By:
Douglas Barbin
July 31st, 2026
For the past year, Cybersecurity Maturity Model Certification (CMMC) compliance has mainly focused on self-assessments. Organizations handling Controlled Unclassified Information (CUI) have spent time evaluating their environments, documenting controls, and identifying gaps against required cybersecurity standards. CMMC Phase 2, originally scheduled for November 10, 2026, was set to mandate independent assessments conducted by Certified Third Party Assessment Organizations (C3PAOs) for new DoD solicitations and contracts involving CUI. However, the Department of War (DoW) paused CMMC Phase 2 on July 13, 2026, and launched a 60-day review to lessen the burden of compliance for small and non-traditional businesses.
By:
Danny Manimbo
July 29th, 2026
If you ask most enterprise leaders, 74% would say their organization could pass an AI compliance audit today. Yet if you ask about the maturity of their AI governance program, only 27% say their programs are fully mature.
News | Artificial Intelligence
By:
Schellman
July 29th, 2026
As AI agents move into production and regulatory pressure grows, organizations face a widening gap between governance confidence and operational readiness.
By:
Adam Bush
July 27th, 2026
I lead Schellman’s PCI practice, not our CMMC practice, so I'll say upfront: I'm not the person to weigh in on assessment mechanics or how any specific contractor should meet its DFARS and/or NIST 800-171 requirements. But I've spent years watching an eerily similar challenge play out in the PCI landscape that ultimately got solved in payments. The Department of War's (DoW's) recent suspension of CMMC Phase II appears to be approaching the same fork in the road that the card industry faced years ago.
By:
Alexis Smith
July 24th, 2026
For organizations that produce, import, export, or trade hydrofluorocarbons (HFCs), the EPA's annual audit process under the AIM Act is now a structured, recurring review with enforceable compliance requirements. The organizations that understand its mechanics early are consistently better positioned to meet that standard.
By:
Sachin Bansal
July 22nd, 2026
Security leaders have heard the phrase “AI has expanded the attack surface” enough times. The more interesting story is the widening gap between what CISOs say they're doing about it and what's actually happening inside their organizations.
By:
Danny Manimbo
July 16th, 2026
In 2020, Microsoft made a sweeping commitment to be carbon negative by 2030 and remove all the carbon it had ever emitted since 1975. It was ambitious, inspiring, and, as of 2025, slipping further out of reach. Microsoft leaders originally referred to their sustainability goals as a “moonshot,” and in their own words from their 2025 Environmental Sustainability Report, the moon has gotten further away.
By:
Douglas Barbin
July 14th, 2026
On July 13, 2026, the Department of War (DoW) immediately suspended CMMC Phase II — specifically, the requirement for third-party (C3PAO) certification assessments that had been set to take effect November 10, 2026. CMMC Phase I self-assessment requirements for CMMC Levels 1 and 2, and the related NIST SP 800-171 / DFARS 252.204-7012 obligation to safeguard federal data, are unchanged.