Photo of M.Yuan ZhouPhoto of Kate GrowleyPhoto of Nkechi Kanu

This special edition covers the Pentagon’s recent suspension of Cybersecurity Maturity Model Certification (CMMC) Phase II requirements and initiation of a 60-day review by the CMMC Reform Task Force, and is hosted by Yuan Zhou, Kate Growley, and Nkechi Kanu. Crowell & Moring’s “Fastest 5 Minutes” is a biweekly podcast that provides a brief summary of significant government contracts legal and regulatory developments that no government contracts lawyer or executive should be without.

Continue Reading Special Edition of the Fastest 5 Minutes: Suspension of CMMC Phase II Requirements
Photo of Olivia LynchPhoto of Cherie Owen

As discussed in more detail here, the U.S. Department of War (DoW) recently issued a memorandum (Memo 26-P-1023, dated July 13, 2026) directing the immediate suspension of Cybersecurity Maturity Model Certification (CMMC) Phase II requirements (Level I and II self assessments are still permitted). Significantly, the memo directs that “all pending and future CMMC implementation milestones across DoW solicitations and contracts are held in abeyance until further notice.” Moreover, the DoW issued a memorandum on implementing these requirements (available here), directing agencies to issue amendments removing CMMC Level 2 and 3 requirements from active solicitations “as soon as practicable.” Contractors should monitor the government’s compliance with this requirement and should be prepared, if needed, to file a bid protest to protect their rights.

Continue Reading CMMC Phase II Suspension Requires Reconsideration of Such Requirements in Solicitations
Photo of Peter J. EyrePhoto of Adelicia R. CliffePhoto of Michael SamuelsPhoto of Jacob HarrisonPhoto of Christian CurranPhoto of Sarah BurgartPhoto of Allison Skager

As Crowell covered in a recent alert, the Department of Defense (DoD) on October 11, 2024 released a final rule (the “Final Program Rule”) formalizing the requirements, assessment processes, and related governance for its Cyber Maturity Model Certification Program (CMMC).

Continue Reading CMMC Final Rule Includes M&A Trigger for New Assessment
Photo of Peter J. EyrePhoto of M.Yuan Zhou

CMMC, DOJ, FedRAMP

This week’s episode covers DOD’s proposed rule regarding Cybersecurity Maturity Model Certification 2.0, DOJ’s new Corporate Whistleblower Awards Pilot Program, and an OMB memo that proposes updates to FedRAMP, and is hosted by Peter Eyre and Yuan Zhou. Crowell & Moring’s “Fastest 5 Minutes” is a biweekly podcast that provides a brief

Photo of Peter J. EyrePhoto of M.Yuan Zhou

This week’s episode covers the Cyber AB’s recently released pre-decisional draft CMMC Assessment Process, an SBA final rule that implements new methods for evaluating expanded sources of small business past performance, a GSA OIG Alert about the Transactional Data Reporting rule, and Senate passage of an amended version of the Preventing Organizational Conflicts of Interest

Photo of Crowell & Moring

More than 300,000 companies within the Defense Department’s supply chain will need to meet new Cybersecurity Maturity Model Certification (CMMC) requirements and pass a third-party assessment to ensure they are adequately protecting sensitive information on their networks. Now, Crowell & Moring has become the first AmLaw 100 firm to achieve Registered Provider Organization (RPO) status

Photo of Kate GrowleyPhoto of Christopher Hebdon

The National Institute of Standards and Technology (NIST) recently released the final version of NIST Special Publication (SP) 800-172, Enhanced Security Requirements for Protecting Controlled Unclassified Information. Designed to supplement the requirements in NIST SP 800-171—the applicable standard under DFARS 252.204-7012—800-172 provides 35 enhanced security requirements to protect controlled unclassified information (CUI) associated with

Photo of Kate GrowleyPhoto of Nkechi KanuPhoto of Christopher Hebdon

Fresh off the heels of the DFARS Interim Rule, the Department of Defense (DoD) released Assessment Guides for Levels 1 – 3 of the Cybersecurity Maturity Model Certification (CMMC). These Guides will be used by Certified Assessors to determine whether contractors have satisfied the practices and processes required to attain CMMC certifications at

Photo of Kate GrowleyPhoto of Christopher Hebdon

The Department of Defense (DoD) has released Version 1.0 of the Cybersecurity Maturity Model Certification (CMMC), Appendices A-F, and an Overview Briefing. While Version 1.0 largely mirrors the draft Version 0.7, the final version includes notable revisions, such as:

  • Process and Practice Descriptions in Appendix B, which include discussions and clarifications