DoD Previews Final Cybersecurity Maturity Model Certification with Revision 0.7
Client Alert | 1 min read | 12.17.19
The Department of Defense (DoD) recently released another revision to its Cybersecurity Maturity Model Certification (CMMC) that, starting next year, independent auditors will use to certify contractor compliance with DoD cybersecurity requirements. Most notably, Revision 0.7 previews the requirements for cybersecurity maturity Levels 4 and 5. Moving beyond the cyber hygiene requirements of Levels 1 through 3, Levels 4 and 5 require even more robust cybersecurity programs capable of addressing the dynamic threats posed by advanced persistent threats (APTs). These two highest levels of certification also implement the enhanced security requirements documented in NIST SP 800-171B, which remains in draft form.
The DoD is expected to announce the final CMMC in January of next year and begin introducing “go/no-go” certification requirements in solicitations as early as June 2020.
Insights
Client Alert | 4 min read | 08.20.25
FAR Council Issues Rewrites to FAR Parts 8 and 12
On August 14, 2025, the Office of Federal Procurement Policy (OFPP) and the Federal Acquisition Regulatory Council (FAR Council) issued draft revisions to FAR Part 8 and FAR Part 12 (as well as to FAR Parts 4 and 40). These are the latest rewrites under the Revolutionary FAR Overhaul (RFO) initiative pursuant to Executive Order 14275, “Restoring Common Sense to Federal Procurement,” which we previously reported on here.
Client Alert | 15 min read | 08.20.25
Client Alert | 2 min read | 08.19.25
Client Alert | 4 min read | 08.19.25
Forged Faces, Real Liability: Deepfake Laws Take Effect in Washington State and Pennsylvania