Contract Scoping

I advise on cybersecurity and data-protection language from either side of the deal, including how personal, contractual, and controlled government data is supposed to be protected once the words are signed.

For buyers

I help you write the cybersecurity and data-protection requirements in the contract and the statement of work (SOW) so vendors actually cover the data you care about, at a scope you can live with.

For sellers

I help you see what that language requires you to build, report, and prove, so you do not sign a baseline the organization or the system cannot meet.

This is technical advice on the commitment. It is not legal advice. Counsel handles contractual applicability and legal effect.

Same issues. Either chair. I help you see what the language requires to be requested and what it requires to be provided.

Matter type Typical issues Side served
Baseline selection Which standard the draft names, level, revision, conflicting references Either side
CMMC / NIST 800-171 / 800-172 CUI handling, control implementation, compliance representations, contractor cybersecurity obligations Either side
FAR / DFARS cyber clauses What 52.204-21, 7012, 7019, 7020, and 7021 reach, and what they require to be shown Either side
CUI and covered systems What data the words cover, which systems they pull in, enclave versus remaining scope Either side
Cloud and inheritance What the provider must still be able to show versus what the customer must still evidence Either side
Vendors and SOW Whether the vendor language covers the data the buyer thinks it covers, and whether the seller can take that language on Either side
Privacy and data-protection language What those words reach, which systems have to carry them Either side
Security volume What the volume must demonstrate, and what the writer must later be able to produce Either side
Before signature Whether the promise can be implemented and evidenced Either side
Contact Me