Photo of Olivia LynchPhoto of Cherie Owen

As discussed in more detail here, the U.S. Department of War (DoW) recently issued a memorandum (Memo 26-P-1023, dated July 13, 2026) directing the immediate suspension of Cybersecurity Maturity Model Certification (CMMC) Phase II requirements (Level I and II self assessments are still permitted). Significantly, the memo directs that “all pending and future CMMC implementation milestones across DoW solicitations and contracts are held in abeyance until further notice.” Moreover, the DoW issued a memorandum on implementing these requirements (available here), directing agencies to issue amendments removing CMMC Level 2 and 3 requirements from active solicitations “as soon as practicable.” Contractors should monitor the government’s compliance with this requirement and should be prepared, if needed, to file a bid protest to protect their rights.

Continue Reading CMMC Phase II Suspension Requires Reconsideration of Such Requirements in Solicitations
Photo of Kate GrowleyPhoto of Nkechi KanuPhoto of Jessica ChaoPhoto of Jacob HarrisonPhoto of Ajan JayantPhoto of Bryan DewanPhoto of Caitlyn Weeks

The Department of War (DoW) is immediately suspending Cybersecurity Maturity Model Certification (CMMC) Phase II requirements, which had been scheduled to take effect on November 10, 2026.

Continue Reading Department of War Immediately Suspends CMMC Phase II Requirements, Launches 60-Day Reform Review
Photo of Kate GrowleyPhoto of Jacob HarrisonPhoto of Ajan JayantPhoto of Bryan Dewan

On June 25, 2026, the Federal Risk & Authorization Management Program (FedRAMP) launched its Consolidated Rules for 2026, marking a significant turning point in how the U.S. government administers security authorizations of private sector cloud offerings. The Consolidated Rules apply to all variants of the FedRAMP ecosystem, including legacy “Rev5” authorization holders, as well as future certifications under the new 20x program. Importantly, the Rules are intended in part to transition Rev5 authorizations over to 20x, with the Rev5 authorization status expected to terminate by the end of 2028. 

Continue Reading Time for a Change: FedRAMP Fundamentally Revamps Program With Consolidated Rules for 2026
Photo of Kate GrowleyPhoto of Nkechi KanuPhoto of Jessica ChaoPhoto of Bryan DewanPhoto of Jacob HarrisonPhoto of Ajan Jayant

Introduction

The Federal Risk and Authorization Management Program (FedRAMP) continues to advance its modernization agenda. On April 8, 2026, FedRAMP released RFC-0031, Updated Incident Communications Procedures for public comment. This RFC proposes replacing the current FedRAMP Incident Communications Procedures (ICP) with what FedRAMP calls “a clear set of reporting requirements … established using a modern rules-based format.” 

Below is a summary of key changes proposed in RFC-0031.    

Continue Reading FedRAMP Solicits Public Comment on Overhaul to Incident Communications Procedures
Photo of Kate GrowleyPhoto of Matthew FerraroPhoto of Jacob CanterPhoto of Jacob HarrisonPhoto of Ajan JayantPhoto of Bryan Dewan

On February 13, 2026, the U.S. Department of Homeland Security (DHS) announced upcoming virtual town hall meetings scheduled for March 2026 regarding the implementation of the Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA).  The meetings will allow industry stakeholders to provide input to DHS to refine the “scope and burden” of the forthcoming CIRCIA final rule.

Continue Reading DHS Announces Virtual Town Halls on CIRCIA Final Rule
Photo of Kate GrowleyPhoto of Nkechi KanuPhoto of Brian Tully McLaughlinPhoto of Scott WisePhoto of Jessica ChaoPhoto of Jacob HarrisonPhoto of Jasmine Masri

Earlier this month, the Department of Justice (DOJ) announced that Swiss Automation Inc., an Illinois-based precision machining company, agreed to pay $421,234 to resolve allegations that it violated the False Claims Act (FCA) by inadequately protecting technical drawings for parts delivered to Department of Defense (DoD) prime contractors.  This settlement reflects DOJ’s persistent emphasis on cybersecurity compliance across all levels of the defense industrial base, reaching beyond prime contractors to encompass subcontractors and smaller suppliers.  The settlement is also a reminder to all contractors not to overlook the often confusing relationship between Controlled Unclassified Information (CUI) and export-controlled information.

Continue Reading An ITAR-ly Critical Reminder of Cybersecurity Requirements: DOJ Settles with Swiss Automation, Inc.
Photo of Nkechi KanuPhoto of Brian Tully McLaughlinPhoto of Kate GrowleyPhoto of Jessica ChaoPhoto of Jacob HarrisonPhoto of Jasmine Masri

On September 30, 2025, the Department of Justice (DOJ) announced that Georgia Tech Research Corporation (GTRC) agreed to pay $875,000 to settle allegations that it violated the False Claims Act (FCA) and federal common law by failing to meet cybersecurity requirements under certain Air Force and Defense Advanced Research Projects Agency (DARPA) contracts.  The settlement adds to the growing list of recoveries under DOJ’s Civil Cyber-Fraud Initiative and is yet another example of DOJ’s ongoing enforcement focus on cybersecurity obligations for federal contractors handling sensitive government information.  The settlement also provides insight into how government contractors may challenge FCA liability when faced with allegations of cybersecurity noncompliance.

Continue Reading From Yellow Jackets to Red Flags: DOJ Stings Georgia Tech for Alleged Cybersecurity Noncompliance
Photo of Nkechi KanuPhoto of Brian Tully McLaughlinPhoto of Stephen M. ByersPhoto of Jessica ChaoPhoto of Jacob HarrisonPhoto of Jasmine Masri

On March 26, 2025, the Department of Justice (DOJ) announced that defense contractor MORSECORP Inc. (MORSE) will pay $4.6 million to settle allegations that MORSE violated the False Claims Act (FCA) by failing to comply with cybersecurity requirements and subsequently submitting false or fraudulent claims for payment in its contracts with the Departments of the Army and Air Force. This is the first FCA settlement that is based on a defense contractor’s failure to reevaluate and promptly update its self-assessment score in the Supplier Performance Risk System (SPRS) after a third-party assessment resulted in a lower score.

Continue Reading For Better or MORSE: Another Settlement Under DOJ’s Civil Cyber-Fraud Initiative
Photo of Kate GrowleyPhoto of Caitlyn WeeksPhoto of Dan WolffPhoto of Nkechi KanuPhoto of Jessica ChaoPhoto of Jacob Harrison

On March 12, 2025, the Government of Canada announced plans to launch the Canadian Program for Cyber Security Certification (CPCSC). CPCSC is a cybersecurity compliance verification program that aims to protect sensitive unclassified government information handled by Canadian government contractors and subcontractors within Canada’s defense sector. Canada will roll out CPCSC to contractors in four phases, with the first phase launching this month.

Continue Reading Canadian CMMC? Canada Proposes Cyber Compliance Regime for Canadian Defense Suppliers
Photo of Adelicia R. CliffePhoto of Alexandra Barbee-Garrett

On November 15, 2024, the Department of Defense (DoD) issued a Proposed Rule implementing Section 1655 of the John S. McCain National Defense Authorization Act (NDAA) for Fiscal Year (FY) 2019 (P.L. 115-232), over six years after Congress enacted the requirement. 

Continue Reading Six Years in the Making, DoD Releases Proposed Rule Requiring Disclosure of Foreign Review of Code for IT, Cybersecurity, Critical Infrastructure, and Weapons System Products and Services