Department Of Defense Issues Class Deviation Delaying Application Of NIST SP 800-171, Revision 3

BB
Bass, Berry & Sims

Contributor

Bass, Berry & Sims is a national law firm with nearly 350 attorneys dedicated to delivering exceptional service to numerous publicly traded companies and Fortune 500 businesses in significant litigation and investigations, complex business transactions, and international regulatory matters. For more than 100 years, our people have served as true partners to clients, working seamlessly across substantive practice disciplines, industries and geographies to deliver highly-effective legal advice and innovative, business-focused solutions. For more information, visit www.bassberry.com.
On May 2, the Department of Defense (DOD) issued a class deviation to DFARS 252.204-7012 "to provide industry time for a more deliberate transition upon the forthcoming release...
United States Government, Public Sector
To print this article, all you need is to be registered or login on Mondaq.com.

On May 2, the Department of Defense (DOD) issued a class deviation to DFARS 252.204-7012 "to provide industry time for a more deliberate transition upon the forthcoming release of [National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171, Revision 3]."

Slated to be finalized later this month, NIST SP 800-171, Revision 3 is a set of updated guidelines intended to help contractors handle confidential unclassified information (CUI) residing on non-federal systems and is part of a broader effort to clarify requirements, strengthen cybersecurity defenses, and increase flexibility for contractors who are developing and implementing cybersecurity programs.

NIST released its initial public draft on May 10, 2023, signaling to contractors the specific areas of focus and outlining what the final standards will require. The public draft worked to remove outdated cybersecurity standards to better reflect current best practices; introduced "organization-defined parameters" to be used to specify certain parameters rather than strict requirements to allow contractors more flexibility and creativity when implementing their cybersecurity approaches; aligned security requirements with updates in NIST SP 800-53, Revision 5 and the NIST SP 800-53B moderate control baseline; created a prototype CUI overlay; and provided additional resources to help organizations mitigate risks. We wrote about the initial public draft in more detail here.

Currently, DFARS 252.204-7012 does not specify which NIST SP 800-171 revision is applicable, and the DOD has interpreted that ambiguity to suggest that compliance with the most recent version is required. With NIST SP 800-171, Revision 3 is set to be finalized this month, and upcoming compliance requirements are set to be confusing. However, the deviation clarifies that contractors subject to the clause must comply with NIST SP 800-171, Revision 2, delaying the incorporation of NIST SP 800-171, Revision 3.

DOD is now directing contracting officers to use the deviation instead of the standard 252.204-7012 clause. Contractors awarded new contracts should ensure their contracts incorporate the deviation rather than the standard 252.204-7012 clause.

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

Department Of Defense Issues Class Deviation Delaying Application Of NIST SP 800-171, Revision 3

United States Government, Public Sector

Contributor

Bass, Berry & Sims is a national law firm with nearly 350 attorneys dedicated to delivering exceptional service to numerous publicly traded companies and Fortune 500 businesses in significant litigation and investigations, complex business transactions, and international regulatory matters. For more than 100 years, our people have served as true partners to clients, working seamlessly across substantive practice disciplines, industries and geographies to deliver highly-effective legal advice and innovative, business-focused solutions. For more information, visit www.bassberry.com.
See More Popular Content From

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More