The Cybersecurity and Infrastructure Security Agency (“CISA”) released a new guide on August 2, 2024 titled, “Software Acquisition Guide for Government Enterprise Consumers: Software Assurance in the Cyber-Supply Chain Risk Management (C-SCRM) Lifecycle” (the “Software Acquisition Guide”).  This guide addresses the cybersecurity risks associated with the acquisition and use of third-party developed software and certain related physical products in an agency enterprise environment, and provides recommendations to agency personnel for understanding, addressing, and mitigating those risks.  This guide was followed on August 6, 2024, by a separate guide issued jointly by CISA and the FBI titled, “Secure By Demand Guide: How Software Customers Can Drive a Secure Technology Ecosystem” (the “Secure By Demand Guide”).  Together, these two guides provide agency and industry personnel a series of questions that can be used to obtain information from suppliers, set technical requirements, and develop contract terms for the acquisition of secure software as contemplated by the Biden Administration’s May 2021 Cybersecurity Executive Order (“EO”) and the Office of Management and Budget (“OMB”) memoranda implementing that Order. 

The specific impact that the guides will have on federal procurements and software developers in the federal supply chain is not yet clear.  With this said, all software producers in the federal supply chain are currently required to fully comply with new secure software development minimum requirements promulgated by the Office of Management and Budget by September 8 of this year, as detailed in our prior post here.  The Software Acquisition Guide in particular builds on those requirements and thus could be adopted by agencies that opt to impose additional obligations on contractors beyond those minimum requirements.

Continue Reading New Guides Released Relating to Secure Software Development Requirements

This is part of an ongoing series of Covington blogs on implementation of Executive Order 14028, “Improving the Nation’s Cybersecurity,” issued by President Biden on May 12, 2021 (the “Cyber EO”).  The first blog summarized the Cyber EO’s key provisions and timelines, and subsequent blogs described the actions taken by various government agencies to implement the Cyber EO from June 2021 through June 2024.  This blog describes key actions taken to implement the Cyber EO during July 2024.  It also describes key actions taken during July 2024 to implement President Biden’s Executive Order on Artificial Intelligence (the “AI EO”), particularly its provisions that impact cybersecurity, national security, and software supply chain security.

Continue Reading July 2024 Developments Under President Biden’s Cybersecurity Executive Order and AI Executive Order

Earlier this month, the FAR Council took action to extend its existing authority to collect information from government contractors for novation requests with a notice in the Federal Register.  While this was a routine action, it is a reminder that the novation process is in need of serious attention.  The

Continue Reading It’s Time to Re-Imagine FAR Subpart 42.12:  Ways to Improve the Novation Process

This is part of an ongoing series of Covington blogs on implementation of Executive Order 14028, “Improving the Nation’s Cybersecurity,” issued by President Biden on May 12, 2021 (the “Cyber EO”).  The first blog summarized the Cyber EO’s key provisions and timelines, and subsequent blogs described the actions taken by various government agencies to implement the Cyber EO from June 2021 through May 2024.  This blog describes key actions taken to implement the Cyber EO, as well as the U.S. National Cybersecurity Strategy, during June 2024.  It also describes key actions taken during May 2024 to implement President Biden’s Executive Order on Artificial Intelligence (the “AI EO”), particularly its provisions that impact cybersecurity, national security, and software supply chain security.

Continue Reading June 2024 Developments Under President Biden’s Cybersecurity Executive Order, National Cybersecurity Strategy, and AI Executive Order

This is part of an ongoing series of Covington blogs on implementation of Executive Order 14028, “Improving the Nation’s Cybersecurity,” issued by President Biden on May 12, 2021 (the “Cyber EO”).  The first blog summarized the Cyber EO’s key provisions and timelines, and subsequent blogs described the actions taken by various government agencies to implement the Cyber EO from June 2021 through April 2024.  This blog describes key actions taken to implement the Cyber EO, as well as the U.S. National Cybersecurity Strategy, during May 2024.  It also describes key actions taken during May 2024 to implement President Biden’s Executive Order on Artificial Intelligence (the “AI EO”), particularly its provisions that impact cybersecurity, national security, and software supply chain security.

Continue Reading May 2024 Developments Under President Biden’s Cybersecurity Executive Order, National Cybersecurity Strategy, and AI Executive Order

A recent decision by the Armed Services Board of Contract Appeals found the Navy liable to a commercial crane manufacturer for delay damages. In Konecranes Nuclear Equip. & Servs., LLC, ASBCA No. 62797, 2024 WL 2698011 (May 7, 2024), the Board reiterated the age-old lesson—you have to read the contract—and provided guidance about how to calculate the delay damages. Beyond that, the Board found apparent inspiration for part of its holding in an unlikely source: a classic song by the Rolling Stones.

Continue Reading You Can’t Always Get What You Want: ASBCA Channels Rolling Stones and Awards Contractor $4.9 Million in Delay Damages

The Federal government may soon adopt new rules for when indefinite delivery contracts and orders are subject to the Cost Accounting Standards. According to a June 18, 2024 notice, the CAS Board is considering multiple different approaches to this issue, and it has invited comments from the public.

Continue Reading Wondering Whether Your IDIQ Award Will Be Subject to CAS?  New Rules May Be Coming Soon from the CAS Board.

On June 7, 2024, the Federal Circuit issued a major decision addressing bid protest jurisdiction and standing at the Court of Federal Claims (“COFC”).  In Percipient.ai, Inc. v. United States, the court found that COFC has jurisdiction to hear a protest challenging a matter of contract administration — even where the matter arose in connection with a task order — and articulated a new test for standing applicable to the facts presented in that case. 

Continue Reading Percipient.ai, Inc. v. U.S.:  Matters of Contract Administration Can Be Fair Game For COFC Protests, Even When They Involve a Task Order

This is part of an ongoing series of Covington blogs on implementation of Executive Order 14028, “Improving the Nation’s Cybersecurity,” issued by President Biden on May 12, 2021 (the “Cyber EO”).  The first blog summarized the Cyber EO’s key provisions and timelines, and the subsequent blogs described the actions taken by various government agencies to implement the Cyber EO from June 2021 through March 2024.  This blog describes key actions taken to implement the Cyber EO, as well as the U.S. National Cybersecurity Strategy, during April 2024.  It also describes key actions taken during April 2024 to implement President Biden’s Executive Order on Artificial Intelligence (the “AI EO”), particularly its provisions that impact cybersecurity, national security, and secure software.

Continue Reading April 2024 Developments Under President Biden’s Cybersecurity Executive Order, National Cybersecurity Strategy, and AI Executive Order

Recently, the Department of Labor (“DOL”) Office of Federal Contract Compliance Programs (“OFCCP”) unveiled new guidance regarding the use of automated systems and artificial intelligence (collectively referred to as “AI”) in the workplace.  This guidance was issued as a part of a series of actions that the Biden administration has taken to address AI in various contexts and industries. 

The OFCCP guidance follows President Biden’s Executive Order on the Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence, which directed the Secretary of Labor to “publish guidance for Federal contractors regarding nondiscrimination in hiring involving AI and other technology-based hiring systems.”  Specifically, the guidance addresses how federal prime contractors and subcontractors should approach employment nondiscrimination risks and best practices when using AI in the context of the laws that OFCCP enforces.

Continue Reading Office of Federal Contract Compliance Programs Releases New Guidance on the Use of Artificial Intelligence in Federal Contracting Employment Processes