Insights

Professional
Practice
Industry
Region
Trending Topics
Location
Type

Sort by:

Client Alerts 58 results

Client Alert | 7 min read | 10.02.26

GSA Issues Final Rule on Large Language Model Procurements

On September 28, 2026, the General Services Administration (GSA) issued a new clause for incorporation into government contracts of artificial intelligence systems, 552.239-7001, Basic Safeguarding of Data within Large Language Model Artificial Intelligence Systems, as a GSA Regulation Deviation (the Final Clause). The Final Clause will become effective on October 19, 2026.
...

Client Alert | 4 min read | 09.21.26

In a First, District Court Dismisses FCA Cybersecurity Complaint for Lack of Materiality

In recent years, the U.S. federal government has taken significant interest in the cybersecurity compliance of its contractor base. In 2025 alone, the U.S. Department of Justice’s (DOJ) Civil Cyber-Fraud Initiative recovered more than $50 million across nine False Claims Act (FCA) cybersecurity fraud settlements, and it has secured almost 20 settlements since its launch in October 2021. Because most defendants facing FCA liability for alleged cybersecurity noncompliance enter into pre-litigation settlements, the last court decision in a cybersecurity FCA case was in 2022. However, earlier this month, on September 2, 2026, in  United States ex rel. Pannek v. Archer Daniels Midland Co., No. 23-cv-15145, 2026 WL 2593317 (N.D. Ill. Sept. 2, 2026), Judge Sunil R. Harjani of the U.S. District Court for the Northern District of Illinois granted a motion to dismiss on materiality grounds and offered additional guidance on what a plaintiff must allege to adequately state an FCA cybersecurity claim.
...

Client Alert | 2 min read | 09.11.26

New ISOO Guidance Directs Federal Agencies to Provide More CUI Guidance to Contractors

On September 2, 2026, the National Archives and Records Administration (NARA), through its Information Security Oversight Office (ISOO), released two new Notices on the topic of Controlled Unclassified Information (CUI): ISOO Notices 2026-07 and 2026-08. 
...

Press Coverage 3 results

Press Coverage | 01.02.26

Gov't Contracts Policies To Watch In 2026

Law360

Publications 7 results

Publication | 01.28.25

Preparing for CMMC in 2025

After years of anticipation and a series of delays, implementation of the U.S. Department of Defense’s Cyber Maturity Model Certification Program (CMMC) is rapidly approaching. Though CMMC is not expected to enter into effect until early-to- mid 2025, DOD contactors can start taking steps now to ensure a smooth transition into this new regulatory era.
...

Publication | 01.28.25

Will Higher Education Institutions Face Enhanced Cybersecurity Requirements?

U.S. colleges and universities watched closely this summer when the DOJ, in a novel move, scrutinized the cybersecurity compliance of a research lab at an academic institution.
...

Webinars 7 results

Webinar | 10.08.25, 12:00 PM EDT - 1:00 PM EDT

Key Takeaways from DOJ’s Civil Cyber-Fraud Initiative

Join Crowell & Moring for a webinar covering the latest developments stemming from the Department of Justice's  Civil Cyber-Fraud Initiative.

Webinar | 09.15.25, 12:00 PM EDT - 1:00 PM EDT

CMMC Clause Rule: What to Know

The Department of Defense (DoD) has released the highly anticipated second final rule for the Cybersecurity Maturity Model Certification Program (CMMC), ushering in its mandatory implementation that begins on November 10. CMMC is a unified assessment model released by the DoD in response to the growing threat of cyberattacks on and data theft from the Defense Industrial Base.  This program requires every DoD contractor that handles sensitive government data to certify compliance with certain cybersecurity controls.  CMMC brings greater scrutiny to contractors’ cybersecurity compliance and greater risks associated with compliance failures. To achieve certification, contractors must prove that their organizations can meet a myriad of security control obligations, a process that can be daunting without familiarity with the policies, procedures, and practices that will be required when the program is finalized.
...

Webinar | 02.20.25, 3:00 PM EST - 4:00 PM EST

Privacy and Cybersecurity Outlook: The 2025 Landscape

Crowell & Moring’s recent publication, The Privacy and Cybersecurity Outlook: The 2025 Landscape, offers clients forward-looking insights on the most significant trends impacting organizations worldwide.

Blog Posts 12 results

Blog Post | 07.22.26

Department of War Immediately Suspends CMMC Phase II Requirements, Launches 60-Day Reform Review

Crowell & Moring's Government Contracts Legal Forum

Blog Post | 07.13.26

Time for a Change: FedRAMP Fundamentally Revamps Program With Consolidated Rules for 2026

Crowell & Moring's Government Contracts Legal Forum