DCMA Revises Cyber Supply Chain Review: Updated Guidebook Modifies Audit Standards
Client Alert | 1 min read | 07.16.19
As anticipated, the Defense Contract Management Agency (DCMA) revised its Contractor Purchasing System Review (CPSR) Guidebook as of June 14, 2019, with the most significant updates to Appendix 24, Supply Chain Management Process, to further address supply chain compliance with DFARS 252.204-7012. As we previously noted, the CPSR Guidebook was revised earlier this year to address DoD guidance related to management and oversight of the supply chain in connection with DFARS 252.204-7012.
While much of the CPSR review criteria remain the same, noteworthy revisions include:
- Asking contractors to “show how they have determined” that their subcontractors have an adequate information system that can handle Covered Defense Information, versus the prior guidance to ask contractors to “validate” the adequacy of subcontractor systems.
- Broadening supply chain requirements by applying the Guidebook’s language to “subcontractors,” rather than just “first tier suppliers” as in the prior version.
- Clarifying that the CPSR review is focused only on the protection of “Covered Defense Information” and not “Controlled Unclassified Information” more broadly.
Insights
Client Alert | 3 min read | 04.30.24
The DOE in 2023 significantly increased its enforcement activity against manufactures and importers alleged to have violated EPCA’s energy and water conservation standards and related certification requirements, based on available public information. As we previously flagged, the substantial rise in enforcement activity comes as the Biden Administration increasingly focuses on EPCA as a means of achieving environmental policy objectives, including reducing carbon emissions. The Department has continued its enforcement efforts in 2024 and early data from this year sheds light on the Department’s enforcement priorities.
Client Alert | 1 min read | 04.30.24
Client Alert | 4 min read | 04.29.24
Red Alert on the Orange Book: The FTC Continues to Crack Down on Improperly Listed Drug Patents
Client Alert | 3 min read | 04.26.24
CFIUS Proposes Enhanced Enforcement and Mitigation Rules and Steeper Penalties for Non-Compliance