1. Home
  2. |Insights
  3. |DoD and GSA Take Aim at Supply Chain Risks

DoD and GSA Take Aim at Supply Chain Risks

Client Alert | 1 min read | 01.15.21

The Department of Defense (DoD) recently implemented additional procedures for the mitigation of cybersecurity risks in its supply chain. Designed to identify and mitigate cybersecurity and related supply chain risks throughout a program’s lifecycle, DoD Instruction 5000.90, Cybersecurity Acquisition Decision Authorities and Program Managers, requires program managers to:

  • Assess contractors’ cybersecurity posture, including, where applicable, verifying compliance with the DoD’s newly introduced Cybersecurity Maturity Model Certification (CMMC);
  • Consider the extent to which contractors have experienced “significant” incidents resulting in network breaches or data loss;
  • Avoid program requirements that may necessitate the use of contractors or suppliers that are owned or controlled by a foreign adversary government or are subject to the jurisdiction of a foreign adversary government;
  • Manage any supply chain risks associated with foreign ownership, control, or influence (FOCI); and
  • Mitigate supply chain risks using a framework that prescribes escalating risk management actions across four risk tolerance levels.

Alongside the DoD, the General Services Administration (GSA) recently introduced, as part of a draft solicitation for the Polaris small business government-wide IT contract, its own Vendor Risk Assessment Program (VRAP). According to the draft solicitation, the VRAP is designed to identify, assess, and monitor supply chain risks associated with FOCI, cybersecurity, and other factors, such as financial performance. 

Contacts

Insights

Client Alert | 4 min read | 02.27.26

New Jersey Expands FLA Protections Effective July 2026: What Employers Need to Know

The New Jersey Family Leave Act (NJFLA) entitles eligible employees to up to 12 weeks of unpaid, job-protected leave per 24-month period for bonding with a new child, caring for a seriously ill family member, or responding to certain public health emergencies. The law covers employers with 30 or more employees worldwide, and employees must have at least one year on the job and 1,000 hours worked in the preceding 12 months to qualify. Unlike the federal Family and Medical Leave Act (FMLA), the NJFLA does not cover an employee’s own serious health condition, but instead pairs with New Jersey’s Temporary Disability Insurance (TDI) and Family Leave Insurance (FLI) programs, which provide partial wage replacement — funded through employee payroll contributions — when employees are out on qualifying leave. ...