The Contracting Education Academy

Contracting Academy Logo
  • Home
  • Training & Education
  • Services
  • Contact Us
You are here: Home / Archives for rulemaking

May 22, 2020 By cs

Coronavirus constraints pose CMMC rule change delays

Social distancing requirements are complicating the Defense Department’s implementation of its unified cybersecurity standard.

Katie Arrington, DoD’s chief information security officer for acquisition, said that while the coronavirus pandemic hasn’t affected training preparations, social distancing efforts have delayed the public hearing needed for the Defense Federal Acquisition Regulation Supplement (DFARS) rule change needed to enforce new cybersecurity standards for contractors.

“The premise of doing all of this is that we’re going through a DFARS rule change,” which requires a public hearing, Arrington said May 8 during a Billington Cybersecurity event on the Cybersecurity Maturity Model Certification (CMMC) program.

Keep reading this article at: https://defensesystems.com/articles/2020/05/13/cmmc-covid-dfar-rule-change-delay.aspx

Filed Under: Government Contracting News Tagged With: CMMC, CMMC AB, CMMC accreditation, CMMC Accreditation Body, coronavirus, COVID-19, cybersecurity, DFARS, DoD, pandemic, public hearing, rulemaking

May 21, 2020 By cs

SBA issues final rule implementing certification for women-owned small businesses

The U.S. Small Business Administration (SBA) on May 11, 2020, published its long-awaited Final Rule implementing important changes for Women-Owned Small Business Concerns (WOSBs) and Economically Disadvantaged Women-Owned Small Business Concerns (EDWOSBs) participating in the Procurement Program for Women-Owned Small Business Concerns (Program).

Among other things, the Final Rule requires a certification for businesses competing for set-aside or sole source contracts under the Program, and to those seeking to be awarded multiple award contracts for pools reserved for WOSBs and EDWOSBs. It also changes EDWOSB requirements to be consistent with the 8(a) Business Development (BD) Program.

The rule becomes effective on July 15, 2020; however, it’s important to note that many of the specific changes do not go into effect until Oct. 15, 2020.

Some of the important points are summarized here in more detail: https://www.mondaq.com/unitedstates/government-contracts-procurement-ppp/934468/sba-issues-final-rule-implementing-certification-for-women-owned-small-businesses

Filed Under: Government Contracting News Tagged With: 8(a), business development, certification, competition, economically disadvantaged, EDWOSB, rulemaking, SBA, self-certification, set-aside, WOSB

February 4, 2020 By cs

Pentagon announces final version of cyber standards for contractors

During an event where Defense Department officials looked to dispel myths about a plan to certify the cybersecurity of its contractors through third-party audits, the department’s head of acquisitions spoke to why the rollout of the program isn’t expected to be done till 2026. 

“We are doing this with what I would call irreversible momentum,” Undersecretary of Defense for Acquisition and Sustainment Ellen Lord said, answering questions from reporters.

Some stakeholders have said the plan to subject companies in the defense industrial base to reviews by independent auditors—instead of allowing them to self-attest to security practices—is moving at break-neck speed.  But Defense officials were pressed at the event to explain why it would take such a long time to fully implement the program.

“We’re being realistic in terms of making sure we have pathfinder projects and then we implement it and learn, get the feedback, and go on,” Lord said.

While the department plans to note CMMC requirements in requests for information starting late spring, specific security levels—ranging 1 through 5, described in a final version 1.0 of the model—won’t be included in requests for proposals till the fall, when it is expected the related rule will be finalized in Defense Federal Acquisition Regulations.

Spring is also when auditors will start attending classes and CMMC training will be available on the Defense Acquisition University website, officials said.

Keep reading this article at: https://www.nextgov.com/cybersecurity/2020/01/pentagon-announces-final-version-cyber-standards-contractors/162807/

Filed Under: Government Contracting News Tagged With: CMMC, cyber, cybersecurity, Cybersecurity Maturity Model Certification, cybersecurity standards, DAU, DFARS, DHS, DoD, Homeland Security, NIST, OMB, rulemaking, supply chain, supply chain security

January 30, 2020 By cs

Final DoD cybersecurity certification model due Friday

The Defense Department official leading the development of an ambitious plan to independently certify military contractors’ cybersecurity practices will review a final version of the plan Friday (Jan. 31, 2020) and shared key details for its implementation.

Stipulations of the Cybersecurity Maturity Model Certification (CMMC) will be written into the Defense Federal Acquisition Regulation Supplement (DFARS) as an update to rule 252.204.7012, which currently requires contractors handling information of certain sensitivity to implement security practices spelled out in National Institute of Standards and Technology (NIST) Special Publication 800-171 and to report cyber incidents within 72 hours.

The major change in the updated rule—which is expected to be open for comment in the spring—will be that contractors will no longer be permitted to self-attest their adherence to the NIST-described practices, as they are now.

The new program will also introduce five levels of tiered requirements for defense contractors. Contractors dealing with information that is not as sensitive would have to meet the “basic cyber hygiene” of level 1, versus the “good cyber hygiene” that implies compliance with the NIST 800-171 controls, or the “advanced” practices that would be required at level 5.

That risk-based approach has gotten the coming CMMC some praise, but the contracting community is on high alert with concerns ranging from the cost of certification to the details of how the audits will function through a nonprofit accreditation body.

Keep reading this article at: https://www.nextgov.com/cybersecurity/2020/01/final-dod-cybersecurity-certification-model-due-friday/162713/

Filed Under: Government Contracting News Tagged With: CMMC, cyber, cybersecurity, Cybersecurity Maturity Model Certification, cybersecurity standards, DFARS, DHS, DoD, Homeland Security, NIST, OMB, rulemaking, supply chain, supply chain security

January 29, 2020 By cs

DoD aims to issue proposed rule for certifying contractors’ cybersecurity in the fall

A sweeping plan to conduct independent third-party cybersecurity audits of prospective Defense Department contractors’ management of sensitive information will be subject to a formal rulemaking process, but the department and the nonprofit organization being established to train and approve certifiers are still moving at a quick clip. 

“Because we’re doing rulemaking, this isn’t going to roll out as hard and fast as we thought,” said a government official delivering a briefing on Defense’s Cybersecurity Maturity Model Certification (CMMC) program at a recent meeting of the Software Supply Chain Assurance forum.

Quarterly meetings of the forum — co-led by Defense, the General Services Administration, the National Institute of Standards and Technology, and Homeland Security Department—are attended by public and private sector representatives and conducted under the Chatham House Rule to encourage a free exchange of ideas.

The official said Defense expects the CMMC requirements to be issued as a proposed rule this fall, but regardless of the related public comment process, officials still plan to include the rules in requests for proposals starting in the third quarter.

“In June, we’re going to give you an [request for information] that says these procurements are targeted to have CMMC requirements,” the official also noted.

Keep reading this article at: https://www.nextgov.com/cybersecurity/2020/01/dod-aims-issue-proposed-rule-certifying-contractors-cybersecurity-fall/162463/

Filed Under: Government Contracting News Tagged With: CMMC, cyber, cybersecurity, Cybersecurity Maturity Model Certification, cybersecurity standards, DHS, DoD, GSA, Homeland Security, NIST, rulemaking, supply chain, supply chain security

  • 1
  • 2
  • 3
  • Next Page »

Popular Topics

abuse acquisition reform acquisition strategy acquisition training acquisition workforce Air Force Army AT&L bid protest budget budget cuts competition cybersecurity DAU DFARS DHS DoD DOJ FAR fraud GAO Georgia Tech GSA GSA Schedule GSA Schedules IG industrial base information technology innovation IT Justice Dept. Navy NDAA OFPP OMB OTA Pentagon procurement reform protest SBA sequestration small business spending technology VA
Contracting Academy Logo
75 Fifth Street, NW, Suite 300
Atlanta, GA 30308
info@ContractingAcademy.gatech.edu
Phone: 404-894-6109
Fax: 404-410-6885

RSS Twitter

Search this Website

Copyright © 2021 · Georgia Tech - Enterprise Innovation Institute