Last year, we noted in a couple posts that the federal government had finally began implementation of its Cybersecurity Maturity Model Certification (CMMC) Program. Apparently, however, the government has concluded that a pause is needed on further implementation due to what it describes as structural issues with the program. On July 13, 2026, the Department of War (DoW)[1] announced that it is suspending the introduction of Phase Two of the Cybersecurity Maturity Model Certification (CMMC) Program. We explore that decision in this post.
Continue reading