{"description":"Documents matching 'Cybersecurity Maturity Model Certification' and of type Rule","count":62,"total_pages":4,"next_page_url":"https://www.federalregister.gov/api/v1/documents?conditions%5Bterm%5D=Cybersecurity+Maturity+Model+Certification&conditions%5Btype%5D%5B%5D=RULE&format=json&page=2","results":[{"title":"Defense Federal Acquisition Regulation Supplement: Assessing Contractor Implementation of Cybersecurity Requirements (DFARS Case 2019-D041)","type":"Rule","abstract":"DoD is issuing a final rule amending the Defense Federal Acquisition Regulation Supplement (DFARS) to incorporate contractual requirements related to the final Cybersecurity Maturity Model Certification program rule, titled Cybersecurity Maturity Model Certification Program. This final DFARS rule also partially implements a section of the National Defense Authorization Act for Fiscal Year 2020 that directed the Secretary of Defense to develop a consistent, comprehensive framework to enhance cybersecurity for the U.S. defense industrial base.","document_number":"2025-17359","html_url":"https://www.federalregister.gov/documents/2025/09/10/2025-17359/defense-federal-acquisition-regulation-supplement-assessing-contractor-implementation-of","pdf_url":"https://www.govinfo.gov/content/pkg/FR-2025-09-10/pdf/2025-17359.pdf","public_inspection_pdf_url":"https://public-inspection.federalregister.gov/2025-17359.pdf?1757421911","publication_date":"2025-09-10","agencies":[{"raw_name":"DEPARTMENT OF DEFENSE","name":"Defense Department","id":103,"url":"https://www.federalregister.gov/agencies/defense-department","json_url":"https://www.federalregister.gov/api/v1/agencies/103","parent_id":null,"slug":"defense-department"},{"raw_name":"Defense Acquisition Regulations System","name":"Defense Acquisition Regulations System","id":97,"url":"https://www.federalregister.gov/agencies/defense-acquisition-regulations-system","json_url":"https://www.federalregister.gov/api/v1/agencies/97","parent_id":103,"slug":"defense-acquisition-regulations-system"}],"excerpts":"unclassified information (CUI), current, \n \n <span class=\"match\">Cybersecurity</span> <span class=\"match\">Maturity</span> <span class=\"match\">Model</span> <span class=\"match\">Certification</span> (CMMC) status, <span class=\"match\">Cybersecurity</span> <span class=\"match\">Maturity</span> <span class=\"match\">Model</span> <span class=\"match\">Certification</span> unique identifier (CMMC UID), \n \n Federal contract information (FCI), \n and \n Plan of action and milestones \n have the meaning given in the Defense Federal Acquisition Regulation Supplement 252.204-7021, Contractor Compliance With the <span class=\"match\">Cybersecurity</span> <span class=\"match\">Maturity</span> <span class=\"match\">Model</span> <span class=\"match\">Certification</span> Level Requirements, clause of this solicitation.\n \n \n (b)(1) \n <span class=\"match\">Cybersecurity</span> <span class=\"match\">Maturity</span> <span class=\"match\">Model</span> <span class=\"match\">Certification</span> (CMMC) level. \n The CMMC level required"},{"title":"Cybersecurity Maturity Model Certification (CMMC) Program","type":"Rule","abstract":"With this final rule, DoD establishes the Cybersecurity Maturity Model Certification (CMMC) Program in order to verify contractors have implemented required security measures necessary to safeguard Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). The mechanisms discussed in this rule will allow the Department to confirm a defense contractor or subcontractor has implemented the security requirements for a specified CMMC level and is maintaining that status (meaning level and assessment type) across the contract period of performance. This rule will be updated as needed, using the appropriate rulemaking process, to address evolving cybersecurity standards, requirements, threats, and other relevant changes.","document_number":"2024-22905","html_url":"https://www.federalregister.gov/documents/2024/10/15/2024-22905/cybersecurity-maturity-model-certification-cmmc-program","pdf_url":"https://www.govinfo.gov/content/pkg/FR-2024-10-15/pdf/2024-22905.pdf","public_inspection_pdf_url":"https://public-inspection.federalregister.gov/2024-22905.pdf?1728650732","publication_date":"2024-10-15","agencies":[{"raw_name":"DEPARTMENT OF DEFENSE","name":"Defense Department","id":103,"url":"https://www.federalregister.gov/agencies/defense-department","json_url":"https://www.federalregister.gov/api/v1/agencies/103","parent_id":null,"slug":"defense-department"},{"raw_name":"Office of the Secretary"}],"excerpts":"requirements for a CMMC Level 2 <span class=\"match\">certification</span> assessment satisfies a CMMC Level 2 self-assessment requirement for the same CMMC Assessment Scope.\n \n \n The term “<span class=\"match\">certificate</span> of assessment” has been replaced with the term “<span class=\"match\">Certificate</span> of CMMC Status” in the final rule. When an OSC has met all the requirements for a Level 2 <span class=\"match\">certification</span> assessment, a <span class=\"match\">Certificate</span> of CMMC Status is obtained from the C3PAO conducting the assessment. See § 170.9. Under CMMC, OSCs are not certified; rather, the assessed network receives a \n \n <span class=\"match\">Certificate</span> of CMMC Status for the"},{"title":"Defense Federal Acquisition Regulation Supplement: Inapplicability of Additional Defense-Unique Laws and Certain Non-Statutory DFARS Clauses to Commercial Item Contracts (DFARS Case 2018-D074)","type":"Rule","abstract":"DoD is issuing a final rule amending the Defense Federal Acquisition Regulation Supplement (DFARS) to implement sections of the National Defense Authorization Acts for Fiscal Years 2018 and 2019 regarding the applicability of certain solicitation provisions and contract clauses to contracts and subcontracts for commercial products, commercial services, and commercially available off-the-shelf items.","document_number":"2024-26054","html_url":"https://www.federalregister.gov/documents/2024/11/15/2024-26054/defense-federal-acquisition-regulation-supplement-inapplicability-of-additional-defense-unique-laws","pdf_url":"https://www.govinfo.gov/content/pkg/FR-2024-11-15/pdf/2024-26054.pdf","public_inspection_pdf_url":"https://public-inspection.federalregister.gov/2024-26054.pdf?1731591921","publication_date":"2024-11-15","agencies":[{"raw_name":"DEPARTMENT OF DEFENSE","name":"Defense Department","id":103,"url":"https://www.federalregister.gov/agencies/defense-department","json_url":"https://www.federalregister.gov/api/v1/agencies/103","parent_id":null,"slug":"defense-department"},{"raw_name":"Defense Acquisition Regulations System","name":"Defense Acquisition Regulations System","id":97,"url":"https://www.federalregister.gov/agencies/defense-acquisition-regulations-system","json_url":"https://www.federalregister.gov/api/v1/agencies/97","parent_id":103,"slug":"defense-acquisition-regulations-system"}],"excerpts":"Covered Defense Information and Cyber Incident Reporting; (4) DFARS provision 252.204-7019, Notice of NIST SP 800-171 DoD Assessment Requirements; (5) DFARS clause 252.204-7020, NIST SP 800-171 DoD Assessment Requirements; and (6) DFARS clause 252.204-7021, <span class=\"match\">Cybersecurity</span> <span class=\"match\">Maturity</span> <span class=\"match\">Model</span> <span class=\"match\">Certification</span> Requirements. \n IV. Expected Impact of the Proposed Rule \n This final rule could impact any large or small business that is awarded a commercial contract by DoD. This rule does not add any new solicitation provisions or contract clauses. Rather, there may"},{"title":"Cybersecurity in the Marine Transportation System","type":"Rule","abstract":"The Coast Guard is updating its maritime security regulations by establishing minimum cybersecurity requirements for U.S.-flagged vessels, Outer Continental Shelf facilities, and facilities subject to the Maritime Transportation Security Act of 2002 regulations. This final rule addresses current and emerging cybersecurity threats in the marine transportation system by adding minimum cybersecurity requirements to help detect risks and respond to and recover from cybersecurity incidents. These include requirements to develop and maintain a Cybersecurity Plan, designate a Cybersecurity Officer, and take various measures to maintain cybersecurity within the marine transportation system. The Coast Guard is also seeking comments on a potential delay for the implementation periods for U.S.-flagged vessels.","document_number":"2025-00708","html_url":"https://www.federalregister.gov/documents/2025/01/17/2025-00708/cybersecurity-in-the-marine-transportation-system","pdf_url":"https://www.govinfo.gov/content/pkg/FR-2025-01-17/pdf/2025-00708.pdf","public_inspection_pdf_url":"https://public-inspection.federalregister.gov/2025-00708.pdf?1736802922","publication_date":"2025-01-17","agencies":[{"raw_name":"DEPARTMENT OF HOMELAND SECURITY","name":"Homeland Security Department","id":227,"url":"https://www.federalregister.gov/agencies/homeland-security-department","json_url":"https://www.federalregister.gov/api/v1/agencies/227","parent_id":null,"slug":"homeland-security-department"},{"raw_name":"Coast Guard","name":"Coast Guard","id":53,"url":"https://www.federalregister.gov/agencies/coast-guard","json_url":"https://www.federalregister.gov/api/v1/agencies/53","parent_id":227,"slug":"coast-guard"}],"excerpts":"by establishing minimum <span class=\"match\">cybersecurity</span> requirements for U.S.-flagged vessels, Outer Continental Shelf facilities, and facilities subject to the Maritime Transportation Security Act of 2002 regulations. This final rule addresses current and emerging <span class=\"match\">cybersecurity</span> threats in the marine transportation system by adding minimum <span class=\"match\">cybersecurity</span> requirements to help detect risks and respond to and recover from <span class=\"match\">cybersecurity</span> incidents. These include requirements to develop and maintain a <span class=\"match\">Cybersecurity</span> Plan, designate a <span class=\"match\">Cybersecurity</span> Officer, and take various"},{"title":"Schools and Libraries Cybersecurity Pilot Program","type":"Rule","abstract":"In this document, the Federal Communications Commission (Commission or FCC) stablishes the Schools and Libraries Cybersecurity Pilot Program (Pilot or Pilot Program). The Pilot Program will enable the Commission to evaluate the impact that using Universal Service Fund (USF or Fund) support for eligible cybersecurity services and equipment will have on protecting school and library broadband networks and data. In so doing, the Commission seeks to address the apparent needs of schools and libraries for additional support for cybersecurity services and equipment, while evaluating the impact that providing that support would have on the USF.","document_number":"2024-15866","html_url":"https://www.federalregister.gov/documents/2024/07/30/2024-15866/schools-and-libraries-cybersecurity-pilot-program","pdf_url":"https://www.govinfo.gov/content/pkg/FR-2024-07-30/pdf/2024-15866.pdf","public_inspection_pdf_url":"https://public-inspection.federalregister.gov/2024-15866.pdf?1722257112","publication_date":"2024-07-30","agencies":[{"raw_name":"FEDERAL COMMUNICATIONS COMMISSION","name":"Federal Communications Commission","id":161,"url":"https://www.federalregister.gov/agencies/federal-communications-commission","json_url":"https://www.federalregister.gov/api/v1/agencies/161","parent_id":null,"slug":"federal-communications-commission"}],"excerpts":"for the proposed project, and the <span class=\"match\">cybersecurity</span> risks the proposed Pilot project will prevent or address. \n • The <span class=\"match\">cybersecurity</span> equipment and services the applicant plans to request as part of its proposed project, the ability of the project to be self-sustaining once established, and whether the applicant has a <span class=\"match\">cybersecurity</span> officer or other senior-level staff member designated to be the <span class=\"match\">cybersecurity</span> officer for its Pilot project. \n \n • Whether the applicant has previous experience implementing <span class=\"match\">cybersecurity</span> protections or measures (answered on"},{"title":"Department of Defense (DoD) Defense Industrial Base (DIB) Cybersecurity (CS) Activities","type":"Rule","abstract":"The DoD is finalizing revisions to the eligibility criteria for the voluntary Defense Industrial Base (DIB) Cybersecurity (CS) Program. These revisions will allow all defense contractors who own or operate an unclassified information system that processes, stores, or transmits covered defense information to benefit from bilateral information sharing. DoD is also finalizing changes to definitions and some technical corrections for readability.","document_number":"2024-04752","html_url":"https://www.federalregister.gov/documents/2024/03/12/2024-04752/department-of-defense-dod-defense-industrial-base-dib-cybersecurity-cs-activities","pdf_url":"https://www.govinfo.gov/content/pkg/FR-2024-03-12/pdf/2024-04752.pdf","public_inspection_pdf_url":"https://public-inspection.federalregister.gov/2024-04752.pdf?1710161113","publication_date":"2024-03-12","agencies":[{"raw_name":"DEPARTMENT OF DEFENSE","name":"Defense Department","id":103,"url":"https://www.federalregister.gov/agencies/defense-department","json_url":"https://www.federalregister.gov/api/v1/agencies/103","parent_id":null,"slug":"defense-department"},{"raw_name":"Office of the Secretary"}],"excerpts":"analyst-to-analyst exchanges, mitigation and remediation strategies, and <span class=\"match\">cybersecurity</span> best practices in a collaborative environment. The shared unclassified and classified cyber threat information is used to bolster a company's <span class=\"match\">cybersecurity</span> posture and mitigate the growing cyber threat. The program's tailored support for small, mid-size, and large companies with varying <span class=\"match\">cybersecurity</span> <span class=\"match\">maturity</span> levels is an asset for participants. The program remains a key element of DoD's <span class=\"match\">cybersecurity</span> efforts by providing services to help protect DIB CS Program participants"},{"title":"Small Business Size Standards: Revised Size Standards Methodology","type":"Rule","abstract":"The U.S. Small Business Administration (SBA or Agency) advises the public that it has revised its size standards methodology white paper, entitled \"SBA's Size Standards Methodology (June 2024)\" (the Revised Methodology or Methodology), explaining how it establishes, reviews, or revises small business size standards. SBA will apply the Revised Methodology to the forthcoming third five-year review of size standards required by the Small Business Jobs Act of 2010. On December 11, 2023, SBA published a notification seeking comments on proposed revisions to its Methodology. This notification describes major changes to the Methodology and their impacts on size standards, followed by a discussion of the comments SBA received on the proposed revisions to the Methodology and Agency's responses.","document_number":"2024-20228","html_url":"https://www.federalregister.gov/documents/2024/09/12/2024-20228/small-business-size-standards-revised-size-standards-methodology","pdf_url":"https://www.govinfo.gov/content/pkg/FR-2024-09-12/pdf/2024-20228.pdf","public_inspection_pdf_url":"https://public-inspection.federalregister.gov/2024-20228.pdf?1726058722","publication_date":"2024-09-12","agencies":[{"raw_name":"SMALL BUSINESS ADMINISTRATION","name":"Small Business Administration","id":468,"url":"https://www.federalregister.gov/agencies/small-business-administration","json_url":"https://www.federalregister.gov/api/v1/agencies/468","parent_id":null,"slug":"small-business-administration"}],"excerpts":"hiring at the expense of obtaining and maintaining Government mandated <span class=\"match\">certifications</span>, or forgo obtaining required <span class=\"match\">certifications</span> with the OEMs, which hurts the portfolio of products they are able to offer and also negatively affects their pricing discounts and profitability. With an increased focus on secure supply chain and numerous <span class=\"match\">certification</span> requirements (such as International Organization for Standardization (ISO) <span class=\"match\">certifications</span>, <span class=\"match\">cybersecurity</span> <span class=\"match\">maturity</span> <span class=\"match\">model</span> <span class=\"match\">certification</span> (CMMC), supply chain risk management, ITAR, security clearances, affirmative"},{"title":"Order No. 918; Critical Infrastructure Protection Reliability Standard CIP-003-11-Cyber Security-Security Management Controls","type":"Rule","abstract":"The Federal Energy Regulatory Commission (Commission) approves the proposed Critical Infrastructure Protection (CIP) Reliability Standard CIP-003-11 (Cyber Security--Security Management Controls). The North American Electric Reliability Corporation (NERC), the Commission- certified Electric Reliability Organization (ERO), submitted the proposed Reliability Standard to mitigate risks posed by a coordinated cyberattack on low-impact facilities, the aggregate impact of which could be much greater.","document_number":"2026-05711","html_url":"https://www.federalregister.gov/documents/2026/03/24/2026-05711/order-no-918-critical-infrastructure-protection-reliability-standard-cip-003-11-cyber","pdf_url":"https://www.govinfo.gov/content/pkg/FR-2026-03-24/pdf/2026-05711.pdf","public_inspection_pdf_url":"https://public-inspection.federalregister.gov/2026-05711.pdf?1774269913","publication_date":"2026-03-24","agencies":[{"raw_name":"DEPARTMENT OF ENERGY","name":"Energy Department","id":136,"url":"https://www.federalregister.gov/agencies/energy-department","json_url":"https://www.federalregister.gov/api/v1/agencies/136","parent_id":null,"slug":"energy-department"},{"raw_name":"Federal Energy Regulatory Commission","name":"Federal Energy Regulatory Commission","id":167,"url":"https://www.federalregister.gov/agencies/federal-energy-regulatory-commission","json_url":"https://www.federalregister.gov/api/v1/agencies/167","parent_id":136,"slug":"federal-energy-regulatory-commission"}],"excerpts":"obsolete due to the rapid evolution of cyber environments and threats.\n 50 \n \n Mr. Haddad argues that “periodic re-\n \n evaluation of threat <span class=\"match\">models</span> must become standard practice, especially for sectors like energy where adversaries have demonstrated persistence and patience.” \n 51 \n \n Beyond an additional study, Mr. Haddad recommends the Commission establish a federal task force for “small utility <span class=\"match\">cybersecurity</span>” including the Commission, DOE, CISA, and NERC, to develop and support the implementation of shared security services and capabilities for"},{"title":"Integration of Powered-Lift: Pilot Certification and Operations; Miscellaneous Amendments Related to Rotorcraft and Airplanes","type":"Rule","abstract":"This final rule adopts permanent amendments and a Special Federal Aviation Regulation (SFAR) for a period of ten years to: facilitate the certification of powered-lift pilots, clarify operating rules applicable to operations involving a powered-lift, and finalize other amendments which are necessary to integrate powered-lift into the National Airspace System (NAS). In this final action, the FAA finalizes its alternate framework to stand-up initial groups of powered-lift pilots and flight instructors. Most notably, the FAA adopts alternate frameworks to facilitate the certification of pilots seeking qualifications in a powered-lift with single functioning flight controls and a single pilot station. In response to commenters, the FAA provides clarification for certain operating rules and adopts a performance-based approach to certain operating rules to enable powered-lift operations. In addition to finalizing provisions for powered-lift, this action also makes changes to practical tests in aircraft that require type ratings, including airplanes and helicopters, training center rotorcraft instructor eligibility, training and testing requirements, and training center use of rotorcraft in flight training.","document_number":"2024-24886","html_url":"https://www.federalregister.gov/documents/2024/11/21/2024-24886/integration-of-powered-lift-pilot-certification-and-operations-miscellaneous-amendments-related-to","pdf_url":"https://www.govinfo.gov/content/pkg/FR-2024-11-21/pdf/2024-24886.pdf","public_inspection_pdf_url":"https://public-inspection.federalregister.gov/2024-24886.pdf?1732110316","publication_date":"2024-11-21","agencies":[{"raw_name":"DEPARTMENT OF TRANSPORTATION","name":"Transportation Department","id":492,"url":"https://www.federalregister.gov/agencies/transportation-department","json_url":"https://www.federalregister.gov/api/v1/agencies/492","parent_id":null,"slug":"transportation-department"},{"raw_name":"Federal Aviation Administration","name":"Federal Aviation Administration","id":159,"url":"https://www.federalregister.gov/agencies/federal-aviation-administration","json_url":"https://www.federalregister.gov/api/v1/agencies/159","parent_id":492,"slug":"federal-aviation-administration"}],"excerpts":"described in Subtitle VII, Part A, Subpart i, Section 40113, Administrative, and Subpart iii, Section 44701, General Requirements; Section 44702, Issuance of <span class=\"match\">Certificates</span>; Section 44703, Airman <span class=\"match\">Certificates</span>; Section 44704, Type <span class=\"match\">Certificates</span>, Production <span class=\"match\">Certificates</span>, Airworthiness <span class=\"match\">Certificates</span>, and Design and Production Organization <span class=\"match\">Certificates</span>; Section 44705, Air Carrier Operating <span class=\"match\">Certificates</span>; and Section 44707, Examination and Rating Air Agencies. Under these sections, the FAA prescribes regulations and minimum standards for practices, methods,"},{"title":"Defense Federal Acquisition Regulation Supplement: Definition of “Commercial Item” (DFARS Case 2018-D066)","type":"Rule","abstract":"DoD is issuing a final rule to amend the Defense Federal Acquisition Regulation Supplement (DFARS) to implement the revised definition of \"commercial item\" in accordance with two sections of the John S. McCain National Defense Authorization Act for Fiscal Year 2019.","document_number":"2023-01294","html_url":"https://www.federalregister.gov/documents/2023/01/31/2023-01294/defense-federal-acquisition-regulation-supplement-definition-of-commercial-item-dfars-case-2018-d066","pdf_url":"https://www.govinfo.gov/content/pkg/FR-2023-01-31/pdf/2023-01294.pdf","public_inspection_pdf_url":"https://public-inspection.federalregister.gov/2023-01294.pdf?1675086319","publication_date":"2023-01-31","agencies":[{"raw_name":"DEPARTMENT OF DEFENSE","name":"Defense Department","id":103,"url":"https://www.federalregister.gov/agencies/defense-department","json_url":"https://www.federalregister.gov/api/v1/agencies/103","parent_id":null,"slug":"defense-department"},{"raw_name":"Defense Acquisition Regulations System","name":"Defense Acquisition Regulations System","id":97,"url":"https://www.federalregister.gov/agencies/defense-acquisition-regulations-system","json_url":"https://www.federalregister.gov/api/v1/agencies/97","parent_id":103,"slug":"defense-acquisition-regulations-system"}],"excerpts":"text; and \n b. In paragraphs (a) and (b), by removing “commercial items” and adding “commercial products and commercial services” in its place. \n The revision reads as follows: \n \n 204.7503 \n \n Use the clause at 252.204-7021, Contractor Compliance with the <span class=\"match\">Cybersecurity</span> <span class=\"match\">Maturity</span> <span class=\"match\">Model</span> <span class=\"match\">Certification</span> Level Requirement, as follows: \n \n \n \n \n PART 205—PUBLICIZING CONTRACT ACTIONS \n \n 205.470 \n \n \n \n \n 17. Amend section 205.470 by removing “commercial items” and adding “commercial products and commercial services” in its place. \n \n \n PART 207—ACQUISITION"},{"title":"Incentives for Advanced Cybersecurity Investment","type":"Rule","abstract":"The Federal Energy Regulatory Commission is revising its regulations to provide incentive-based rate treatment for the transmission of electric energy in interstate commerce and the sale of electric energy at wholesale in interstate commerce by utilities for the purpose of benefitting consumers by encouraging investments by utilities in Advanced Cybersecurity Technology and participation by utilities in cybersecurity threat information sharing programs, as directed by the Infrastructure Investment and Jobs Act of 2021.","document_number":"2023-08929","html_url":"https://www.federalregister.gov/documents/2023/05/03/2023-08929/incentives-for-advanced-cybersecurity-investment","pdf_url":"https://www.govinfo.gov/content/pkg/FR-2023-05-03/pdf/2023-08929.pdf","public_inspection_pdf_url":"https://public-inspection.federalregister.gov/2023-08929.pdf?1683031517","publication_date":"2023-05-03","agencies":[{"raw_name":"DEPARTMENT OF ENERGY","name":"Energy Department","id":136,"url":"https://www.federalregister.gov/agencies/energy-department","json_url":"https://www.federalregister.gov/api/v1/agencies/136","parent_id":null,"slug":"energy-department"},{"raw_name":"Federal Energy Regulatory Commission","name":"Federal Energy Regulatory Commission","id":167,"url":"https://www.federalregister.gov/agencies/federal-energy-regulatory-commission","json_url":"https://www.federalregister.gov/api/v1/agencies/167","parent_id":136,"slug":"federal-energy-regulatory-commission"}],"excerpts":"cy-framework-and-<span class=\"match\">cybersecurity</span>-framework-nist-special-publication-800-53. \n \n \n \n \n 89 \n  \n See \n NIST, \n <span class=\"match\">Cybersecurity</span> Framework, https://www.nist.gov/cyberframework. \n \n \n \n \n 90 \n  S\n ee, e.g., \n CISA, \n National Cyber Awareness System Alerts, https://www.cisa.gov/uscert/ncas/alerts. \n \n \n \n \n 91 \n  \n See \n DOE, \n <span class=\"match\">Cybersecurity</span> Capability <span class=\"match\">Maturity</span> <span class=\"match\">Model</span>, https://www.energy.gov/ceser/<span class=\"match\">cybersecurity</span>-capability-<span class=\"match\">maturity</span>-<span class=\"match\">model</span>-c2m2. \n \n \n \n \n 92 \n  As we discuss in section III.B.1., when considering whether to add a <span class=\"match\">cybersecurity</span> investment to the"},{"title":"Medicare Program; Hospital Inpatient Prospective Payment Systems for Acute Care Hospitals (IPPS) and the Long-Term Care Hospital Prospective Payment System and Policy Changes and Fiscal Year (FY) 2026 Rates; Changes to the FY 2025 IPPS Rates Due to Court Decision; Requirements for Quality Programs; and Other Policy Changes; Health Data, Technology, and Interoperability: Electronic Prescribing, Real-Time Prescription Benefit and Electronic Prior Authorization","type":"Rule","abstract":"This final rule revises the Medicare hospital inpatient prospective payment systems (IPPS) for operating and capital-related costs of acute care hospitals; makes changes relating to Medicare graduate medical education (GME) for teaching hospitals; updates the payment policies and the annual payment rates for the Medicare prospective payment system (PPS) for inpatient hospital services provided by long-term care hospitals (LTCHs); updates and makes changes to requirements for certain quality programs; and makes other policy- related changes. We are also finalizing the provisions of the interim final action with comment period regarding the changes to the FY 2025 IPPS rates due to the court decision in Bridgeport Hosp. v. Becerra. Lastly, it finalizes certain updates to the ONC Health Information Technology (IT) Certification Program.","document_number":"2025-14681","html_url":"https://www.federalregister.gov/documents/2025/08/04/2025-14681/medicare-program-hospital-inpatient-prospective-payment-systems-for-acute-care-hospitals-ipps-and","pdf_url":"https://www.govinfo.gov/content/pkg/FR-2025-08-04/pdf/2025-14681.pdf","public_inspection_pdf_url":"https://public-inspection.federalregister.gov/2025-14681.pdf?1753992911","publication_date":"2025-08-04","agencies":[{"raw_name":"DEPARTMENT OF HEALTH AND HUMAN SERVICES","name":"Health and Human Services Department","id":221,"url":"https://www.federalregister.gov/agencies/health-and-human-services-department","json_url":"https://www.federalregister.gov/api/v1/agencies/221","parent_id":null,"slug":"health-and-human-services-department"},{"raw_name":"Centers for Medicare & Medicaid Services","name":"Centers for Medicare & Medicaid Services","id":45,"url":"https://www.federalregister.gov/agencies/centers-for-medicare-medicaid-services","json_url":"https://www.federalregister.gov/api/v1/agencies/45","parent_id":221,"slug":"centers-for-medicare-medicaid-services"},{"raw_name":"Office of the Secretary"}],"excerpts":"Improvement Advanced (BPCI Advanced) <span class=\"match\">model</span>, will continue to be paid under the IPPS and, therefore, are eligible to receive empirically justified Medicare DSH payments and uncompensated care payments until the <span class=\"match\">Model's</span> final performance year, which ends on December 31, 2025. For further information regarding the BPCI Advanced <span class=\"match\">model</span>, we refer readers to the CMS website at \n https://innovation.cms.gov/innovation-<span class=\"match\">models</span>/bpci-advanced \n .\n \n • Transforming Episode Accountability <span class=\"match\">Model</span> (TEAM) is a new episode-based payment <span class=\"match\">model</span>. Hospitals participating in TEAM"},{"title":"Investment of Customer Funds by Futures Commission Merchants and Derivatives Clearing Organizations","type":"Rule","abstract":"The Commodity Futures Trading Commission (\"Commission\" or \"CFTC\") is amending its regulations governing the types of investments that futures commission merchants and derivatives clearing organizations may make with funds held for the benefit of customers engaging in futures, foreign futures, and cleared swaps transactions. The Commission is also revising asset-based and issuer-based concentration limits for the investment of customer funds. The Commission is also specifying market risk capital charges that a futures commission merchant must take on new investments added to the list of permitted investments in computing the firm's adjusted net capital. The amendments also revise regulations that require each futures commission merchant to report to the Commission, and to the firm's designated self-regulatory organization, the name, location, and amount of customer funds held by each depository, including any investments of customer funds held by the depository. Lastly, the Commission is eliminating the requirement that each depository holding customer funds must provide the Commission with read-only electronic access to such accounts for the futures commission merchant to treat the funds as customer segregated funds.","document_number":"2024-30927","html_url":"https://www.federalregister.gov/documents/2025/01/22/2024-30927/investment-of-customer-funds-by-futures-commission-merchants-and-derivatives-clearing-organizations","pdf_url":"https://www.govinfo.gov/content/pkg/FR-2025-01-22/pdf/2024-30927.pdf","public_inspection_pdf_url":"https://public-inspection.federalregister.gov/2024-30927.pdf?1736889333","publication_date":"2025-01-22","agencies":[{"raw_name":"COMMODITY FUTURES TRADING COMMISSION","name":"Commodity Futures Trading Commission","id":77,"url":"https://www.federalregister.gov/agencies/commodity-futures-trading-commission","json_url":"https://www.federalregister.gov/api/v1/agencies/77","parent_id":null,"slug":"commodity-futures-trading-commission"}],"excerpts":"180-calendar-day maximum remaining time-to-<span class=\"match\">maturity</span> requirement for each individual Specified Foreign Sovereign Debt security.\n \n \n \n 255 \n  Final Commission regulation 1.25(f)(1) and (2).\n \n \n \n \n 256 \n  Proposal at 81245-81246.\n \n \n \n In addition, data regarding the new issuances of short-term Specified Foreign Sovereign Debt supports the lower 60-day dollar-weighted average time-to-<span class=\"match\">maturity</span> requirement and the 180-day maximum remaining time-to-<span class=\"match\">maturity</span> requirement proposed.\n 257 \n \n Therefore, the proposed time-to-<span class=\"match\">maturity</span> conditions more effectively account"},{"title":"Medicare and Medicaid Programs; CY 2026 Payment Policies Under the Physician Fee Schedule and Other Changes to Part B Payment and Coverage Policies; Medicare Shared Savings Program Requirements; and Medicare Prescription Drug Inflation Rebate Program","type":"Rule","abstract":"This major final rule addresses: changes to the physician fee schedule (PFS); other changes to Medicare Part B payment policies to ensure that payment systems are updated to reflect changes in medical practice, relative value of services, and changes in the statute; codification of establishment of new policies for: the Medicare Prescription Drug Inflation Rebate Program under the Inflation Reduction Act of 2022; the Ambulatory Specialty Model; updates to the Medicare Diabetes Prevention Program expanded model; updates to drugs and biological products paid under Part B; Medicare Shared Savings Program requirements; updates to the Quality Payment Program; updates to policies for Rural Health Clinics and Federally Qualified Health Centers; update to the Ambulance Fee Schedule regulations; codification of the Inflation Reduction Act and Consolidated Appropriations Act, 2023 provisions; updates to the Medicare Promoting Interoperability Program.","document_number":"2025-19787","html_url":"https://www.federalregister.gov/documents/2025/11/05/2025-19787/medicare-and-medicaid-programs-cy-2026-payment-policies-under-the-physician-fee-schedule-and-other","pdf_url":"https://www.govinfo.gov/content/pkg/FR-2025-11-05/pdf/2025-19787.pdf","public_inspection_pdf_url":"https://public-inspection.federalregister.gov/2025-19787.pdf?1761945018","publication_date":"2025-11-05","agencies":[{"raw_name":"DEPARTMENT OF HEALTH AND HUMAN SERVICES","name":"Health and Human Services Department","id":221,"url":"https://www.federalregister.gov/agencies/health-and-human-services-department","json_url":"https://www.federalregister.gov/api/v1/agencies/221","parent_id":null,"slug":"health-and-human-services-department"},{"raw_name":"Centers for Medicare & Medicaid Services","name":"Centers for Medicare & Medicaid Services","id":45,"url":"https://www.federalregister.gov/agencies/centers-for-medicare-medicaid-services","json_url":"https://www.federalregister.gov/api/v1/agencies/45","parent_id":221,"slug":"centers-for-medicare-medicaid-services"}],"excerpts":"new mandatory <span class=\"match\">model</span> that we believe will improve beneficiary and provider engagement, incentivize preventive care, and increase financial accountability for certain specialists. The <span class=\"match\">model</span> will build upon lessons learned from previous Innovation Center <span class=\"match\">models</span> and the Merit-based Incentive Payment System (MIPS) under the Quality Payment Program. We believe the <span class=\"match\">model</span> will answer the call to create a more cohesive and efficient health system that enhances the quality of care and reduces costs over time. To promote preventive care, the <span class=\"match\">model</span> will incentivize"},{"title":"Patient Protection and Affordable Care Act; HHS Notice of Benefit and Payment Parameters for 2026; and Basic Health Program","type":"Rule","abstract":"This final rule includes payment parameters and provisions related to the HHS-operated risk adjustment and risk adjustment data validation (HHS-RADV) programs, as well as 2026 benefit year user fee rates for issuers that participate in the HHS-operated risk adjustment program and the 2026 benefit year user fee rates for issuers offering qualified health plans (QHPs) through Federally-facilitated Exchanges (FFEs) and State-based Exchanges on the Federal platform (SBE-FPs). This final rule also includes requirements related to modifications to the calculation of the Basic Health Program (BHP) payment; and changes to the Initial Validation Audit (IVA) sampling approach and Second Validation Audit (SVA) pairwise means test for HHS-RADV. It also addresses HHS' authority to engage in compliance reviews of and take enforcement action against lead agents of insurance agencies for violations of HHS' Exchange standards and requirements; HHS' system suspension authority to address noncompliance by agents and brokers; an optional fixed-dollar premium payment threshold; permissible plan-level adjustment to the index rate to account for cost-sharing reductions (CSRs); reconsideration standards for certification denials; changes to the approach for conducting Essential Community Provider (ECP) certification reviews; a policy to publicly share aggregated, summary- level Quality Improvement Strategy (QIS) information on an annual basis; and revisions to the medical loss ratio (MLR) reporting and rebate requirements for qualifying issuers that meet certain standards.","document_number":"2025-00640","html_url":"https://www.federalregister.gov/documents/2025/01/15/2025-00640/patient-protection-and-affordable-care-act-hhs-notice-of-benefit-and-payment-parameters-for-2026-and","pdf_url":"https://www.govinfo.gov/content/pkg/FR-2025-01-15/pdf/2025-00640.pdf","public_inspection_pdf_url":"https://public-inspection.federalregister.gov/2025-00640.pdf?1736802922","publication_date":"2025-01-15","agencies":[{"raw_name":"DEPARTMENT OF HEALTH AND HUMAN SERVICES","name":"Health and Human Services Department","id":221,"url":"https://www.federalregister.gov/agencies/health-and-human-services-department","json_url":"https://www.federalregister.gov/api/v1/agencies/221","parent_id":null,"slug":"health-and-human-services-department"},{"raw_name":"Office of the Secretary"}],"excerpts":"hierarchy specification(s) related to the addition of the PrEP ACF in the child <span class=\"match\">models</span> that needs to be addressed when finalizing these new factors for the <span class=\"match\">models</span>. To explain, we first note that because the HHS risk adjustment child <span class=\"match\">models</span> do not contain RXCs, the costs of HIV treatment (inclusive of the HIV treatment medication regimens captured in RXC 1 in the adult <span class=\"match\">models</span>) are accounted for in the HCC 1 coefficient in the child <span class=\"match\">models</span>. As such, in contrast to the adult <span class=\"match\">models</span>, where the RXC 1 coefficient is generally larger than the PrEP ACF or HCC"},{"title":"Risk-Informed, Technology-Inclusive Regulatory Framework for Advanced Reactors","type":"Rule","abstract":"The U.S. Nuclear Regulatory Commission (NRC) is amending its regulations by adding a risk-informed, performance-based, and technology-inclusive regulatory framework for commercial nuclear plants in response to the Nuclear Energy Innovation and Modernization Act (NEIMA). The current application and licensing requirements were primarily developed to address license requests concerning light water- cooled reactors and operational requirements for those types of reactors. This final rule responds to NEIMA by creating an alternative, technology-inclusive regulatory framework to accommodate licensing of future commercial nuclear plants, including advanced reactor designs that may not employ light-water technology.","document_number":"2026-06048","html_url":"https://www.federalregister.gov/documents/2026/03/30/2026-06048/risk-informed-technology-inclusive-regulatory-framework-for-advanced-reactors","pdf_url":"https://www.govinfo.gov/content/pkg/FR-2026-03-30/pdf/2026-06048.pdf","public_inspection_pdf_url":"https://public-inspection.federalregister.gov/2026-06048.pdf?1774615514","publication_date":"2026-03-30","agencies":[{"raw_name":"NUCLEAR REGULATORY COMMISSION","name":"Nuclear Regulatory Commission","id":383,"url":"https://www.federalregister.gov/agencies/nuclear-regulatory-commission","json_url":"https://www.federalregister.gov/api/v1/agencies/383","parent_id":null,"slug":"nuclear-regulatory-commission"}],"excerpts":"of the <span class=\"match\">cybersecurity</span> program requirements in § 73.110(d) and (e) would apply. For example, the licensee would only need to develop a <span class=\"match\">cybersecurity</span> program that implements the following requirements:\n \n • Analyze modifications of any asset before implementation to demonstrate compliance with the potential consequences in § 73.110(a); \n • Ensure employees and contractors are aware of <span class=\"match\">cybersecurity</span> requirements and have some level of <span class=\"match\">cybersecurity</span> training; \n • Evaluate and manage <span class=\"match\">cybersecurity</span> risks to the plant; \n • Review the <span class=\"match\">cybersecurity</span> plan for"},{"title":"Facilitating Implementation of Next Generation 911 Services (NG911); Improving 911 Reliability","type":"Rule","abstract":"In this document, the Federal Communications Commission (the FCC or Commission) adopts rules to ensure that emerging Next Generation 911 (NG911) networks are reliable and interoperable. NG911 is replacing legacy 911 technology across the country with internet Protocol (IP)- based infrastructure that will support new 911 capabilities, including text, video, and data. However, for NG911 to be fully effective, NG911 networks must be designed to safeguard the reliability of critical components and support the interoperability needed to seamlessly transfer 911 calls and data from one network to another. The rules require entities essential to delivering emergency calls in the NG911 environment to implement common sense measures to safeguard the reliability of NG911 networks and reduce the risk of 911 outages, and require certain entities to report on their support for NG911 interoperability. The rules also eliminate unnecessary and burdensome legacy rules to increase flexibility and encourage technical innovation to make NG911 services reliable, interoperable, and accessible to all.","document_number":"2026-13998","html_url":"https://www.federalregister.gov/documents/2026/07/10/2026-13998/facilitating-implementation-of-next-generation-911-services-ng911-improving-911-reliability","pdf_url":"https://www.govinfo.gov/content/pkg/FR-2026-07-10/pdf/2026-13998.pdf","public_inspection_pdf_url":"https://public-inspection.federalregister.gov/2026-13998.pdf?1783601118","publication_date":"2026-07-10","agencies":[{"raw_name":"FEDERAL COMMUNICATIONS COMMISSION","name":"Federal Communications Commission","id":161,"url":"https://www.federalregister.gov/agencies/federal-communications-commission","json_url":"https://www.federalregister.gov/api/v1/agencies/161","parent_id":null,"slug":"federal-communications-commission"}],"excerpts":"audits of monitoring links and aggregation points annually.\n 17 \n \n \n \n \n 17 \n  \n Id. \n § 9.19(c)(3).\n \n \n \n The Commission delegated oversight of the reliability rules and <span class=\"match\">certification</span> process to PSHSB. The Bureau established the 911 Reliability <span class=\"match\">Certification</span> System (911RCS) to receive filings and <span class=\"match\">certifications</span>, and it was empowered to review <span class=\"match\">certifications</span>, revise <span class=\"match\">certification</span> forms and procedures, investigate noncompliance, and order remedial action.\n 18 \n \n \n \n \n 18 \n  \n Id. \n § 0.392(j).\n \n \n \n Since adopting the reliability rules in 2013, the"},{"title":"Administrative Simplification; Adoption of Standards for Health Care Claims Attachments Transactions and Electronic Signatures","type":"Rule","abstract":"This final rule implements requirements of the Administrative Simplification subtitle of the Health Insurance Portability and Accountability Act of 1996 (HIPAA), and the Patient Protection and Affordable Care Act, as amended by the Health Care and Education Reconciliation Act of 2010, enacted on March 30, 2010--collectively, the Affordable Care Act. Specifically, this final rule adopts standards for health care claims attachments transactions, which will support health care claims transactions, and a standard for electronic signatures to be used in conjunction with health care claims attachments transactions.","document_number":"2026-05676","html_url":"https://www.federalregister.gov/documents/2026/03/24/2026-05676/administrative-simplification-adoption-of-standards-for-health-care-claims-attachments-transactions","pdf_url":"https://www.govinfo.gov/content/pkg/FR-2026-03-24/pdf/2026-05676.pdf","public_inspection_pdf_url":"https://public-inspection.federalregister.gov/2026-05676.pdf?1774037709","publication_date":"2026-03-24","agencies":[{"raw_name":"DEPARTMENT OF HEALTH AND HUMAN SERVICES","name":"Health and Human Services Department","id":221,"url":"https://www.federalregister.gov/agencies/health-and-human-services-department","json_url":"https://www.federalregister.gov/api/v1/agencies/221","parent_id":null,"slug":"health-and-human-services-department"},{"raw_name":"Office of the Secretary"}],"excerpts":"compatibility across systems. \n \n Comment: \n A commenter stated that the proposed rule's reference to the limited uptake of the current referral <span class=\"match\">certification</span> and authorization transaction standard being due to not having established standards for attachments (87 FR 78446) may be a result of an onerous process for <span class=\"match\">certification</span> and authorization. The commenter stated that if limited uptake of the referral <span class=\"match\">certification</span> and authorization transactions is a standards issue, it is imperative that the new attachments standard be simple and practical in order"},{"title":"Medicare Program; Hospital Inpatient Prospective Payment Systems for Acute Care Hospitals (IPPS) and the Long-Term Care Hospital Prospective Payment System and Policy Changes and Fiscal Year (FY) 2027 Rates; Requirements for Quality Programs; Other Policy Changes; and Adoption of Updated Versions of Certain Health Information Technology Standards","type":"Rule","abstract":"This final rule will revise the Medicare hospital inpatient prospective payment systems (IPPS) for operating and capital-related costs of acute care hospitals; make changes relating to Medicare graduate medical education (GME) for teaching hospitals; update the payment policies and the annual payment rates for the Medicare prospective payment system (PPS) for inpatient hospital services provided by long-term care hospitals (LTCHs); update and make changes to requirements for certain quality programs; and make other policy- related changes. ONC also adopts certain health information technology (health IT) standards and specifications on behalf of HHS.","document_number":"2026-15833","html_url":"https://www.federalregister.gov/documents/2026/08/04/2026-15833/medicare-program-hospital-inpatient-prospective-payment-systems-for-acute-care-hospitals-ipps-and","pdf_url":"https://www.govinfo.gov/content/pkg/FR-2026-08-04/pdf/2026-15833.pdf","public_inspection_pdf_url":"https://public-inspection.federalregister.gov/2026-15833.pdf?1785528912","publication_date":"2026-08-04","agencies":[{"raw_name":"DEPARTMENT OF HEALTH AND HUMAN SERVICES","name":"Health and Human Services Department","id":221,"url":"https://www.federalregister.gov/agencies/health-and-human-services-department","json_url":"https://www.federalregister.gov/api/v1/agencies/221","parent_id":null,"slug":"health-and-human-services-department"},{"raw_name":"Centers for Medicare & Medicaid Services","name":"Centers for Medicare & Medicaid Services","id":45,"url":"https://www.federalregister.gov/agencies/centers-for-medicare-medicaid-services","json_url":"https://www.federalregister.gov/api/v1/agencies/45","parent_id":221,"slug":"centers-for-medicare-medicaid-services"},{"raw_name":"Office of the Secretary"}],"excerpts":"with physician ownership (POHs) and our policy intent for future rulemaking. \n The Comprehensive Care for Joint Replacement CJR Expanded (CJR-X) <span class=\"match\">Model</span> builds upon the CJR <span class=\"match\">Model</span> test that ran from April 1, 2016 to December 31, 2024. Based on the strength of evidence from the CJR <span class=\"match\">Model</span>, the CMS Innovation Center is expanding the <span class=\"match\">model</span> nationally, including U.S. Territories starting January 1, 2028. The <span class=\"match\">model</span> will focus on improving care and reducing spending for Medicare beneficiaries undergoing lower extremity joint replacement (LEJR) procedures. Participating"},{"title":"Credit for Production of Clean Hydrogen and Energy Credit","type":"Rule","abstract":"This document contains final regulations implementing the credit for production of clean hydrogen and certain provisions of the energy credit as enacted by the Inflation Reduction Act of 2022. The regulations provide rules for: determining lifecycle greenhouse gas emissions rates resulting from hydrogen production processes; petitioning for provisional emissions rates; verifying production and sale or use of clean hydrogen; modifying or retrofitting existing qualified clean hydrogen production facilities; using electricity from certain renewable or zero-emissions sources to produce qualified clean hydrogen; and electing to treat part of a specified clean hydrogen production facility instead as property eligible for the energy credit. These regulations affect all taxpayers who produce qualified clean hydrogen and claim the clean hydrogen production credit, elect to treat part of a specified clean hydrogen production facility as property eligible for the energy credit, or produce electricity from certain renewable or zero-emissions sources used by taxpayers or related persons to produce qualified clean hydrogen.","document_number":"2024-31513","html_url":"https://www.federalregister.gov/documents/2025/01/10/2024-31513/credit-for-production-of-clean-hydrogen-and-energy-credit","pdf_url":"https://www.govinfo.gov/content/pkg/FR-2025-01-10/pdf/2024-31513.pdf","public_inspection_pdf_url":"https://public-inspection.federalregister.gov/2024-31513.pdf?1736354471","publication_date":"2025-01-10","agencies":[{"raw_name":"DEPARTMENT OF THE TREASURY","name":"Treasury Department","id":497,"url":"https://www.federalregister.gov/agencies/treasury-department","json_url":"https://www.federalregister.gov/api/v1/agencies/497","parent_id":null,"slug":"treasury-department"},{"raw_name":"Internal Revenue Service","name":"Internal Revenue Service","id":254,"url":"https://www.federalregister.gov/agencies/internal-revenue-service","json_url":"https://www.federalregister.gov/api/v1/agencies/254","parent_id":497,"slug":"internal-revenue-service"}],"excerpts":"version of 45VH2-GREET as the most recent GREET <span class=\"match\">model</span>.\n \n Several comments recommended changes to proposed § 1.45V-1(a)(8)(ii). Some comments requested that, instead of identifying 45VH2-GREET as the “most recent GREET <span class=\"match\">model</span>” under section 45V(c)(1)(B), the final regulations identify the R&amp;D GREET <span class=\"match\">model</span> developed by Argonne National Laboratory and published by the DOE as the most recent GREET <span class=\"match\">model</span>. Comments further recommended that the final regulations require the use of 45VH2-GREET as a “successor <span class=\"match\">model</span>” only if 45VH2-GREET closely aligns in function"}]}