Cybersecurity Maturity Model Matures: DoD Adds New Requirements to Draft Cybersecurity Certification
Client Alert | 1 min read | 09.10.19
The Defense Department has released Revision 0.4 of its Cybersecurity Maturity Model Certification (CMMC) that, starting next year, independent auditors are to use to certify contractor compliance with DoD cybersecurity requirements. Revision 0.4 more than doubles the number of cybersecurity controls across the CMMC’s five maturity “Levels.” But the DoD emphasizes that it will further down-select these controls and that mature contractor processes may counteract gaps in the final controls’ implementation. In addition to NIST SP 800-171 (the default standard under DFARS 252.204-7012), Revision 0.4 now incorporates requirements from the NIST Cybersecurity Framework, ISO 27001, and CIS Critical Security Controls, as well as from “additional DIB inputs.” Notably missing is NIST SP 800-171B, which remains under review.
The DoD is requesting feedback on Revision 0.4 through September 25, 2019, and plans on releasing Revision 0.6 for comment in November 2019. The final CMMC is expected in January 2020.
Insights
Client Alert | 2 min read | 05.27.25
Federal Circuit Resolves Circuit Split on Scope of IPR Estoppel
As part of the 2012 America Invents Act, statutory estoppel was included to balance the interests of patent owners and patent challengers following an inter partes review (“IPR”). Estoppel prevents an IPR petitioner from later asserting in court that a claim “is invalid on any ground that the petitioner raised or reasonably could have raised” during the IPR. 35 U.S.C. § 315(e)(2). As applied, estoppel prevents petitioners from later relying in district court or in ITC proceedings on most patents or printed publications – the limited bases upon which petitioner can rely in an IPR. But a question remained, and contradictory district court decisions arose, as to whether petitioners would be estopped from relying on a prior art commercial product (known as “device art,” which could not itself have been raised in the IPR) even if a printed publication describing the product (i.e. a patent or technical manual) was available and presumably could have been raised.
Client Alert | 6 min read | 05.27.25
U.S. Departments of State and Treasury Issue Immediate Sanctions Relief for Syria
Client Alert | 3 min read | 05.23.25
Executive Order Seeks Most-Favored-Nation Drug Pricing and HHS Announces Price Targets
Client Alert | 4 min read | 05.22.25
Opportunities for Procurement on the Horizon as UK Concludes Free Trade Agreement With India