The 60-day review is finished and recommendations are drafted, but the package now has to clear General Counsel, the small business office, OMB and the White House before anyone outside sees it. The estimate for a public release is the back half of October — at the earliest.
Read issueTwo of the DFARS cybersecurity clauses your contracts have cited for five years no longer exist under their old numbers. The self-assessment and SPRS duties they carried are still yours.
Read issueA new National Archives notice orders federal agencies to hand contractors specific, written CUI instructions on every CUI-related contract. Clarity is good news for the well-prepared. For everyone else, it removes the last excuse.
Read issueA class deviation issued September 3 tells contracting officers to strike third-party assessment requirements from CMMC clauses. It changes who checks your work. It does not change the work.
Read issueNo assessor was involved and no breach was alleged. A former employee’s suit reached back nearly three years — and liability attached to the one network where covered defense information actually lived.
Read issueA wave of new reporting says the industry has been diagnosing the wrong problem. The bigger obstacle to readiness has been sitting in the paperwork the whole time.
Read issueThe Pentagon just delayed the certification deadline everyone’s been racing toward. Your compliance obligations didn’t get the memo.
Read issue