UPDATES
CMMC News
Confused by CMMC? You’re not alone. We’re here to help you make sense of it and develop a plan that makes sense.
Latest News on the Cybersecurity Maturity Model Certification (CMMC)
CMMC Paused with 60 Day Review
On July 13, 2026, the Department of War announced the suspension of CMMC Phase 2 along with the CMMC Third-Party Assessment Organization (C3PAO) assessment requirements that were scheduled to begin appearing in contracts on November 10, 2026. A 60-day CMMC Reform Task Force will study the program's future and report back on or about September 13. Meanwhile, all prior cybersecurity requirements remain in force.
If you build, supply, or support the systems our warfighters depend on, you carry the burden of protecting critical data from U.S. adversaries, and the CMMC Phase 2 pause announcement doesn’t change that.
Still in force during the pause:
- CMMC self-assessments
- SPRS scoring
- Annual affirmations
- DFARS 252.204-7012
- FedRAMP Moderate (or equivalent) for CUI in the cloud
- ITAR/EAR data sovereignty, and the FAR 52.204-21 basics
- DIBCAC still assesses
- DOJ still prosecutes False Claims Act cases
- Primes still set their own bar
- China, Russia, and Iran aren’t letting off the gas.
If you’ve been preparing for third-party assessments, keep going.
Stopping now only surrenders progress toward the mission.
Get notified as soon as news breaks on CMMC
Speak with an Expert
Confused by CMMC? You’re not alone.
We’re here to help you make sense of the requirements and develop a plan.
Enter your info below and one of our CMMC experts will help answer any questions you have.
Protecting the American Dream
