this post was submitted on 14 Jul 2026
14 points (100.0% liked)

Cybersecurity

10307 readers
38 users here now

c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.

THE RULES

Instance Rules

Community Rules

If you ask someone to hack your "friends" socials you're just going to get banned so don't do that.

Learn about hacking

Hack the Box

Try Hack Me

Pico Capture the flag

Other security-related communities !databreaches@lemmy.zip !netsec@lemmy.world !securitynews@infosec.pub !cybersecurity@infosec.pub !pulse_of_truth@infosec.pub

Notable mention to !cybersecuritymemes@lemmy.world

founded 3 years ago
MODERATORS
 

The Department of War today announces the immediate suspension of the Cybersecurity Maturity Model Certification (CMMC) Phase II requirements, which were originally scheduled to come into effect on November 10, 2026. All Phase I self-assessment requirements remain firmly in place.

you are viewing a single comment's thread
view the rest of the comments
[โ€“] thebardingreen@lemmy.starlightkel.xyz 2 points 4 days ago (1 children)

Having worked with compliance across multiple industries, CMMC was created for very good reasons, but was poorly implemented, also like it was being deliberately sabotaged (spoiler: it was).

Our supply chain security is a joke in America and the big players have wanted it to stay that way this whole time. I do not think meaningful security standards can be adopted in a system with this level of blatant corruption.

I've also had to do compliance for California Dept. Of Cannabis Control regulations. I've been telling people for years: If you want to do security theater, follow the NIST SP 800-171. If you want to do real security, follow CA Cannabis Control standards. I'm not joking.

[โ€“] jacksilver@lemmy.world 2 points 4 days ago

The biggest issues I've had with CMMC is that it seems to have been designed without any consideration for software development.