Insights

Professional
Practice
Industry
Region
Trending Topics
Location
Type

Sort by:

Client Alerts 6 results

Client Alert | 4 min read | 09.21.26

In a First, District Court Dismisses FCA Cybersecurity Complaint for Lack of Materiality

In recent years, the U.S. federal government has taken significant interest in the cybersecurity compliance of its contractor base. In 2025 alone, the U.S. Department of Justice’s (DOJ) Civil Cyber-Fraud Initiative recovered more than $50 million across nine False Claims Act (FCA) cybersecurity fraud settlements, and it has secured almost 20 settlements since its launch in October 2021. Because most defendants facing FCA liability for alleged cybersecurity noncompliance enter into pre-litigation settlements, the last court decision in a cybersecurity FCA case was in 2022. However, earlier this month, on September 2, 2026, in  United States ex rel. Pannek v. Archer Daniels Midland Co., No. 23-cv-15145, 2026 WL 2593317 (N.D. Ill. Sept. 2, 2026), Judge Sunil R. Harjani of the U.S. District Court for the Northern District of Illinois granted a motion to dismiss on materiality grounds and offered additional guidance on what a plaintiff must allege to adequately state an FCA cybersecurity claim.
...

Client Alert | 2 min read | 07.13.26

Department of War Immediately Suspends CMMC Phase II Requirements, Launches 60-Day Reform Review

The Department of War (DoW) is immediately suspending Cybersecurity Maturity Model Certification (CMMC) Phase II requirements, which had been scheduled to take effect on November 10, 2026.
...

Client Alert | 2 min read | 07.07.26

Time for a Change: FedRAMP Fundamentally Revamps Program With Consolidated Rules for 2026

On June 25, 2026, the Federal Risk & Authorization Management Program (FedRAMP) launched its Consolidated Rules for 2026, marking a significant turning point in how the U.S. government administers security authorizations of private sector cloud offerings. The Consolidated Rules apply to all variants of the FedRAMP ecosystem, including legacy "Rev5" authorization holders, as well as future certifications under the new 20x program. Importantly, the Rules are intended in part to transition Rev5 authorizations over to 20x, with the Rev5 authorization status expected to terminate by the end of 2028. 
...

Blog Posts 6 results

Blog Post | 07.22.26

Department of War Immediately Suspends CMMC Phase II Requirements, Launches 60-Day Reform Review

Crowell & Moring's Government Contracts Legal Forum

Blog Post | 07.13.26

Time for a Change: FedRAMP Fundamentally Revamps Program With Consolidated Rules for 2026

Crowell & Moring's Government Contracts Legal Forum

Blog Post | 04.22.26

FedRAMP Solicits Public Comment on Overhaul to Incident Communications Procedures

Crowell & Moring’s Government Contracts Legal Forum