Any change to CISA's requirements since the December "hack"?

Has there been any change to CISA's requirement for Gov't locations to not have SolarWinds monitor Cloud applications and Internet sites?