Executive Gov
  • Home
  • Acquisition & Procurement
  • Agencies
    • DoD
    • Intelligence
    • DHS
    • Civilian
    • Space
  • Cybersecurity
  • Technology
  • Awards
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news
No Result
View All Result
Executive Gov
  • Home
  • Acquisition & Procurement
  • Agencies
    • DoD
    • Intelligence
    • DHS
    • Civilian
    • Space
  • Cybersecurity
  • Technology
  • Awards
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news
No Result
View All Result
Executive Gov
No Result
View All Result
Home Cybersecurity

DOW CIO Issues Memo on Cybersecurity Service Provider Certification Requirements

by Jane Edwards
July 29, 2026
in Cybersecurity, DoD, News
Kirsten Davies. The DOW CIO has issued a memo on cybersecurity service provider certification requirements.

Kirsten Davies, chief information officer at the Department of War, has issued a directive-type memorandum outlining the minimum baseline requirements for organizations to be certified and authorized as a DOW cybersecurity service provider.

  • DOW CIO Kirsten Davies has released new CSSP certification guidance
  • The policy covers alignment for AI, quantum and industrial control systems
  • Explore AI, cybersecurity and more at the Potomac Officers Club’s DOW summits

Kirsten Davies, chief information officer at the Department of War and a 2026 Wash100 awardee, has issued a directive-type memorandum, or DTM, outlining the minimum baseline requirements for an organization to be certified and authorized as a DOW cybersecurity service provider, or CSSP.

Table of Contents

    • You might also like
    • Navy Names John Cremins Deputy Under Secretary for Intelligence & Security
    • Paul Kearns to Retire as Director of Argonne National Laboratory
    • Air Force Publishes Open Architecture Standards for Mission Systems, Autonomy
  • What Are the Minimum Requirements to Become a Certified DOW CCSP?
  • What Are the Minimum Cybersecurity Activities CSSPs Must Perform?
  • Which Systems & Networks Must Align With a DOW CSSP?
  • Who Authorizes & Certifies DOW Cybersecurity Service Providers?
  • How Does the Policy Fit Into DOW’s Broader Cybersecurity Push?

You might also like

Navy Names John Cremins Deputy Under Secretary for Intelligence & Security

Paul Kearns to Retire as Director of Argonne National Laboratory

Air Force Publishes Open Architecture Standards for Mission Systems, Autonomy

DOW CIO Issues Memo on Cybersecurity Service Provider Certification Requirements

Join us at the Potomac Officers Club’s 2026 Air & Space Summit tomorrow, July 30, for a panel discussion on advancing multilevel security with AI and machine learning for the modern warfighter. Secure your seat now! Then mark your calendar for the 2026 Navy Summit on Aug. 27, which will feature a panel discussion on modernizing the Navy’s enterprise networks for information warfare readiness. Register today to join the conversation.

The memo, titled “Cybersecurity Service Provider Definition Clarification,” issued Tuesday and signed by Davies establishes policy, assigns responsibilities and sets procedures for CSSP certification across the department. 

The DTM takes effect immediately and applies to the Office of the Secretary of War, the military departments, the Joint Staff, combatant commands, the DOW Office of Inspector General and all other DOW components. The memo is set to expire on July 28, 2028.

What Are the Minimum Requirements to Become a Certified DOW CCSP?

The memo directs CSSPs to continuously monitor DOW cyber terrain to detect, analyze and respond to anomalous, suspicious or malicious activity. CSSPs must maintain personnel and resources to triage time-sensitive events, with a maximum of 72 hours to triage an incident and 24 hours to report it to U.S. Cyber Command.

CSSPs are also required to maintain a valid certification and an authorization to operate; failing to do so results in suspension of CSSP services. Certification standards are detailed in DOD Manual 8530.01 and the CSSP Minimum Cybersecurity Activities Checklist.

What Are the Minimum Cybersecurity Activities CSSPs Must Perform?

To be certified, CSSPs must carry out a defined set of baseline activities. These include:

  • Correlating asset and vulnerability data with cyberthreat intelligence to identify exploits and threat opportunities
  • Malware notification, including confirming that subscribers acknowledge reported findings
  • Detection processes across three network tiers — internet access points, enclave and perimeter boundaries, and internal host-level monitoring
  • Orders and cyber protection condition compliance, including implementing and reporting on DOW orders
  • Cyber incident handling, categorization and reporting, in coordination with USCYBERCOM and the DOW Cyber Crime Center
  • Law enforcement and counterintelligence coordination for forensic investigations of compromised systems
  • Incident response analysis, including forensic media analysis and intrusion assessments
  • Sustainment and continuous self-assessment, including annual compliance reviews

Which Systems & Networks Must Align With a DOW CSSP?

The DTM extends CSSP alignment requirements beyond traditional IT networks. According to the memo, the requirement applies to:

  • Cloud instances
  • Coalition or mission partner environments
  • Special access programs
  • Intelligence networks
  • Industrial control systems
  • Internet of Things devices
  • Operational technology
  • Artificial intelligence systems
  • Quantum computers and networks

The memo states this alignment requirement cannot be waived or risk-accepted by authorizing officials, regardless of a system’s network, connectivity or mission.

Who Authorizes & Certifies DOW Cybersecurity Service Providers?

Under the memo, the DOW CIO approves or disapproves all CSSP certification requests and forwards approvals to the commander of USCYBERCOM. The DOW CIO also serves as the authorizing official for special access program systems that do not process sensitive compartmented information and adjudicates CSSP certification appeals in coordination with USCYBERCOM.

USCYBERCOM, in turn, implements general service CSSP processes. It functions as both certifier and authorizing official for general service and special access program systems at the top-secret collateral level and below.

For intelligence community elements within the DOW, the director of national intelligence ensures each element serves as the authorizing official for its own systems processing top-secret sensitive compartmented information.

How Does the Policy Fit Into DOW’s Broader Cybersecurity Push?

The DOW Office of the CIO recently opened applications for its Cyber Apprenticeship Program, a paid initiative designed to recruit and train future civilian cybersecurity professionals supporting national security missions. In March, Davies told Senate lawmakers during a hearing that the department is undertaking a broad effort to transform the department’s technology ecosystem and cybersecurity program into a warfighting advantage.

The new CSSP memo also follows two other recent administration cybersecurity actions. The White House recently launched the Gold Eagle initiative to coordinate the identification and remediation of vulnerabilities across critical infrastructure sectors. In June, President Trump signed a memo directing the reestablishment of the Committee on National Security Systems to strengthen the cybersecurity of the nation’s national security systems.

Stay connected via Google News
Follow us for the latest travel updates and guides.
Add as preferred source on Google
Share5Tweet19
Previous Post

Paul Kearns to Retire as Director of Argonne National Laboratory

Next Post

Navy Names John Cremins Deputy Under Secretary for Intelligence & Security

Recommended For You

Treasury Seeks Comments on Implications of Digital Asset Adoption for Consumers, Investors, Businesses

by Jane Edwards
July 8, 2022
Treasury Seeks Comments on Implications of Digital Asset Adoption for Consumers, Investors, Businesses

The Department of the Treasury is soliciting public comments, recommendations and insights on the implications of the development and use of digital assets as well as financial market...

Read moreDetails

Carlos Del Toro’s NavSec Strategic Guidance Focuses on Maintaining Naval Dominance

by Angeline Leishman
October 12, 2021
Carlos Del Toro

Carlos Del Toro, the secretary of the Department of the Navy, has released guidance detailing the planning, investments, budgeting and other efforts of his agency to maintain U.S....

Read moreDetails

CACI Pledges to Provide Resources, Education Assistance to Alabama Tech Magnet School; CEO John Mengucci Quoted

by Charles Lyons-Burt
August 19, 2022
CACI Pledges to Provide Resources, Education Assistance to Alabama Tech Magnet School; CEO John Mengucci Quoted

CACI has entered into an agreement to support a Huntsville, Alabama-based residential magnet high school that specializes in cyber technology and engineering training and preparation.In conjunction with the...

Read moreDetails

DIU Launches Vendor Solicitation for Next Phase of HyCAT Project

by Jamie Bennet
January 24, 2023
DIU Launches Vendor Solicitation for Next Phase of HyCAT Project

The Department of Defense has issued a second commercial solutions opening for its ongoing Hypersonic and High-Cadence Airborne Testing Capabilities project.The notice posted by the Defense Innovation Unit stated...

Read moreDetails

GAO Reports Progress, Challenges in Govt Cloud Migration Efforts

by Darwin McDaniel
May 7, 2019
GAO Reports Progress, Challenges in Govt Cloud Migration Efforts

The Government Accountability Office recommends that federal agencies continue to adopt the cloud to reduce the cost of modernizing information technology platforms and services. GAO said Monday that 16...

Read moreDetails
Sign Up For Our Newsletter
Subscribe to our mailing list to receives daily updates direct to your inbox!
Invalid email address
Your privacy is guranteed.
Thanks for subscribing!

Sponsors

About ExecutiveGov

ExecutiveGov, published by Executive Mosaic, is a site dedicated to the news and headlines in the federal government. ExecutiveGov serves as a news source for the hot topics and issues facing federal government departments and agencies such as Gov 2.0, cybersecurity policy, health IT, green IT and national security. We also aim to spotlight various federal government employees and interview key government executives whose impact resonates beyond their agency.

CATEGORIES

  • Acquisition & Procurement
  • Announcements
  • Articles
  • Artificial Intelligence
  • Awards
  • Big Data & Analytics News
  • C4ISR
  • Civilian
  • Cloud
  • Contract Awards
  • Cybersecurity
  • Defense And Intelligence
  • Defense Security Cooperation
  • DHS
  • Digital Assets
  • Digital Modernization
  • DoD
  • Events
  • Executive Moves
  • Executive Spotlights
  • Federal Civilian
  • Financial Reports
  • Foreign Military Sales
  • General News
  • GovCon Expert
  • Government Cloud
  • Government Technology
  • GSA
  • Healthcare IT
  • Industry News
  • Intelligence
  • Legislation
  • M&A Activity
  • National Security
  • News
  • Policy Updates
  • Press Releases
  • Profiles
  • Space
  • Videos
  • Wash100
Sign Up For Our Newsletter
Subscribe to our mailing list to receives daily updates direct to your inbox!
Invalid email address
Your privacy is guranteed.
Thanks for subscribing!

Copyright 2026 Executive Mosaic. All Rights Reserved. Site Archive

No Result
View All Result
  • Home
  • Acquisition & Procurement
  • Agencies
    • DoD
    • Intelligence
    • DHS
    • Civilian
    • Space
  • Cybersecurity
  • Technology
  • Awards
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news

Copyright 2026 Executive Mosaic. All Rights Reserved. Site Archive

Get your free GovCon news!

Get your latest GovCon news and insights. Become a VIP and subscribe to the GovConWire Daily News.

Invalid email address
We promise not to spam you. You can unsubscribe at any time.
Thanks for subscribing!