Are you ready? The trend towards ever more prescriptive cybersecurity controls further reaches DOD contractors
October 24, 2024
Are you ready? The trend towards ever more prescriptive cybersecurity controls further reaches DOD contractorsOctober 24, 2024 Cybersecurity requirements continue to proliferate, both globally and within the US. Whether because of these new requirements, or because of the escalating threat environment, companies should urgently consider assessing their current cybersecurity posture against existing and forthcoming regulations, as well against the latest threats. On October 11, 2024, the US Department of Defense (DOD) finalized its Cybersecurity Maturity Model Certification (CMMC) rule, which mandates cybersecurity requirements for nearly all DOD contracts. The CMMC is structured in three levels, with requirements scaling based on the sensitivity of information handled:
The CMMC level required for each contract will be determined based on the type and sensitivity of information, with requirements flowing down to subcontractors. Notably, contractors meeting at least 80% of Level 2 or 3 requirements can receive conditional eligibility with a Plan of Actions and Milestones (POAM) to comply within 180 days. The rule will phase in over four years, with Level 1 and Level 2 self-assessment requirements beginning in the first year and full implementation anticipated within a few years. The DOD projects compliance costs of approximately $39 billion over ten years. This could significantly impact smaller companies as achieving certification, particularly for higher levels, may require considerable financial and operational resources. Further, contractors will not be eligible to win contracts until they have achieved the appropriate CMMC certification. This final rule reflects updates to the proposed rule, including an extended initial phase rollout. Additionally, External Service Providers (ESPs) used by contractors are no longer required to get their own CMMC assessment if they do not handle CUI. Further guidance on contract implementation will be published by mid-2025. Contractors should consider urgently reviewing their cybersecurity measures and prepare for compliance with the new CMMC requirements to ensure eligibility for DOD contracts now, as the certification process is likely to be lengthy. The rule finalization is indicative of a trend of increasing cybersecurity requirements and expectations. Also reflective of that trend is the issuance of new guidance on October 15 by the New York Department of Financial Services highlighting certain cybersecurity risks posed by artificial intelligence (AI), including AI-enabled social engineering and AI-enhanced cyberattacks. While the guidance is not a new requirement and only applies to state-regulated financial institutions, it makes clear that NY DFS expects a reasonable, risk-based cybersecurity program to address emerging AI-driven cybersecurity risks. The cybersecurity risk assessments NY DFS already requires should now incorporate cybersecurity risks such as deepfakes, and address the organization’s own use of AI, AI used by third-party service providers and vendors, and address potential vulnerabilities in AI applications. As with the DoD’s CMMC requirements and controls, we can expect NY DFS to update its cybersecurity regulations as technologies and threats evolve.
__________ Latest Insights
Latest News
Latest Events
legal updates June 02, 2026 Illinois tax increases part two: Digital asset privilege tax, prediction ma... legal updates June 01, 2026 Illinois tax increases part one: Digital services taxes legal updates May 29, 2026 Consumer Lens - Session 1 | The Rise of European Class Actions podcasts and webcasts May 29, 2026 Tax NOLs in Cross-Border Structures Webinar client news June 02, 2026 Next stop, public ownership: Eversheds Sutherland advises DfT on GTR transi... firm news June 01, 2026 Eversheds Sutherland strengthens restructuring offering with senior partner... firm news June 01, 2026 Eversheds Sutherland strengthens Commercial Advisory practice with technolo... firm news May 29, 2026 Eversheds Sutherland Advises Powerlaw Corp. on NASDAQ Listing as PWRL virtual Spanish employment law training June 02, 2026 2pm - 5pm (BST) Virtual virtual UK employment law training June 09, 2026 1pm - 4pm (BST) Virtual virtual Nordic (Denmark, Finland, Norway and Sweden) employment law training June 16, 2026 12.45pm - 4pm (BST) Virtual virtual Introduction to Swiss employment law June 23, 2026 2pm - 5pm (GMT) Virtual |