By:
Douglas Barbin
July 31st, 2026
For the past year, Cybersecurity Maturity Model Certification (CMMC) compliance has mainly focused on self-assessments. Organizations handling Controlled Unclassified Information (CUI) have spent time evaluating their environments, documenting controls, and identifying gaps against required cybersecurity standards. CMMC Phase 2, originally scheduled for November 10, 2026, was set to mandate independent assessments conducted by Certified Third Party Assessment Organizations (C3PAOs) for new DoD solicitations and contracts involving CUI. However, the Department of War (DoW) paused CMMC Phase 2 on July 13, 2026, and launched a 60-day review to lessen the burden of compliance for small and non-traditional businesses.
By:
Adam Bush
July 27th, 2026
I lead Schellman’s PCI practice, not our CMMC practice, so I'll say upfront: I'm not the person to weigh in on assessment mechanics or how any specific contractor should meet its DFARS and/or NIST 800-171 requirements. But I've spent years watching an eerily similar challenge play out in the PCI landscape that ultimately got solved in payments. The Department of War's (DoW's) recent suspension of CMMC Phase II appears to be approaching the same fork in the road that the card industry faced years ago.
By:
Douglas Barbin
July 14th, 2026
On July 13, 2026, the Department of War (DoW) immediately suspended CMMC Phase II — specifically, the requirement for third-party (C3PAO) certification assessments that had been set to take effect November 10, 2026. CMMC Phase I self-assessment requirements for CMMC Levels 1 and 2, and the related NIST SP 800-171 / DFARS 252.204-7012 obligation to safeguard federal data, are unchanged.
By:
Andrew Parks
April 28th, 2026
The Cybersecurity Maturity Model Certification (CMMC) has officially shifted from proposed framework to an enforceable requirement for organizations supporting the U.S. Department of Defense (DoD). With the Final Rule now in effect and contractual mandates accelerating, defense contractors and subcontractors can no longer treat CMMC as a future initiative.
By:
Marci Womack
March 9th, 2026
For years, the Cybersecurity Maturity Model Certification (CMMC) lived in a world of drafts, delays, and speculation. Now, however, there are two key rules underpinning the CMMC program. The first is the foundational 32 CFR Part 170, which went into effect in December 2024 and formally established the CMMC framework.
By:
Todd Connor
February 4th, 2026
The long-anticipated Cybersecurity Maturity Model Certification (CMMC) Final Rule, published on September 10, 2025, officially became effective November 10, 2025. This shift from voluntary guidance to mandatory, enforceable contract requirements under the Defense Federal Acquisition Regulation Supplement (DFARS) marks a turning point for every organization that supports the federal defense supply chain. This critical milestone also signifies that full implementation is just beginning.
By:
Schellman
August 28th, 2025
TAMPA, Fla. – August 27, 2025 – Schellman, a leading provider of attestation and compliance services and a top 50 CPA firm, is proud to announce that Marci Womack, Managing Director in Schellman's Federal Practice overseeing the emerging Cybersecurity Maturity Model Certification (CMMC) assessment program, has been appointed to Cyber AB’s inaugural CMMC Third-Party Assessment Organizations (C3PAOs) Advisory Council.
FedRAMP | Federal Assessments | CMMC
By:
Matt Hungate
August 19th, 2025
If you develop or sell commercial-off-the-shelf (COTS) technology that ends up in Department of Defense (DoD) environments, there’s a new bar you have to clear. Katie Arrington, the acting DoD CIO has issued a new memo that directly impacts how you manage your software supply chain, and it’s going to change how COTS vendors prepare for procurement.