Author: James Goepel

  • The Final CMMC Rule Explained: Key Takeaways

    The eagerly awaited CMMC (Cybersecurity Maturity Model Certification) final rule has now been published in the Federal Register, and while it may not be an easy read, its importance cannot be overstated. This article, based on a recent joint webinar presented by FutureFeed, NeoSystems, and Holland & Knight, will distill the essentials of the final…

  • DoD Takes Next Step Toward CMMC

    When it introduced CMMC 2.0 in 2021, the United States Department of Defense signaled that it was simultaneously both softening some of the requirements that were in early versions of its Cybersecurity Maturity Model Certification (“CMMC”) program and taking a more structured approach to implementing CMMC. As part of that structured implementation, DoD formalized CMMC by crafting an…

  • Disseminating CUI to Others

    Controlled Unclassified Information (“CUI”) is sensitive, unclassified information. This means that not only must CUI not be available to the general public, but also that access to the information must not be granted to anyone unless they have a “lawful government purpose” to handle that information. Things get even a little more confusing when CUI is subject to export controls,…

  • NIST SP 800-171r3 Final Public Draft Released

    The National Institute of Standards and Technology (“NIST”) released two updated DRAFT documents today that are critical to FutureFeed users and the broader CMMC ecosystem. The first, NIST SP 800-171r3, was released as a “Final Public Draft”. As a Final Public Draft, the document is expected to largely remain unchanged, except for minor typographical or other…

  • Don’t Panic! NIST SP 800-171r3 and FutureFeed

    NIST released an initial public draft of NIST SP 800-171 r3 (“r3”) on May 10, 2023. This blog post discusses that draft and our plans for incorporating r3 into FutureFeed. NIST 800-171 Discussion Draft Last year NIST announced that they would be updating 800-171, and asked for public feedback. They used that feedback, as well…

  • DoD Publishes new DFARS Rule Impacting SPRS

    The United States Department of Defense recently published a notice that a new rule, DFARS 252.204-7024, will be published soon. In her recent article (available here for free), Sara Friedman publishes analysis of that new rule, including comments from Robert Metzger, Eric Crusius, and me. The biggest takeaway I see is that DoD is laying a foundation for…

End of content

End of content