Security News

Cybersecurity news aggregator

INFO News SC Media

Pentagon suspends CMMC phase 2 cybersecurity requirements

  • What: Pentagon suspends CMMC Phase 2 cybersecurity requirements
  • Impact: Affects defense contractors and their compliance obligations
Read Full Article →

Government Regulations Pentagon suspends CMMC phase 2 cybersecurity requirements July 14, 2026 Share By SC Staff (Defense Department) The Pentagon has placed an immediate freeze on forthcoming cybersecurity requirements, suspending the Cybersecurity Maturity Model Certification (CMMC) Phase 2 requirements that were set to take effect Nov. 10. This decision comes after government research suggested the policy would drive many businesses out of the defense industrial base at a time when the U.S. military urgently needs their innovations, with further coverage provided by Defensescoop. The suspension of CMMC Phase 2 was announced by Defense Department Chief Information Officer Kirsten Davies and Under Secretary of Defense for Acquisition and Sustainment Michael Duffey. A new CMMC Reform Task Force will review the entire program and submit recommendations within 60 days. The Pentagon plans to release a request for information to gather stakeholder feedback. CMMC is a tiered cybersecurity framework requiring defense contractors to implement specific cyber controls. The program, established in 2019, faced backlash for its complexity and cost burden, particularly on small businesses. The Defense Department is currently enforcing cybersecurity compliance through NIST Special Publication 800-171 Revision 2. Officials stated this pause aims to keep companies in the defense industrial base and reduce red tape, not to reduce cybersecurity. Concerns about industry readiness, misconceptions, and the significant cost for small businesses to achieve compliance, estimated at over $7 billion annually, influenced this decision. A mismatch between the number of companies needing assessments and the limited number of approved assessors also contributed to the suspension. Source: Defensescoop SC Staff Related Government Regulations EU proposes minimum age for unsupervised social media use SC Staff July 13, 2026 The proposed regulations stem from a report by a panel of experts convened to address the harms associated with social media. Government Regulations Regulatory frameworks are enablers, not burdens Chris Mierzwa July 10, 2026 When done correctly, regulations can help companies restore operations quickly and maintain trust after a breach. Government Regulations EU moves closer to reviving CSAM scanning law after parliamentary vote SC Staff July 9, 2026 The European Parliament voted to send a bill that would give tech companies the legal right to scan for child sexual abuse material to EU member countries for approval. Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Business Impact Analysis (BIA) British Standard 7799 Chain of Custody Competitive Intelligence Data Custodian Due Care Due Diligence You can skip this ad in 5 seconds

Share this article