GSA Quietly Raises the Cybersecurity Bar for Contractors Handling CUI
Article by: Steffanie Lee, Associate On January 5, 2026, the General Services Administration (“GSA”) issued CIO-IT Security-21-112 Revision 1, a procedural guide establishing new requirements for protecting Controlled Unclassified Information (“CUI”) in nonfederal contractor systems. While not promulgated as a FAR rule, the guide establishes a mandatory approval framework that contracting officers may apply...
Read More
What Federal Contractors Should Know About the Government Shutdown
Those of us who have spent time working in—or with—the federal government over the past several decades know that government shutdowns are not entirely uncommon. There have actually been a total of 21 government shutdowns over the past 50 years, with the last occurring in 2019 and the longest lasting 35 days. By the...
Read More
Two CAS Moves in One Day: What Small Contractors Need to Know
On September 11, 2025, the Office of Management & Budget’s (“OMB”) Cost Accounting Standards Board, which is chaired by the Office of Federal Procurement Policy (“OFPP”), dropped two important updates: A final rule that simplifies how revenue and leases are handled under CAS; and A proposed rule that would scale back or align four...
Read More
Federal Circuit, Sitting En Banc, Reverses Landmark Panel Decision on Bid Protest Standing
Back in June 2024, we wrote about a 3-judge panel’s holding in Percipient.AI, Inc. v. United States, 104 F.4th 839 (Fed. Cir. 2024), that a contractor was permitted to bring a bid protest against the government alleging violations of a procurement statute even though it did not “challenge a contract, proposed contract, or solicitation...
Read More
Proposed SBA Rule Would Drastically Change the Impact of Small Business Size/Status Recertifications
The SBA recently released a proposed rule that would bring significant changes to small business size and small business socioeconomic program (Woman-Owned Small Business Program, Veteran-Owned Small Business Program, etc.) recertifications. Such recertifications are especially important in the context of indefinite delivery/indefinite quantity (IDIQ) contracts, which contemplate the award of future task orders to...
Read More
DoJ Files False Claims Act Suit Against University Based on Alleged Failure to Implement Adequate Cybersecurity Controls
On August 22, 2024, the Department of Justice (DoJ) filed a lengthy complaint againstGeorgia Tech alleging that the university had misrepresented its compliance with several important cybersecurity regulations that outline what contractors must to do to protect government information residing on, passing through, or accessible by contractor systems. Ironically, the complaint focuses on allegedly...
Read More