Beating Others to the Punch, DHS Proposes CUI Changes to Acquisition Regulations
Client Alert | 1 min read | 02.07.17
On the last full day of the Obama Administration, the Department of Homeland Security (DHS) published a proposed rule that would make several amendments to the Homeland Security Acquisition Regulation (HSAR) regarding Controlled Unclassified Information (CUI). Despite recent developments, the proposed rule is open for comment until March 20, 2017, and seeks to impose several obligations, including: (1) contractors handling CUI under a contract must be in compliance with a bevy of DHS policies and procedures at the time of contract award; (2) contractors operating federal information systems must meet numerous information security obligations prior to handling CUI on those systems; (3) contractors must report known or suspected incidents affecting CUI within one to eight hours, depending on the type of CUI at issue; and (4) contractors must adhere to specific breach notification and credit monitoring requirements in response to incidents affecting personally identifiable information (PII), a subset of CUI.
Contacts

Partner, Crowell Global Advisors Senior Director
- Washington, D.C.
- D | +1.202.624.2698
- Washington, D.C. (CGA)
- D | +1 202.624.2500
Insights
Client Alert | 4 min read | 01.14.26
PFAS Reporting Gets Real in 2026
State regulation of PFAS-containing products will ramp up significantly in 2026. Most notably, companies will have to comply with Minnesota’s sweeping new product-reporting requirements. As we explain below, Minnesota’s requirements cast a wide net, capturing companies that may not sell products directly into the state. This and other features of the state’s reporting program are likely to present significant compliance challenges for a wide range of businesses.
Client Alert | 3 min read | 01.13.26
Client Alert | 7 min read | 01.13.26
Client Alert | 4 min read | 01.13.26

