The U.S. Department of Defense’s Cybersecurity Maturity Model Certification (CMMC) Program will become operational at some point in fiscal year 2025. In October, the DOD issued a Final Rule to address evolving cybersecurity requirements and cyber threats while defining the security controls that DOD intends defense contractors and subcontractors to implement. The program will require defense contractors and subcontractors to obtain the requisite certification level depending on whether their respective information systems will process, store, or transmit Federal Contract Information and/or Controlled Unclassified Information (CUI). The Rule spawned a litany of questions during the public comment period, most notably around the area of CUI. In this Feature Comment, Alexander Major and Philip Lee address the fundamental challenge facing the CMMC: how can contractors protect the controlled unclassified data that DOD can’t/won’t/isn’t properly identifying?

Read More

Photo of Alex Major Alex Major

Mr. Major is a partner and co-leader of the firm’s Government Contracts & Export Controls Practice Group. Mr. Major focuses his practice on federal procurement, cybersecurity liability and risk management, and litigation. A prolific author and thought leader in the area of cybersecurity…

Mr. Major is a partner and co-leader of the firm’s Government Contracts & Export Controls Practice Group. Mr. Major focuses his practice on federal procurement, cybersecurity liability and risk management, and litigation. A prolific author and thought leader in the area of cybersecurity, his professional experience involves a wide variety of litigation and counseling matters dealing with procurement laws and federal regulations and standards. His diverse experience includes complex litigation in federal court under the qui tam provisions of the False Claims Act and bid protest actions. He counsels all sizes of companies on issues relating to compliance with government regulations including, among other things, cybersecurity (NIST, FIPS, FedRAMP, and DFARS) requirements, multiple award schedule compliance, Section 508 issues, country of origin requirements under the Buy American and Trade Agreements Acts, cost accounting, and small business requirements. He also regularly conducts internal investigations to assist companies ensure that they are in full compliance with the law.

Photo of Philip Lee Philip Lee

Philip Lee represents government contractors in a broad range of industries including professional services, information technology, and aerospace in bid protests, investigations, contract claims, including terminations for convenience and default, and disputes between subcontractors and prime contractors. He leverages his legal experience and…

Philip Lee represents government contractors in a broad range of industries including professional services, information technology, and aerospace in bid protests, investigations, contract claims, including terminations for convenience and default, and disputes between subcontractors and prime contractors. He leverages his legal experience and practical knowledge to assist companies with the review and analysis of federal and state solicitations, compliance with federal procurement regulations and related statutes, including small business regulations and issues, and the preparation and negotiation of teaming agreements, joint venture agreements, and subcontracts.

Prior to joining the firm, Philip was an attorney-advisor for the Department of Homeland Security where he provided legal advice and recommendations on a variety of procurement matters including research and development, tests, and evaluation activities performed by public and private sector entities. He also previously served as a contracting officer with the Department of the Interior and was responsible for ensuring contracts, modifications, and both government and contractor performance were compliant with statutory law, the Federal Acquisition Regulation (FAR), and appropriations law.

Philip’s previous experience as both a government attorney and contracting officer provides a unique government contracts perspective to government contractors.  This includes real-world experience in all aspects of the procurement cycle, from pre-solicitation to contract award and administration.  Philip’s practical experience in federal procurement was further augmented while serving as an attorney-advisor where he counseled contracting officers with solicitation and pre-award reviews as well as defending bid protests before the Government Accountability Office.  Philip’s unique insight provides a valuable perspective to government contractors and their procurement issues.