ARTICLE
10 January 2024

Proposed CMMC Rule Would Strengthen Cyber Requirements But May Give Rise To FCA Exposure

AP
Arnold & Porter

Contributor

Arnold & Porter is a firm of more than 1,000 lawyers, providing sophisticated litigation and transactional capabilities, renowned regulatory experience and market-leading multidisciplinary practices in the life sciences and financial services industries. Our global reach, experience and deep knowledge allow us to work across geographic, cultural, technological and ideological borders.
Cybersecurity has been a hot-button FCA issue ever since Attorney General Lisa Monaco announced cybersecurity initiatives in late 2021.
United States Technology
To print this article, all you need is to be registered or login on Mondaq.com.

Cybersecurity has been a hot-button FCA issue ever since Attorney General Lisa Monaco announced cybersecurity initiatives in late 2021. In the last couple of years, DOJ has announced a few cyber-related settlements, and we expect to see more cyber-related FCA investigations and recoveries going forward. Given the potential FCA implications, we at Qui Notes have been waiting for the Department of Defense to issue its long-awaited proposed rule which, if enacted, will establish the Cybersecurity Maturity Model Certification (CMMC) Program. Comments on the proposed rule are due February 26.

Of particular relevance for potential FCA exposure, the rule would require defense contractors to affirm compliance with the applicable CMMC Level after each assessment, after the contractor closes out any "Plan of Actions and Milestones," and annually thereafter. The rule would require that these affirmations be submitted by a senior official responsible for ensuring compliance with CMMC. As our readers know, any affirmations or certifications of compliance bring with them FCA risk. And, of course, if the rule is enacted as proposed, contractors who delay their efforts to achieve CMMC compliance could also face increased FCA risk.

For a more in-depth overview of the proposed rule, check out this Advisory. Otherwise, we at Qui Notes will be tracking the progress of the proposed rule and other cyber FCA developments.

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

We operate a free-to-view policy, asking only that you register in order to read all of our content. Please login or register to view the rest of this article.

See More Popular Content From

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More