DoD's New Year's Gift: More Time to Meet Cyber Safeguarding Requirements
Client Alert | less than 1 min read | 12.30.15
On December 30, DoD issued an interim rule amending the DFARS Safeguarding Rule in several respects, including to provide contractors up to December 31, 2017, to comply with the security control requirements identified in DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting, and detailed in NIST Special Publication 800-171, Protecting Controlled Unclassified Information in Nonfederal Information Systems and Organizations. Despite the additional time to comply, within 30 days of contract award, contractors must still notify the DoD Chief Information Officer of any NIST SP 800-171 security requirements not yet implemented.
Contacts

Partner and Crowell Global Advisors Senior Director
- Washington, D.C.
- D | +1.202.624.2698
- Washington, D.C. (CGA)
- D | +1 202.624.2500
Insights
Client Alert | 7 min read | 08.19.26
CMS’s Final Rule Bans Federal Medicaid Funding for Youth Gender-Affirming Care
On August 13, 2026, the Centers for Medicare and Medicaid Services (CMS) published its final rule banning the use of federal funds — through Medicaid and the Children’s Health Insurance Program (CHIP) — to pay for gender-affirming care for children and youth. The final rule takes effect October 13, 2026 (“Prohibition on Federal Medicaid and Children's Health Insurance Program Funding for Sex-Rejecting Procedures Furnished to Children”). While CMS finalized several key elements of its late-2025 proposed rule (Client Alert December 24, 2025), the proposed Medicare hospital Condition of Participation rule remains in proposed form.
Client Alert | 2 min read | 08.19.26
Client Alert | 7 min read | 08.17.26
Delayed Notification of Cyberattacks May Trigger HIPAA Breach Notification Rule
Client Alert | 4 min read | 08.14.26
License to Hack? The White House Greenlights Private-Sector Offensive Cyber Operations
