1. Home
  2. |Insights
  3. |DoD Previews New Third-Party Cyber Certification Requirements

DoD Previews New Third-Party Cyber Certification Requirements

Client Alert | 1 min read | 06.17.19

The Department of Defense is moving closer to a third-party certification to ensure compliance with its standard cybersecurity requirements – what is being called the “Cybersecurity Maturity Model Certification” (CMMC). While still in the early stages of development, the CMMC would likely require all contractors subject to DFARS 252.204-7012 to obtain a certification issued by an independent third party stating that the contractor has sufficiently implemented its required cybersecurity controls. Holding this certification would be a “go/no-go” condition to compete for relevant DoD work. Although NIST SP 800-171 is the default cybersecurity standard currently required under -7012, DoD is also exploring the creation of a new standard that would govern the certification. DoD is projecting that the CMMC will start appearing in solicitations as early as Fall 2020, but much work remains to be done – including potential revisions to -7012 – and will no doubt be informed by extensive industry engagement. 

Contacts

Insights

Client Alert | 7 min read | 08.19.26

CMS’s Final Rule Bans Federal Medicaid Funding for Youth Gender-Affirming Care

On August 13, 2026, the Centers for Medicare and Medicaid Services (CMS) published its final rule banning the use of federal funds — through Medicaid and the Children’s Health Insurance Program (CHIP) — to pay for gender-affirming care for children and youth. The final rule takes effect October 13, 2026 (“Prohibition on Federal Medicaid and Children's Health Insurance Program Funding for Sex-Rejecting Procedures Furnished to Children”). While CMS finalized several key elements of its late-2025 proposed rule (Client Alert December 24, 2025), the proposed Medicare hospital Condition of Participation rule remains in proposed form....