Security News

Cybersecurity news aggregator

🏛️
INFO News SecurityWeek

Pentagon Suspends CMMC Phase 2 as It Rethinks Contractor Cybersecurity Rules

  • What: Pentagon suspends CMMC Phase 2 to review cybersecurity rules
  • Impact: Affects defense contractors and government information handling
Read Full Article →

Compliance Pentagon Suspends CMMC Phase 2 as It Rethinks Contractor Cybersecurity Rules A new CMMC review and reform task force will conduct a comprehensive review of the program. By Eduard Kovacs | July 14, 2026 (2:37 AM ET) Flipboard Reddit Whatsapp Whatsapp Email The Pentagon is suspending Cybersecurity Maturity Model Certification (CMMC) phase two requirements that were set to take effect in November, pending a 60-day review of the entire program. Kirsten Davies, CIO at the Department of War (formerly the Department of Defense), said the move clears bureaucratic obstacles without lowering the bar on cybersecurity, noting that contractors must still meet phase one requirements and existing regulations for handling government information. A newly formed CMMC review and reform task force will collect industry feedback and then recommend scaled-back security measures to speed up contracting for small and nontraditional businesses. “The Department of War is taking decisive action to clear bureaucratic roadblocks and revitalize our defense industrial base in support of Secretary of War Pete Hegseth’s directive to aggressively scale warfighter readiness,” said Davies, adding, “[But] I want to be clear, across the Department of War and our defense industrial base, investing in and dynamically maintaining robust cybersecurity remains a critical, nonnegotiable priority.” Undersecretary of War for Acquisition and Sustainment Michael Duffey framed the pause as necessary to keep smaller manufacturers from being squeezed out of defense work by compliance costs. The CMMC is a framework for verifying that companies handling government information meet baseline cybersecurity standards before they can win defense contracts. Contractors and subcontractors that process federal contract information (FCI) or controlled unclassified information (CUI) are subject to the framework, regardless of their size. Advertisement. Scroll to continue reading. CMMC 2.0 streamlined the program from five levels to three: Level 1 covers protection of FCI, Level 2 covers CUI based on NIST 800-171, and Level 3 focuses on critical CUI against advanced persistent threats. The rule took effect on November 10, 2025, kicking off a multi-year phased rollout, with phase one requiring Level 1 and Level 2 self-assessments. The second phase was set to start on November 10, 2026, and would require Level 2 third-party certification assessments for new contracts. However, when announcing the changes on Monday, officials cited a shortage of approved third-party assessors as one reason the November deadline was no longer feasible. Phase three, scheduled for November 2027, would introduce Level 3 certification requirements, while the fourth and final phase would bring full implementation across applicable contracts by 2028. Related : UK Government Rolls Out Agentic AI Defense Plan Alongside Industry Pledge Related : CISA Reportedly Using Anthropic’s Mythos to Scan Government Software for Flaws Related : White House Issues Memo to Bolster NSS Cybersecurity Written By Eduard Kovacs Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Eduard Kovacs Third US Security Expert Sentenced to Prison for Helping Ransomware Gang China, India-Linked Hackers Both Targeted Same Pakistani Police Force ‘HalluSquatting’ Turns AI Hallucinations Into Botnet Delivery Mechanism Palo Alto Networks Patches 13 Vulnerabilities Microsoft Patches Defender ‘RoguePlanet’ Vulnerability AI Coding Tools Tricked Into Hacking Developer Machine via Decades-Old Technique Google Patches 382 Chrome Vulnerabilities BlueHammer Vulnerability Exploited in Ransomware Attacks Latest News Hacker Conversations: Jesse McGraw (GhostExodus), From Blackhat Hacker to Redemption Cybersecurity M&A Roundup: 37 Deals Announced in June 2026 RabbitMQ Vulnerability Threatens Enterprise Systems Zimbra Patches Critical Code Execution Vulnerability EU Targets Russian Intelligence Officers Accused of Running a Yearslong Cyber Spying Campaign Organizations Warned of Exploited Joomla Extension Vulnerabilities Progress Prompts ShareFile Storage Zone Controller Shutdown Amid Security Concerns Centers Laboratory Data Breach Affects 540,000 Individuals Trending Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Why Email Security Keeps Failing (And What Has to Change) July 8, 2026 Join this live webinar as we break down why email-layer defenses alone can't keep pace with the modern phishing ecosystem, how agentic AI is changing the capacity equation for security teams, and more. Register Virtual Event: 2026 Cloud Security Summit July 16, 2026 This year's summit will help organizations learn how to utilize tools, controls, and design models needed to properly secure cloud environments. Interact with leading solution providers and other end users facing similar challenges in securing a variety of cloud deployments. Register People on the Move BlueVoyant has appointed Ravi Subramanian as CFO and Jamie Coleman as CCO. Solana Foundation has appointed Michael Coates as Chief Information Security Officer. Michael Sikorski has joined Coinbase as Chief Information Security Officer. More People On The Move Expert Insights The Shift Toward Business-Aligned Risk Management Moving from isolated, technical data to a continuous risk lifecycle can help organizations align security controls with actual business consequences. (Steve Durbin) How to Conduct a Successful Audit of AI-Driven Software Development As AI-generated code becomes commonplace, CISOs need new audit strategies to measure developer practices, govern AI tool usage, and identify software risks before they reach production. (Matias Madou) Frontier AI: Six Questions Every Enterprise Should Ask Security Vendors From model selection and automation to validation and measurable results, the right questions can help enterprises separate genuine AI capabilities from marketing hype. (Joshua Goldfarb) The AI Token Costs That Can Break Cybersecurity As cybersecurity platforms embrace agentic AI, organizations must balance detection performance against the escalating costs of token consumption, deployment architecture, and AI credits. (Danelle Au) When Information Becomes the Attack Surface – Understanding AI Agent Traps From hidden content injections to cognitive state poisoning, attackers are turning trusted data sources into traps for autonomous AI. (Etay Maor) Flipboard Reddit Whatsapp Whatsapp Email

Share this article