Forget The Showers. April Brings Flurry of New Cyber Guidance.
Client Alert | 1 min read | 05.01.18
April has marked a busy month for those following the DoD’s approach to contractor cybersecurity. Earlier in the month, the DoD published a much-anticipated revision to their Frequently Asked Questions regarding DFARS 252.204-7012 and other cybersecurity requirements, reflecting feedback on various questions posed by industry over the past year and including new information regarding:
- COTS and commercial items
- Scope of covered defense information
- Conflicts with foreign laws
- Subcontractor flowdowns
- System security plans (SSPs) and plans of action & milestones (POAMs)
- Requirements for FIPS-validation, multifactor authentication, and marking
- Cybersecurity requirements beyond NIST SP 800-171
- Cloud service providers
- Examples of cyber incidents
- Guidance for small businesses
- DCMA oversight
Then just weeks later, the DoD issued proposed guidance for evaluating contractor cybersecurity, including implementation of NIST SP 800-171. Importantly, contractors may comment on the draft guidance through May 31 – and would be well-served to familiarize themselves with the new FAQs before doing so.
Contacts

Partner, Crowell Global Advisors Senior Director
- Washington, D.C.
- D | +1.202.624.2698
- Washington, D.C. (CGA)
- D | +1 202.624.2500
Insights
Client Alert | 4 min read | 03.05.26
The U.S. Department of Labor (DOL) has proposed another revision to independent contractor regulations, one that would provide for more leeway in classifying workers as contractors. DOL’s proposed rule, published on February 26, 2026, would rescind the Biden DOL’s March 2024 independent contractor regulation and reinstate a framework substantially tracking the prior Trump rule of January 2021. The proposed rule would also apply the narrower analysis to worker classifications under the Family and Medical Leave Act (FMLA) and the Migrant and Seasonal Agricultural Worker Protection Act (MSPA). The comment period closes in late April 2026; until then, the 2024 rule remains in effect for purposes of private litigation.
Client Alert | 8 min read | 03.05.26
Client Alert | 4 min read | 03.04.26
Sixth Circuit Finds EFAA Arbitration Bar to Entire Case — Not Just Sexual Harassment Claims
Client Alert | 3 min read | 03.02.26

