
The Department of Defense (“DOD”) has announced the immediate suspension of the Cybersecurity Maturity Model Certification (CMMC) Phase II requirements, which were scheduled to take effect on November 10, 2026. This announcement is significant because, as we noted in our prior advisory, Phase II was expected to move CMMC toward more formal assessment requirements for many defense contractors and subcontractors. But the suspension of Phase II should not be read as a suspension of defense … [Read more] about CMMC Phase II is Suspended, but Defense Contractors’ Cybersecurity Obligations are Not


