← Back

Wire · regulatory

Another Overhaul Planned for DoD's Effort to Manage Contractors' Cybersecurity

Published

15 July 2026

Topic

regulatory

Sectors

Cybersecurity

Geography

United States

Source

Read at vitallaw.com

Verified

Fusion42 · 15 July 2026 · Fusion42 review

The US Department of Defense has suspended Phase 2 of its Cybersecurity Maturity Model Certification (CMMC) program, scheduled for November implementation, citing compliance burden concerns on small contractors. Phase 1 self-attestation requirements remain in place following November 2025 enforcement start.

This Wire brief sits within Fusion42's coverage of Cybersecurity.

◆ The Wire takeaway

If you sell to the US military, the certification wall you've been preparing for just got postponed—but Phase 1 stays in force. Use the reprieve to build the compliance capability defensively; the more elaborate second phase is coming back, and buyers are still demanding it as a contract condition.

Coverage

1 source · 15 Jul 2026

Related on Wire

Topics

Cybersecuritycmmc-suspensiondod-compliancesmall-business-burdencybersecurity-requirementsdefense-contractor