What DoD Contractors Need to Know: New Changes to Cybersecurity and Cloud Computing Regulations

Justin A. Chiarodo and Philip E. Beshara

As the federal government and contracting community near the end of a year filled with headline-grabbing cyber incidents, the Department of Defense (DoD) has recently issued interim cybersecurity and cloud computing regulations that amend the DFARS and impose important new information safeguarding, reporting, and cloud computing requirements. These are major changes that impact all DoD contractors, and if your company holds DoD contracts you should carefully review these new requirements and assess them as part of your broader corporate cybersecurity strategy.

This alert highlights the key requirements in the Interim Rule (available here).

Information Safeguarding and Cybersecurity Reporting

The Interim Rule expands DoD’s cybersecurity safeguarding and reporting requirements, including the types of information covered by the requirements, governing standards, and triggering events. Up until now, many of DoD’s cybersecurity requirements applied to select groups of defense contractors—those deemed “operationally critical” under the 2015 NDAA or “cleared defense contractors” under the 2013 NDAA, and contractors handling “unclassified controlled technical information,” or “UCTI,” under the DFARS. Continue reading “What DoD Contractors Need to Know: New Changes to Cybersecurity and Cloud Computing Regulations”

Déjà Vu All Over Again: Six Tips to Prepare for a Government Shutdown

Justin A. Chiarodo and Heather L. Petrovich

With Congress quickly approaching a September 30 funding deadline with no adequate spending measures in place, and the Office of Management and Budget now directing agencies to prepare contingency plans, the possibility of a government shutdown is becoming increasingly likely. Unfortunately, government contractors faced these challenges just two short years ago during a 16-day shutdown. Among other challenges, contractors may face a lack of incremental funding; the inability to enter into new contracts or contract modifications; closed government facilities; furloughed government employees; delayed payments; increased indirect costs; and unexercised and deferred contract options. This alert highlights steps government contractors can take to protect their business interests in the event of a shutdown.

Review Your Contracts 

Reviewing your contracts is good advice in all times, but particularly so when facing a shutdown. Several key areas are worth reviewing before a shutdown. First, contractors should consider the amount and type of contract funding for each contract. A shutdown will affect incrementally funded contracts more than fully funded contracts. Though exceptions may apply, the funding for incrementally funded contracts may lapse in the event of a shutdown, which could cause the contract work to come to a halt. Fully funded contracts may be impacted by furloughed employees, facility closures, or other unexpected costs. Second, the place of contract performance may affect the ongoing work on a contract if the contractor is performing at a government facility. Many government facilities will close during a shutdown and furloughed employees or limited hours may affect those government facilities that do remain open. Third, the period of contract performance may affect a contract in that the government cannot exercise options and contract extensions during a shutdown. Fourth, the statement of work could also affect how the shutdown applies to a contract. For instance, national security and emergency preparedness contracts are much more likely to be funded during a shutdown than facility maintenance work. Nonetheless, even those exempt contracts may still be affected if the statement of work requires contractors or projects to interact with furloughed employees. Continue reading “Déjà Vu All Over Again: Six Tips to Prepare for a Government Shutdown”

SBA Proposes Anticipated Small Business Subcontracting Rule

Justin A. Chiarodo and Philip E. Beshara

A recent proposed rule issued by the Small Business Administration (SBA) previews long-awaited changes to SBA’s regulations governing small business government contracting programs. These changes will impact both large and small government contractors alike and warrant close attention. This alert highlights key elements in the proposed rule, including major changes to subcontracting limitations for small business set-asides that first arose in the FY 2013 National Defense Authorization Act (NDAA). Given the explosive growth in enforcement for small business program violations, and draconian new penalties for such violations, all contractors should take steps to ensure they comply with the upcoming rule changes.

Changed Method for Calculating Subcontracting Limitations

The FY 2013 NDAA implemented a number of changes to small business programs in federal procurements (we recently covered these changes here). The primary reform in the NDAA—now addressed in the SBA’s proposed rule—is a significant shift in the method of limiting subcontracting under set-aside procurements. The SBA and FAR currently require prime small business concerns on set-aside contracts to incur set percentages of costs incurred under the contract based on the contract type (e.g., at least 50 percent of the personnel or manufacturing costs incurred under service and supply contracts). The challenges in monitoring this cost-based method led Congress to amend the Small Business Act. That statute now limits the percentage of the total contract price a prime awardee can subcontract out. Consistent with the statute, the proposed rule would amend 13 CFR § 125.6 to require small business primes to perform 50 percent of the total contract price for service and supply contracts, 15 percent for general construction, and 25 percent for specialty trade construction. Continue reading “SBA Proposes Anticipated Small Business Subcontracting Rule”

Government Contractors and Executive Order – Fair Pay and Safe Workplaces: New Federal Labor Law Compliance Issues

Justin A. Chiarodo, Deborah P. Kelly, and Lyndsay A. Gorton

DOD, FYSA, SITREP – government contractors are familiar with the alphabet soup that goes hand-in-hand with doing business with the federal government as well as most common labor laws and their acronyms: Federal Labor Standards Act, (“FLSA”), the Family and Medical Leave Act (“FMLA”), or Occupational Safety and Health Act of 1971 (“OSHA”). Now, the question is whether contractors comply with these laws and recent developments in government contractor employment law. On July 31, 2014 the White House issued the Executive Order – Fair Pay and Safe Workplaces (the “Executive Order”) which creates new requirements that will add pre and post-award reporting demands on many new government services and construction contracts. The purpose of this alert is to help government contractors sort through the dense language of the Executive Order and provide a roadmap for what to do going forward so that violations of labor laws don’t lead to suspension or debarment.

  1. What’s New? The Basics of Executive Order – Fair Pay and Safe Workplaces The Executive Order applies to all new “procurement contracts for goods and services” with an expected value exceeding $500,000. The new requirements do not apply to contracts for “commercially available off-the-shelf items,” or contracts presently being performed. According to the White House Fact Sheet for the Executive Order, the new requirements will be applied in stages, on a “prioritized basis” beginning in 2016. Neither the Executive Order nor the Fact Sheet define “prioritized basis,” but presumably, government contracts with the highest expected values and most hazardous contract conditions will be among the first to report under the new requirements. The 2016 date provides some time for both the Federal Acquisition Regulatory (“FAR”) Council and Department of Labor (“DOL”) to issue guidance for implementation as required by the Executive Order.

Continue reading “Government Contractors and Executive Order – Fair Pay and Safe Workplaces: New Federal Labor Law Compliance Issues”

The Expansion of the Business Systems Rule Beyond DoD

David M. Nadler, Justin A. Chiarodo, David Yang, and Stephanie M. Harden

With the potential for millions of dollars in withholdings on contract payments, Department of Defense (DoD) contractors have become all too familiar with the Business Systems Rule since it was first implemented in 2011. The Department of Energy (DoE) is now following in the steps of DoD and promulgating its own Business Systems Rule. On April 1, 2014, DoE issued a Notice of Proposed Rulemaking for its Business Systems Rule, which is largely modeled off of the DoD rule. This expansion of the Business Systems Rule beyond DoD warrants careful attention by contractors who may not have previously been covered, as effective and proactive compliance is essential to mitigating the risk of withholdings under the rule.

Overview of the DoD Business Systems Rule

The DoD Business Systems Rule permits DoD to withhold contractor payments on covered contracts if one or more “significant deficiencies” are found in any of the six business systems covered by the rule. The term “significant deficiency” is broadly defined as “a shortcoming in the system that materially affects the ability of officials of DoD and the Contractor to rely upon information produced by the system that is needed for management purposes”–a definition which leaves great discretion to the Contracting Officers responsible for determining system acceptability. Continue reading “The Expansion of the Business Systems Rule Beyond DoD”

DOD and GSA Seek Comments on Draft Cybersecurity Implementation Plan

Justin A. Chiarodo and Daniel A. Broderick

On Wednesday, March 12, 2014, the Department of Defense (DOD) and General Services Administration (GSA) Joint Working Group on Improving Cybersecurity and Resilience Through Acquisition (Working Group) requested public comments on its draft implementation plan (draft plan) for federal cybersecurity acquisition. See 79 Fed. Reg. 14042 (Mar. 12, 2014). The draft plan is the first of several steps toward implementing the recommendations outlined in the Working Group’s recently finalized report on Improving Cybersecurity and Resilience Through Acquisition (summarized here).

As comments are due on April 28, 2014, federal contractors and other stakeholders should act quickly to submit their views on what will have a significant and lasting impact on federal cybersecurity acquisition practices.

The draft plan proposes a repeatable, scalable, and flexible framework for addressing cyber risk in federal acquisitions, and by design, it will affect nearly all contracting entities. The draft plan proposes a “taxonomy” for categorizing procurements so that the government can effectively prioritize those in need of additional resources, attention, and safeguards. As proposed, the taxonomy is modeled on Federal Information and Communications Technology (ICT) acquisitions—though the Working Group has asked whether this framework is a workable model for the categorization of all acquisitions. The Working Group would use the ICT framework to categorize all acquisitions that present cyber risk, after which it would separately assess the risks within each category. Categories that present greater cybersecurity risk (based on threats, vulnerabilities, and impacts) would receive more and faster attention in acquisitions. The taxonomy is, in our view, the most significant new development in the draft plan, as it will serve as the principal basis for categorizing the extent of cyber regulations for procurements. This aspect of the plan accordingly warrants particularly close attention. Continue reading “DOD and GSA Seek Comments on Draft Cybersecurity Implementation Plan”

DoD and GSA Issue Final Report on Improving Cybersecurity and Resilience through Acquisition

Justin A. Chiarodo and Daniel A. Broderick

On January 23, 2014, the Department of Defense (DoD) and General Services Administration (GSA) Joint Working Group on Improving Cybersecurity and Resilience Through Acquisition (Working Group) submitted its eagerly anticipated final report on integrating cybersecurity requirements into all federal procurements. This report, which satisfies Executive Order (EO) 13636 and Presidential Policy Directive (PPD) 21, includes recommendations on the increased use of cybersecurity standards in all federal acquisition activities, including strategic planning, capabilities needs assessment, systems acquisitions, and program and budget development.

The final report is perhaps most notable as another step toward an era where most every government contractor must satisfy baseline cybersecurity requirements. While the final report does not provide explicit guidance on the details of creating such a new procurement environment, in light of recent, imminent and forthcoming government activity, including the final rule imposing cybersecurity and reporting obligations on DoD contractors (issued November 18, 2013 and summarized here), the upcoming final cybersecurity framework of the National Institute of Standards and Technology (NIST) (to be released in mid-February), and the forthcoming final rule governing the safeguarding of government contractor information systems (likely finalized next year), we view this final report as a bellwether. Government contractors who ignore the final report and the course it has set do so at their own peril. Continue reading “DoD and GSA Issue Final Report on Improving Cybersecurity and Resilience through Acquisition”

Final DFARS Rule Imposes New Cybersecurity and Reporting Obligations

Justin A. Chiarodo and Daniel A. Broderick

Last November, the U.S. Department of Defense (DoD) issued a final rule imposing enhanced cybersecurity and reporting obligations on contractors and subcontractors with information systems containing unclassified controlled technical information (UCTI). 78 Fed. Reg. 69273 (Nov. 18, 2013). UCTI is defined to mean technical information with a military or space application that is subject to controls on its access, use, reproduction, modification, performance, display, release, disclosure, or dissemination.

The final rule adds a new subpart (224.73) and corresponding contract clause (252.204-7012) to the Defense Federal Acquisition Regulation Supplement (DFARS), and together they direct contractors that handle UCTI to (1) implement enhanced safeguards and (2) report and investigate certain incidents affecting such information.

This final rule implements one part of the broader and more controversial proposed rule, published in June 2011. 76 Fed. Reg. 38089 (June 29, 2011). That rule, which proposed substantial compliance obligations for protection of unclassified information, applied to a larger class of nonpublic information, including nonpublic information either provided by or on behalf of the DoD or collected, developed, received, or transmitted in conjunction with the contractor’s support of an official DoD activity. Unlike the proposed rule, however, this final rule is narrower in scope because it concerns only a single category of data: UCTI. Continue reading “Final DFARS Rule Imposes New Cybersecurity and Reporting Obligations”

AAA Expands Review of Arbitration Awards With New Appellate Rules

Scott Arnold, Justin A. Chiarodo and Christian N. Curran

The American Arbitration Association (AAA) recently adopted optional Appellate Rules which significantly change the resolution of post-award issues. The new Appellate Rules, effective November 1, 2013, permit appeals of arbitration rulings directly to an AAA appellate panel. Given the difficulty in overturning traditional arbitration awards, these new rules could help protect against factually and legally flawed outcomes. However, they also could add both time and expense to an arbitration, limiting the efficiencies and cost savings that often lead contractors to use arbitration provisions in the first place. This alert discusses the new Appellate Rules, and some things to keep in mind when evaluating whether to use them.

New Appeal Grounds

One of the traditional features of arbitration compared to litigation is that arbitrations are designed to reach a final decision sooner. Vacating an arbitration award is extremely difficult and can generally only be done under limited circumstances (e.g., plain and obvious bias of an arbitrator, fraud or corruption, misconduct of an arbitrator, or if arbitrators exceed their powers). See Federal Arbitration Act, 9 U.S.C. § 10. An arbitration panel’s legal or factual errors alone are not traditional grounds to overturn an award.

Addressing some of these limitations, the new Appellate Rules provide an optional appellate proceeding for parties who agree to use the rules-either by stipulation or contract provision-to appeal an award based on two grounds: “(1) an error of law that is material or prejudicial; or (2) determinations of fact that are clearly erroneous.” Appellate Rule A-10. Continue reading “AAA Expands Review of Arbitration Awards With New Appellate Rules”

First Circuit Ends Closely Watched Takeda Suit With Limited Ruling

Justin A. Chiarodo

The First Circuit recently affirmed the dismissal of a closely watched False Claims Act (FCA) suit in United States ex rel. Ge v. Takeda Pharmaceutical Co. because the relator’s complaint failed to identify any examples of actual false claims presented to the federal government. The relator Helen Ge, alleged that Takeda, a pharmaceutical company, failed to inform the U.S. Food and Drug Administration (FDA) of adverse events associated with its drugs Uloric, Kapidex/Dexlant, Prevacid, and Actos. Federal law requires Takeda to inform the FDA of such adverse events. According to Ge, claims for the reimbursement of Takeda drugs under federal Medicare and state Medicaid programs must have been false because Takeda failed to inform the FDA of adverse events associated with those drugs. The First Circuit held that such allegations do not rise to the level of particularity required by the federal rules.

The Takeda case has been closely watched since the district court dismissed the case in November 2012. The district court’s dismissal order stated that compliance with the FDA’s reporting requirements was not a material condition of payment. Although the FDA has the discretion to remove drugs that are marketed in violation of the adverse-event reporting requirement, it is not required to do so. Thus, in the district court’s view, claims such as Ge’s would always be subject to dismissal. Continue reading “First Circuit Ends Closely Watched Takeda Suit With Limited Ruling”

Exit mobile version
%%footer%%