The US Department of Defense is implementing the Cybersecurity Maturity Model Certification 2.0 (CMMC), requiring over 300,000 military contracting companies to enhance their cybersecurity protections. Despite the critical importance of these safeguards, more than half of defense contractors are reportedly unprepared for the initial phase of CMMC, which is set to begin imminently. Whistleblowers have played a significant role in exposing non-compliance, leading to major settlements by companies such as Raytheon and Aerojet Rocketdyne under the False Claims Act. The new requirements not only impact primary contractors but also extend to subcontractors and external service providers, including cloud service providers, who may not fully understand their obligations under CMMC.
Many contractors and their service providers face confusion regarding the scope of CMMC, particularly in distinguishing between subcontractors and external service providers, and in understanding which IT and information security services fall under compliance requirements. Failure to include all relevant service providers in CMMC assessments could result in non-compliance and potential loss of business. Registered Practitioner Organizations are offering guidance to help organizations navigate these complexities, emphasizing the need for comprehensive compliance programs that address both direct and indirect CMMC obligations across the defense supply chain.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
Help Net Security reported findings from the 2026 Secureframe National Cybersecurity Summit showing CMMC adoption spreading across the defense industrial base while many contractors still center security programs on compliance rather than resilience. The survey highlighted high readiness costs, assessor inconsistency, CUI scoping challenges, third-party risk, reported supply-chain compromises, and widespread concern about AI-driven attacks.
Follow-on coverage noted that CMMC enforcement had commenced, reinforcing that the program had moved from planning into active implementation. The reporting underscored the operational impact on defense-sector organizations seeking or maintaining DoD contracts.
News coverage across several security and government publications described the start of CMMC enforcement as a major compliance shift for the defense supply chain. The reports emphasized that prime contractors and lower-tier suppliers would now face formal cybersecurity certification requirements.
The Department of Defense began enforcement of the Cybersecurity Maturity Model Certification program, ending years of warnings and preparation for the defense industrial base. The new rules started applying to contractors and subcontractors handling covered defense information.
A report published after CMMC enforcement began alleged that some defense contractors were silencing or sidelining cybersecurity watchdogs instead of addressing compliance and security concerns. The reporting framed this as a governance problem affecting the credibility of contractor cybersecurity practices.
As enforcement started, security and compliance experts published guidance explaining how CMMC obligations extend to subcontractors, managed service providers, and other third parties in the defense supply chain. The guidance focused on scoping, responsibility boundaries, and certification implications.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
helpnetsecurity.com
Open sourcescworld.com
Open sourcenextgov.com
Open sourcegovinfosecurity.com
Open sourcebankinfosecurity.com
Open sourcedatabreaches.net
Open sourcetrustedsec.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.