The Department of War today announces the immediate suspension of the Cybersecurity Maturity Model Certification (CMMC) Phase II requirements, which were originally scheduled to come into effect on November 10, 2026. All Phase I self-assessment requirements remain firmly in place.


Having worked with compliance across multiple industries, CMMC was created for very good reasons, but was poorly implemented, almost like it was being deliberately sabotaged (spoiler: it was).
Our supply chain security is a joke in America and the big players have wanted it to stay that way this whole time. I do not think meaningful security standards can be adopted in a system with this level of blatant corruption.
I’ve also had to do compliance for California Dept. Of Cannabis Control regulations. I’ve been telling people for years: If you want to do security theater, follow the NIST SP 800-171. If you want to do real security, follow CA Cannabis Control standards. I’m not joking.
The biggest issues I’ve had with CMMC is that it seems to have been designed without any consideration for software development.