small-logo
ProfessionalsCapabilitiesInsights & NewsCareersLocations
About UsAlumniOpportunity & InclusionPro BonoCorporate Social Responsibility
Stay Connected:
facebookinstagramlinkedintwitteryoutube

Investigations, Enforcement, & Compliance Alerts

    • Email
    • LinkedIn
    • Facebook
    • Twitter
    Share this page
  • RSSRSS
Topics
Contributors
Start Date
End Date

Sort by:

4 results

April 11, 2025

|

7 min read

Navigating the Maze: A Comparison of Selected Federal Cybersecurity Regulations

Cybersecurity requirements for contractors doing business with the U.S. federal government are nothing new. 

...Read more

September 30, 2024

|

5 min read

The DOD Proposes DFARS Amendments to Promote Contractor Compliance with CMMC 2.0

Last month, the U.S. Department of Defense (DOD) published a Proposed Rule setting out planned revisions to the Defense Federal Acquisition Regulations (DFARS) to implement the requirements of the Cybersecurity Maturity Model Certification program (CMMC 2.0) proposed in December 2023.[1] CMMC 2.0 is a framework for verifying a DOD contractor’s implementation of cybersecurity measures that the DOD requires to protect sensitive unclassified information including Controlled Unclassified Information (CUI), and Federal Contract Information (FCI). The Proposed Rule revises the DFARS to reference the CMMC 2.0 requirements that were proposed in December 2023. This includes changes to the existing CMMC clause at DFARS 252.204-7021, the creation of a new solicitation provision to accompany DFARS 252.204-7021 which will provide notice of the CMMC 2.0 requirement, the establishment of a plan for a phased rollout of the Proposed Rule, and the addition of certain new definitions. The Proposed Rule’s comment period ends on October 15, 2024.

...Read more

October 16, 2023

|

5 min read

Be Prepared for CMMC Changes

The Department of Defense (DOD) is expected to finalize a new rule by the end of 2023 that will significantly enhance the Cybersecurity Maturity Model Certification (CMMC) framework and related cybersecurity requirements for defense contractors. 

...Read more

October 10, 2023

|

7 min read

Coming Soon: NIST Revision 3 Requirements for Defense Contractor Protection Of Controlled Unclassified Information

The National Institute of Standards and Technology (NIST) continues to update its guidance, through Special Publication 800-171 (NIST SP 800-171) on how defense contractors and subcontractors of federal agencies should protect Controlled Unclassified Information (CUI). NIST SP 800-171 revision 3, which is expected to be published in early 2024, contains significant changes from the current version (revision 2). Among many modifications, the initial public draft of revision 3, released on May 10, 2023, introduces new security controls, incorporates more detailed security requirements, and provides mechanisms for agencies to tailor their security requirements to their specific needs. These changes may require contractors currently handling CUI to review and revise their information security controls to remain in compliance with their contracts.

...Read more

About This Blog

Winston & Strawn’s Investigations, Enforcement, & Compliance Alerts highlight and analyze significant issues and developments in government investigations, enforcement, civil and criminal trial defense and litigation, compliance, and related matters, providing insights on the legal and strategic implications for individuals and corporations conducting domestic and international business.

Contributors

Suzanne Jaffe Bloom

Partner

Angela M. Machala

Partner

Cari Stinebower

Partner

Jonathan D. Brightbill

Partner

Bryant Gardner

Partner

Steven Grimes

Partner

Alessandra Swanson

Partner

Jack Knight

Partner

James N. Mastracchio

Partner

Susan Elizabeth Seabrook

Partner

Marcelo Blackburn

Partner

Sofia Arguello

Partner

Sean G. Wieber

Partner

Cristina I. Calvar

Partner

Benjamin Sokoly

Of Counsel

Related Capabilities

  • Compliance Programs
  • Crisis Management
  • Environmental Litigation & Enforcement
  • White Collar & Government Investigations
  • Government Program Fraud, False Claims Act & Qui Tam Litigation
  • Government Contracts & Grants
  • Health Care
Logo
facebookinstagramlinkedintwitteryoutube

Copyright © 2025. Winston & Strawn LLP

AlumniCorporate Transparency Act Task ForceDEI Compliance Task ForceEqual Rights AmendmentLaw GlossaryThe Oval UpdateWinston MinutePrivacy PolicyCookie PolicyFraud & Scam AlertsNoticesSubscribeAttorney Advertising