Biden Administration Orders Sweeping Directives to Federal Agencies and Contractors to Improve U.S. Cybersecurity
Client Alert | 1 min read | 05.13.21
The Biden Administration issued a detailed Executive Order (EO) on Improving the Nation’s Cybersecurity yesterday aimed at strengthening the Federal Government’s cybersecurity defense posture. The EO calls for the creation of new cybersecurity standards, as well as updates to FAR- and DFARS-based contract requirements, affecting both information and operational technology. Much of the EO addresses implementation throughout the Federal Civilian Executive Branch (FCEB) Agencies and the Department of Defense (DoD). The EO encompasses a broad array of cybersecurity initiatives for fast track implementation in partnership with the private sector, notably including:
- Requiring mandatory breach reporting to the Federal Government, applicable to both contractors and cloud service providers (CSPs) accessing Federal information systems;
- Implementing mandatory multifactor authentication, encryption and logging requirements for Federal information systems, applicable to contractors operating networks on behalf of the Federal Government;
- Creating a software supply chain security standard, including a consumer software labeling program, focused on secure software development practices that will impact Federal software acquisitions;
- Modernizing security practices including Zero Trust Architecture and accelerated movement to secure cloud services through FedRAMP;
- Establishing a Cyber Safety Review Board, modeled after the National Transportation Safety Board (NTSB), which will provide the Federal Government greater authorities to investigate significant cyber incidents occurring on contractor and CSP networks; and
- Standardizing a Federal Government Playbook for incident response activities, which will create a new standard of care for private industry and government contractors.
The EO directs the Federal Government to prioritize these initiatives over the next year, with some actions to be implemented as soon as within the next 30 days. Contractors should anticipate a myriad of proposed regulatory changes over the next 60 – 90 days as agencies begin implementing these wide-ranging cyber initiatives.
Contacts

Partner, Crowell Global Advisors Senior Director
- Washington, D.C.
- D | +1.202.624.2698
- Washington, D.C. (CGA)
- D | +1 202.624.2500
Insights
Client Alert | 4 min read | 12.04.25
District Court Grants Preliminary Injunction Against Seller of Gray Market Snack Food Products
On November 12, 2025, Judge King in the U.S. District Court for the Western District of Washington granted in part Haldiram India Ltd.’s (“Plaintiff” or “Haldiram”) motion for a preliminary injunction against Punjab Trading, Inc. (“Defendant” or “Punjab Trading”), a seller alleged to be importing and distributing gray market snack food products not authorized for sale in the United States. The court found that Haldiram was likely to succeed on the merits of its trademark infringement claim because the products at issue, which were intended for sale in India, were materially different from the versions intended for sale in the U.S., and for this reason were not genuine products when sold in the U.S. Although the court narrowed certain overbroad provisions in the requested order, it ultimately enjoined Punjab Trading from importing, selling, or assisting others in selling the non-genuine Haldiram products in the U.S. market.
Client Alert | 21 min read | 12.04.25
Highlights: CMS’s Proposed Rule for Medicare Part C & D (CY 2027 NPRM)
Client Alert | 11 min read | 12.01.25

