UPDATES
CMMC News
Latest News on the Cybersecurity Maturity Model Certification (CMMC)
CMMC Suspended with 60 Day Review
On July 13, 2026, the Department of War announced the suspension of CMMC Phase 2 along with the CMMC Third-Party Assessment Organization (C3PAO) assessment requirements that were scheduled to begin appearing in contracts on November 10, 2026. A 60-day CMMC Reform Task Force will study the program’s future and report back on or about September 13. Meanwhile, all prior cybersecurity requirements remain in force.
If you build, supply, or support the systems our warfighters depend on, you carry the burden of protecting critical data from U.S. adversaries, and the CMMC Phase 2 pause announcement doesn’t change that.
CMMC self-assessments, SPRS scoring, annual affirmations, DFARS 252.204-7012, FedRAMP Moderate (or equivalent) for CUI in the cloud, ITAR/EAR data sovereignty, and the FAR 52.204-21 basics are all still in force.
DIBCAC still assesses, DOJ still prosecutes False Claims Act cases, primes still set their own bar, and China, Russia, and Iran aren’t letting off the gas.
If you’ve been preparing for third-party assessments, keep going. Stopping now only surrenders progress toward the mission.
Have questions about the latest CMMC news? Speak with an expert
Podcasts
DoD Says CMMC Costs Too Much. What Comes Next Could Cost More.
NIST SP 800-171 revision 4?
The DoD Said This Was “Out of Scope”… Now They’re Asking About It
Articles
What is Brilliant at the Basics? What It Means for DIB Contractors
CMMC Phase 2 Suspended with 60 Day Review. What Happens Next?
What is the False Claims Act? Why LOGZONE Settled for $507K
SUBSCRIBE
