The document provides an overview of the Department of Defense’s Cybersecurity Maturity Model Certification (CMMC) 2.0, which establishes revised standards to…
Cybersecurity
Cybersecurity is critical to protecting research data and information systems from unauthorized access or misuse, ensuring the integrity of federally funded research.
Featured
Security Tomorrow, Today: Cybersecurity Updates from DARPA: June 2025 COGR Meeting
The document summarizes a June 2025 briefing presented COGR by Jesse Watkins, Deputy Director of the Security and Intelligence Directorate at DARPA, and Kris West...
What’s Hot in Cybersecurity & Implications for Institutions: February 2025 Meeting
This document provides an extensive overview of emerging cybersecurity standards and regulatory changes affecting institutions, particularly focusing on the...
Resources
Point of Contact
External Links
All Cybersecurity Articles
Overview of DOD Cybersecurity Model Certification 2.0 – Updated October 2025
The document provides an overview of the Department of Defense’s Cybersecurity Maturity Model Certification (CMMC) 2.0, which establishes revised standards to ensure contractors—including universities working with Controlled Unclassified Information (CUI) or Federal Contract Information (FCI)—appropriately protect sensitive data. CMMC 2.0 simplifies compliance by reducing certification levels from…
COGR’s September 2025 Update
The September 2025 COGR Update provides an overview of recent federal developments affecting U.S. research institutions, including proposed regulatory changes, executive orders, litigation updates, and agency-specific policy shifts impacting research funding, compliance, security, and administration.
COGR February 2025 Update
The February 2025 COGR Update provides a detailed account of significant regulatory, policy, and administrative changes impacting U.S. research institutions, driven largely by executive orders from the Administration that restrict DEI programs, roll back regulations, and alter research funding and compliance practices. It highlights widespread operational disruptions, legal challenges over reduced
Overview of OSTP Guidelines for Research Security Programs at Covered Institutions
The OSTP Research Security Program Guidelines, released July 9, 2024, establish four required elements for research security compliance—cybersecurity, foreign travel security, research security training, and export control training—at institutions exceeding a $50 million annual federal R&D threshold, with detailed timetables for agency and institutional implementation. The Guidelines promote u
COGR Joins a Multi-Association Response to the Request for Comments to Docket Number DoD–2023–OS–0063 / Regulatory Identifier Number (RIN) 0790–AL49, “Cybersecurity Maturity Model Certification (CMMC) Program”
The collective comments submitted by the American Council on Education (ACE), Association of American Universities (AAU), Association of Public and Land-Grant Universities (APLU), COGR, and EDUCAUSE address the Department of Defense’s proposed updates to the Cybersecurity Maturity Model Certification (CMMC) Program. The associations commend the DoD for recognizing that fundamental research general…
COGR, EDUCAUSE, and AAU Submit Joint Comment Letter to GSA on Cyber Threat and Incident Reporting & Information Sharing (FAR 2021-017)
EDUCAUSE, COGR, and the Association of American Universities (AAU) submitted comments expressing concern over the scope and impact of the proposed changes in Federal Acquisition Regulation Case 2021-017, which would require all federal contractors—including higher education institutions engaged in fundamental research—to comply with broad cyber incident reporting and software bill of materials (SB
COGR Supports EDUCAUSE Response to FAR: Prohibition on a ByteDance Covered Application
The letter from EDUCAUSE, addressed to the General Services Administration, provides comments on the Federal Acquisition Regulation (FAR) Case 2023–010, specifically regarding the prohibition on the use of ByteDance applications, such as TikTok, within federal contracts and federally funded research environments. EDUCAUSE, representing over 2,100 higher education institutions, expresses appreciati
Laws, Policies, & Agency Guidance Concerning Research Security
Laws, Policies & Agency Guidance Concerning Research SecurityThis section provides links to statutes, regulations, and other sources of legal requirements related to science and security, links to federal research agency policy and guidance in this area. Resources are grouped in reverse chronological order (i.e., most recent resources are listed first) under t
COGR Supports EDUCAUSE Response to NIST’s Cybersecurity for R&D Request for Comment
The letter from EDUCAUSE, represented by Senior Advisor Jarret S. Cummings, responds to the NIST’s request for comments on cybersecurity for research and development. EDUCAUSE, an association of over 2,100 colleges, universities, and related organizations focused on advancing higher education through IT, thanks NIST for considering input from the higher education sector and formally submits the co
Pagination
- 1
- 2