On February 7, 2023, the House Committee on Armed Services (the “Committee”) held a hearing entitled “The Pressing Threat of the Chinese Community Party to U.S. National Defense.” This hearing marked the Committee’s first in the 118th Congress and it focused on U.S. strategic competition with the Chinese Communist Party (“CCP”) of the People’s Republic of China (“PRC”). This overview is the first in a series of legislative updates we will provide on congressional oversight activities related to China throughout the Congress, including specific activities focused on trade controls, supply chain dependencies, and PRC-sourced telecommunications infrastructure in U.S. networks.
Continue Reading Key Takeaways from the House Armed Services Committee Hearing on the Chinese Communist Party Threat to U.S. National DefenseDecember 2022 Developments Under President Biden’s Cybersecurity Executive Order
This is the twentieth in a series of Covington blogs on implementation of Executive Order 14028, “Improving the Nation’s Cybersecurity,” issued by President Biden on May 12, 2021 (the “Cyber EO”). The first blogsummarized the Cyber EO’s key provisions and timelines, and the subsequent blogs described the actions taken by various Government agencies to implement the Cyber EO from June 2021 through November 2022. This blog describes key actions taken to implement the Cyber EO during December 2022.
Continue Reading December 2022 Developments Under President Biden’s Cybersecurity Executive OrderGAO Releases New Procedures for Classified Bid Protests
GAO recently released new procedures for filing and handling bid protests involving classified material. The procedures emphasize that classified material cannot be filed on GAO’s Electronic Protest Docketing System (EPDS) under any circumstances. Instead:
Continue Reading GAO Releases New Procedures for Classified Bid ProtestsNIST Requests Comments on Potential Significant Updates to the Cybersecurity Framework
On January 19, 2023, the National Institute of Standards and Technology (“NIST”) published a Concept Paper setting out “Potential Significant Updates to the Cybersecurity Framework” and requesting public feedback and comments on the proposed revisions by March 3, 2023. Originally released in 2014 and previously updated in 2018, the…
Continue Reading NIST Requests Comments on Potential Significant Updates to the Cybersecurity FrameworkDoD Seeks Early Input Regarding FY2023 NDAA Implementation in Acquisition Regulations
The Department of Defense is seeking early input on implementation of the James M. Inhofe National Defense Authorization Act for Fiscal Year 2023 (the “FY2023 NDAA”) in the Federal Acquisition Regulation and Defense Federal Acquisition Regulation. Although this early engagement process will not replace the formal rulemaking process, it presents a significant opportunity for government contractors, technology providers, industry associations, and other interested parties to provide their perspectives on acquisition-related provisions of this year’s NDAA. Providing early input can ensure that industry’s perspective is heard. Indeed, providing input at this stage may impact the future rulemaking process by guiding areas of focus and influencing ways the rule makers ask for input during the rulemaking process.
Continue Reading DoD Seeks Early Input Regarding FY2023 NDAA Implementation in Acquisition Regulations
FY2023 NDAA Makes Notable Changes to FedRAMP Program
On December 23, 2022, President Biden signed the James M. Inhofe National Defense Authorization Act for Fiscal Year 2023 (the “FY2023 NDAA”) into law. As described in Covington’s Client Alert, FY23 NDAA: Provisions of Interest for Almost All Government Contractors, the FY23 NDAA contains provisions of interest for almost all U.S. Government contractors. One provision likely to be of particular interest to U.S. contractors who provide or plan to provide cloud computing services to the U.S. Government is the FedRAMP Authorization Act (the “Act”), which codifies the Federal Risk and Authorization Management Program (“FedRAMP”).
Of note, the Act creates a “presumption of adequacy” that cloud providers with authorization from one agency can use that authorization with other agencies. This is an expansion compared to the current process which allows authorizations by the FedRAMP Joint Authorization Board, but not authorizations from individual agencies, to serve as the basis for an agency’s own authorization process. It also creates the Federal Secure Cloud Advisory Committee, comprised of 15 members of the public and private sector, to provide recommendations regarding FedRAMP and the acquisition of cloud services more generally.
Continue Reading FY2023 NDAA Makes Notable Changes to FedRAMP ProgramNDAA Prohibits Government Purchase and Use of Certain Semiconductors
On December 23, 2022, President Biden signed the James M. Inhofe National Defense Authorization Act for Fiscal Year 2023 into law. The Act contains two significant prohibitions regarding the procurement and use of semiconductor products and services from specific Chinese companies and other foreign countries of concern that will come into effect in December 2027.
Continue Reading NDAA Prohibits Government Purchase and Use of Certain SemiconductorsNew Contractor Conflict of Interest Rules May Be Coming Soon, with a Special Focus on Consulting and Advisory Contracts
In legislation passed last week, Congress directed the FAR Council to issue new rules for contractor organizational conflicts of interest. The legislation itself did not create any new OCI standards, but provided factors for the council to consider, focusing on conflicts of interest for companies that act as consultants to the government.
It is unclear at this point what the precise nature and extent of the resulting changes to the OCI rules may be. But the new law makes it likely that there will be some fairly significant revisions. Congress set a deadline of Summer 2024 for the new regulations, so the contracting community should be on the lookout for a notice of proposed rulemaking in the coming months, and should not hesitate to submit comments for the government’s consideration.
Continue Reading New Contractor Conflict of Interest Rules May Be Coming Soon, with a Special Focus on Consulting and Advisory ContractsCongress Offers Greater Hope for Defense Contractors Battling Inflation; Actual Relief Is Still Not Clear
As part of the FY23 National Defense Authorization Act (“NDAA”), Congress has given the Department of Defense authority to pay defense contractors for increased costs due to inflation. Section 822 of the NDAA amends Public Law 85-804 (50 U.S.C. 1431) to allow contractors to apply for adjustments, while also giving the DoD wide discretion to grant or deny requests. President Biden is expected to sign the FY23 NDAA soon, and Section 822 has the potential to be welcome news for contractors who have been battling inflation under multi-year, fixed-price contracts.
As readers of this blog know from prior posts, DoD has issued position papers over the last year that attempt to address inflation with existing legal tools, but as a practical matter, the Department has provided few options for contractors impacted by rising costs. The new NDAA provision could finally provide DoD with the legal support it needs to aid contractors struggling with inflation. However, many questions remain about how this law will work and whether it will actually meet the growing needs of the defense industrial base. In particular, Congress has not yet appropriated money to fund applications for relief, and DoD must prepare guidance for implementing the statute. Both of these things will need to happen before contractors can apply for and potentially receive inflation-based price adjustments under this amended Public Law 85-804 authority.
This post discusses the amendment and analyzes the hurdles that remain between defense contractors and inflationary relief.
Continue Reading Congress Offers Greater Hope for Defense Contractors Battling Inflation; Actual Relief Is Still Not ClearNovember 2022 Developments Under President Biden’s Cybersecurity Executive Order
This is the nineteenth in a series of Covington blogs on implementation of Executive Order 14028, “Improving the Nation’s Cybersecurity,” issued by President Biden on May 12, 2021 (the “Cyber EO”). The first blog summarized the Cyber EO’s key provisions and timelines, and the subsequent blogs described the actions taken…
Continue Reading November 2022 Developments Under President Biden’s Cybersecurity Executive Order