• +1 (571) 500-1010
  • [email protected]
  • 11130 Fairfax Blvd. Ste. 303, Fairfax, VA 22030
Facebook-f X-twitter Instagram Linkedin
  • Practice Areas
    • Corporate Transactions
    • Estate & Real Property Litigation
    • Government Contracts
    • Litigation
    • International
    • Appellate Practice
    • Servicios Legales
  • About
    • About XLP
    • Our Team
    • News & Info
    • Contact
    • Privacy Policy
  • Contact
  • Careers
  • Practice Areas
    • Corporate Transactions
    • Estate & Real Property Litigation
    • Government Contracts
    • Litigation
    • International
    • Appellate Practice
    • Servicios Legales
  • About
    • About XLP
    • Our Team
    • News & Info
    • Contact
    • Privacy Policy
  • Contact
  • Careers
Business Law Federal Contracting
By: [email protected] Jun 18

In recent years cybersecurity has become an important concern for the Government, and that has resulted in changes to the Federal Acquisition Regulation (FAR) and the Defense Federal Acquisition Regulation Supplement (DFARS). There is a big change on the horizon that all defense contractors should be aware of—the Department of Defense (DoD) is launching a Cybersecurity Maturity Model Certification (CMMC) program. Because all DoD contractors will be required to be certified by a third party to continue to do business with the Government, this a development that will affect all DoD contractors.  

CMMC version 1.02 requires DoD contractors and their supply chains to have systems in place that meet the certification level cybersecurity requirements for the data that they will be required to handle under DoD contracts and subcontracts. The stringency of the requirements will depend on the nature of the information, with Level 1 being the most basic and Level 5 being the strictest. The vast majority of contracts will likely require Levels 1 through 3.  

Previously, contractors were able to self-certify cybersecurity compliance. When CMMC is implemented, third-party certification will be required. Currently, implementation is expected in November when the CMMC requirement is included in solicitations. A draft DFARS rule establishing the CMMC requirements is in progress and is also expected later this year. 

What does this change mean for contractors? For one, certification will be required to be eligible for award. This may affect a contractor’s costs, and it could affect a contractor’s proposal and teaming strategy. Likewise, a lack of certification may provide the basis for a post-award protest. The implementation of CMMC also creates an additional compliance concern for contractors. The Government could use a contractor’s failure to maintain its certification as a basis for termination. Additionally, a contractor that misrepresents its certification may be subject to liability under the False Claims Act or be sued by a teaming partner for breach of contract.    

Cybersecurity is not only a concern for DoD contractors. There are cybersecurity requirements that apply to non-DoD contractors. Specifically, FAR 52.204-21 imposes 15 relatively basic cybersecurity requirements on all contractors that process, transmit, or store contract information. For example, FAR 52.204-21 requires contractors to authenticate the identities of users, processes, or devices before allowing access to organizational information systems. Given the importance of cybersecurity, a new FAR rule is expected that would include requirements similar to the DoD’s CMMC. 

 Cybersecurity has become a key operating principle for the Government and contractors. With CMMC, the Government is increasing the importance of the issue and adding third party verification. Contractors should stay attuned to the evolving requirements and contact Executive Law Partners for assistance in understanding how these changes could affect their business.  

Share:

Recent Posts

  • XLP Chronicles, Edition 11- November
  • XLP Chronicles, Edition 10- October
  • XLP Chronicles, Edition 9- September
  • Business Basics for Veterans
  • XLP Chronicles, Edition 7- July

Archives

  • November 2022
  • October 2022
  • September 2022
  • August 2022
  • July 2022
  • June 2022
  • May 2022
  • April 2022
  • March 2022
  • February 2022
  • September 2021
  • July 2021
  • June 2021
  • February 2021
  • December 2020
  • September 2020
  • June 2020

Categories

  • Business Law
  • Criminal Law
  • Family Law
  • Federal Contracting
  • Financial Law
  • Law service
  • XLP Chronicles
  • XLP News & Media

Search

Categories

  • Business Law (18)
  • Criminal Law (2)
  • Family Law (1)
  • Federal Contracting (13)
  • Financial Law (1)
  • Law service (13)
  • XLP Chronicles (10)
  • XLP News & Media (13)

Executive Law Partners, PLLC is a full-service firm, offering advisory, transactional and litigation services to emerging and mid-market businesses in the US and overseas. All of our attorneys have had careers in business and government, giving us a unique understanding of the business decisions faced by our clients.

X-twitter Facebook-f Linkedin Instagram

Office

  • 11130 Fairfax Blvd. Ste 303,
    Fairfax, VA
  • (571) 500-1010
  • [email protected]
  • Office Hours:
    By Appointment Only

Useful Links

  • About XLP
  • Contact
  • Privacy Policy
  • Capabilities Brief
  • About XLP
  • Contact
  • Privacy Policy
  • Capabilities Brief

Practice Areas

  • Corporate Transactions & Counsel
  • International
  • Government Contracts
  • Litigation
  • Estate & Real Property Litigation
  • Appellate Practice
  • Servicios Legales
  • Corporate Transactions & Counsel
  • International
  • Government Contracts
  • Litigation
  • Estate & Real Property Litigation
  • Appellate Practice
  • Servicios Legales

Copyright © 2021-2026 Executive Law Partners, PLLC. All rights reserved.