On June 25, 2026, the Federal Risk & Authorization Management Program (FedRAMP) launched its Consolidated Rules for 2026, marking a significant turning point in how the U.S. government administers security authorizations of private sector cloud offerings. The Consolidated Rules apply to all variants of the FedRAMP ecosystem, including legacy “Rev5” authorization holders, as well as future certifications under the new 20x program. Importantly, the Rules are intended in part to transition Rev5 authorizations over to 20x, with the Rev5 authorization status expected to terminate by the end of 2028.
Continue Reading Time for a Change: FedRAMP Fundamentally Revamps Program With Consolidated Rules for 2026
Kate Growley
Kate M. Growley (CIPP/US, CIPP/G) is a director with Crowell & Moring International and based in Hong Kong. Drawing from over a decade of experience as a practicing attorney in the United States, Kate helps her clients understand, navigate, and shape the policy and regulatory environment for some of the most complex data issues facing multinational companies, including cybersecurity, privacy, and digital transformation. Kate has worked with clients across every major sector, with particular experience in technology, health care, manufacturing, and aerospace and defense. Kate is a Certified Information Privacy Professional (CIPP) in both the U.S. private and government sectors by the International Association of Privacy Professionals (IAPP). She is also a Registered Practitioner with the U.S. Cybersecurity Maturity Model Certification (CMMC) Cyber Accreditation Body (AB).
Logged Out: How LOGZONE’s DIBCAC Challenges Put It Squarely in DOJ’s Crosshairs
On June 18, 2026, the U.S. Department of Justice (DOJ) announced that LOGZONE Inc., a defense contractor based in Huntsville, Alabama, agreed to pay $507,144 to resolve allegations that it violated the False Claims Act (FCA) by knowingly failing to satisfy cybersecurity requirements in its contracts with the U.S. Department of the Navy. The resolution is the latest action under DOJ’s Civil Cyber-Fraud Initiative and the first publicly reported settlement this fiscal year. It underscores a continued enforcement posture in which noncompliance with contractual cybersecurity obligations serves as the basis for potential FCA liability. Notably, this settlement did not arise from a whistleblower complaint but from a government-initiated assessment, signaling to contractors that proactive government assessments can pose enforcement consequences.
Continue Reading Logged Out: How LOGZONE’s DIBCAC Challenges Put It Squarely in DOJ’s CrosshairsGovernment Contractors, Take Note: Illinois Court Curtails Broad BIPA Exemption
A recent Illinois appellate decision has narrowed a key protection that state and local government contractors have long been able to rely on under Illinois’ Biometric Information Privacy Act (BIPA). In Thomas v. Cornerstone Services, Inc., the Illinois Appellate Court held that BIPA’s government contractor exemption does not provide blanket immunity to contractors simply because they hold a contract or subcontract with a state agency or local unit of government. The ruling carries important compliance implications for contractors and subcontractors operating across both government and private-sector markets.
Continue Reading Government Contractors, Take Note: Illinois Court Curtails Broad BIPA ExemptionFedRAMP Solicits Public Comment on Overhaul to Incident Communications Procedures
Introduction
The Federal Risk and Authorization Management Program (FedRAMP) continues to advance its modernization agenda. On April 8, 2026, FedRAMP released RFC-0031, Updated Incident Communications Procedures for public comment. This RFC proposes replacing the current FedRAMP Incident Communications Procedures (ICP) with what FedRAMP calls “a clear set of reporting requirements … established using a modern rules-based format.”
Below is a summary of key changes proposed in RFC-0031.
Continue Reading FedRAMP Solicits Public Comment on Overhaul to Incident Communications ProceduresAI for Government: 7 Days for Contractor Comments on GSA Proposed Contract Clause for AI Systems
On March 6, 2026, the General Services Administration (GSA) issued a significant proposed contract clause, GSAR 552.239-7001, Basic Safeguarding of Artificial Intelligence Systems (“Clause”), for inclusion in GSA Schedule solicitations and contracts for AI capabilities. The proposed clause would impose substantial new requirements related to AI sources, intellectual property rights, data use, change management, and performance standards. The Clause would also take precedence over any other contract terms (including commercial licensing terms) related to AI, including a Seller’s terms of sale and service to which the Government had previously agreed. GSA requests comments by March 20, 2026.
An analysis of the proposed clause follows below.
Continue Reading AI for Government: 7 Days for Contractor Comments on GSA Proposed Contract Clause for AI SystemsDHS Announces Virtual Town Halls on CIRCIA Final Rule
On February 13, 2026, the U.S. Department of Homeland Security (DHS) announced upcoming virtual town hall meetings scheduled for March 2026 regarding the implementation of the Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA). The meetings will allow industry stakeholders to provide input to DHS to refine the “scope and burden” of the forthcoming CIRCIA final rule.
Continue Reading DHS Announces Virtual Town Halls on CIRCIA Final RuleFedRAMP Proposes Updates to Authorization Process—Six New RFCs Released for Public Comment
What is FedRAMP?
The Federal Risk and Authorization Management Program (FedRAMP) is a government-wide initiative established to standardize the security assessment, authorization, and continuous monitoring of cloud products and services used by federal agencies. FedRAMP’s primary objective is to ensure that cloud service providers (CSPs) implement robust security controls to protect federal information in cloud environments. By leveraging a consistent framework for security assessment and authorization, FedRAMP is intended to reduce duplication of effort, cost, and time for both agencies and vendors.
Continue Reading FedRAMP Proposes Updates to Authorization Process—Six New RFCs Released for Public CommentCMMC for AI? Defense Policy Law Imposes AI Security Framework and Requirements on Contractors
In an important first, the yearly defense policy law, the National Defense Authorization Act (NDAA) for Fiscal Year 2026, directs the Department of Defense (DoD) to develop and implement a framework addressing the cybersecurity and physical security of artificial intelligence and machine learning technologies (AI/ML) acquired by the Pentagon.
Continue Reading CMMC for AI? Defense Policy Law Imposes AI Security Framework and Requirements on ContractorsThe FY 2026 National Defense Authorization Act
On December 18, 2025, the Fiscal Year 2026 National Defense Authorization Act (FY 2026 NDAA) (P.L. 119-60) was signed into law. The Act makes significant changes to defense acquisition, sourcing restrictions, and interactions between the Defense Industrial Base (DIB) and the Department of Defense (DOD).
Continue Reading The FY 2026 National Defense Authorization ActAn ITAR-ly Critical Reminder of Cybersecurity Requirements: DOJ Settles with Swiss Automation, Inc.
Earlier this month, the Department of Justice (DOJ) announced that Swiss Automation Inc., an Illinois-based precision machining company, agreed to pay $421,234 to resolve allegations that it violated the False Claims Act (FCA) by inadequately protecting technical drawings for parts delivered to Department of Defense (DoD) prime contractors. This settlement reflects DOJ’s persistent emphasis on cybersecurity compliance across all levels of the defense industrial base, reaching beyond prime contractors to encompass subcontractors and smaller suppliers. The settlement is also a reminder to all contractors not to overlook the often confusing relationship between Controlled Unclassified Information (CUI) and export-controlled information.
Continue Reading An ITAR-ly Critical Reminder of Cybersecurity Requirements: DOJ Settles with Swiss Automation, Inc.