TEST Paragraph
Awards
Events/Products/Programs
Legislation
Politics and Policy
Regulations
Safety
State/Local News
Workforce Development
On Aug. 15, the U.S. Department of Defense issued a proposed rule, Assessing Contractor Implementation of Cybersecurity Requirements, which seeks to implement contractual requirements for DOD contracts related to the recently proposed Cybersecurity Maturity Model Certification 2.0 Program. Comments on the proposed rule are due Oct. 15.
Previously, on Dec. 26, 2023, the DOD released a proposed rule and guidance documents to establish CMMC 2.0. As proposed, CMMC 2.0 would require federal contractors and subcontractors competing for DOD contracts to demonstrate continued compliance with a range of cybersecurity measures to maintain eligibility for performing and winning new federal awards. ABC joined coalition comments on that rule submitted Feb. 26, 2024, calling for more clarity and urging a flexible implementation of CMMC requirements. This rule has yet to be finalized.
The Aug. 15 proposed rule largely defers to CMMC 2.0 as previously proposed, with a focus on providing guidance to contracting officers as well as standard contracting clauses and solicitation provisions to incorporate CMMC 2.0.
However, the proposed rule includes new provisions of note, including:
For more information on the proposed rule and cybersecurity requirements impacting federal contractors, see Wiley Rein’s legal analysis of the proposal and ABC’s Cybersecurity Resource Guide.