← Back

Wire · regulatory

COMMENTARY: What Security Leaders Do Now in Wake of CMMC Pause

Published

15 July 2026

Topic

regulatory

Sectors

CybersecurityDefense Tech

Geography

United States

Source

Read at nationaldefensemagazine.org

Verified

Fusion42 · 16 July 2026 · Fusion42 review

The US Department of Defense suspended CMMC Phase 2's third-party assessment requirement in July 2026, but this removes the independent verification layer whilst NIST SP 800-171 compliance obligations remain unchanged. Security leaders now face heightened personal liability under the Justice Department's Civil Cyber-Fraud Initiative, which has settled 15 cases since 2021, with no breach required—only a mismatch between attestation and actual environment.

This Wire brief sits within Fusion42's coverage of Cybersecurity and Defense Tech.

◆ The Wire takeaway

You just lost the auditor but kept the audit. The compliance requirement you were outsourcing to a third party is now your personal signature on a False Claims Act document—and Justice has settled 15 cyber-fraud cases since 2021 with zero breaches required, just a gap between what you claimed and what your logs show.

Coverage

1 source · 15 Jul 2026

Related on Wire

Topics

CybersecurityDefense Techcmmc-pausedefence-supply-chaincyber-compliancefalse-claims-actnist-800-171