Skip to content

32 CFR Part 236, Department of Defense (DoD) Defense Industrial Base (DIB) Cybersecurity (CS) Activities

In effectDoD · Regulation · October 4, 2016

Summary

DoD contractors must report cyber incidents that affect covered defense information or their ability to support DoD, and eligible contractors may join DoD's voluntary program for sharing cyber threat information.

Read it on www.ecfr.gov

What FedXchange has recorded

No changes recorded. The watch records a new document and any change in its status.

Issuer
Department of Defense (DoD), including the Defense Federal Acquisition Regulation Supplement (DFARS) and the Cybersecurity Maturity Model Certification (CMMC)
Type
Regulation
Number
32 CFR Part 236
Issued
October 4, 2016
Status
In effect

Still in force, possibly with amendments.

First issued for a voluntary program in 2012 and 2013, rewritten by an interim final rule on October 2, 2015 and finalized October 4, 2016; eligibility was widened by a final rule published March 12, 2024.

Get new governance by email

A weekly email on Fridays, an alert on the day the watch finds something new, or both. Free.

Send me

We use your address only to send what you choose, and every email has a one-click unsubscribe. Read the privacy notice.