US: Pentagon Suspends CMMC Phase II Requirements for Defense Contractors
ID: 61d49d66-000e-5d0f-87cc-f2e97cb0f5fa
STIX ID: report--61d49d66-000e-5d0f-87cc-f2e97cb0f5fa
Feed Name: Infosecurity Magazine (News)
The DoD has suspended CMMC Phase II requirements originally due in November 2026 and will create a CMMC Reform Task Force to conduct a 60-day review aimed at reducing compliance costs and bureaucratic burdens while aligning cybersecurity requirements with acquisition transformation goals; meanwhile, enforcement will rely on NIST SP 800-171 self-assessments and select government-led assessments. Experts warn contractors should continue preparing for compliance despite the pause, viewing it as temporary breathing room rather than a relaxation of standards.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
