In Viderity Inc. – Costs, GAO found an agency’s investigation into a potential conflict of interest to be unreasonable where the agency “failed to inquire with” the awardee-intervenor “as to whether the firm had a business relationship with” an agency evaluator. The decision was issued on September 1, 2026.
Continue Reading GAO Finds Conflict Investigation Unreasonable Where Agency Failed to Ask Awardee About Business Relationship
Darby Rourick
Darby Rourick is a government contracts lawyer that advises on federal contracting compliance requirements and on government and internal investigations that stem from these obligations. She has particular experience in federal cybersecurity and information technology supply chain issues. Darby has an active investigations practice and advises contractors when faced with cyber incidents involving government information, as well as representing contractors facing allegations of cyber fraud under the False Claims Act. She also counsels clients on cybersecurity incident response; compliance with federal cybersecurity laws, regulations, and standards; supplier and subcontractor security issues; and cybersecurity related investigations.
Darby has particular regulatory experience with:
Government cybersecurity supply chain issues like the Cybersecurity Maturity Model Certification (CMMC), DFARS 7012, and NIST SP 800-171 requirements; and
Information handling, marking, and dissemination requirements, including those relating to Covered Defense Information (CDI) and Controlled Unclassified Information (CUI)
She also assist clients when allegations of non-compliance arise with procurement requirements, such as in the following areas:
Procurement fraud and FAR mandatory disclosure requirements;
Allegations of violations of cybersecurity regulation;
Cyber incidents and data spills; and
Compliance with MIL-SPEC requirements, the Qualified Products List, and other sourcing obligations.
CMMC Reform Task Force Updates September 2026
Several months into the Department of War’s (DoW) suspension of the next phase of the Cybersecurity Maturity Model Certification (CMMC) Program, contractors are continuing to navigate uncertainty relating to the program. With the Department’s review underway, this post takes stock of where the program stands, what remains in effect, and what contractors should be considering.
Continue Reading CMMC Reform Task Force Updates September 2026DoW Issues Revision 3 of its Class Deviation on Security Requirements
On September 3, 2026 the Department of War (DoW) issued Revision 3 to its Class Deviation and associated Procedures, Guidance and Information (PGI) that implements a new Part 240 (consistent with the Revolutionary FAR Overhaul of Part 40, which we reported on in July). Like the proposed FAR Rule, this DFARS Class Deviation addresses supply chain and information security issues but is focused on requirements that are unique for DoW contracts.
Continue Reading DoW Issues Revision 3 of its Class Deviation on Security RequirementsProposed FAR Part 40 Rule: Consolidation of Supply Chain Security and Information Security Requirements and New Changes to the Rules
On June 23, 2026, the Federal Acquisition Regulatory Council (“FAR Council”) issued proposed rules covering several parts of the Federal Acquisition Regulation (“FAR”). The proposed rules mark the beginning of the long-awaited notice-and-comment phase of the Revolutionary FAR Overhaul (“RFO”). This blog post, focusing on FAR Part 40, provides an overview of the proposed changes to the regulations and the associated contract clauses in FAR Part 52, including the inclusion of requirements around the handling of Controlled Unclassified Information (“CUI”).
Continue Reading Proposed FAR Part 40 Rule: Consolidation of Supply Chain Security and Information Security Requirements and New Changes to the RulesThe New Executive Order on “Promoting Efficiency, Accountability, and Performance in Federal Contracting”: What Federal Contractors Need to Know
On April 30, 2026, President Trump issued an Executive Order (EO) titled, “Promoting Efficiency, Accountability, and Performance in Federal Contracting.” This EO directs agencies to make fixed-price contracts the default form of contracting, and requires agency officials to execute written justifications to use other forms of contracting. Of particular note for large contractors, the EO directs that, “[w]ithin 90 days of the date of this order, each agency head shall review and, to the maximum extent practicable and consistent with law, seek to modify, restructure, or renegotiate its 10 largest non-fixed-price contracts by dollar value . . . to facilitate use of fixed prices and performance-based incentives for contract deliverables to the maximum extent practicable.”
Continue Reading The New Executive Order on “Promoting Efficiency, Accountability, and Performance in Federal Contracting”: What Federal Contractors Need to KnowMarch 2025 Cybersecurity Developments Under the Trump Administration
This is the second blog in a series of Covington blogs on cybersecurity policies, executive orders (“EOs”), and other actions of the new Trump Administration. This blog describes key cybersecurity developments that took place in March 2025.
Trump Administration Executive Order on Achieving Efficiency
On March 19, 2025, the Trump…
Continue Reading March 2025 Cybersecurity Developments Under the Trump AdministrationJanuary and February 2025 Cybersecurity Developments Under the Biden and Trump Administrations
This is the first in a new series of Covington blogs on cybersecurity policies, executive orders, and other actions of the new Trump Administration. This blog describes key cybersecurity developments that took place in January and February 2025. Below, we outline three developments affecting cybersecurity in January and February 2025, including one from the Biden Administration, which has not been rescinded.
Biden Administration Issues Second Cybersecurity Executive Order
On January 16, in one of the final acts of the Biden Administration, the White House issued Executive Order (”EO”) 14144 on “Strengthening and Promoting Innovation in the Nation’s Cybersecurity.” EO 14144 expands on the National Cybersecurity Strategy and EO 14028, Improving the Nation’s Cybersecurity, which we first previously wrote about here. This new EO requires a range of additional security enhancements to U.S. government and supporting digital infrastructure, including improving accountability for software and cloud service providers, strengthening the security of Federal communications and identity management systems, and promoting innovative developments and use of emerging technologies for cybersecurity across agencies and with the private sector.
Continue Reading January and February 2025 Cybersecurity Developments Under the Biden and Trump AdministrationsPresident Biden signs the National Defense Authorization Act for Fiscal Year 2025
This is the first blog in a series covering the Fiscal Year 2025 National Defense Authorization Act (“FY 2025 NDAA”). This first blog will cover: (1) NDAA sections affecting acquisition policy and contract administration that may be of greatest interest to government contractors; (2) initiatives that underscore Congress’s commitment to strengthening cybersecurity, both domestically and internationally; and (3) NDAA provisions that aim to accelerate the Department of Defense’s adoption of AI and Autonomous Systems and counter efforts by U.S. adversaries to subvert them. …
Continue Reading President Biden signs the National Defense Authorization Act for Fiscal Year 2025
Penn State Agrees to Pay $1.25M in Settlement for Cybersecurity Non-Compliance False Claims Act Allegations
On Tuesday, October 22, 2024, Pennsylvania State University (“Penn State”) reached a settlement with the Department of Justice (“DoJ”), agreeing to pay the US Government (“USG”) $1.25M for alleged cybersecurity compliance violations under the False Claims Act (“FCA”). This settlement follows a qui tam action filed by a whistleblower and former employee of Penn State’s Applied Research Laboratory. The settlement agreement provides some additional insight into the priorities of DoJ’s Civil Cyber Fraud Initiative (“CFI”) and the types of cybersecurity issues of interest to the Department. It also highlights the extent to which DoJ is focusing on the full range of cybersecurity compliance obligations that exist in a company’s contract in enforcement actions.
Continue Reading Penn State Agrees to Pay $1.25M in Settlement for Cybersecurity Non-Compliance False Claims Act AllegationsCybersecurity Maturity Model Certification (CMMC) Program Final Rule Announced
On October 11, 2024, the U.S. Department of Defense (“DoD”) released an unpublished version of the Cybersecurity Maturity Model Certification (“CMMC”) Program Rule. The final rule will be published in the Federal Register on October 15, 2024 and will become effective sixty days after publication. This rule formally establishes the CMMC Program for DoD and is one of two complementary sets of regulations that govern operation of the Program.
Continue Reading Cybersecurity Maturity Model Certification (CMMC) Program Final Rule Announced