Our October 16, 2015 blog discussed DOD's cybersecurity regulatory changes. This blog updates that information.
After issuing its earlier rule, the DOD has issued a new interim rule delaying most compliance implementation until December 31, 2017. This is apparently in recognition of the difficulties and expense associated with implementation as noted in our earlier blog.
In that same vein, the interim rule amends flowdown requirements to limit subcontractor coverage to those providing "operationally critical support." But, although most compliance implementation is delayed, informing DOD of certain cybersecurity shortcoming at the time of awards remains a current requirement.
The interim rule is available at this link as of the time this blog was published: https://www.federalregister.gov/articles/2015/12/30/2015-32869/defense-federal-acquisition-regulation-supplement-network-penetration-reporting-and-contracting-for?utm_campaign=email+a+friend&utm_medium=email&utm_source=federalregister.gov.