Beating Others to the Punch, DHS Proposes CUI Changes to Acquisition Regulations
Client Alert | 1 min read | 02.07.17
On the last full day of the Obama Administration, the Department of Homeland Security (DHS) published a proposed rule that would make several amendments to the Homeland Security Acquisition Regulation (HSAR) regarding Controlled Unclassified Information (CUI). Despite recent developments, the proposed rule is open for comment until March 20, 2017, and seeks to impose several obligations, including: (1) contractors handling CUI under a contract must be in compliance with a bevy of DHS policies and procedures at the time of contract award; (2) contractors operating federal information systems must meet numerous information security obligations prior to handling CUI on those systems; (3) contractors must report known or suspected incidents affecting CUI within one to eight hours, depending on the type of CUI at issue; and (4) contractors must adhere to specific breach notification and credit monitoring requirements in response to incidents affecting personally identifiable information (PII), a subset of CUI.
Contacts

Partner and Crowell Global Advisors Senior Director
- Washington, D.C.
- D | +1.202.624.2698
- Washington, D.C. (CGA)
- D | +1 202.624.2500
Insights
Client Alert | 4 min read | 06.25.26
Twin Executive Orders Seek to Spur Quantum Leap in Technology and Cybersecurity
On June 22, 2026, President Trump signed two executive orders, “Securing the Nation Against Advanced Cryptographic Attacks” (Quantum Security EO) and “Ushering in the Next Frontier of Quantum Innovation” (Quantum Innovation EO), marking the most significant federal action on quantum technology since the Quantum Computing Cybersecurity Preparedness Act of 2022, which directed agencies to harden their information systems against quantum-enabled hacking. The orders seek to speed the development of quantum computers, which are advanced processors that can calculate multiple possibilities simultaneously and thus solve problems exponentially faster than traditional computers. At the same time, the orders look to protect against the danger that quantum technology can “break” traditional encryption by easily decoding it. Of particular note for government contractors, the Quantum Security EO directs agencies to update federal acquisition regulations to require contractors by 2031 to adopt information processing standards that resist quantum-enabled codebreaking.
Client Alert | 7 min read | 06.24.26
Client Alert | 3 min read | 06.24.26
Client Alert | 4 min read | 06.23.26
EPA Hands Over AI Data Center Regulation to States and Communities to Develop Best Practices

