Skip to main content
Leech Tishman: Legal Services
  • Why LT
    • About Us
    • Leadership
    • Life at LT
    • Careers
  • People
  • Capabilities
    • Practice Groups
      • Business Restructuring & Insolvency
        • Business Restructuring & Insolvency Overview
        • Bankruptcy Chapters 7 and 13 Debtor
        • Bankruptcy Chapter 11 Debtor
        • Bankruptcy Chapter 11 Subchapter V Debtor
        • Business Wind Down and Liquidation
        • Court Appointed Trustees and Receivers
        • Creditors’ Rights
        • Official Committee of Unsecured Creditors in Chapter 11 Bankruptcy Proceedings
        • Prosecution and Defense of Avoidance Actions in Bankruptcy
        • Real Estate-Related Insolvency
      • Construction
      • Corporate
        • Corporate Overview
        • Asset Protection
        • Business Succession
        • Capital Markets
        • Commercial Contracts
        • Construction
        • Corporate Compliance & Ethics Program
        • Corporate Governance
        • Data Privacy & Cybersecurity
        • General Counsel
        • Government Relations
        • Investment Advisory
        • Lending
        • Mergers & Acquisitions
        • Nonprofits & Tax-Exempt Organizations
        • Secured Transactions
        • Securities
        • Software Development and Licensing
        • Start-Up Services
        • Tax
        • Women/Minority-Owned Businesses
      • Healthcare
        • Healthcare Overview
        • Healthcare Litigation
        • Healthcare Regulatory Compliance
        • Healthcare Corporate Transactions
        • Healthcare Government Investigations
      • Intellectual Property
        • Intellectual Property Overview
        • Copyright Protection
        • Litigation – Copyright
        • Litigation – Patent
        • Litigation – Trademark
        • Patent Preparation and Prosecution
        • Patent Validity, Infringement and Freedom to Operate Opinions
        • Trade Secret
        • Technology Agreements and Transactions
        • Trademark Clearance, Preparation, Prosecution and Maintenance
      • Labor & Employment
        • Labor & Employment Overview
        • Discrimination, Sexual Harassment and Employment Litigation
        • Employment Policies & Prevention
        • ERISA, Employee Benefits & Executive Compensation
        • Immigration
        • Public Sector Employment
        • Restrictive Covenants / Non-Competes
        • Traditional Labor Law
        • Wage and Hour
        • Workplace Investigations
        • Workplace Privacy
        • Workplace Safety/OSHA
      • Litigation
        • Litigation Overview
        • ADA Title III Defense Litigation
        • Alternative Dispute Resolution
        • Appellate
        • Commercial Litigation
        • Construction Litigation
        • Defamation: Libel, Slander, and Commercial Disparagement
        • E-Discovery
        • Election Law
        • Family Law and Matrimonial Law
        • Government & Internal Investigations
        • Insurance Coverage
        • Trusts & Estates Litigation
        • Product Liability Defense
        • Real Estate Litigation
        • Restrictive Covenants / Non-Competes
        • Shareholder / Equity Disputes
        • White Collar Defense
      • Real Estate
        • Real Estate Overview
        • Assessments and Appeals
        • Development
        • Environmental
        • Franchise Development & Leasing
        • Landlord/Tenant Law
        • Leasing
        • New York Co-Ops and Condominiums (Closing Capabilities)
        • Oil & Gas
        • Permitting and Zoning
        • Real Estate Litigation
        • Real Estate-Related Insolvency
        • Transactional Commercial
        • Transactional Residential
        • Leech Tishman Closings
      • Tax
      • Trusts & Estates
        • Trusts & Estates Overview
        • Asset Protection
        • Basic & Complex Estate Planning
        • Charitable Planning & Giving
        • Federal Estate, Gift, and Fiduciary Taxation and Compliance
        • Florida Homestead Exemption
        • Guardianships
        • Marital Agreements
        • Private Foundations
        • Probate and Orphans’ Court Practice
        • Special Needs Planning
        • State Estate, Inheritance, and Fiduciary Taxation and Compliance
        • Tax
        • Trust & Estate Administration
        • Trusts & Estates Litigation
        • Trust Creation, Modification, and Termination
    • Industries
      • Aviation & Aerospace
      • Beauty & Wellness
      • Cannabis
      • Data Privacy & Cybersecurity
      • Energy & Natural Resources
      • Entertainment & Sports
      • Healthcare
      • Life Sciences
    • International
      • International Overview
      • Asia Practice
      • Europe Practice
      • Latin America Practice
      • Middle East Practice
  • Insights
    • Client Alerts
    • Tariff Tracker
    • Firm News
    • Press
    • Events
    • Success Stories
    • Podcasts
    • Resources
    • Videos
  • Offices
  • Careers
  • Payments
  • Contact
Leech Tishman: Legal Services
  • Careers
  • Payments
  • Contact
  • Why LT
    • About Us
    • Leadership
    • Life at LT
    • Careers
  • People
  • Capabilities
    • Practice Groups
      • Business Restructuring & Insolvency
        • Business Restructuring & Insolvency Overview
        • Bankruptcy Chapters 7 and 13 Debtor
        • Bankruptcy Chapter 11 Debtor
        • Bankruptcy Chapter 11 Subchapter V Debtor
        • Business Wind Down and Liquidation
        • Court Appointed Trustees and Receivers
        • Creditors’ Rights
        • Official Committee of Unsecured Creditors in Chapter 11 Bankruptcy Proceedings
        • Prosecution and Defense of Avoidance Actions in Bankruptcy
        • Real Estate-Related Insolvency
      • Construction
      • Corporate
        • Corporate Overview
        • Asset Protection
        • Business Succession
        • Capital Markets
        • Commercial Contracts
        • Construction
        • Corporate Compliance & Ethics Program
        • Corporate Governance
        • Data Privacy & Cybersecurity
        • General Counsel
        • Government Relations
        • Investment Advisory
        • Lending
        • Mergers & Acquisitions
        • Nonprofits & Tax-Exempt Organizations
        • Secured Transactions
        • Securities
        • Software Development and Licensing
        • Start-Up Services
        • Tax
        • Women/Minority-Owned Businesses
      • Healthcare
        • Healthcare Overview
        • Healthcare Litigation
        • Healthcare Regulatory Compliance
        • Healthcare Corporate Transactions
        • Healthcare Government Investigations
      • Intellectual Property
        • Intellectual Property Overview
        • Copyright Protection
        • Litigation – Copyright
        • Litigation – Patent
        • Litigation – Trademark
        • Patent Preparation and Prosecution
        • Patent Validity, Infringement and Freedom to Operate Opinions
        • Trade Secret
        • Technology Agreements and Transactions
        • Trademark Clearance, Preparation, Prosecution and Maintenance
      • Labor & Employment
        • Labor & Employment Overview
        • Discrimination, Sexual Harassment and Employment Litigation
        • Employment Policies & Prevention
        • ERISA, Employee Benefits & Executive Compensation
        • Immigration
        • Public Sector Employment
        • Restrictive Covenants / Non-Competes
        • Traditional Labor Law
        • Wage and Hour
        • Workplace Investigations
        • Workplace Privacy
        • Workplace Safety/OSHA
      • Litigation
        • Litigation Overview
        • ADA Title III Defense Litigation
        • Alternative Dispute Resolution
        • Appellate
        • Commercial Litigation
        • Construction Litigation
        • Defamation: Libel, Slander, and Commercial Disparagement
        • E-Discovery
        • Election Law
        • Family Law and Matrimonial Law
        • Government & Internal Investigations
        • Insurance Coverage
        • Trusts & Estates Litigation
        • Product Liability Defense
        • Real Estate Litigation
        • Restrictive Covenants / Non-Competes
        • Shareholder / Equity Disputes
        • White Collar Defense
      • Real Estate
        • Real Estate Overview
        • Assessments and Appeals
        • Development
        • Environmental
        • Franchise Development & Leasing
        • Landlord/Tenant Law
        • Leasing
        • New York Co-Ops and Condominiums (Closing Capabilities)
        • Oil & Gas
        • Permitting and Zoning
        • Real Estate Litigation
        • Real Estate-Related Insolvency
        • Transactional Commercial
        • Transactional Residential
        • Leech Tishman Closings
      • Tax
      • Trusts & Estates
        • Trusts & Estates Overview
        • Asset Protection
        • Basic & Complex Estate Planning
        • Charitable Planning & Giving
        • Federal Estate, Gift, and Fiduciary Taxation and Compliance
        • Florida Homestead Exemption
        • Guardianships
        • Marital Agreements
        • Private Foundations
        • Probate and Orphans’ Court Practice
        • Special Needs Planning
        • State Estate, Inheritance, and Fiduciary Taxation and Compliance
        • Tax
        • Trust & Estate Administration
        • Trusts & Estates Litigation
        • Trust Creation, Modification, and Termination
    • Industries
      • Aviation & Aerospace
      • Beauty & Wellness
      • Cannabis
      • Data Privacy & Cybersecurity
      • Energy & Natural Resources
      • Entertainment & Sports
      • Healthcare
      • Life Sciences
    • International
      • International Overview
      • Asia Practice
      • Europe Practice
      • Latin America Practice
      • Middle East Practice
  • Insights
    • Client Alerts
    • Tariff Tracker
    • Firm News
    • Press
    • Events
    • Success Stories
    • Podcasts
    • Resources
    • Videos
  • Offices
    • How can we help you?

Insights

News Types

  • All
  • Client Alerts
  • Tariff Tracker
  • Firm News
  • Press
  • Events
  • Success Stories
  • Executive Orders
  • Resources
  • Videos
  • 30 Years, 30 Stories

Archives

Navigating DOJ Cybersecurity Enforcement: The CMMC Program for Defense Contractors

April 9, 2026

By: Lydia A. Pappas, Esq.

Download this article here

Any company hoping to do business with the Department of Defense (“DOD”) has a new set of rules to follow with the Cybersecurity Maturing Model Certification (“CMMC”) program, which went into effect in November 2025.

The program’s cybersecurity standards will look familiar for companies who have worked with the DOD before, but corporations and regulators alike will have to adjust to new assessment and reporting requirements.

What Is the CMMC?

The CMMC program was designed to assess how compliant defense contractors are when it comes to cybersecurity regulations. The program looks at whether a contractor can adequately protect any Federal Contract Information (“FCI”) or Controlled Unclassified Information (“CUI”) on their systems.

It is mandatory for all entities doing business with the Department of Defense (“DOD”) to complete the CMMC certification. Prime and sub-contractors must meet one of the program’s three compliance levels by implementing the proper cybersecurity controls and processes for any systems that store, transmit, or process FCI or CUI. Contractors must also conduct regular assessments and adhere to reporting requirements.

The CMMC’s compliance levels correspond with existing and widely accepted cybersecurity standards, such as the Federal Acquisition Regulations (“FAR”). Therefore, compliance with the CMMC requirements should not be onerous if a corporation has already been operating within industry best practices.

Contractors who fail to complete the CMMC certification will not be permitted to receive or share DOD information.

Levels of Compliance Under the CMMC

It’s essential for companies that operate under federal contracts to be aware of and comply with the requisite level of security.

The CMMC’s first compliance level — designed for smaller companies that handle FCI but not CUI — outlines foundational requirements based on FAR Clause 52.204-21. As discussed in a previous alert, FAR 52.204-21 has 15 basic safeguarding controls, which includes limiting system access and monitoring security. Contractors are also expected to conduct (and report) self-assessments annually. The lack of third-party assessment makes the first compliance level more financially achievable but places responsibility, and risk, for accurate reporting on the company itself.

The second compliance level contains more advanced requirements and is geared towards contractors handling CUI. This level requires contractors to implement all 110 practices listed in NIST Special Publication 800-171 Rev. 2 — not those listed in the latest revision. Contractors subject to this compliance level are mandated to be assessed by an authorized third party to re-obtain CMMC certification every three years. Certain programs may allow for self-assessment instead. Every year, however, companies are expected to provide documentation to verify their compliance with NIST 800-171. Organizations that were already processing CUI and working with the DOD prior to the CMMC program should find level two fairly easy to achieve. After all, those companies were already required to implement NIST 800-171 under DFARS Clause 252.204-7012.

The third and final compliance level is targeted at organizations operating the highest priority programs with CUI. The cybersecurity processes at this level must include continuous improvements across the network and swift defense responses. On top of NIST 800-171, this level incorporates additional requirements pulled from NIST 800-172. Compliance assessments are conducted every three years by the DOD itself.

Companies need to consider the kinds of projects and sensitive data they want to work with to then determine the compliance level to aim for. The more sensitive (and more profitable) the project, the higher the compliance level needed. While it can be costly to get certified in the higher compliance levels, the potential loss in business for contractors is too large to forego certification.

It’s best to get started on implementing the new requirements as soon as possible to avoid delays in getting new DOD contracts. Obtaining the requisite CMMC certification can take up to 12 months based on the availability of the DOD or third-party assessor.

That said, if a company has not yet received its CMMC certification, the DOD may still give them a contract contingent on receiving a plan of action that describes how and when the CMMC controls will be met.

The GSA Deviations From the CMMC

In January 2026, the General Services Administration (“GSA”) issued new requirements for protecting CUI. At first glance, the requirements seem in line with the CMMC, but there are some differences that could create a challenge for contractors doing business with both the DOD and GSA.

The distinguishing factor is that the CMMC requirements are based on revision two of NIST 800-171 while the GSA rules are based on revision three. The differences between the two revisions are more significant than you may think. Revision three contains more assessment requirements, creating a higher bar of security for contractors and, in turn, higher costs associated with compliance. An analysis of the differences between revisions two and three can be found on the NIST website.

The DOD will likely bring the CMMC program in line with revision three of the NIST standards in the future, so defaulting current compliance efforts to that revision will likely save companies from spending more on updates later when the CMMC catches up.

The GSA rules also call for assessments to be completed by different organizations than the CMMC. There are two options for contractors under GSA rules: an assessment organization approved by the GSA’s chief information security officer or a Federal Risk and Authorization Management (“FedRAMP”) assessment organization, which evaluates the cybersecurity of cloud services used by federal agencies. Due to the agency’s limited resources, it may be more expedient for companies to use a FedRAMP assessor for swift approval.


This alert is part six of an ongoing series through which Leech Tishman will track developments in the DOJ’s Cybersecurity Fraud Enforcement program and issue continuing legal updates addressing compliance obligations, impacted industries, and the relevant regulatory requirements. View the previous alert in the series here.

Leech Tishman’s Labor & Employment attorneys regularly counsel clients on compliance with statutory and common law requirements. Our team is prepared to assist your company in understanding and implementing the obligations and compliance measures required under the DOJ’s Cybersecurity Fraud Enforcement program. For assistance or additional information, please contact Lydia A. Pappas at lpappas@leechtishman.com, attorney in Leech Tishman’s Labor & Employment Practice Group.

Share on:
  • Facebook
  • Twitter
  • LinkedIn
  • Careers
  • Insights
  • Payments
  • People
  • Contact
  • Chicago, IL
  • Los Angeles, CA
  • Miami/FLL, FL
  • New York, NY
  • Philadelphia, PA
  • Pittsburgh, PA
  • Sarasota, FL
  • State College, PA
  • Washington, D.C.

Sign up for our Client Alerts

Newsletter Signup
  • LinkedIn
  • Twitter
  • Facebook

Copyright © 2026 Leech Tishman: Legal Services All rights reserved.

  • Terms and Conditions
  • Privacy Policy
  • Personnel Privacy Policy
We use cookies to provide and improve your experience on our website. By clicking Accept you are agreeing to the use of these cookies. However, you do have the option to select Deny but your digital experience may be negatively impacted.