Skip to main content
Leech Tishman: Legal Services
  • Why LT
    • About Us
    • Leadership
    • Life at LT
    • Careers
  • People
  • Capabilities
    • Practice Groups
      • Business Restructuring & Insolvency
        • Business Restructuring & Insolvency Overview
        • Bankruptcy Chapters 7 and 13 Debtor
        • Bankruptcy Chapter 11 Debtor
        • Bankruptcy Chapter 11 Subchapter V Debtor
        • Business Wind Down and Liquidation
        • Court Appointed Trustees and Receivers
        • Creditors’ Rights
        • Official Committee of Unsecured Creditors in Chapter 11 Bankruptcy Proceedings
        • Prosecution and Defense of Avoidance Actions in Bankruptcy
        • Real Estate-Related Insolvency
      • Construction
      • Corporate
        • Corporate Overview
        • Asset Protection
        • Business Succession
        • Capital Markets
        • Commercial Contracts
        • Construction
        • Corporate Compliance & Ethics Program
        • Corporate Governance
        • Data Privacy & Cybersecurity
        • General Counsel
        • Government Relations
        • Investment Advisory
        • Lending
        • Mergers & Acquisitions
        • Nonprofits & Tax-Exempt Organizations
        • Secured Transactions
        • Securities
        • Software Development and Licensing
        • Start-Up Services
        • Tax
        • Women/Minority-Owned Businesses
      • Healthcare
        • Healthcare Overview
        • Healthcare Litigation
        • Healthcare Regulatory Compliance
        • Healthcare Corporate Transactions
        • Healthcare Government Investigations
      • Intellectual Property
        • Intellectual Property Overview
        • Copyright Protection
        • Litigation – Copyright
        • Litigation – Patent
        • Litigation – Trademark
        • Patent Preparation and Prosecution
        • Patent Validity, Infringement and Freedom to Operate Opinions
        • Trade Secret
        • Technology Agreements and Transactions
        • Trademark Clearance, Preparation, Prosecution and Maintenance
      • Labor & Employment
        • Labor & Employment Overview
        • Discrimination, Sexual Harassment and Employment Litigation
        • Employment Policies & Prevention
        • ERISA, Employee Benefits & Executive Compensation
        • Immigration
        • Public Sector Employment
        • Restrictive Covenants / Non-Competes
        • Traditional Labor Law
        • Wage and Hour
        • Workplace Investigations
        • Workplace Privacy
        • Workplace Safety/OSHA
      • Litigation
        • Litigation Overview
        • ADA Title III Defense Litigation
        • Alternative Dispute Resolution
        • Appellate
        • Commercial Litigation
        • Construction Litigation
        • Defamation: Libel, Slander, and Commercial Disparagement
        • E-Discovery
        • Election Law
        • Family Law and Matrimonial Law
        • Government & Internal Investigations
        • Insurance Coverage
        • Trusts & Estates Litigation
        • Product Liability Defense
        • Real Estate Litigation
        • Restrictive Covenants / Non-Competes
        • Shareholder / Equity Disputes
        • White Collar Defense
      • Real Estate
        • Real Estate Overview
        • Assessments and Appeals
        • Development
        • Environmental
        • Franchise Development & Leasing
        • Landlord/Tenant Law
        • Leasing
        • New York Co-Ops and Condominiums (Closing Capabilities)
        • Oil & Gas
        • Permitting and Zoning
        • Real Estate Litigation
        • Real Estate-Related Insolvency
        • Transactional Commercial
        • Transactional Residential
        • Leech Tishman Closings
      • Tax
      • Trusts & Estates
        • Trusts & Estates Overview
        • Asset Protection
        • Basic & Complex Estate Planning
        • Charitable Planning & Giving
        • Federal Estate, Gift, and Fiduciary Taxation and Compliance
        • Florida Homestead Exemption
        • Guardianships
        • Marital Agreements
        • Private Foundations
        • Probate and Orphans’ Court Practice
        • Special Needs Planning
        • State Estate, Inheritance, and Fiduciary Taxation and Compliance
        • Tax
        • Trust & Estate Administration
        • Trusts & Estates Litigation
        • Trust Creation, Modification, and Termination
    • Industries
      • Aviation & Aerospace
      • Beauty & Wellness
      • Cannabis
      • Data Privacy & Cybersecurity
      • Energy & Natural Resources
      • Entertainment & Sports
      • Healthcare
      • Life Sciences
    • International
      • International Overview
      • Asia Practice
      • Europe Practice
      • Latin America Practice
      • Middle East Practice
  • Insights
    • Client Alerts
    • Tariff Tracker
    • Firm News
    • Press
    • Events
    • Success Stories
    • Podcasts
    • Resources
    • Videos
  • Offices
  • Careers
  • Payments
  • Contact
Leech Tishman: Legal Services
  • Careers
  • Payments
  • Contact
  • Why LT
    • About Us
    • Leadership
    • Life at LT
    • Careers
  • People
  • Capabilities
    • Practice Groups
      • Business Restructuring & Insolvency
        • Business Restructuring & Insolvency Overview
        • Bankruptcy Chapters 7 and 13 Debtor
        • Bankruptcy Chapter 11 Debtor
        • Bankruptcy Chapter 11 Subchapter V Debtor
        • Business Wind Down and Liquidation
        • Court Appointed Trustees and Receivers
        • Creditors’ Rights
        • Official Committee of Unsecured Creditors in Chapter 11 Bankruptcy Proceedings
        • Prosecution and Defense of Avoidance Actions in Bankruptcy
        • Real Estate-Related Insolvency
      • Construction
      • Corporate
        • Corporate Overview
        • Asset Protection
        • Business Succession
        • Capital Markets
        • Commercial Contracts
        • Construction
        • Corporate Compliance & Ethics Program
        • Corporate Governance
        • Data Privacy & Cybersecurity
        • General Counsel
        • Government Relations
        • Investment Advisory
        • Lending
        • Mergers & Acquisitions
        • Nonprofits & Tax-Exempt Organizations
        • Secured Transactions
        • Securities
        • Software Development and Licensing
        • Start-Up Services
        • Tax
        • Women/Minority-Owned Businesses
      • Healthcare
        • Healthcare Overview
        • Healthcare Litigation
        • Healthcare Regulatory Compliance
        • Healthcare Corporate Transactions
        • Healthcare Government Investigations
      • Intellectual Property
        • Intellectual Property Overview
        • Copyright Protection
        • Litigation – Copyright
        • Litigation – Patent
        • Litigation – Trademark
        • Patent Preparation and Prosecution
        • Patent Validity, Infringement and Freedom to Operate Opinions
        • Trade Secret
        • Technology Agreements and Transactions
        • Trademark Clearance, Preparation, Prosecution and Maintenance
      • Labor & Employment
        • Labor & Employment Overview
        • Discrimination, Sexual Harassment and Employment Litigation
        • Employment Policies & Prevention
        • ERISA, Employee Benefits & Executive Compensation
        • Immigration
        • Public Sector Employment
        • Restrictive Covenants / Non-Competes
        • Traditional Labor Law
        • Wage and Hour
        • Workplace Investigations
        • Workplace Privacy
        • Workplace Safety/OSHA
      • Litigation
        • Litigation Overview
        • ADA Title III Defense Litigation
        • Alternative Dispute Resolution
        • Appellate
        • Commercial Litigation
        • Construction Litigation
        • Defamation: Libel, Slander, and Commercial Disparagement
        • E-Discovery
        • Election Law
        • Family Law and Matrimonial Law
        • Government & Internal Investigations
        • Insurance Coverage
        • Trusts & Estates Litigation
        • Product Liability Defense
        • Real Estate Litigation
        • Restrictive Covenants / Non-Competes
        • Shareholder / Equity Disputes
        • White Collar Defense
      • Real Estate
        • Real Estate Overview
        • Assessments and Appeals
        • Development
        • Environmental
        • Franchise Development & Leasing
        • Landlord/Tenant Law
        • Leasing
        • New York Co-Ops and Condominiums (Closing Capabilities)
        • Oil & Gas
        • Permitting and Zoning
        • Real Estate Litigation
        • Real Estate-Related Insolvency
        • Transactional Commercial
        • Transactional Residential
        • Leech Tishman Closings
      • Tax
      • Trusts & Estates
        • Trusts & Estates Overview
        • Asset Protection
        • Basic & Complex Estate Planning
        • Charitable Planning & Giving
        • Federal Estate, Gift, and Fiduciary Taxation and Compliance
        • Florida Homestead Exemption
        • Guardianships
        • Marital Agreements
        • Private Foundations
        • Probate and Orphans’ Court Practice
        • Special Needs Planning
        • State Estate, Inheritance, and Fiduciary Taxation and Compliance
        • Tax
        • Trust & Estate Administration
        • Trusts & Estates Litigation
        • Trust Creation, Modification, and Termination
    • Industries
      • Aviation & Aerospace
      • Beauty & Wellness
      • Cannabis
      • Data Privacy & Cybersecurity
      • Energy & Natural Resources
      • Entertainment & Sports
      • Healthcare
      • Life Sciences
    • International
      • International Overview
      • Asia Practice
      • Europe Practice
      • Latin America Practice
      • Middle East Practice
  • Insights
    • Client Alerts
    • Tariff Tracker
    • Firm News
    • Press
    • Events
    • Success Stories
    • Podcasts
    • Resources
    • Videos
  • Offices
    • How can we help you?

Insights

News Types

  • All
  • Client Alerts
  • Tariff Tracker
  • Firm News
  • Press
  • Events
  • Success Stories
  • Executive Orders
  • Resources
  • Videos
  • 30 Years, 30 Stories

Archives

Navigating DOJ Cybersecurity Enforcement: A Foundation for Best Practices with the NIST Framework

March 27, 2026

By: Lydia A. Pappas, Esq.

Download this article here

The Department of Justice’s increased enforcement of cybersecurity regulations leaves government contractors with two options: Comply fully with cybersecurity guidelines, or risk penalties such as expensive legal cases and debarment.

Government contracts typically include a specific set of cybersecurity rules meant to protect controlled unclassified information (“CUI”), which includes technical data, research, and sensitive project information. Although unclassified, CUI can nonetheless pose risks to national security if hackers use the information to gain insight into other classified projects.

Government agencies, therefore, require contractors to comply with rules such as the Federal Acquisition Regulations (“FAR”) or the Cybersecurity Maturing Model Certification (“CMMC”) program. But the foundation for most Government-imposed guidelines was first created by the National Institute of Standards and Technology (“NIST”), an agency under the U.S. Department of Commerce.

The NIST framework for protecting CUI includes detailed technical recommendations to secure information systems and manage cybersecurity risks. It was developed in response to several high-profile data breaches in the 2010s when hackers realized it was easier to access sensitive information through private companies with less secure systems than directly through government systems.

The framework was initially released in 2015 as NIST Special Publication 800-171. It has since been revised multiple times and was supplemented by the 2021 release of NIST Special Publication 800-172.

The NIST publications are not in themselves a law but a detailed security guideline. However, the NIST framework forms the core and defines key terms for various mandatory regulations, including the CMMC, the FAR, and the Department of Defense Federal Acquisition Regulation Supplement (“DFARS”).

NIST Special Publication 800-171: The Foundation

It’s imperative for organizations handling CUI to comply with the NIST framework. This applies regardless of contract size and includes defense contractors, research institutions, and healthcare providers. Any vulnerabilities in cybersecurity systems can harm national interests.

At first glance, the NIST framework can seem like a complicated, endless list, but it is essentially a commonsense outline of already existing industry standards. NIST 800-171 outlines 110 security requirements to protect CUI in non-federal systems and organizations.

Those requirements are organized into 14 control families:

    1. Access Control: Controlling who can access systems and data, limiting access to authorized individuals, imposing strong password policies, and automatically locking sessions after a period of inactivity.
    2. Awareness and Training: Training all employees to understand the security risks associated with their jobs and be able to recognize potential threats (such as phishing emails).
    3. Audit and Accountability: Creating automatic logs of who did what and when throughout the system. Logs are critical when investigating a breach.
    4. Configuration Management: Controlling what can be downloaded to a device connected to the system, which prevents the inadvertent introduction of unauthorized software or malware.
    5. Identification Authentication: Utilizing passwords and multi-factor authentication to verify user identities prior to granting access.
    6. Incident Response: Creating a plan for when a breach occurs. Security incidents are inevitable, no matter how strong your systems are. You need to have a plan to detect, analyze, contain, eradicate, recover, and properly report an attack.
    7. Maintenance: Ensuring maintenance is performed regularly and by authorized personnel.
    8. Media Protection: Properly destroying any media that contains CUI once it is no longer needed. Media is anything that can store data, such as a thumb-drive, external hard drive, and even CDs or printed hard copies.
    9. Personal Security: Thoroughly screening individuals prior to granting them access to CUI and disabling access immediately upon de-authorization of an individual.
    10. Physical and Environmental Protection: Restricting physical access to server rooms by locking doors, controlling access to workstations and printers, and maintaining visitor logs.
    11. Risk Assessment: Regularly monitoring systems for new vulnerabilities and taking steps to address them once identified.
    12. Security Assessment: Testing your own security plans to ensure they stay up to date and effective.
    13. System and Communications Protection: Protecting the flow of information over and out of the network with firewalls and encryption and insulating your private network from the public internet.
    14. System and Information Integrity: Utilizing anti-virus and anti-malware software, monitoring systems for indications of an attack or breach, and having a plan for security patches if necessary.

All 110 requirements and associated objectives need to be implemented for a company to be compliant with NIST 800-171.

NIST Special Publication 800-172: The Expansion

NIST 800-172 added 35 additional requirements to the NIST 800-171 in 2021, expanding 10 of the control families outlined above. The supplemental requirements include proactively hunting for cyber threats, rotating passwords, using two-person access controls, and more.

Companies hoping to snag top priority contracts with the U.S. Department of Defense must meet the heightened security requirements of the NIST 800-172, otherwise they’ll fall short of the necessary CMMC trust level.


This alert is part four of an ongoing series through which Leech Tishman will track developments in the DOJ’s Cybersecurity Fraud Enforcement program and issue continuing legal updates addressing compliance obligations, impacted industries, and the relevant regulatory requirements. View the previous alert in the series here.

Leech Tishman’s Labor & Employment attorneys regularly counsel clients on compliance with statutory and common law requirements. Our team is prepared to assist your company in understanding and implementing the obligations and compliance measures required under the DOJ’s Cybersecurity Fraud Enforcement program. For assistance or additional information, please contact Lydia A. Pappas at lpappas@leechtishman.com, attorney in Leech Tishman’s Labor & Employment Practice Group.

Share on:
  • Facebook
  • Twitter
  • LinkedIn
  • Careers
  • Insights
  • Payments
  • People
  • Contact
  • Chicago, IL
  • Los Angeles, CA
  • Miami/FLL, FL
  • New York, NY
  • Philadelphia, PA
  • Pittsburgh, PA
  • Sarasota, FL
  • State College, PA
  • Washington, D.C.

Sign up for our Client Alerts

Newsletter Signup
  • LinkedIn
  • Twitter
  • Facebook

Copyright © 2026 Leech Tishman: Legal Services All rights reserved.

  • Terms and Conditions
  • Privacy Policy
  • Personnel Privacy Policy
We use cookies to provide and improve your experience on our website. By clicking Accept you are agreeing to the use of these cookies. However, you do have the option to select Deny but your digital experience may be negatively impacted.