1. Home
  2. |Insights
  3. |The FAR Regulators Enter the Cyber Fray

The FAR Regulators Enter the Cyber Fray

Client Alert | 1 min read | 08.28.12

On the heels of the latest demise of cyber legislation, the FAR Council has proposed new cybersecurity regulations for safeguarding government information ("other than public information") residing on or transiting through contractors' systems. While lacking some of the detail (such as certain NIST standards) contained in a predecessor proposal by DOD, the proposed FAR rule establishes broad requirements for basic cybersecurity safeguards for "all Federal contractors and appropriate subcontractors," including mandates for  (1) "the best level of security and privacy available, given facilities, conditions, and environment"; (2) "at least one physical and one electronic barrier" for such information; (3) "sanitization" prior to disposal of information and electronic media; and (4) "intrusion protection," such as "updated malware protection services."

Insights

Client Alert | 6 min read | 09.11.26

It’s LIVE: The Cyber Resilience Act Reporting Is Mandatory as of Today - 11 September 2026

The wait is over. As of today, manufacturers of connected products (both hardware and software) must comply with the Cyber Resilience Act’s (“CRA”) vulnerability and incident reporting obligations. The CRA’s Single Reporting Platform (“SRP”), operated by the European Union Agency for Cybersecurity (“ENISA”), is now the EU-wide gateway through which those notifications must flow....