Find notable cyber news and cases, enriched with sources, timelines, and signals.

DoD final CMMC rule and ISACA credentialing rollout

Public Sector Action
First reported
Last updated
Happening score
H score 25
1 unique sources, 1 articles

Summary

Hide ▲

The US Department of Defense published the final CMMC rule, starting a three-year rollout of cybersecurity requirements across DoD contracts. The change matters because contractors handling FCI and CUI must meet stricter controls to keep working in the defense supply chain. ISACA's new role as global credentialing authority and CAICO formalizes how the program will train, test, and certify assessors through 2028.

Related Happenings

US Department of Defense (DoD) Cybersecurity Maturity Model Certification (CMMC) Phase II Suspended the Phase II requirements pending review and announced a 60-day program review

Public Sector Action
H score67 First: 14.07.2026 18:28 Last: 14.07.2026 18:28 Sources 1

About this happening: The US Department of Defense suspended CMMC Phase II requirements pending review, delaying a planned November 10, 2026 compliance step for defense contractors and su...

Pentagon suspends CMMC phase two for 60-day review

Public Sector Action
H score24 First: 14.07.2026 09:37 Last: 14.07.2026 09:37 Sources 1

About this happening: The Pentagon suspended CMMC phase two and opened a 60-day review, delaying new certification requirements for defense contractors and subcontractors. The pause...

Timeline

  1. 17.12.2025 16:05 1 articles · 7mo ago

    DoD publishes final CMMC rule

    Legal Policy Action Update

    The US Department of Defense published the final Cybersecurity Maturity Model Certification (CMMC) rule in the Federal Register, formalizing cybersecurity requirements for defense contractors that handle Federal Contract Information (FCI) and Controlled Unclassified Information (CUI).

    Show sources
  2. 17.12.2025 16:05 1 articles · 7mo ago

    CMMC rule takes effect and rollout begins

    Industry Or Public Sector Update

    The final CMMC rule took effect, launching a three-year rollout of cybersecurity requirements across DoD contracts through 2028 and requiring organizations supplying or working into the DoD to maintain a CMMC credential.

    Show sources
  3. 17.12.2025 16:05 2 articles · 7mo ago

    ISACA named global CMMC credentialing authority

    Initial Disclosure

    The US Department of Defense appointed ISACA as the global credentialing authority for the Cybersecurity Maturity Model Certification (CMMC) program and made it the exclusive CMMC Assessor and Instructor Certification Organization (CAICO), with ISACA saying the rollout will affect more than 200,000 organizations.

    Show sources