DOD Meeting Makes Clear DOD Cybersecurity Rule Will Trigger New Requirements

Dec 15, 2015

We previously notified you of a meeting on the new updated Department of Defense (DOD) rule on cybersecurity, DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting (August 2015), and its October 2015 Class Deviation. The meeting, hosted by DOD, made clear that these new updated rules pose significant new obligations for DOD contractors and subcontractors. Your company's procurement and legal compliance representatives need to be on top of these matters.


Key Developments: 


DOD considers the new obligations to be triggered under the clause when performance of the DOD contract or subcontract involves ?Covered Defense Information? (CDI) or operationally critical support (OCS). These significant obligations require contractor information systems to comply with new NIST 800-171 standards and, where the contractor uses cloud services, require notification and use of Government-approved cloud services providers for cloud storage or transmission under DOD contracts. Contractors are required to report a cyber incident that affects a covered system or the CDI, or that affects the contractors ability to perform the OCS requirements. Contractors have the right to seek additional compensation to meet these obligations, but to do so they must initiate specific steps before agreeing to the new terms. 


Triggers: 


Application of the clause is triggered if a DOD contract would provide the contractor, or the contractor otherwise would collect, develop, receive, transmit, use or store, of any of the following four types of CDI in support of performance of your DOD contract or subcontract:


  • Controlled technical information [CTI].
  • Critical information (operations security).
  • Export controlled information.
  • Any other information, marked or otherwise identified in the contract, that requires safeguarding or dissemination controls pursuant to and consistent with law, regulations, and Government-wide policies (e.g., privacy, proprietary business information).


The clause also is triggered if the contractor would provide OCS, meaning supplies or services the Government designates as ?for airlift, sealift, intermodal transportation services, or logistical support that is essential to the mobilization, deployment, or sustainment of the Armed Forces in a contingency operation.


Requirements:


Compliance with the clause requires that a contractors covered systems and protection of CDI meet the new NIST SP 800-171 standards. Use of cloud services (CS) to store or transit CDI in performance of the contract requires DOD notice and use of DOD-approved cloud services. Contractors must rapidly report directly to DOD on a cyber incident that affects, or risks affecting, a covered contractor information system or CDI, or that affects the contractors ability to perform the operationally critical support requirements. Only pre-approved personnel can do the reporting. The requirements apply to contractors and subcontractors.


Takeaways and Next Steps:


  • Ensure your company's procurement and legal compliance representatives are up to speed on these new, significant changes for DOD contracts. 


  • If asked to include the new clause in your existing contract, you have the right to seek compensation for the increased costs and time needed to address the additional requirements. You must notify the Contracting Officer (or your prime) of the impact of this change and your right to an equitable adjustment, and negotiate the terms before you accept the clause, or risk losing your right to seek compensation. 


  • New DOD procurements and contracts will include the clause. Proactively check whether they trigger clause requirements and factor your compliance costs, and any required waiver or approvals, into proposal preparations and the ultimate contract. Its likely that most companies will need to do something.


You have options. If you would like to understand your requirements or would like assistance in this area, please contact a FortneyScott attorney.

18 Apr, 2024
The EEOC’s final Pregnant Workers Fairness Act (“PWFA”) regulations were republished in the Federal Register on April 19 and will become effective on June 18th. The final regulations and guidance clarified and, in some cases, expanded on employers’ accommodation obligations for pregnancy related conditions from what the EEOC originally included in the proposed regulations.
On March 29, 2024, the Office of Management and Budget published revisions to federal data that cove
09 Apr, 2024
On March 29, 2024, the Office of Management and Budget published revisions to federal data that covered entities must collect on race and ethnicity.
02 Apr, 2024
On January 29, 2024, on the 15th anniversary of the enactment of the Lily Ledbetter Fair Pay Act, the Biden Administration announced a proposed regulation to prohibit federal contractors and subcontractors from using job applicant’s prior salary history when setting pay and to require federal contractors to disclose the expected salary range in job postings. The proposal was published in the Federal Register on January 30, 2024 and comments were due on April 1, 2024.
OFCCP Contractor Portal
26 Mar, 2024
OFCCP announced on March 25, 2025 that its contractor portal will open for federal contractor certification on April 1, 2024 and close on July 1, 2024.
14 Mar, 2024
Join our skilled presenters as they discuss the actions of the DOL (Wage & Hour; OFCCP; OSHA), the NLRB, and recent Court arguments confronting the Chevron doctrine, with a focus on the impact on the workplace.
31 Jan, 2024
On January 30, 2024, the Biden Administration published a proposed regulation to prohibit federal contractors and subcontractors from using job applicant’s prior salary history when setting pay and to require federal contractors to disclose the expected salary range in job postings.
Show More
18 Apr, 2024
The EEOC’s final Pregnant Workers Fairness Act (“PWFA”) regulations were republished in the Federal Register on April 19 and will become effective on June 18th. The final regulations and guidance clarified and, in some cases, expanded on employers’ accommodation obligations for pregnancy related conditions from what the EEOC originally included in the proposed regulations.
On March 29, 2024, the Office of Management and Budget published revisions to federal data that cove
09 Apr, 2024
On March 29, 2024, the Office of Management and Budget published revisions to federal data that covered entities must collect on race and ethnicity.
02 Apr, 2024
On January 29, 2024, on the 15th anniversary of the enactment of the Lily Ledbetter Fair Pay Act, the Biden Administration announced a proposed regulation to prohibit federal contractors and subcontractors from using job applicant’s prior salary history when setting pay and to require federal contractors to disclose the expected salary range in job postings. The proposal was published in the Federal Register on January 30, 2024 and comments were due on April 1, 2024.
OFCCP Contractor Portal
26 Mar, 2024
OFCCP announced on March 25, 2025 that its contractor portal will open for federal contractor certification on April 1, 2024 and close on July 1, 2024.
14 Mar, 2024
Join our skilled presenters as they discuss the actions of the DOL (Wage & Hour; OFCCP; OSHA), the NLRB, and recent Court arguments confronting the Chevron doctrine, with a focus on the impact on the workplace.
31 Jan, 2024
On January 30, 2024, the Biden Administration published a proposed regulation to prohibit federal contractors and subcontractors from using job applicant’s prior salary history when setting pay and to require federal contractors to disclose the expected salary range in job postings.
On January 9, 2024, the Department of Labor’s Wage and Hour Administration (“W&H”) issued its long-a
17 Jan, 2024
On January 9, 2024, the Department of Labor’s Wage and Hour Administration (“W&H”) issued its long-awaited final regulation, “Employee or Independent Contractor Classification Under the Fair Labor Standards Act.”
17 Nov, 2023
FortneyScott is pleased to announce that its co-founder Jacqueline Scott became President of the global bar organization, Union Internationale des Avocats (UIA). As President of the UIA, Jacqueline Scott has responsibility for overseeing and leading the UIA’s attorney members in 110 countries. UIA fosters professional development and the exchange of information and ideas internationally, promotes the rule of law, defends the independence and freedom of lawyers worldwide, and emphasizes friendship, collegiality and networking among members. Additional information on Ms. Scott and her new UIA responsibilities is available here .
15 Nov, 2023
For the first time as President of the Union Internationale des Avocats ("UIA"), FortneyScott co-founder Jacqueline Scott attended the 67th UIA Congress in Italy late last month. The UIA is a global, multicultural organization that brings together the legal profession and whose members represent 110 countries. Ms. Scott provided her first Presidential Speech for the closing of the Congress, "Defense of the Defense" . You can view the video or read the transcript is also available.
15 Nov, 2023
FortneyScott and DCI Consulting Group Launch DEI Risk Assessment DEI program evaluation offers privileged critical information to mitigate risk Washington, D.C.: Fortney & Scott, LLC (FortneyScott), a leading Washington, DC law firm representing and advising a broad range of employers, has partnered with DCI Consulting Group, Inc. (DCI), a Washington, D.C.-based human resources data analytics and consulting firm, to offer a comprehensive, multi-disciplined DEI Risk Assessment. Employers and their C-Suites and Boards of Directors are facing growing challenges to their Diversity, Equity, and Inclusion (DEI) programs. In response, employers are turning to Fortney Scott and DCI as outside experts to assess their legal compliance and provide advice as to best practices. As a result, we have developed a proactive, comprehensive, and attorney-client privileged DEI Risk Assessment. This DEI Risk Assessment is a crucial first step to identifying and mitigating potential legal exposure, and includes: 1. Self-Evaluation of DEI Programs & Commitments 2. Listening Sessions with Executives & DEI Leaders 3. Legal Review & Risk Assessment of Policies, Procedures and Practices 4. Scorecard & Best Practice Recommendations “Following the recent rulings by the Supreme Court in UNC and Harvard, it is clear that the legal risks for corporate DEI programs have substantially increased.” said FortneyScott Co-Founder David S. Fortney. “The critical step for employers now is to conduct an attorney-privileged assessment of their DEI programs -- that includes necessary workforce analyses and benchmarking based on best practices -- to determine how their DEI programs should be implemented going forward.” About FortneyScott FortneyScott is a Washington, DC-based law firm counseling and advising clients on the full spectrum of DEI and workplace-related matters. The firm offers clients unparalleled experience and expertise by its attorneys, who formerly held senior positions at the U.S. Department of Labor (DOL), Equal Employment Opportunity Commission (EEOC) and other government agencies, in corporate and Congressional legal staffs, in major law firms, and who served as a judge on an international tribunal. About DCI DCI Consulting Group is a human resources risk management consulting firm strategically headquartered in Washington, D.C. Members of DCI’s staff are recognized experts in a variety of spaces, including systemic compensation discrimination analyses, affirmative action plan development and implementation, pay equity analyses, DEIA metrics, employee selection and test validation, and OFCCP audit and litigation support. DCI also offers proprietary software and related support to clients. FortneyScott Media Contact: DCI Media Contact: info@fortneyscott.com news@dciconsult.com 202-689-1200 14-448-7355
More Posts
Share by: