Finally Heard – Cyber Help for Small Businesses is on Its Way
Client Alert | 1 min read | 08.22.18
New cybersecurity legislation was recently passed that aims to help smaller government contractors in their efforts to safeguard sensitive customer data. The NIST Small Business Cybersecurity Act requires the National Institute of Standards and Technology (NIST) to issue guidance and resources, within the next year, to help small- and medium-sized businesses identify, assess, and reduce cybersecurity risks. Partly in response to the rising number of cyberattacks targeting small businesses, the legislation is the latest in a series of efforts more broadly focused on supply chain security throughout the procurement process. Under the Act, NIST must also:
- Ensure future resources can vary with the nature and size of the small business, as well as the nature and sensitivity of the data handled.
- Encourage the use of technology neutral, commercial off-the-shelf (COTS) solutions.
- Promote awareness of basic controls, a workplace cybersecurity culture, and third-party stakeholder relationships.
Contacts
Partner, Crowell Global Advisors Senior Director
- Washington, D.C.
- D | +1.202.624.2698
- Washington, D.C. (CGA)
- D | +1 202.624.2500
Insights
Client Alert | 8 min read | 10.01.25
On September 29, 2025, the U.S. Department of Commerce Bureau of Industry and Security (BIS) announced a sweeping Interim Final Rule (IFR), (the “Affiliates Rule”) expanding which entities qualify as Entity List or Military End-User entities, thereby subjecting those entities to elevated export control restrictions under the Export Administration Regulations (EAR). U.S. export restrictions applicable to entities on the Entity List, Military End-User (MEU) List, and Specially Designated Nationals and Blocked Persons (SDN List) now apply to foreign affiliates that are, in the aggregate, owned 50% or more by one or more of the aforementioned entities. An entity that becomes subject to these restrictions because of its ownership structure will be subject to the most restrictive controls that attach to any of its parent entities, regardless of ownership stakes.
Client Alert | 2 min read | 10.01.25
CPSC Shutdown Plan: Continue Enforcement, Pause Public Engagement and Civil Penalties
Client Alert | 2 min read | 10.01.25
Client Alert | 2 min read | 09.30.25
CARB Issues Preliminary List of Entities Covered by California Climate Disclosure Laws