Executive Gov
  • Home
  • Acquisition & Procurement
  • Agencies
    • Department of War
    • Intelligence
    • DHS
    • Civilian
    • Space
  • Cybersecurity
  • Technology
  • Awards
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news
No Result
View All Result
Executive Gov
  • Home
  • Acquisition & Procurement
  • Agencies
    • Department of War
    • Intelligence
    • DHS
    • Civilian
    • Space
  • Cybersecurity
  • Technology
  • Awards
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news
No Result
View All Result
Executive Gov
No Result
View All Result
Home Cybersecurity

DOW CIO Issues Memo on Cybersecurity Service Provider Certification Requirements

by Jane Edwards
July 29, 2026
in Cybersecurity, Department of War, DoD, News
Kirsten Davies. The DOW CIO has issued a memo on cybersecurity service provider certification requirements.

Kirsten Davies, chief information officer at the Department of War, has issued a directive-type memorandum outlining the minimum baseline requirements for organizations to be certified and authorized as a DOW cybersecurity service provider.

  • DOW CIO Kirsten Davies has released new CSSP certification guidance
  • The policy covers alignment for AI, quantum and industrial control systems
  • Explore AI, cybersecurity and more at the Potomac Officers Club’s DOW summits

Kirsten Davies, chief information officer at the Department of War and a 2026 Wash100 awardee, has issued a directive-type memorandum, or DTM, outlining the minimum baseline requirements for an organization to be certified and authorized as a DOW cybersecurity service provider, or CSSP.

Table of Contents

    • You might also like
    • VA OIG Flags Delay, Cost and Security Risks in Benefits Platform Modernization
    • NIST Seeks Input on National Vulnerability Database Modernization
    • DOE Seeks Input for Genesis Mission Initiative to Build Open-Weight AI Models
  • What Are the Minimum Requirements to Become a Certified DOW CCSP?
  • What Are the Minimum Cybersecurity Activities CSSPs Must Perform?
  • Which Systems & Networks Must Align With a DOW CSSP?
  • Who Authorizes & Certifies DOW Cybersecurity Service Providers?
  • How Does the Policy Fit Into DOW’s Broader Cybersecurity Push?

You might also like

VA OIG Flags Delay, Cost and Security Risks in Benefits Platform Modernization

NIST Seeks Input on National Vulnerability Database Modernization

DOE Seeks Input for Genesis Mission Initiative to Build Open-Weight AI Models

DOW CIO Issues Memo on Cybersecurity Service Provider Certification Requirements

Join us at the Potomac Officers Club’s 2026 Air & Space Summit tomorrow, July 30, for a panel discussion on advancing multilevel security with AI and machine learning for the modern warfighter. Secure your seat now! Then mark your calendar for the 2026 Navy Summit on Aug. 27, which will feature a panel discussion on modernizing the Navy’s enterprise networks for information warfare readiness. Register today to join the conversation.

The memo, titled “Cybersecurity Service Provider Definition Clarification,” issued Tuesday and signed by Davies establishes policy, assigns responsibilities and sets procedures for CSSP certification across the department. 

The DTM takes effect immediately and applies to the Office of the Secretary of War, the military departments, the Joint Staff, combatant commands, the DOW Office of Inspector General and all other DOW components. The memo is set to expire on July 28, 2028.

What Are the Minimum Requirements to Become a Certified DOW CCSP?

The memo directs CSSPs to continuously monitor DOW cyber terrain to detect, analyze and respond to anomalous, suspicious or malicious activity. CSSPs must maintain personnel and resources to triage time-sensitive events, with a maximum of 72 hours to triage an incident and 24 hours to report it to U.S. Cyber Command.

CSSPs are also required to maintain a valid certification and an authorization to operate; failing to do so results in suspension of CSSP services. Certification standards are detailed in DOD Manual 8530.01 and the CSSP Minimum Cybersecurity Activities Checklist.

What Are the Minimum Cybersecurity Activities CSSPs Must Perform?

To be certified, CSSPs must carry out a defined set of baseline activities. These include:

  • Correlating asset and vulnerability data with cyberthreat intelligence to identify exploits and threat opportunities
  • Malware notification, including confirming that subscribers acknowledge reported findings
  • Detection processes across three network tiers — internet access points, enclave and perimeter boundaries, and internal host-level monitoring
  • Orders and cyber protection condition compliance, including implementing and reporting on DOW orders
  • Cyber incident handling, categorization and reporting, in coordination with USCYBERCOM and the DOW Cyber Crime Center
  • Law enforcement and counterintelligence coordination for forensic investigations of compromised systems
  • Incident response analysis, including forensic media analysis and intrusion assessments
  • Sustainment and continuous self-assessment, including annual compliance reviews

Which Systems & Networks Must Align With a DOW CSSP?

The DTM extends CSSP alignment requirements beyond traditional IT networks. According to the memo, the requirement applies to:

  • Cloud instances
  • Coalition or mission partner environments
  • Special access programs
  • Intelligence networks
  • Industrial control systems
  • Internet of Things devices
  • Operational technology
  • Artificial intelligence systems
  • Quantum computers and networks

The memo states this alignment requirement cannot be waived or risk-accepted by authorizing officials, regardless of a system’s network, connectivity or mission.

Who Authorizes & Certifies DOW Cybersecurity Service Providers?

Under the memo, the DOW CIO approves or disapproves all CSSP certification requests and forwards approvals to the commander of USCYBERCOM. The DOW CIO also serves as the authorizing official for special access program systems that do not process sensitive compartmented information and adjudicates CSSP certification appeals in coordination with USCYBERCOM.

USCYBERCOM, in turn, implements general service CSSP processes. It functions as both certifier and authorizing official for general service and special access program systems at the top-secret collateral level and below.

For intelligence community elements within the DOW, the director of national intelligence ensures each element serves as the authorizing official for its own systems processing top-secret sensitive compartmented information.

How Does the Policy Fit Into DOW’s Broader Cybersecurity Push?

The DOW Office of the CIO recently opened applications for its Cyber Apprenticeship Program, a paid initiative designed to recruit and train future civilian cybersecurity professionals supporting national security missions. In March, Davies told Senate lawmakers during a hearing that the department is undertaking a broad effort to transform the department’s technology ecosystem and cybersecurity program into a warfighting advantage.

The new CSSP memo also follows two other recent administration cybersecurity actions. The White House recently launched the Gold Eagle initiative to coordinate the identification and remediation of vulnerabilities across critical infrastructure sectors. In June, President Trump signed a memo directing the reestablishment of the Committee on National Security Systems to strengthen the cybersecurity of the nation’s national security systems.

Stay connected via Google News
Follow us for the latest travel updates and guides.
Add as preferred source on Google
Share5Tweet19
Previous Post

Paul Kearns to Retire as Director of Argonne National Laboratory

Next Post

Navy Names John Cremins Deputy Under Secretary for Intelligence & Security

Recommended For You

SDA to Solicit Satellites for Future Space Transport Layer; Derek Tournear Quoted

by Nichols Martin
April 15, 2021
Derek Tournear

The Space Development Agency (SDA) will launch a solicitation for a new set of 150 satellites in August 2021, for a network of communications satellites planned to begin...

Read moreDetails

William Bryan: DHS S&T’s Program Aims to Test Critical Infrastructure GPS Vulnerabilities

by Matthew Nelson
June 2, 2020
william-bryan-dhs-sts-program-aims-to-test-critical-infrastructure-gps-vulnerabilities

The Department of Homeland Security's science and technology directorate is inviting global positioning technology manufacturers and critical infrastructure owners and operators to determine whether their assets are safe from...

Read moreDetails

New MQ-9 Reaper Facility Unveiled at Robins Air Force Base

by Christine Thropp
July 15, 2022
New MQ-9 Reaper Facility Unveiled at Robins Air Force Base

A U.S. Air Force contractor for depot maintenance, engineering support and software development has opened a new MQ-9 Reaper aircraft facility at Robins Air Force Base, Georgia, as...

Read moreDetails

Raytheon’s Thomas Kennedy, Anthony O’Brien to Speak at Baird’s 2019 Global Industrial Conference on Nov. 7

by William McCormick
August 11, 2022
Raytheon’s Thomas Kennedy, Anthony O’Brien to Speak at Baird's 2019 Global Industrial Conference on Nov. 7

Raytheon announced on Tuesday that 2019 Wash100 Award recipient, Chairman and CEO of the company Thomas Kennedy and Vice President and Chief Financial Officer Anthony O'Brien will speak...

Read moreDetails

NASA’s Ames Research Center to Demo Air Traffic Mgmt Simulator

by Scott Nicholas
December 12, 2016
NASA's Ames Research Center to Demo Air Traffic Mgmt Simulator

NASA's Ames Research Center in Califonia has created a full-scale simulator designed to mimic a variety of air traffic management scenarios as part of efforts to ensure air travel safety and...

Read moreDetails
Sign Up For Our Newsletter
Subscribe to our mailing list to receives daily updates direct to your inbox!
Invalid email address
Your privacy is guranteed.
Thanks for subscribing!

Sponsors

About ExecutiveGov

ExecutiveGov, published by Executive Mosaic, is a site dedicated to the news and headlines in the federal government. ExecutiveGov serves as a news source for the hot topics and issues facing federal government departments and agencies such as Gov 2.0, cybersecurity policy, health IT, green IT and national security. We also aim to spotlight various federal government employees and interview key government executives whose impact resonates beyond their agency.

CATEGORIES

  • Acquisition & Procurement
  • Announcements
  • Articles
  • Artificial Intelligence
  • Awards
  • Big Data & Analytics News
  • C4ISR
  • Civilian
  • Cloud
  • Contract Awards
  • Cybersecurity
  • Defense And Intelligence
  • Defense Security Cooperation
  • Department of War
  • DHS
  • Digital Assets
  • Digital Modernization
  • DoD
  • Events
  • Executive Moves
  • Executive Spotlights
  • Federal Civilian
  • Financial Reports
  • Foreign Military Sales
  • General News
  • GovCon Expert
  • Government Cloud
  • Government Technology
  • GSA
  • Healthcare IT
  • Industry News
  • Intelligence
  • Intelligence Community
  • Legislation
  • M&A Activity
  • National Security
  • News
  • Policy Updates
  • Press Releases
  • Profiles
  • Space
  • Technology
  • Videos
  • Wash100
Sign Up For Our Newsletter
Subscribe to our mailing list to receives daily updates direct to your inbox!
Invalid email address
Your privacy is guranteed.
Thanks for subscribing!

Copyright 2026 Executive Mosaic. All Rights Reserved. Site Archive

No Result
View All Result
  • Home
  • Acquisition & Procurement
  • Agencies
    • Department of War
    • Intelligence
    • DHS
    • Civilian
    • Space
  • Cybersecurity
  • Technology
  • Awards
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news

Copyright 2026 Executive Mosaic. All Rights Reserved. Site Archive

Get your free GovCon news!

Get your latest GovCon news and insights. Become a VIP and subscribe to the GovConWire Daily News.

Invalid email address
We promise not to spam you. You can unsubscribe at any time.
Thanks for subscribing!