The Department of War has suspended its CMMC Phase II requirements, originally set to take effect in November 2026. This decision, announced by CIO Kirsten Davies, aims to reduce compliance burdens for smaller businesses and accelerate the expansion of the Defense Industrial Base. While third-party assessments for Phase II are paused, underlying cybersecurity obligations and Phase I self-assessments remain in effect, with the Department of Justice continuing its Civil Cyber-Fraud Initiative. AI
RANK_REASON Policy change by a government department impacting industry compliance. [lever_c_demoted from significant: ic=1 ai=0.1]
Read on Mastodon — fosstodon.org →
- C3PAO
- Civil Cyber-Fraud Initiative
- Controlled Unclassified Information
- Cybersecurity Maturity Model Certification
- Department of Justice United States
- Department of War
- DIBCAC
- Kirsten Davies
- NIST SP 800-171
- Small Business Administration
AI-generated summary · Google Gemini · from 1 sources. How we write summaries →