The answer is to modernize accountability through an enterprise model that combines a formalized independent assessment, continuous external monitoring, and shared remediation support where small suppliers cannot…
Department of Defense Chief Information Officer Kirsten Davies delivers remarks at a CIO town hall at the Mark Center, Alexandria Va., Feb. 10, 2026. (DoD photo by U.S. Navy Petty Officer 1st Class Alexander Kubitza)
The task force held its first meeting Thursday, just days removed from CIO Kirsten Davies initiating a pause of CMMC phase 2 requirements and a review of…
By adopting pre-accredited cloud platforms, defense organizations can bypass laborious compliance hurdles and redirect critical resources to AI tools, argues CIO.
The Defense Department wants to introduce PQC requirements into the CMMC program, but experts warn industry and the underlying technology is far from ready.
While not an explicit violation of the CMMC program, the suit highlights the Defense Department’s increasing scrutiny of the defense industry not implementing required cybersecurity measures for…
A new report from the Government Accountability Office found that the Pentagon has not completely identified factors beyond its control that risk the CMMC program’s overall success.
ISACA has assumed responsibility as Cybersecurity Assessor and Instructor Certification Organization, and will work to scale the number of third-party CMMC assessors to meet a rising demand.
Experts told DefenseScoop that readiness gaps are fueled by CMMC’s controversial history, misconceptions of what the rule change means and challenges in proving compliance.