Tag: cmmc
6 articles

CMMC Pause Doesn't Halt Compliance Imperative
The pause on CMMC Phase 2.0 doesn't let you off the compliance hook - you still need to prioritize protecting controlled unclassified information (CUI) within your environment. Keep moving forward with necessary security measures to ensure CUI protection, as requirements remain in place despite validation delays.

Defense Contractors Question Accuracy of Rising Cybersecurity Scores
Defense contractors are reporting their highest cybersecurity scores in five years, but there's a catch: they're also losing confidence in the accuracy of those scores. The average SPRS score has soared to +51 in 2026, up from +33 in 2025, sparking questions about what's behind the sudden surge.

Sharpening Cybersecurity Standards
Don't let your guard down now - Katie Arrington stresses that now is not the time to relax cybersecurity standards, especially after self-attestation failed to protect the war industrial base. The Cybersecurity Maturity Model Certification was created to ensure verification and accountability.

CMMC Pause Spurs Urgent Gap Assessments
The Department of Defense's sudden pause on CMMC Phase 2 has created an urgent need for gap assessments, especially for small and non-traditional businesses struggling to meet compliance requirements. This 60-day review aims to ease the burden, but existing obligations, including Phase 1 self-assessment requirements, remain in force.

Pentagon Scraps Cybersecurity Certification Phase, Launches Reform Review
The Department of Defense is shaking things up in the world of cybersecurity certification, suspending Phase 2 of its Cybersecurity Maturity Model Certification (CMMC) program and launching a 60-day review to explore a more streamlined approach. This move aims to ease compliance burdens, especially for small and medium-sized businesses.

Pentagon Hits Pause on Cybersecurity Certification Requirements
The Pentagon has hit pause on its cybersecurity certification requirements, citing prohibitive compliance costs and bureaucratic burdens that could stifle innovation in the US defense industrial base. This 60-day suspension sparks a review that may reshape enforcement and acquisition rules for defense contractors.