Kate Growley
- Indexed articles, last 90 days
- 4
- Latest publication
- Sep 15, 2026
- Outlet visibility, for Mondaq
- Top 500K sites
- Earliest in this view
- Jul 8, 2026
Latest articles
New ISOO Guidance Directs Federal Agencies To Provide More CUI Guidance To Contractors (opens the original)
Read excerpt
On September 2, 2026, the National Archives and Records Administration (NARA), through its Information Security Oversight Office (ISOO), released two new Notices on the topic of Controlled Unclassified Information (CUI). In part, the new ISOO guidance requires federal agencies to provide contractors with specific guidance“[f]or all contracts requiring access to CUI.”Some topics agencies must address include CUI identification, safeguarding requirements, and any processes for challenging CUI desi
Last Call: “FAR CUI Rule” Draft Language Provides An Opportunity For Contractors To Weigh In By This Week (opens the original)
Read excerpt
The FAR Council recently released an updated draft of the much-anticipated “FAR CUI Rule” that would apply to contractors government-wide. The revised “FAR CUI Rule” proposal, if adopted, would establish greater uniformity and clarity across the federal government for protecting CUI. It would also represent a significant compliance commitment. Entities should consider submitting comments on the proposed language on or before July 23, 2026, when the public comment period closes. The FAR Council r
Department Of War Immediately Suspends CMMC Phase II Requirements, Launches 60-Day Reform Review (opens the original)
Read excerpt
The Department of War (DoW) is immediately suspending Cybersecurity Maturity Model Certification (CMMC) Phase II requirements, which had been scheduled to take effect on November 10, 2026, along with other pending and future CMMC implementation milestones in current contracts. DoW plans to establish a CMMC Reform Task Force and conduct a 60-day study of CMMC. DFARS 252.204-7012 and CMMC Phase I self-assessment requirements remain unaffected. Contractors are still required to protect federal data
Time For A Change: FedRAMP Fundamentally Revamps Program With Consolidated Rules For 2026 (opens the original)
Read excerpt
FedRAMP’s Consolidated Rules for 2026 mark a significant turning point in how the U.S. Government administers security authorizations of private sector cloud offerings. The Rules are intended in part to transition Rev5 authorizations over to 20x, with the Rev5 authorization status expected to terminate by the end of 2028. Current Rev5-authorized cloud providers can maintain their existing certifications for now, but the Consolidated Rules introduce several substantive changes that providers must
Publishing over time
Last 90 days. Choose a month to open its work.
Recurring subjects
Named in the text we hold. One piece can cover several.
Audience
Top 500K sites
For Mondaq, the outlet · Measured Aug 1, 2026
Website popularity band, not a count of readers or article views.
About this data
Counts cover the work we have indexed. Tone needs enough text and a confident classification. Excerpts and episode notes are not full articles or transcripts.
Identity or attribution wrong? Suggest a correction.