Low urgency

DOD halts cybersecurity requirements for CMMC Phase 2: ‘The math just simply doesn't math’ - defensescoop.com

Detected July 30, 2026 · in Export Controls & ITAR (DDTC / BIS / DFARS)

DOD halts cybersecurity requirements for CMMC Phase 2, citing that 'the math just simply doesn't math'.

Aforeworn detected this change in the Export Controls & ITAR (DDTC / BIS / DFARS) space on July 30, 2026 and published this briefing so affected operators are forewarned rather than caught off guard. It is rated Low urgency. Defense contractors and subcontractors subject to CMMC Phase 2 cybersecurity requirements. should confirm how it applies to their specific situation before acting. There is a time constraint attached: Not specified.. Acting after that point can mean penalties, a lapsed licence, or lost eligibility — exactly the kind of surprise Aforeworn exists to prevent. Aforeworn monitors Export Controls & ITAR (DDTC / BIS / DFARS) continuously and turns every detected change into a plain-English briefing like this one, so you always know first. Forewarned is forearmed.

What changed

The Department of Defense has paused the implementation of CMMC Phase 2 cybersecurity requirements.

Who it affects

Defense contractors and subcontractors subject to CMMC Phase 2 cybersecurity requirements.

What you must do

No immediate action required; monitor for future updates on CMMC Phase 2.

Deadline

Not specified.

Source: https://news.google.com/rss/articles/CBMijwFBVV95cUxPU29rc1VIeXhBT2RVTUtqMDMxeTNhVjRHbkZTNEpEMG9JdVpHZEU3cVBlOUFMY0l4amNnWjNNa3RCX19lNlQ0VkZYNncwRUdHRlVuVHBNZEtkUWhqQk5RZ3haX25HTDBVaUJIMkt3aHVKdjN3QUNTelBvUUViSDFnX0VnMEpObHlOX3RWYzEwUQ?oc=5

Never miss a change like this again

Aforeworn watches Export Controls & ITAR (DDTC / BIS / DFARS) around the clock and alerts you the moment a rule moves — with a plain-English brief on what to do.

Start your free trial

Related changes in Export Controls & ITAR (DDTC / BIS / DFARS)