No Post-Thanksgiving Break for Cyber – DoD and NIST Publish New Guidance
Client Alert | 1 min read | 12.01.17
Both the Department of Defense and National Institute of Standards & Technology (NIST) have put pen to paper and provided new information for contractors looking to comply with DFARS 252.204-7012 and its accompanying cybersecurity requirements under NIST Special Publication (SP) 800-171. Earlier this week, the DoD posted guidance explaining that contractors can still use system security plans (SSPs) under the original version of NIST SP 800-171 to “document implementation” under the DFARS Clause, despite that version not including SSPs as a security control requirement. Separately, NIST published a draft of NIST SP 800-171A, Assessing Security Requirements for Controlled Unclassified Information, providing guidance to both contractors and their customers regarding how to conduct assessments under NIST SP 800-171. Importantly, the draft is open to comment through December 27, 2017, providing contractors with a unique opportunity to weigh in on how their customers may ultimately judge compliance with the DFARS Clause’s security requirements.
Contacts

Partner and Crowell Global Advisors Senior Director
- Washington, D.C.
- D | +1.202.624.2698
- Washington, D.C. (CGA)
- D | +1 202.624.2500
Insights
Client Alert | 4 min read | 06.17.26
From Checkout To Opt-Out: The EU Withdrawal Button Is Here – What E-Commerce Businesses Need To Know
From June 19, 2026, all online traders active within the EU are required to provide a “withdrawal button” on their websites and apps. The introduction of this withdrawal button represents a significant shift in the online consumer cancellation landscape. In this alert, we provide an overview of what this requirement means in practice and why compliance is so important.
Client Alert | 6 min read | 06.17.26
Client Alert | 6 min read | 06.16.26
What United States v. Bankman-Fried Means for Health Care Fraud Defense
Client Alert | 2 min read | 06.15.26
Kansas Federal Court Applies “Selective Enforcement” Theory to Reject DTSA Claim

