Wire · regulatory
COMMENTARY: What Security Leaders Do Now in Wake of CMMC Pause
◆ Sectors
◆ Geography
◆ Source
◆ Verified
Fusion42 · 16 July 2026 · Fusion42 review
The US Department of Defense suspended CMMC Phase 2's third-party assessment requirement in July 2026, but this removes the independent verification layer whilst NIST SP 800-171 compliance obligations remain unchanged. Security leaders now face heightened personal liability under the Justice Department's Civil Cyber-Fraud Initiative, which has settled 15 cases since 2021, with no breach required—only a mismatch between attestation and actual environment.
This Wire brief sits within Fusion42's coverage of Cybersecurity and Defense Tech.
◆ ◆ The Wire takeaway
You just lost the auditor but kept the audit. The compliance requirement you were outsourcing to a third party is now your personal signature on a False Claims Act document—and Justice has settled 15 cyber-fraud cases since 2021 with zero breaches required, just a gap between what you claimed and what your logs show.
◆ Coverage
1 source · 15 Jul 2026
◆ Related on Wire
◆ Topics