Tag Archives: DoD

Department of Defense suspends CMMC Phase II implementation and seeks industry input on future reforms

The Department of Defense (DoD) Chief Information Officer CIO suspended implementation of the Cybersecurity Maturity Model Certification (CMMC) Phase II on July 13, 2026  and launched a CMMC Review and Reform Task Force to reassess the CMMC program, reduce compliance burdens, and gather direct industry feedback regarding future cybersecurity requirements. Based on the recently issued … Continue Reading

Navigating DoD’s CMMC Program Final Rule

On October 15, 2024, the U.S. Department of Defense (DoD) released its final rule to establish the Cybersecurity Maturity Model Certification (CMMC) Program (Final CMMC Program Rule). The CMMC Program allows the DoD to verify that defense prime contractors and subcontractors (defense contractors) have implemented security safeguards for Federal Contract Information (FCI) and Controlled Unclassified … Continue Reading

DoD Advances CMMC: Key Takeaways from the Proposed August 2024 DFARS Rule

On August 15, 2024, the US Department of Defense (DoD) published a proposed rule to amend the Defense Federal Acquisition Regulation Supplement (DFARS) in order to implement the Cybersecurity Maturity Model Certification (CMMC) program. DoD is executing a phased rollout of CMMC, and the August 2024 proposed rule is the second proposed rule DoD has … Continue Reading

Department of Defense Updates Section 1260H Chinese Military Companies List

On January 31, 2024, the Department of Defense (DOD) released an update to the Chinese Military Company (CMC) List in accordance with Section 1260H of the National Defense Authorization Act (NDAA) for Fiscal Year 2021. DOD added sixteen entities to the 1260H CMC List and removed three previously designated entities that no longer met “some … Continue Reading

Recently-Released Cybersecurity Verification Mandate Creates Uncertainty for Department of Defense Suppliers

Protection of the Defense Industrial Base (DIB) from the growing panoply of cybersecurity threats has been a consistent point of emphasis for senior Department of Defense (DOD) officials during the Trump Administration. The DOD took a significant step toward addressing that concern on January 31, 2020 with the release of Version 1.0 of the Cybersecurity … Continue Reading

Preventing the Next Snowden – Insider Threat Program Deadline Looming

Government contractors that hold a facility security clearance (FCL) must have a written program in place no later than November 30, 2016 to begin implementing insider threat requirements published by the Department of Defense (DoD) in Change 2 to DoD 5220.22-M, National Industrial Security Program Operating Manual (NISPOM). In particular, on May 18, 2016, the … Continue Reading
LexBlog