this post was submitted on 14 Jul 2026
14 points (100.0% liked)

Cybersecurity

10307 readers
38 users here now

c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.

THE RULES

Instance Rules

Community Rules

If you ask someone to hack your "friends" socials you're just going to get banned so don't do that.

Learn about hacking

Hack the Box

Try Hack Me

Pico Capture the flag

Other security-related communities !databreaches@lemmy.zip !netsec@lemmy.world !securitynews@infosec.pub !cybersecurity@infosec.pub !pulse_of_truth@infosec.pub

Notable mention to !cybersecuritymemes@lemmy.world

founded 3 years ago
MODERATORS
 

The Department of War today announces the immediate suspension of the Cybersecurity Maturity Model Certification (CMMC) Phase II requirements, which were originally scheduled to come into effect on November 10, 2026. All Phase I self-assessment requirements remain firmly in place.

top 7 comments
sorted by: hot top controversial new old
[–] Marija@lemmy.zip 0 points 4 days ago (1 children)

Curious what replaces it long-term.

[–] solrize@lemmy.ml 0 points 5 days ago (1 children)

So they're admitting their stuff is crap and that they expect for it to stay that way.

[–] sylver_dragon@lemmy.world 2 points 5 days ago (1 children)

More like, the business are whining that security is hard and expensive; so, they shouldn't be required to do it.

While I'm no fan of checkbox security, CMMC was kinda like the sign in front of rollercoasters. Except instead of a minimum height, CMMC was saying, "your network must be at least this secure to hold CUI".

Seriously, I dealt with this stuff for years as a contractor for the US FedGov. It's not rocket science. It's not even hard. But, it does require that you document your shit and do a bit better than accepting the defaults. It won't make your network secure. But if you are struggling to meet the basic controls, I guarantee that your security is bad.

[–] solrize@lemmy.ml 1 points 5 days ago* (last edited 5 days ago) (1 children)

CMMC is more about how well your processes work. Low level = more chaotic, stuff basically works but people have to scurry around and improvise when it breaks. Mid level = it can break but procedures for fixing it are documented and regular. High level = can't break. No attempt at certifying to any level at all = never mind, just wing everything.

I wonder how much turning everything into piles of AI crap is involved with this.

[–] thebardingreen@lemmy.starlightkel.xyz 2 points 4 days ago (1 children)

Having worked with compliance across multiple industries, CMMC was created for very good reasons, but was poorly implemented, also like it was being deliberately sabotaged (spoiler: it was).

Our supply chain security is a joke in America and the big players have wanted it to stay that way this whole time. I do not think meaningful security standards can be adopted in a system with this level of blatant corruption.

I've also had to do compliance for California Dept. Of Cannabis Control regulations. I've been telling people for years: If you want to do security theater, follow the NIST SP 800-171. If you want to do real security, follow CA Cannabis Control standards. I'm not joking.

[–] jacksilver@lemmy.world 2 points 4 days ago

The biggest issues I've had with CMMC is that it seems to have been designed without any consideration for software development.