By:
Adam Bush
July 27th, 2026
I lead Schellman’s PCI practice, not our CMMC practice, so I'll say upfront: I'm not the person to weigh in on assessment mechanics or how any specific contractor should meet its DFARS and/or NIST 800-171 requirements. But I've spent years watching an eerily similar challenge play out in the PCI landscape that ultimately got solved in payments. The Department of War's (DoW's) recent suspension of CMMC Phase II appears to be approaching the same fork in the road that the card industry faced years ago.
Payment Card Assessments | PCI DSS
By:
Bill Soverns
February 18th, 2026
Managing scripts on payment pages has become a key focus area under PCI DSS, particularly as third-party and dynamically loaded scripts introduce new risk. As attacks targeting client-side scripts continue to increase and PCI DSS v4.x places greater emphasis on ongoing monitoring, organizations are expected to demonstrate not only visibility into payment page scripts, but also effective controls to detect unauthorized changes.