Insights

Professional
Practice
Industry
Region
Trending Topics
Location
Type

Sort by:

Firm News 4 results

Firm News | 9 min read | 01.02.25

Crowell & Moring Elects 12 New Partners, Promotes Four to Senior Counsel and 25 to Counsel

Crowell & Moring elected 12 new partners effective January 1, 2025. The firm also promoted four lawyers to the senior counsel and 25 associates to counsel.

Firm News | 9 min read | 01.09.23

Crowell & Moring Elects 16 New Partners, Promotes Five to Senior Counsel, and 25 to Counsel

Crowell & Moring elected 16 lawyers to the firm’s partnership, effective January 1, 2023. The firm also promoted five lawyers to the position of senior counsel and 25 associates to the position of counsel.

Client Alerts 89 results

Client Alert | 4 min read | 06.10.25

Trump Administration Cyber Executive Order Revises Prior Administrations’ Requirements

On June 6, 2025 President Trump signed an Executive Order, Sustaining Select Efforts to Strengthen the Nation’s Cybersecurity and Amending Executive Order 13694 and Executive Order 14144 (the “Trump Cyber EO”). The Trump Cyber EO rescinds and modifies select Biden administration guidance from EO 14144 covering several cybersecurity regimes, including digital identity verification, artificial intelligence, and secure software development practices, and it amends Obama administration guidance from EO 13694 authorizing sanctions on persons involved in malicious cyber activities. We have provided a summary of significant changes made by the Trump Cyber EO below.
...

Client Alert | 2 min read | 05.15.25

DoD Specifies Implementation Requirements for NIST 800-171 Cyber Standard

The Department of Defense (DoD) has released a memorandum establishing the DoD Organization-Defined Parameters (ODPs) for use in National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171 Revision (Rev) 3. Currently, DoD’s cybersecurity regimes require government contractors to comply with NIST SP 800-171 Rev. 2. However, the release of this memorandum may indicate DoD’s intention to soon incorporate Rev. 3 into DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting (DFARS 7012) as well as the forthcoming Cybersecurity Maturity Model Certification (CMMC).
...

Client Alert | 2 min read | 03.31.25

Canadian CMMC? Canada Proposes Cyber Compliance Regime for Canadian Defense Suppliers

On March 12, 2025, the Government of Canada announced plans to launch the Canadian Program for Cyber Security Certification (CPCSC). CPCSC is a cybersecurity compliance verification program that aims to protect sensitive unclassified government information handled by Canadian government contractors and subcontractors within Canada’s defense sector. Canada will roll out CPCSC to contractors in four phases, with the first phase launching this month.
...

Press Coverage 14 results

Press Coverage | 01.02.25

Legal Tech's Predictions For Cybersecurity In 2025

Legaltech News

Press Coverage | 11.08.24

Cybersecurity & CMMC

Federal News Network

Publications 17 results

Publication | 01.28.25

Changes to Critical Infrastructure Requirements

In 2025, owners and operators of critical infrastructure will have new security and information sharing obligations to consider under the National Security Memorandum 22 (“NSM-22” or the “Memorandum”). NSM- 22 replaces the Obama-era Presidential Policy Directive 21: Critical Infrastructure Security and Resilience (PPD-21).
...

Publication | 01.28.25

Preparing for CMMC in 2025

After years of anticipation and a series of delays, implementation of the U.S. Department of Defense’s Cyber Maturity Model Certification Program (CMMC) is rapidly approaching. Though CMMC is not expected to enter into effect until early-to- mid 2025, DOD contactors can start taking steps now to ensure a smooth transition into this new regulatory era.
...

Publication | 01.28.25

Will Higher Education Institutions Face Enhanced Cybersecurity Requirements?

U.S. colleges and universities watched closely this summer when the DOJ, in a novel move, scrutinized the cybersecurity compliance of a research lab at an academic institution.
...

Events 12 results

Event | 04.10.25, 8:00 AM EDT - 1:00 PM EDT

Crowell's CMMC Day

You are invited to attend Crowell's CMMC Day, an in-person event dedicated to exploring the complexities of CMMC implementation and associated legal risks. This event will feature a series of insightful conversations with industry experts on topics such as prepping for assessments, risk management, and the government and private sector’s perspectives on CMMC. 

Event | 11.19.24, 8:00 AM EST - 9:30 AM EST

CMMC Finalized: How to Prepare & Achieve Certification

Crowell is honored to host Ms. Stacy Bostjanick, the Defense Department’s CMMC Program Director, who will be joined live by Crowell attorneys Evan Wolff and Michael Gruden for an engaging fireside chat.

Event | 09.12.24, 8:00 AM EDT - 12:30 PM EDT

Cybersecurity Symposium: The Cyberside Chat

Crowell & Moring Counsel Michael Gruden, a member of the firm's Privacy & Cybersecurity Group, will be speaking at the Cybersecurity Symposium: The Cyberside Chat, taking place on Thursday, September 12 in Washington, D.C. His panel, "The Black, White, and Grey of Cybersecurity Compliance," will be taking place at 11:35 AM ET.

Webinars 18 results

Webinar | 05.20.25, 10:00 AM EDT - 12:00 PM EDT

SPX Technologies: AI in Legal and Cybersecurity for DoD Contractors

10:00 a.m. - 11:15 a.m. ET (1 hour 15 minutes)
...

Webinar | 01.27.25, 10:00 AM EST - 10:45 AM EST

Cyber For All: A FAR CUI Proposed Rule Webinar

The FAR Council recently released a proposed rule (the “FAR CUI Rule”) that would amend the FAR to implement federal government-wide Controlled Unclassified Information (CUI) cybersecurity, training, and incident reporting requirements for government contractors and subcontractors.  

Webinar | 05.15.24, 1:00 PM EDT - 2:00 PM EDT

NIST SP 800-171 Transitions to Revision 3: What to Know

As the National Institute for Standards and Technology (NIST) prepares to release its highly anticipated Revision 3 to the security standard required by CMMC and current DoD contracts alike, join Crowell attorneys Evan Wolff and Michael Gruden in a robust discussion with one of the key architects of Revision 3, NIST’s own Senior Computer Scientist, Victoria Pillitteri.

Blog Posts 14 results

Blog Post | 11.08.18

SEC Encourages Internal Accounting Controls to Guard Against Cyber Fraud

Crowell & Moring's Data Law Insights

Podcasts 7 results

Podcast | 10.25.24

Special Edition of the Fastest 5 Minutes: CMMC

This week’s special edition focuses on DOD’s final rule formalizing the requirements, assessment processes, and related governance for its Cyber Maturity Model Certification Program (CMMC), and is hosted by Peter Eyre, Yuan Zhou, and Michael Gruden. Crowell & Moring's "Fastest 5 Minutes" is a biweekly podcast that provides a brief summary of significant government contracts legal and regulatory developments that no government contracts lawyer or executive should be without.
...

Podcast | 01.04.24

Special Edition of the Fastest 5 Minutes: CMMC

This special edition covers DoD’s proposed rule for the Cybersecurity Maturity Model Certification Program, and is hosted by Peter Eyre, Michael Gruden, and Nkechi Kanu. Crowell & Moring's "Fastest 5 Minutes" is a biweekly podcast that provides a brief summary of significant government contracts legal and regulatory developments that no government contracts lawyer or executive should be without.
...

Podcast | 01.19.22

Byte-Sized Q&A: What is CISA and Why is it Important to Government Contractors?

Crowell & Moring’s “Byte-Sized Q&A” podcast takes the complex world of government contracts cybersecurity and breaks it down into byte-sized pieces. In this episode of Byte Sized Q&A, Evan Wolff and Michael Gruden discuss the Cybersecurity Infrastructure Security Agency (CISA) and why it is important for contractors to take note of CISA’s actions.
...