Article
Pentagon Suspends CMMC Phase 2 Requirements And Launches Review Of Cybersecurity Certification Program
The US Department of Defense has suspended Phase 2 of its Cybersecurity Maturity Model Certification (CMMC) program, halting third-party assessment requirements that were set to take effect in November 2026. While this provides relief from expanded certification burdens, defense contractors must understand that underlying cybersecurity obligations remain fully in force. What does this mean for contractors' compliance strategies and their obligations to protect federal contract information?
WilmerHale