WSJ logo
Forbes logo
Fox News logo
CNN logo
Bloomberg logo
Los Angeles Times logo
Washington Post logo
The Epoch Times logo
Telemundo logo
New York Times
NY Post logo
NBC logo
Daily Beast logo
USA Today logo
Miami Herald logo
CNBC logo
Dallas News logo

DFARS Investigation and Compliance Consultant/Lawyer 

When your company enters into a contract with the U.S. Department of Defense (DoD), part of the agreement is that it will satisfy with the agency’s cybersecurity expectations. Because you may have access to extremely sensitive information that other countries are actively trying to obtain, these expectations are rigorous.

John W. Sellers
Attorney John Sellers
DFARS Investigation and Compliance Team Lead
Former DOJ Trial Attorney
envelope iconContact John
Glenn Karabeika
Glenn Karabeika
DFARS Investigation and Compliance Team
Former HSI Special Agent

Currently, those expectations are laid out in the Defense Federal Acquisition Regulation Supplement (DFARS), Title 48, Chapter 2 of the Code of Federal Regulations (CFR). These DFARS regulations explain what the expectations are for which government defense contractors, what the protocol is if there has been a cyberattack or data breach, and what the penalties are for failing to comply with the regulations.

Given the significant liability that can follow noncompliance, it is extremely important for defense contractors to create, maintain, and audit their cybersecurity system for DFARS compliance.

Cybersecurity in the Defense Industry is Crucial

Governments and foreign nations across the world have turned to hacking and cyberwarfare to gather sensitive and important information about their adversaries, including those that are at odds with the United States.

Given that the information that defense contractors need to provide goods or services to the DoD or other national security agencies often has to do with America’s most closely-guarded secrets, it should come as no surprise that these contractors are likely to become targets of a cyberattack, perhaps even a sophisticated one perpetrated by a powerful foreign state.

The DoD knows this and has acted with increasing urgency to get its contractors to buttress their cybersecurity protocols. Now, it is generally a non-negotiable requirement for defense companies to agree to take strong cybersecurity positions in order to obtain a defense contract. Additionally, defense contractors who do get awarded a contract should be prepared not just for audits and investigations by the federal government, but also for modifications to their cybersecurity compliance obligations.

DFARS Outlines the Defense Department’s Requirements

Those cybersecurity obligations are currently laid out in the DFARS regulations.

Generally, defense contractors must create cybersecurity systems that meet the requirements created by the National Institute of Standards and Technology (NIST) in its Special Publication 800-171 (NIST SP 800-171).

Because the best practices in cybersecurity are in a constant arms race with the best practices in cyberattacks, these Special Publications by the NIST are constantly being revised. Before they can even begin to implement a compliant cybersecurity system, defense contractors need to make sure that they are looking at the right requirements. Contractors can validate the currentness of the publications on NIST’s website, which also lists old versions of the requirements and how they are different.

The two main goals of DFARS and the NIST requirements are to implement adequate protections for the sensitive data that defense contractors routinely handle, and to quickly report any potential data breaches that may have led to unauthorized access of that information.

To reach those goals, NIST SP 800-171 lays out the “recommended security requirements” in 14 different categories:

  1. Access control
  2. Awareness and training
  3. Audit and accountability
  4. Configuration management
  5. Identification and authentication
  6. Incident response
  7. Maintenance
  8. Media protection
  9. Personnel security
  10. Physical protection
  11. Risk assessment
  12. Security assessment
  13. System and communications protection
  14. System and information integrity

Defense contractors are expected to comply with these “recommended requirements” and frequently go through DFARS investigations to ensure that they are doing so. If one of these investigations uncovers evidence of noncompliance, it can lead to some stunningly high repercussions.

Put our highly experienced team on your side

Dr. Nick Oberheiden
Dr. Nick Oberheiden

Founder

Attorney-at-Law

Lynette S. Byrd
Lynette S. Byrd

Former DOJ Trial Attorney

Partner

Brian J. Kuester
Brian J. Kuester

Former U.S. Attorney

Kevin McCarthy
Hon. Kevin McCarthy

55th Speaker, U.S. House of Representatives (ret.)

Government Consultant

Mike Pompeo
Mike Pompeo

Of Counsel

Former U.S. Secretary of State

John W. Sellers
John W. Sellers

Former Senior DOJ Trial Attorney

Linda Julin McNamara
Linda Julin McNamara

Federal Appeals Attorney

Nicholas B. Johnson
Nicholas B. Johnson

Former Prosecutor

Roger Bach
Roger Bach

Former Special Agent (DOJ)

Chris Quick
Chris J. Quick

Former Special Agent (FBI & IRS-CI)

Michael S. Koslow
Michael S. Koslow

Former Supervisory Special Agent (DOD-OIG)

Ray Yuen
Ray Yuen

Former Supervisory Special Agent (FBI)

The Penalties of Noncompliance are Very High

Defense contractors who secure a national defense contract with the DoD, agree to the agency’s demands for a strong cybersecurity system, and then fail to deliver on that promise – even if the failure was in spite of all of its best efforts – the consequences can be massive.

First, the contractor is likely to receive a stop-work order from the DoD. This halts all of your performance under the contract and, importantly, stops all pending payments to your company. To lift the stop-work order, your company will have to reach DFARS compliance.

Second, it will put a significant blemish on your company’s business reputation and brand. Your company signed an agreement that promised that it would implement an adequate cybersecurity system. Even a mistaken allegation of noncompliance can hurt your reputation. If the allegation is not groundless, odds are not small that the contract will be rescinded and your company will struggle to acquire a new one with the government in the future.

But worst of all is the potential for legal liability under the federal False Claims Act. While this law is best known as the leading whistleblower law for reporting government program fraud, 31 U.S.C. § 3729(a)(1)(B) also forbids knowingly making a material and false statement in relation to a claim against the government.

Because defense contracts are claims against the government, and your company’s failure to uphold its promised cybersecurity obligations under the contract could arguably be deemed a “false statement” that is “material” to the contract, it is not unforeseeable for the federal government to try pressing a civil claim under the False Claims Act.

Such a claim carries massive penalties, because the False Claims Act imposes treble damages for violations.

Not only would your company have to reimburse the DoD for damages related to the breach of contract, it would also be liable for three times the amount that it received from the DoD while it was out of compliance with DFARS requirements.

Several Frequently Asked Questions About DFARS Compliance and Investigations

If I Hire a DFARS Consultant or Third Party to Create a Cybersecurity System, Will My Company Still Be Liable if it Fails?

Yes, your company will be held vicariously liable if you got third party help to implement a cybersecurity system to satisfy DFARS requirements. Even if your company completely contracted all of the work out to another party, your company will still be held liable for its failure.

This is why it is so important to find the right DFARS consultants.

Why Should I Hire Outside Help for DFARS Compliance?

Because merely understanding the obligations that you have to satisfy is difficult enough on its own. Actually implementing them requires an in-depth understanding of cybersecurity systems that many defense contractors do not have in-house.

Additionally, by hiring DFARS compliance consultants you can free up resources in your business for what your company actually focuses on – performing its obligations under the defense contract. It lets everyone do what they are best at doing, making everything more efficient and enhancing everyone’s productivity.

The fact that defense contractors are still liable for the failures of the DFARS compliance firm that they hired does not undercut the benefits of the setup. The defense contractor would also be liable for cybersecurity failures if they handled DFARS compliance in-house. By bringing in a consultant or compliance firm that handles DFARS for a living, you level up your cybersecurity capacities and reduce the odds of noncompliance, all without affecting your exposure to liability.

My Company Found Evidence of a Data Breach. What Do We Do?

There are specific DFARS obligations related to data breaches. Broadly speaking, though, defense contractors must immediately investigate the breach, identify which machines and accounts were compromised, and determine the scope of the breach. They must then report the incident within 72 hours to the DoD through its online cyber incident report.

The information that has to be included in this report is listed on the form.

It is not uncommon for defense contractors to hesitate if they find evidence of a data breach. After all, reporting it to the DoD tacitly admits to the shortcomings of their cybersecurity system.

There are 3 extremely important reasons for hesitant contractors to stop hesitating and notify the Department of Defense:

  1. If the agency learns that a contractor was aware of a data breach and did not report it, the penalties will be extreme
  2. Just because there was a data breach does not necessarily mean that the cybersecurity system was not in compliance with DFARS requirements
  3. National security is at stake

Will DFARS Obligations Update in the Future?

Yes, the DoD’s cybersecurity requirements update frequently. In fact, the DoD has a proposed rule that is currently going through the rulemaking process that would completely overhaul the DFARS system with the Cybersecurity Maturity Model Certification (CMMC) Program.

Oberheiden P.C. has written a blog post that details the progress of this proposed rule and the changes that it would make in the cybersecurity needs of defense contractors.

Why Doesn’t Oberheiden P.C. Call Itself the Best DFARS Firm?

That is something that we prefer to let our clients say about us. You can read their testimonials here.


Federal Cybersecurity and DFARS Compliance Consultants at Oberheiden P.C.

Cybersecurity is a notoriously technical field. So is compliance. Finding a good consultant that works at the nexus of these areas is extremely important for defense contractors who want to make sure that they are up-to-date and following their obligations under DFARS.

The DFARS compliance and investigation consultants and lawyers at Oberheiden P.C. help defense contractors understand their contractual cybersecurity obligations, see how they can build cybersecurity systems that are adequate enough to secure a lucrative government contract, assist in implementing such a system, provide audits that test those that have been put in place, and represent contractors who are being investigated for DFARS compliance.

Contact them online or call their national law office at (888) 680-1745.

Further Information About Our Import/Export Compliance and Defense

Why Clients Trust Oberheiden P.C.

  • 2,000+ Cases Won
  • Available Nights & Weekends
  • Experienced Trial Attorneys
  • Former Department of Justice Trial Attorney
  • Former Federal Prosecutors, U.S. Attorney’s Office
  • Former Agents from FBI, OIG, DEA
  • Serving Clients Nationwide
Contact Us 888-680-1745 866-781-9539