DOD Proposed New Cybersecurity Rules
Client Alert | 1 min read | 03.08.10
On March 3, DoD issued a notice of, and requested comments on, proposed rules levying information security requirements for safeguarding unclassified "DoD information" and reporting security breaches when contractors and subcontractors may have such information "resident on or transiting" their information systems. The proposed rule not only mandates that contractors "shall provide adequate security to safeguard DoD information," but also (1) requires flowdown to subcontractors; (2) establishes extreme standards in some areas (e.g., "best level of security and privacy available"); (3) incorporates National Institute of Standards and Technology (NIST) standards in some areas, but not others; and (4) acknowledges that the contractor will still need to comply with all other applicable security standards, such as "CPI, PII, For Official Use Only, Privacy Act, ITAR, EAR, and HIPAA."
Contacts
Insights
Client Alert | 4 min read | 01.14.26
PFAS Reporting Gets Real in 2026
State regulation of PFAS-containing products will ramp up significantly in 2026. Most notably, companies will have to comply with Minnesota’s sweeping new product-reporting requirements. As we explain below, Minnesota’s requirements cast a wide net, capturing companies that may not sell products directly into the state. This and other features of the state’s reporting program are likely to present significant compliance challenges for a wide range of businesses.
Client Alert | 3 min read | 01.13.26
Client Alert | 7 min read | 01.13.26
Client Alert | 4 min read | 01.13.26

