Beyond the CMMC: New Cybersecurity Assessments for Government Contractors

Winston & Strawn – The General Services Administration (GSA) recently announced changes to procedural guidance that may affect contractor eligibility for GSA contracts. GSA issued the IT Security Procedural Guide: Protecting Controlled Unclassified Information (CUI) in Nonfederal Systems and Organizations Process, which set out a cybersecurity framework for protecting CUI that is similar to the Cybersecurity Maturity Model Certification (CMMC) for DoD contracts. The guidance sets forth both substantive cybersecurity requirements and an assessment process for those cybersecurity requirements, but differs from the CMMC in several important respects.
