The Trump Administration has declared this month National Slavery and Human Trafficking Prevention Month, calling on industry associations, law enforcement, private businesses, and others to work toward ending modern slavery and human trafficking. This proclamation follows the Administration’s efforts to combat human trafficking, which we have previously discussed here, and comes on the heels of an OMB memorandum released last fall aimed at “enhanc[ing] the effectiveness of anti-trafficking requirements in Federal acquisition while helping contractors manage and reduce the burden associated with meeting these responsibilities.”
Continue Reading Trump Administration Renews Focus on Anti-Human Trafficking Efforts
Momentum In Drug Pricing Reform: House Passes New Legislation on the Heels of Presidential Candidates’ Drug Pricing Proposals
Late last week, House Democrats passed Speaker Nancy Pelosi’s Elijah E. Cummings Lower Drug Costs Now Act. This bill would, among other things, permit the Department of Health and Human Services (“HHS”) to negotiate lower prices for 250 of the costliest drugs on behalf of Medicare beneficiaries and other consumers.
Continue Reading Momentum In Drug Pricing Reform: House Passes New Legislation on the Heels of Presidential Candidates’ Drug Pricing Proposals
DoD Releases Version 0.7 of Its Cybersecurity Maturity Model Certification
On December 13, the Department of Defense (“DoD”) released the latest version of its Cybersecurity Maturity Model Certification (“CMMC”). This is the third iteration of the draft model that DoD has publicly released since it issued the first draft in October. (We previously discussed Version 0.4 and Version 0.6 of the CMMC in prior blog posts.)
DoD describes the CMMC as “a DoD certification process that measures a DIB sector company’s ability to protect FCI [Federal Contract Information] and CUI [Controlled Unclassified Information].” DoD has stated publicly that it intends to begin incorporating certification requirements into solicitations starting in Fall 2020, with compliance audits beginning in late 2020 or early 2021. Depending the sensitivity of the information that contractors will receive in the course of performing work for DoD, they will be expected to demonstrate compliance through third party audits with the requirements set forth under one of five certification levels. This applies even where contractors will not be handling FCI or CUI in the course of performing their contracts.[1]
The two most significant updates to the model in this version of the draft are (i) the addition of “Practices” for obtaining Level 4 and 5 certifications, and (ii) an expansion of “clarifications” section, which now covers the requirements of Levels 2 and 3 of the model, in addition to Level 1. These changes and others are discussed in more detail below. Given the expected release in late January 2020, it is likely that the requirements in this draft will closely resemble those that will be set forth in Version 1.0 of the CMMC framework, which is anticipated to serve as the basis for the first contractor audits.Continue Reading DoD Releases Version 0.7 of Its Cybersecurity Maturity Model Certification
Commerce Department Proposes Rule Impacting Information and Communications Technology Supply Chains
On November 27, 2019, the Department of Commerce issued a proposed rule to implement the May 15, 2019 Executive Order entitled “Securing the Information and Communications Technology and Services Supply Chain.” Once finalized and effective, the regulations will govern the process and procedures that the Secretary of Commerce will use to determine whether certain transactions involving information and communications technology or services (“ICTS”) should be prohibited or otherwise restricted. As currently drafted, the proposed rule goes further than many other legal authorities, in that it allows the government to prohibit or otherwise restrict a broad range of wholly commercial transactions that the Secretary determines present national security risks.
Details on key aspects of the proposed rule are in a Client Alert that we published on November 27, available here. The public comment period remains open until December 27. Given the breadth of the proposed rule and the significant number of open questions, thoughtful comments will be critically important in scoping a final rule.
Continue Reading Commerce Department Proposes Rule Impacting Information and Communications Technology Supply Chains
New FAR Rule Expands Counterfeit Reporting Obligations
Last week, the FAR Council issued a Final Rule, setting forth new FAR provisions that require the reporting of certain counterfeit and suspect counterfeit parts and certain major or critical nonconformances to the Government – Industry Data Exchange Program (“GIDEP”).[1] This Final Rule comes more than five years after the rule was first proposed in the Federal Register in June 2014. The FAR Council describes the Final Rule as “significantly de-scoped” from the version proposed in 2014, but it nonetheless constitutes a significant expansion of the existing counterfeit part reporting obligations, which to date have applied only to electronic parts under DOD contracts.
Continue Reading New FAR Rule Expands Counterfeit Reporting Obligations
OFCCP Proposes Rule Removing TRICARE Health Care Providers from Its Regulatory Authority
On November 6, 2019, the Department of Labor’s Office of Federal Contract Compliance Programs (“OFCCP”) issued a Notice of Proposed Rulemaking (“NPRM”) aimed at resolving what OFCCP describes as a “decade of confusion.”[1] At issue is a long-standing question concerning the scope of OFCCP’s enforcement authority over health care providers participating in TRICARE, a federal health care program covering millions of military personnel, veterans, and their families. In particular, the NPRM requests comments on proposed regulations that would amend OFCCP’s definition of “subcontractor” and thereby remove TRICARE providers–and potentially other categories of providers–from OFCCP’s regulatory authority entirely. The deadline for filing comments is December 6, 2019.
Continue Reading OFCCP Proposes Rule Removing TRICARE Health Care Providers from Its Regulatory Authority
What Is Lowest Priced Technically Acceptable? GAO Clarifies Reach of New LPTA Restrictions
As previously discussed on this blog, the National Defense Authorization Act for Fiscal Year 2017 and the NDAA for Fiscal Year 2018 imposed new limitations on when the Department of Defense can use Lowest Price Technically Acceptable source selection methods. Just last month, the Department of Defense issued a final rule amending the Defense Federal Acquisition Regulation Supplement to implement those provisions. Now, in Inserso Corp., B-417791, B-417791.3, Nov. 4, 2019, GAO has weighed in on what counts as LPTA for purposes of those restrictions. This decision may indicate a potentially significant limitation on the reach of the NDAA provisions, new DFARS rule, and proposed FAR rule.
Continue Reading What Is Lowest Priced Technically Acceptable? GAO Clarifies Reach of New LPTA Restrictions
DoD Releases Version 0.6 of its Cybersecurity Maturity Model Certification
On November 7, the Office of the Assistant Secretary of Defense for Acquisition released Version 0.6 of its draft Cybersecurity Maturity Model Certification (CMMC) for public comment. The CMMC was created in response to growing concerns by Congress and within DoD over the increased presence of cyber threats and intrusions aimed at the Defense Industrial Base (DIB) and its supply chains.
The model updates Version 0.4, which DoD released on September 4, 2019, and which we wrote about here. The CMMC establishes the framework necessary for contractors to obtain one of five certification levels necessary to perform work on certain DoD contracts, including those that require the handling of Controlled Unclassified Information. Whereas Version 0.4 merely listed the capabilities, controls, and processes that were expected to apply to each certification level, this version provides some additional discussion and clarification to assist contractors with meeting Level 1 certifications.
DoD has not explicitly asked for comment on this version of the CMMC, and has stated that the updated model is being released “so that the public can review the draft model and begin to prepare for the eventual CMMC roll out.” For this reason, although additional changes are to be expected to the model, contractors should review the general requirements closely to ensure that they are positioned to continue bidding on DoD contracts once DoD begins including a requirement to obtain a specific certification level in Requests for Proposal in Fall 2020.
Continue Reading DoD Releases Version 0.6 of its Cybersecurity Maturity Model Certification
Not So Fast Guy: Recent GAO Decision Provides Rule For When Agency Deadlines Are Unreasonably Short
Tight deadlines are a fact of life in the world of government contracting. Indeed, it is not unusual for the government to expect a contractor to provide large amounts of information in just a few short days. And the draconian penalty for missing such a deadline is usually the rejection of a proposal.
But can an agency’s deadline be unreasonably short? Yes. In MCR Federal, LLC, GAO determined that the agency’s deadline for submitting its final proposal revision (“FPR”) was so short that it deprived the protester of a fair opportunity to improve its proposal.Continue Reading Not So Fast Guy: Recent GAO Decision Provides Rule For When Agency Deadlines Are Unreasonably Short
The More Things Change, the More They Stay the Same: GAO’s FY 2019 Protest Statistics
GAO released its Fiscal Year 2019 protest statistics yesterday, and there are both noticeable changes and relative constants:
- Protest filings are down by 16%, which means about 400 fewer protests than FY18. The reason why is anyone’s guess, but it’s likely related in large part to GAO’s new Electronic Protest