Latest News

What we’re talking about

BIS is considering 50%
Export Compliance News

BIS is considering a 50% Rule for Listed Entities

The Bureau of Industry and Security (BIS) is considering a 50% rule to address loopholes that are being used by subsidiaries of parent organizations on the BIS entity list.  The proposed regulation would be similar to current to regulations enacted by the Office of Foreign Asset Controls (OFAC).  This action would impose licensing requirements across

Read More »
Self Disclosure and Cooperation
Export Compliance News

Self Disclosure and Cooperation Leads to Non-Prosecution

Self disclosure and cooperation in the investigation of export regulation violations by an entity’s acquiror has led to a waiver of prosecution against the acquiring company (White Deer Management LLC).  The Department of Justice’s National Security Division and the Southern District of Texas’s United States Attorney’s Office have also decided to decline prosecution of the

Read More »
Sequencing MIL-STD-810
Product Testing News

Sequencing MIL-STD-810 Test Methods

Sequencing MIL-STD-810 tests methods can be a challenge when developing an Environmental Test and Evaluation Master Plan (ETEMP).  Determining a representative test sequence is essential for generating representative cumulative environmental stressors that will provide an accurate evaluative process.  The standard provides, in most cases, vague and general guidance in Part 1 and in each of

Read More »
Guidance for Advanced Computing ICs
Cyber Security

Guidance for Advanced Computing ICs

The Bureau of Industry and Security (BIS) has issued new guidance for Advanced Computing ICs in an effort to prevent diversion of electronics that could be implemented in Weapons of Mass Destruction (WMD).  The BIS also updated Supplement No. 3 to Part 732 “Know Your Customer” Guidance and Red Flags to provide a due diligence

Read More »
DoD Acquisition Nominee
Cyber Security

DoD Acquisition Nominee and CMMC

DoD Acquisition nominee Michael Duffy plans to review Cybersecurity Maturity Model Certification (CMMC) implementation in an effort to balance a need for security and excessive regulation.  Duffy also recognized the need for affordability for the Defense Industrial Base (DIB) to maintain cybersecurity best practices to protect Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). Duffy

Read More »
Organizations not Ready for CMMC
Cyber Security

Organizations Are Not Ready for CMMC

Recent studies have shown that organizations are not ready for CMMC.  The Aware but not Prepared report from Redspin states that only half of the Defense Industrial Base (DIB) are even moderately prepared for a Level 2 certification.  Despite a five year roll out for the final rule from the Department of Defense (DoD) DIB

Read More »
defense export handbook
Export Compliance News

Defense Export Handbook – An Overview for Businesses

The International Trade Administration (ITA) has released the 2025 Defense Export Handbook to provide an overview of U.S. trade laws governing the export of defense products.  This handbook also gives guidance to new-to-market exporters on evaluating international markets and includes contact information for export control, trade promotion, and licensing.  The publication describes U.S. statutes that

Read More »
Cyber Security

Integrated Business Management Systems for Effectiveness

Integrated business management systems provide more effective solutions to the challenges facing organizations today.  This approach consolidates business processes and systems across teams and unifies objectives.  It can effectively address requirements for quality management, export compliance, information security management, and other concerns, ensuring compliance without gaps, duplication of efforts, or teams working at cross purposes.

Read More »
cmmc final rule
Cyber Security

CMMC Final Rule to be Implemented in 2025

The Department of Defense (DoD) has released its Cybersecurity Maturity Model Certification (CMMC) final rule.  This rule will now require contractors to verify that required security measures have been implemented for Federal Contract Information (FCI) and Controlled Unclassified Information (CUI).  These requirements will are to be implemented in early to mid-2025 when verification of security

Read More »
Developments in the ITAR
Export Compliance News

ITAR Developments and U.S. Foreign Policy

AUKUS Pillar I and Pillar II ITAR developments continue as the U.S. responds to national security threats with strategic trade controls and security partnerships. In recent news, AUKUS Pillar II has greatly eased the transfer of defense articles and technologies between Australia, the United Kingdom, and the United States. This trilateral security partnership was created

Read More »
Validated End User
Cyber Security

Validated End User (VEU) Program Expanded

The Bureau of Industry and Security (BIS) has expanded its Validated End User (VEU) Program to include controls for data centers in an effort to create a trusted ecosystem for artificial intelligence (AI) development.  The VEU will now review applicants data centers to ensure application of appropriate safeguards and security measures.  This update to the

Read More »
Ransomware Possible Cause of Death
Cyber Security

Ransomware Possible Cause of Death

Ransomware may have been the possible cause of death of a patient in Dusseldorf.  A ransomware attack on thirty servers at the Dusseldorf University hospital on September 9, 2020 prevented immediate emergency treatment and resulted in the patient having to be transported to a facility 20 miles away where she died from a delay of

Read More »
Voluntary Self Disclosure Process
Export Compliance News

Voluntary Self Disclosure Process Changed by BIS

The Bureau of Industry and Security (BIS) has amended the Voluntary Self Disclosure (VSD) process in the Export Administration Regulations (EAR).  The newly released amendment to CFR 15 Section 764.5 and Supplement No. 1 to part 766 provides guidance for settlement determinations of penalties for administrative enforcement cases.  This action evolved from a series of

Read More »
DFAR Amendment for Contractor Implementation
Cyber Security

DFAR Amendment for Contractor Implementation

The Department of Defense (DoD) has proposed a Defense Federal Acquisition Regulation Supplement (DFAR) amendment for contractor implementation of Cybersecurity Maturity Model Certification (CMMC).  DFARS case 2019-D041 was first published in September 2020 with an effective date of November 20, 2020 to allow for the development of CMMC 2.0.  CMMC 2.0 establishes a framework for

Read More »
Suit Filed Against Georgia Tech
Cyber Security

Suit Filed Against Georgia Tech by U.S. Government

A suit filed against Georgia Tech by the United States Government alleges that the university’s affiliate, Georgia Tech Research Corporation (GTRC) knowingly failed to meet its cybersecurity requirements for the Department of Defense (DoD).  The suit was initiated by a whistleblower complaint from members of Georgia Tech’s Cybersecurity team.   The lawsuit alleges that the Georgia

Read More »
AUKUS Defense Trade
Export Compliance News

AUKUS Defense Trade Moves Forward

The U.S. Department of State announced on August 15, 2024 that progress had been made in the AUKUS defense trade integration. This has resulted in an interim final rule amendment to the International Traffic in Arms Regulations (ITAR) that will facilitate billions of dollars in secure license-free defense trade between Australia, the United Kingdom, and

Read More »
Secret Link