Insights

Professional
Practice
Industry
Region
Trending Topics
Location
Type

Sort by:

Client Alerts 45 results

Client Alert | 2 min read | 01.29.26

Software De-Simplified: Trump Administration Rescinds Standardized Secure Software Development Attestation Requirements

On January 23, 2026, Office of Management and Budget (OMB) Director Russell T. Vought issued OMB Memorandum M-26-05 (Memo). The Memo rescinds prior OMB memoranda (M-22-18 and M-23-16) that required federal agencies to collect the Secure Software Development Attestation Form from entities selling software or products containing software to the U.S. government. The Trump administration previously retracted a Biden administration directive that called for formalization of the Attestation Form collection process in the Federal Acquisition Regulation (FAR). Many in industry saw this as a sign that the Trump administration disfavored the Attestation Form. Now, the Memo has gone one step further to officially terminate agencies’ obligation to collect the Form from their software suppliers.
...

Client Alert | 3 min read | 01.21.26

FedRAMP Proposes Updates to Authorization Process—Six New RFCs Released for Public Comment

The Federal Risk and Authorization Management Program (FedRAMP) is a government-wide initiative established to standardize the security assessment, authorization, and continuous monitoring of cloud products and services used by federal agencies. FedRAMP’s primary objective is to ensure that cloud service providers (CSPs) implement robust security controls to protect federal information in cloud environments. By leveraging a consistent framework for security assessment and authorization, FedRAMP is intended to reduce duplication of effort, cost, and time for both agencies and vendors.
...

Client Alert | 3 min read | 01.07.26

CMMC for AI? Defense Policy Law Imposes AI Security Framework and Requirements on Contractors

In an important first, the yearly defense policy law, the National Defense Authorization Act (NDAA) for Fiscal Year 2026, directs the Department of Defense (DoD)  to develop and implement a framework addressing the cybersecurity and physical security of artificial intelligence and machine learning technologies (AI/ML) acquired by the Pentagon.
...

Press Coverage 3 results

Press Coverage | 01.02.26

Gov't Contracts Policies To Watch In 2026

Law360

Publications 7 results

Publication | 01.28.25

Preparing for CMMC in 2025

After years of anticipation and a series of delays, implementation of the U.S. Department of Defense’s Cyber Maturity Model Certification Program (CMMC) is rapidly approaching. Though CMMC is not expected to enter into effect until early-to- mid 2025, DOD contactors can start taking steps now to ensure a smooth transition into this new regulatory era.
...

Publication | 01.28.25

Will Higher Education Institutions Face Enhanced Cybersecurity Requirements?

U.S. colleges and universities watched closely this summer when the DOJ, in a novel move, scrutinized the cybersecurity compliance of a research lab at an academic institution.
...

Webinars 7 results

Webinar | 10.08.25, 12:00 PM EDT - 1:00 PM EDT

Key Takeaways from DOJ’s Civil Cyber-Fraud Initiative

Join Crowell & Moring for a webinar covering the latest developments stemming from the Department of Justice's  Civil Cyber-Fraud Initiative.

Webinar | 09.15.25, 12:00 PM EDT - 1:00 PM EDT

CMMC Clause Rule: What to Know

The Department of Defense (DoD) has released the highly anticipated second final rule for the Cybersecurity Maturity Model Certification Program (CMMC), ushering in its mandatory implementation that begins on November 10. CMMC is a unified assessment model released by the DoD in response to the growing threat of cyberattacks on and data theft from the Defense Industrial Base.  This program requires every DoD contractor that handles sensitive government data to certify compliance with certain cybersecurity controls.  CMMC brings greater scrutiny to contractors’ cybersecurity compliance and greater risks associated with compliance failures. To achieve certification, contractors must prove that their organizations can meet a myriad of security control obligations, a process that can be daunting without familiarity with the policies, procedures, and practices that will be required when the program is finalized.
...

Webinar | 02.20.25, 3:00 PM EST - 4:00 PM EST

Privacy and Cybersecurity Outlook: The 2025 Landscape

Crowell & Moring’s recent publication, The Privacy and Cybersecurity Outlook: The 2025 Landscape, offers clients forward-looking insights on the most significant trends impacting organizations worldwide.

Blog Posts 6 results

Blog Post | 01.26.26

FedRAMP Proposes Updates to Authorization Process—Six New RFCs Released for Public Comment

Crowell & Moring’s Government Contracts Legal Forum

Blog Post | 01.22.26

FedRAMP Proposes Updates to Authorization Process—Six New RFCs Released for Public Comment

Crowell & Moring’s Government Contracts Legal Forum

Blog Post | 01.08.26

CMMC for AI? Defense Policy Law Imposes AI Security Framework and Requirements on Contractors

Crowell & Moring’s Government Contracts Legal Forum