Time to call an MSP.
Discover leading Managed IT Service Providers across USA, Canada & the United Kingdom.
- 100s of leading MSPs
- Find a MSP near you
- Latest IT news for SMBs
What Does the CMMC Phase II Suspension Mean for Contractors?
On July 13, 2026, the Department of War (DoW) announced the suspension of CMMC Phase II certification requirements and Phase III milestones pending a 60-day program review. Although it removes the immediate assessment requirements, it does not remove your obligation to protect controlled unclassified information under DFARS 252.204-7012. If you work in the Defense Industrial Base, you have likely spent the past year preparing for CMMC Level 2 certification. Then, without warning, the rules changed. On July 13, 2026, the Department of War announced it was suspending CMMC Phase IIrequirement
On July 13, 2026, the Department of War (DoW) announced the suspension of CMMC Phase II certification requirements and Phase III milestones pending a 60-day program review. Although it removes the immediate assessment requirements, it does not remove your obligation to protect controlled unclassified information under DFARS 252.204-7012. If you work in the Defense Industrial Base, you have likely spent the past year preparing for CMMC Level 2 certification. Then, without warning, the rules changed. On July 13, 2026, the Department of War announced it was suspending CMMC Phase IIrequirements before the initial November 10, 2026 deadline. For contractors mid-assessment or mid-remediation, the announcement raises an obvious question: what does this mean for your compliance program? Intelligent Technical Solutions (ITS) has helped defense contractors navigate cybersecurity compliance for years. We track changes like this closely because a paused certification requirement is not the same as a paused security obligation. Misrepresenting your cybersecurity posture can put your contracts at risk and may create False Claims Act exposure. In this article, we'll cover: What Is CMMC Phase II, and who does it affect? What changed with the CMMC Phase II suspension? What do defense contractors still need to do? What Is CMMC Phase II, and who does it affect? What changed with the CMMC Phase II suspension? What do defense contractors still need to do? What Is CMMC Phase II, and Who Does It Affect? CMMC Phase II was the second stage of the Department's planned CMMC rollout. It would have required certain Defense Industrial Base contractors and subcontractors to pass a Level 2 assessment by a certified third-party assessment organization, or C3PAO. The requirement would have applied to certain contracts involving controlled unclassified information, or CUI. Prime contractors would also have needed to pass the right security requirements down to affected subcontractors. Phase II is now suspended, along with the government-led Level 3 assessments planned for Phase III. However, Phase I self-assessments, SPRS reporting, and existing DFARS obligations remain in effect. Read: CMMC Certification: Its Process and Timeline Explained What Changed with the CMMC Phase II Suspension? The Department of War suspended the CMMC Phase II requirements that were set to begin on November 10, 2026. This means certain third-party and government-led assessment requirements will not take effect as planned.
Read full post on itsasap.comMSPdb™ News
Managed IT Support That Safely Integrates IT and OT Networks for Industrial Businesses
How to Build a 12-Month AI Roadmap for a Midmarket Company
Many midmarket leaders know they need an AI plan but are unsure where to begin. A 12-month AI roadmap should start with readiness, move into a controlled pilot, expand based on what works, and scale only after you can measure real adoption. A rushed rollout can leave security and data gaps unaddressed. Below, we break
Many midmarket leaders know they need an AI plan but are unsure where to begin. A 12-month AI roadmap should start with readiness, move into a controlled pilot, expand based on what works, and scale only after you can measure real adoption. A rushed rollout can leave security and data gaps unaddressed. Below, we break
Read full post on mdltechnology.com
2026 Cybersecurity Awareness Month: Four Essentials to Protect Your Business
Key Takeaways Cybersecurity Awareness Month is a national initiative held every October that highlights essential actions you can take to reduce cyber risk. The Cybersecurity and Infrastructure Security Agency (CISA) serves as the federal lead and offers no-cost resources to help businesses and government organizations educate employees, customers and vendors. It’s also a good time…
Key Takeaways Cybersecurity Awareness Month is a national initiative held every October that highlights essential actions you can take to reduce cyber risk. The Cybersecurity and Infrastructure Security Agency (CISA) serves as the federal lead and offers no-cost resources to help businesses and government organizations educate employees, customers and vendors. It’s also a good time…
Read full post on skyterratech.com
How to Compare IT Service Plans: Month-to-Month vs. the Multi-Year MSP Contract
Key Takeaways: Whether you’ve been on one managed IT provider’s website or 100, you likely see the same three things promised over and over: responsiveness, proactivity, and security. That uniform messaging makes it harder to compare companies side by side. Fortunately, you can find differences between companies in two places: what the plan includes versus…
Key Takeaways: Whether you’ve been on one managed IT provider’s website or 100, you likely see the same three things promised over and over: responsiveness, proactivity, and security. That uniform messaging makes it harder to compare companies side by side. Fortunately, you can find differences between companies in two places: what the plan includes versus…
Read full post on intrust-it.com
GLBA Compliance IT Cost in Texas: What Financial Firms Pay in 2026
GLBA compliance IT cost in Texas runs about $175 to $250 per user a month ... Learn More
GLBA compliance IT cost in Texas runs about $175 to $250 per user a month ... Learn More
Read full post on uprite.com
A Guide to Understanding IT Services for Small Businesses in Alpharetta
Most small businesses in Alpharetta face a familiar struggle: technology that should be driving growth instead drains time, energy, and resources. Whether it’s a network outage during a critical client meeting, a cybersecurity scare that disrupts operations, or simply not knowing whether your IT systems are keeping pace with competitors, these challenges are real and
Most small businesses in Alpharetta face a familiar struggle: technology that should be driving growth instead drains time, energy, and resources. Whether it’s a network outage during a critical client meeting, a cybersecurity scare that disrupts operations, or simply not knowing whether your IT systems are keeping pace with competitors, these challenges are real and
Read full post on integricom.net
US Compliance Teams: Make AI for Healthcare Compliance Audit Ready
Practical checklist for US healthcare compliance teams to inventory AI, meet HIPAA, NIST, FDA, ONC, and FTC rules, and be audit ready.
Practical checklist for US healthcare compliance teams to inventory AI, meet HIPAA, NIST, FDA, ONC, and FTC rules, and be audit ready.
Read full post on mytekrescue.com
Zero Trust Adoption Trends for Small Businesses
Zero trust adoption trends are reshaping small-business security. Learn what matters, where to start, and how to protect access without slowing work.
Zero trust adoption trends are reshaping small-business security. Learn what matters, where to start, and how to protect access without slowing work.
Read full post on rj-pro.net
5 AI Use Cases That Actually Move the Needle for Small Business
Artificial intelligence has a lot of potential, but small businesses don’t need another tool or complicated technology initiative. They need practical ways to save time, reduce manual work, and help employees focus on the work…
Artificial intelligence has a lot of potential, but small businesses don’t need another tool or complicated technology initiative. They need practical ways to save time, reduce manual work, and help employees focus on the work…
Read full post on thrivenextgen.com
A Case Study in Identity Based Business Compromise
Three identity attacks bypassed MFA at one company: a fake help desk call, a fraudulent remote hire, and a stolen session. See how each was caught and stopped.
Three identity attacks bypassed MFA at one company: a fake help desk call, a fraudulent remote hire, and a stolen session. See how each was caught and stopped.
Read full post on netfriends.com