The U.S. Department of Defense’s Cybersecurity Maturity Model Certification (CMMC) Program will become operational at some point in fiscal year 2025. In October, the DOD issued a Final Rule to address evolving cybersecurity requirements and cyber threats while defining the security controls that DOD intends defense contractors and subcontractors to implement. The program will require
Alex Major
Mr. Major is a partner and co-leader of the firm’s Government Contracts & Export Controls Practice Group. Mr. Major focuses his practice on federal procurement, cybersecurity liability and risk management, and litigation. A prolific author and thought leader in the area of cybersecurity, his professional experience involves a wide variety of litigation and counseling matters dealing with procurement laws and federal regulations and standards . His diverse experience includes complex litigation in federal court under the qui tam provisions of the False Claims Act and bid protest actions. He counsels all sizes of companies on issues relating to compliance with government regulations including, among other things, cybersecurity (NIST, FIPS, FedRAMP, and DFARS) requirements, multiple award schedule compliance, Section 508 issues, country of origin requirements under the Buy American and Trade Agreements Acts, cost accounting, and small business requirements. He also regularly conducts internal investigations to assist companies ensure that they are in full compliance with the law.
Surviving And Thriving In The Small Business Administration’s 8(a) Program: Maximizing Opportunities For NHOs, ANCs, and Tribes
Alex Major, Franklin Turner, Philip Lee, and Marcos Gonzalez co-authored the article “Surviving And Thriving In The Small Business Administration’s 8(a) Program: Maximizing Opportunities For NHOs, ANCs, And Tribes” for Briefing Papers. The article provides an overview of the Small Business Administration’s 8(a) Business Development Program, which provides socially and economically disadvantaged small business owners…
OMB Issues Guidance to Agencies on Responsible Artificial Intelligence Acquisitions
Contractors interested in offering federal agencies artificial intelligence (AI) can now glean insight into how agencies are expected to conduct AI acquisitions. On September 24, 2024, the Office of Management and Budget (OMB) issued Memorandum M-24-18, Advancing the Responsible Acquisition of Artificial Intelligence in Government (the Memorandum), providing guidance and directing agencies “to improve their capacity for the responsible acquisition of AI” systems or services, including subcomponents. The Memorandum builds on the White House’s Executive Order 14110, Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence, and OMB Memorandum M-24-10, Advancing Governance, Innovation, and Risk Management for Agency Use of Artificial Intelligence. Taking effect on March 23, 2025, M-24-18 will apply to all solicitations and contract option exercises for AI systems covered under the Memorandum.Continue Reading OMB Issues Guidance to Agencies on Responsible Artificial Intelligence Acquisitions
A Standard on Many Levels: A Look at CMMC 2.0 in Final
Over the course of the past few years, gallons of ink have been spilled addressing the seemingly ever-pending US Department of Defense’s (DoD) Cybersecurity Maturity Model Certification (CMMC) Program. After keeping us waiting for years, it finally arrived when, on October 15, 2024, DoD published its Final Rule to establish the CMMC Program. See 89 Fed. Reg. 83092 (Oct. 15, 2024). Effective December 16, 2024, the Rule will require certain defense contractors to have implemented security measures to achieve a particular CMMC level necessary to safeguard Federal Contract Information (FCI) or Controlled Unclassified Information (CUI) as a condition of contract award. Codified at 34 C.F.R. Part 170, the CMMC Program will be augmented by a separate proposed acquisition rule to add a new 48 C.F.R. Part 204, amending the Defense Federal Acquisition Regulation Supplement (DFARS) to address procurement considerations related to the CMMC Program, including allowing DoD to require a specific CMMC level in a solicitation or contract. See 89 Fed. Reg. 66327 (Aug. 15, 2024) or our analyses here and here. The date when that DFARS clause will become final is still unclear, but most suspect it will be soon.Continue Reading A Standard on Many Levels: A Look at CMMC 2.0 in Final
Feature Comment: The New Madness? CMMC-Mania — It’s Arrived!
The arrival of the Cybersecurity Maturity Model Certification (CMMC) program will bring redefining changes to all companies selling to the DoD, suggest Alex Major and Cara Wulf in this Feature Comment for The Government Contractor.
DOJ Went Down to Georgia: Lessons Learned from Recent Cybersecurity Enforcement Actions
Johnny, rosin up your bow and play your fiddle hard
’Cause Hell’s broke loose in Georgia and the Devil deals the cards
And if you win, you get this shiny fiddle made of gold
But if you lose the Devil gets your soul
~ The Charlie Daniels Band
Some might say there’s little difference between dealing with the devil and being a federal contractor. And for the unwary or unprepared, that may not be far off. Federal contracting comes with a litany of “fine print” that would make “Old Scratch” proud. However, as most savvy contractors recognize, it’s all hiding in plain sight, with the devil in the details. Take, for example, the cybersecurity requirements found in the Federal Acquisition Regulations (FAR) at 52.204-21 and the Department of Defense (DoD) FAR Supplement (DFARS) at 252.204-7012, -7019, and -7020. These requirements have been the topic of countless articles, trainings, webinars, whole conferences, etc., so it is surprising while simultaneously not surprising that they form the basis of a federal False Claims Act (FCA) claim the Department of Justice (DOJ) recently filed in its complaint in intervention.Continue Reading DOJ Went Down to Georgia: Lessons Learned from Recent Cybersecurity Enforcement Actions
A New Frontier in Corporate Accountability: The DOJ’s Corporate Whistleblower Awards Pilot Program
On August 1, 2024, the US Department of Justice (DOJ) Criminal Division introduced its Corporate Whistleblower Awards Pilot Program (Program), which, like a modern-day Western posse, aims to bring justice to the wild frontier of corporate America. The DOJ is enticing anyone willing to saddle up and provide information on corporate outlaws—i.e., those involved in corruption, financial crimes, foreign corruption, bribery, and/or healthcare fraud. In sum, the Program closes the gaps left by existing whistleblower programs and bolsters the DOJ’s efforts to combat corporate crime. For those who decide to ride with it, the DOJ is promising substantial financial rewards—up to 30 percent of the loot recovered from those outlaws—to insiders, whistleblowers, and relators who come forward with information leading to significant criminal or civil forfeiture actions. As the Program unfolds over its three-year pilot period, it will—or should—be closely watched by False Claims Act defense counsel, plaintiff’s counsel, corporate leaders, and potential whistleblowers alike. If successful, it could permanently expand whistleblower incentives and further embolden an already aggressive DOJ (as if more encouragement were needed), signaling a new frontier in corporate governance and accountability in the United States.Continue Reading A New Frontier in Corporate Accountability: The DOJ’s Corporate Whistleblower Awards Pilot Program
Feature Comment: A Rule of Three: NIST Special Publication 800-171 Rev. 3—Finale or Punchline?
The third revision of NIST Special Publication 800-171 brings substantial changes across several key areas: the structure of control families has been expanded to better address new threats, individual security controls have been updated to enhance overall system security, and the criteria for tailoring these controls to specific organizational needs have been clarified, all in…
Big Bang?: The Federal Circuit, Percipient.ai, and Expanding Jurisdiction
In Percipient.ai v. United States, the US Court of Appeals for the Federal Circuit may have triggered a legal “Big Bang” moment in government procurement law. The case centered on whether the Federal Acquisition Streamlining Act’s (FASA) “task order bar” could suppress claims alleging violations of 10 U.S.C. § 3453, which mandates a preference for commercial products. The Panel’s interpretation of the Tucker Act’s definition of “interested party” expanded the universe of standing, allowing prospective subcontractors to exert gravitational influence in legal challenges regardless of their role as indirect offerors. At the risk of offending real physicists, from a legal perspective, the Percipient.ai v. United States decision looks to expand a universe of legal scrutiny. Like the cosmic forces that shape galaxies, the Percipient.ai decision may shape the parameters of government contracting jurisdiction and procedural fairness in the procurement process.Continue Reading Big Bang?: The Federal Circuit, Percipient.ai, and Expanding Jurisdiction
Chambers Ranks McCarter Government Contracts Practice Band 1 Nationwide
McCarter’s Government Contracts team is grateful to its clients for once again honoring it with a Band 1 Nationwide ranking by Chambers USA: America’s Leading Lawyers for Business. It appreciates the recognition that “McCarter & English, LLP is lauded for its ability to provide guidance on a broad array of issues including transactions, regulatory …