Skip to main content
All

CMMC Phase 2 is on Hold, but Cybersecurity Compliance and Enforcement Are Not: What Government Contractors Need to Know

Monday, September 28, 2026
Noon-1 p.m. ET
Arnold & Porter Webinar
Register

Although CMMC Phase 2 is currently on hold, cybersecurity compliance obligations—and the enforcement risks associated with them—remain a pressing concern for government contractors. Contractors must continue to meet existing cybersecurity requirements and track evolving obligations, such as the FAR Council’s proposed rule addressing safeguarding and handling of Controlled Unclassified Information (CUI).

Join Arnold & Porter attorneys Tirzah Lollar and Tom Pettit for a practical discussion of the cybersecurity issues government contractors should be addressing now. They will examine the current regulatory landscape, emerging compliance requirements, and the government’s growing use of the False Claims Act to enforce cybersecurity obligations.

Topics will include:

  • DoD cybersecurity requirements and the implications of the CMMC Phase 2 pause for ongoing compliance obligations.
  • GSA and other non-DoD cybersecurity requirements affecting federal contractors.
  • The FAR Council’s proposed CUI rule and its potential impact on contractor compliance programs.
  • Cyber incident response strategies, including key considerations following a suspected or confirmed incident.
  • Cybersecurity enforcement through the False Claims Act and practical steps to reduce FCA risk.

Meet the Speakers

Tirzah S. Lollar
Partner
Arnold & Porter
Thomas A. Pettit
Senior Associate
Arnold & Porter