<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<REGINFO_RIN_DATA xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" RUN_DATE="2026-04-05-04:00" xsi:noNamespaceSchemaLocation="https://www.reginfo.gov/public/xml/REGINFO_XML_Ver10262011.xsd">
    <RIN_INFO>
        <RIN>0750-AK81</RIN>
        <PUBLICATION>
            <PUBLICATION_ID>202110</PUBLICATION_ID>
            <PUBLICATION_TITLE>The Regulatory Plan and the Unified Agenda of Federal Regulatory and Deregulatory Actions</PUBLICATION_TITLE>
        </PUBLICATION>
        <AGENCY>
            <CODE>0750</CODE>
            <NAME>Defense Acquisition Regulations Council</NAME>
            <ACRONYM>DARC</ACRONYM>
        </AGENCY>
        <PARENT_AGENCY>
            <CODE>0700</CODE>
            <NAME>Department of Defense</NAME>
            <ACRONYM>DOD</ACRONYM>
        </PARENT_AGENCY>
        <RULE_TITLE>Assessing Contractor Implementation of Cybersecurity Requirements (DFARS Case 2019-D041)</RULE_TITLE>
        <ABSTRACT><![CDATA[<!DOCTYPE html>
<html>
<head>
</head>
<body>
<p>DoD is finalizing an interim rule to implement the following methodology and framework in order to protect against the theft of intellectual property and sensitive information from the Defense Industrial Base (DIB) sector:</p>
<ul>
<li><em>The National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171 DoD Assessment Methodology</em>. A standard methodology to assess contractor implementation of the cybersecurity requirements in NIST SP 800-171, Protecting Controlled Unclassified Information (CUI) In Nonfederal Systems and Organizations.</li>
</ul>
<ul>
<li><em>The Cybersecurity Maturity Model Certification (CMMC) Framework</em>. A DoD certification process that measures a company&rsquo;s institutionalization of processes and implementation of cybersecurity practices. See RIN 0790-AL49 for information on a rule amending title 32 of the Code of Federal Regulations with regard to CMMC, which will inform the DFARS final rule.</li>
</ul>
<p>This rule&nbsp;provides the Department with: (1) the ability to assess at a corporate level a contractor&rsquo;s implementation of NIST SP 800-171 security requirements, as required by DFARS clause 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting; and (2) assurances that a DIB contractor can adequately protect sensitive unclassified information at a level commensurate with the risk, accounting for information flow down to its subcontractors in a multi-tier supply chain.</p>
</body>
</html>]]></ABSTRACT>
        <PRIORITY_CATEGORY>Economically Significant</PRIORITY_CATEGORY>
        <RIN_STATUS>Previously Published in The Unified Agenda</RIN_STATUS>
        <RULE_STAGE>Long-Term Actions</RULE_STAGE>
        <MAJOR>Yes</MAJOR>
        <UNFUNDED_MANDATE_LIST>
            <UNFUNDED_MANDATE>No</UNFUNDED_MANDATE>
        </UNFUNDED_MANDATE_LIST>
        <CFR_LIST>
            <CFR>48 CFR 204</CFR>
            <CFR>48 CFR 212</CFR>
            <CFR>48 CFR 217</CFR>
            <CFR>48 CFR 252</CFR>
        </CFR_LIST>
        <LEGAL_AUTHORITY_LIST>
            <LEGAL_AUTHORITY>41 U.S.C 1303</LEGAL_AUTHORITY>
            <LEGAL_AUTHORITY>Pub. L. 116-92, sec. 1648</LEGAL_AUTHORITY>
        </LEGAL_AUTHORITY_LIST>
        <LEGAL_DLINE_LIST/>
        <RPLAN_ENTRY>No</RPLAN_ENTRY>
        <TIMETABLE_LIST>
            <TIMETABLE>
                <TTBL_ACTION>Interim Final Rule</TTBL_ACTION>
                <TTBL_DATE>09/29/2020</TTBL_DATE>
                <FR_CITATION>85 FR 48513</FR_CITATION>
            </TIMETABLE>
            <TIMETABLE>
                <TTBL_ACTION>Interim Final Rule Effective</TTBL_ACTION>
                <TTBL_DATE>11/30/2020</TTBL_DATE>
            </TIMETABLE>
            <TIMETABLE>
                <TTBL_ACTION>Final Action</TTBL_ACTION>
                <TTBL_DATE>12/00/2022</TTBL_DATE>
            </TIMETABLE>
        </TIMETABLE_LIST>
        <RFA_REQUIRED>Yes</RFA_REQUIRED>
        <SMALL_ENTITY_LIST>
            <SMALL_ENTITY>Businesses</SMALL_ENTITY>
        </SMALL_ENTITY_LIST>
        <GOVT_LEVEL_LIST>
            <GOVT_LEVEL>Federal</GOVT_LEVEL>
        </GOVT_LEVEL_LIST>
        <FEDERALISM>No</FEDERALISM>
        <ENERGY_AFFECTED>No</ENERGY_AFFECTED>
        <COMPLIANCE_COST>
            <INITIAL_PUBLIC_COST>0</INITIAL_PUBLIC_COST>
            <BASE_YEAR>2021</BASE_YEAR>
            <RECURRING_PUBLIC_COST>0</RECURRING_PUBLIC_COST>
        </COMPLIANCE_COST>
        <PRINT_PAPER>Yes</PRINT_PAPER>
        <INTERNATIONAL_INTEREST>No</INTERNATIONAL_INTEREST>
        <AGENCY_CONTACT_LIST>
            <CONTACT>
                <FIRST_NAME>Jennifer</FIRST_NAME>
                <LAST_NAME>Johnson</LAST_NAME>
                <TITLE>Defense Acquisition Regulations System</TITLE>
                <AGENCY>
                    <CODE>0750</CODE>
                    <NAME>Defense Acquisition Regulations Council</NAME>
                    <ACRONYM>DARC</ACRONYM>
                </AGENCY>
                <PHONE>571 372-6100</PHONE>
                <EMAIL>jennifer.d.johnson1.civ@mail.mil</EMAIL>
                <MAILING_ADDRESS>
                    <STREET_ADDRESS>3060 Defense Pentagon, Room 3B941,</STREET_ADDRESS>
                    <CITY>Washington</CITY>
                    <STATE>DC</STATE>
                    <ZIP>20301-3060</ZIP>
                </MAILING_ADDRESS>
            </CONTACT>
        </AGENCY_CONTACT_LIST>
    </RIN_INFO>
</REGINFO_RIN_DATA>
