlements and the White House National Cybersecurity Strategy Implementation Plan, and is hosted by Peter Eyre and Yuan Zhou. Crowell & Moring’s “Fastest 5 Minutes” is a biweekly podcast that provides a brief summary of significant government contracts legal and regulatory developments that no government contracts…
Biden Admin Eyes IoT Cyber Practices

On June 18, 2023, the Biden-Harris administration announced the launch of a new “U.S. Cyber Trust Mark” program (hereinafter the “Program”). First proposed by Federal Communication Commission (“FCC”) Chairwoman Jessica Rosenworcel, the Program aims to increase transparency and competition across the smart devices sector and to assist consumers in making informed decisions about the security of the devices they purchase.
Continue Reading Biden Admin Eyes IoT Cyber PracticesFastest 5 Minutes: DHS Cybersecurity, Embracing Commercial Innovation, Bid Protests

This week’s episode covers a DHS final rule implementing measures to safeguard Controlled Unclassified Information and facilitate improved incident reporting to DHS, a letter from Silicon Valley defense technology and venture capital firms calling on DoD to better embrace and scale commercial innovation for military use, a bid protest decision in which the Court found…
Fastest 5 Minutes: National Cyber Security Strategy, CHIPS, Conflicts of Interest

This week’s episode covers the National Cyber Security Strategy, a final DFARS clause requiring disclosure of use of workforce and facilities in the China, the Department of Commerce’s first Notice of Funding Opportunity under the CHIPS and Science Act of 2022, and congressional inquiries about financial conflicts of interest and ethically questionable behavior by senior…
Biden Administration Releases Comprehensive National Cybersecurity Strategy



On March 2, 2023, the Biden Administration released the 35-page National Cybersecurity Strategy (the “Strategy”) with a goal “to secure the full benefits of a safe and secure digital ecosystem for all Americans.”
Summary and Analysis
The Strategy highlights the government’s commitment to investing in cybersecurity research and new technologies to protect the nation’s security and improve critical infrastructure defenses. It outlines five pillars of action, each of which implicates critical infrastructure entities, from strengthening their cybersecurity processes, to receiving support from the federal government. For example, the Strategy highlights improving the security of Internet of Things (IoT) devices and expanding IoT cybersecurity labels, investing in quantum-resisting systems, developing a stronger cyber workforce, evolving privacy-enhancing platforms, and adopting security practices that are aligned with the National Institute of Standards and Technology (NIST) framework are some other suggested approaches that the private sector could take.
Continue Reading Biden Administration Releases Comprehensive National Cybersecurity StrategyFastest 5 Minutes: Buy American Act, Small Business, DOJ’s Civil Fraud Initiative

This week’s episode covers the final rule implementing further revisions to the Buy American Act, a proposed rule that would amend the FAR to account for recent changes in the Small Business Administration’s regulations, the NIST Secure Software Development Framework, and the first False Claims Act settlement under the DOJ’s Civil Cyber-Fraud Initiative, and is …
Byte-Sized Q&A – What Should Contractors Know About the Cybersecurity Provisions Included In, and Left Out of, the National Defense Authorization Act
Crowell & Moring’s “Byte-Sized Q&A” podcast takes the complex world of government contracts cybersecurity and breaks it down into byte-sized pieces. In this episode, Evan Wolff and Chris Hebdon discuss the notable cybersecurity provisions and omissions in the National Defense Authorization Act (NDAA) for Fiscal Year 2022.
Listen: Crowell.com | PodBean | SoundCloud
Fastest 5 Minutes – Bid Protests, Data Safeguarding, Defense Innovation Unit

This week’s episode covers increased minimum wage for certain federal contract workers, a protest decision involving proposal misrepresentation, cybersecurity and data safeguarding updates from DOD and NIST, and highlights from the Defense Innovation Unit Annual Report, and is hosted by Peter Eyre and Monica Sterling. Crowell & Moring’s “Fastest 5 Minutes” is a biweekly podcast …
National Defense Authorization Act for Fiscal Year 2022: Acquisition Policy Changes of Which Government Contractors Should Be Aware














During December 2021, the House and Senate reached agreement on a compromise National Defense Authorization Act (NDAA) for Fiscal Year (FY) 2022. On December 23, 2021, Congress presented S. 1605 to President Biden, which he signed on December 27, 2021.
The FY2022 NDAA contains numerous provisions relating to acquisition policy—which provide new opportunities for government contractors, will result in the imposition of new clauses or reporting requirements on government contractors, require government reporting to Congress on acquisition authorities and programs, alter processes and/or procedures to which government contractors are subject, etc. Crowell & Moring’s Government Contracts Group discusses the most consequential changes in the FY2022 NDAA for government contractors below.
Continue Reading National Defense Authorization Act for Fiscal Year 2022: Acquisition Policy Changes of Which Government Contractors Should Be Aware

