Photo of Luis Hidalgo

Luis Hidalgo

Luis assists clients with government contracts. A former accountant and auditor, Luis thrived on investigative work but was keenly aware that his role never included resolving any of the problems he uncovered. He chose to pursue a career as an attorney, where he could combine his passions for fact-finding, problem-solving, and creativity.

Key point: Historically, civilian‑agency contractors who handled Controlled Unclassified Information (CUI) enjoyed an informal compliance environment, with a requirement to adhere to NIST SP 800‑171 often framed as self‑attestation. That world is now decisively over, with the GSA following a path similar, but not identical, to the DoD’s CMMC requirements.

Key point: Beginning November 10, 2025, DoD contracting officers will begin adding Cybersecurity Maturity Model Certification (CMMC) requirements to solicitations, and contracting officers “shall not award a contract, task order, or delivery order to a [contractor] that does not have a current CMMC status at the CMMC level required by the solicitation.”