What is a Department of Defense (DoD) class deviation? It is a deviation from the Federal Acquisition Regulation (FAR) or Defense Federal Acquisition Regulation (DFARS) that affects more than one contract. They are issued by an authorized official and are used to deviate from the FAR or DFARS and offer flexibility in the acquisition process. Class deviations are supposed to be temporary. If the class deviation will become permanent, the Government is supposed to issue a proposed revision to the FAR or DFARS.
Topics: Contracts & Subcontracts Administration, System Award Management (SAM), Government Regulations, Cost Accounting Standards (CAS), Federal Acquisition Regulation (FAR), Cybersecurity
The FAR Council issued a proposed rule on January 15, 2025, to expand the CUI requirements into FAR under Executive Order 13556 Controlled Unclassified Information. Controlled Unclassified Information is information that the government creates or possesses, or that an entity creates or possesses for or on behalf of the government, that a law, regulation, or governmentwide policy requires or permits an agency to handle using safeguarding or dissemination controls. CUI may not be released to the public.
Topics: Contracts & Subcontracts Administration, DFARS Business Systems, Contractor Purchasing System Review (CPSR), Government Regulations, Federal Acquisition Regulation (FAR), Cybersecurity
On October 15, 2024, the Department of Defense (“DoD”) published the final rule of the Cybersecurity Maturity Model Certification (“CMMC”) requirements in Title 32 of the Code of Federal Regulations, effective December 16, 2024. The Final Rule updates DoD national security regulations to ensure contractors have implemented cyber security measures to safeguard Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). CMMC will be contractually required when the Defense Federal Acquisition Regulation (“DFARS”) clause has not been finalized (see our article, “DoD Issues CMMC Proposed Rule – Submit your comments by October 15, 2024”). We will refer to this DFARS clause throughout this blog as the DFARS CMMC Clause Final Rule.
Topics: Contracts & Subcontracts Administration, Government Regulations, Federal Acquisition Regulation (FAR), Cybersecurity
DoD issued a proposed rule dated August 15, 2024 (DFARS Case 2019-D041) to amend DFARS to incorporate contractual requirements related to the Cybersecurity Maturity Module Certification (CMMC) Program. This implements a section of the National Defense Authorization Act for FY 2020 to enhance cybersecurity for the US defense industrial base. DoD is estimating that the final rule will be issued during Quarter 1 2025. Contractors should take heed and provide comments by the October 15, 2024, due date.
Topics: Government Regulations, Federal Acquisition Regulation (FAR), Cybersecurity
Since the Department of Justice (DOJ) started promoting its initiative on Cyber Security reporting there have been several settlements related to cyber security noncompliance, four of which involve defense contractors.
Topics: DFARS Business Systems, Cybersecurity
The FAR Council submitted a proposed rule amending FAR subparts, provisions, and clauses on October 3, 2023, to implement an Executive order on cyber threats, incident reporting, and information sharing for Federal contracts. This revision is being made to strengthen and standardize contractual requirements for cybersecurity across Federal agencies. The proposed rule also implements OMB Memorandum M-21-07 Completing the Transition to internet Protocol Version 6 (IPv6), dated November 19, 2020.
Topics: DFARS Business Systems, Contractor Purchasing System Review (CPSR), Government Regulations, Federal Acquisition Regulation (FAR), Cybersecurity
On June 9, 2023, the Office of Management and Budget (OMB) issued M-23-16, Update to Memorandum M-22-18, providing an extension to the deadline for software developers to submit attestation forms to Federal agencies.
Topics: DFARS Business Systems, Contractor Purchasing System Review (CPSR), Cybersecurity
On April 27, 2023, The Cybersecurity and Infrastructure Security Agency (CISA) of The Department of Homeland Security (DHS) published a draft Secure Software Development Attestation Form. Software producers that sell to the government will be required to complete the self-attestation form to attest that the software they produce was developed in conformity with specified secure development practices.
Topics: DFARS Business Systems, Contractor Purchasing System Review (CPSR), Cybersecurity
DoD Issued a Final Rule amending the Defense Acquisition Regulation Supplement (DFARS) to require contracting officers to consider Supplier Performance Risk System (SPRS) risk assessments when evaluating a suppliers quote or offer. The final rule is effective March 22, 2023. The Supplier Performance Risk System (SPRS) is the authoritative source to retrieve supplier product and performance information assessments for the DoD acquisition community to use in identifying, assessing, and monitoring unclassified performance.
Topics: Contracts & Subcontracts Administration, DFARS Business Systems, Cybersecurity
Office of Management and Budget (OMB) issued a memorandum dated September 14, 2022, Subject Enhancing the Security of the Software Supply Chain through Secure Software Development Practices. This is a result of the President’s Executive Order on Improving the Nation’s Cybersecurity.
Topics: DFARS Business Systems, Contractor Purchasing System Review (CPSR), Cybersecurity