US Regulation

The United States has no omnibus federal cyber or privacy statute. Its rules are assembled from sectoral laws, an SEC disclosure regime enforced through litigation, defense-contracting clauses, and a growing set of state privacy laws — an enforcement-by-case, patchwork structure that contrasts with the EU's comprehensive statutes (16b). The SolarWinds case illustrates how the disclosure regime operates in practice: on Nov 20, 2025 the SEC agreed to dismiss, with prejudice, the remaining claims in its cybersecurity case against SolarWinds and its CISO Timothy Brown. When filed in Oct 2023, the case had been read as the opening of an era of personal liability for security executives, and the SDNY had already thrown out most of the claims on Jul 18, 2024. The structure of the system determines which sub-segments carry a demand tailwind and when.

The shape of the system

The United States has repeatedly declined to pass a comprehensive federal privacy or cybersecurity law. What exists instead is four overlapping layers, each generating its own compliance demand:

Layer Instruments Who it binds Demand it creates
Federal sectoral HIPAA/HITECH (health), GLBA (financial), FERPA (education), FTC Act §5 (unfair/deceptive) Regulated industries GRC, data protection, breach response, sectoral compliance tooling
Cross-cutting cyber SEC disclosure rules, CIRCIA (pending), TSA/pipeline directives, EO-driven federal-agency mandates Public companies, critical infrastructure, federal suppliers Incident response, disclosure governance, board reporting, attestation
Defense/national-security CMMC, DFARS 7012/7019/7020, ITAR/EAR export controls, FedRAMP Defense industrial base, federal cloud vendors Certification, managed compliance, GovCloud, assessment services
State quilt CCPA/CPRA + ~20 state privacy laws, NYDFS 500, state breach-notification statutes Anyone touching state residents' data Consent/DSAR automation, privacy ops, multi-state compliance

The structural consequence is that the US manufactures GRC and TPRM demand precisely because it is fragmented: a national vendor must satisfy 20 state regimes plus its sectoral and cross-cutting obligations simultaneously, which is exactly the problem compliance-automation platforms (Vanta, Drata, OneTrust) and TPRM vendors (SecurityScorecard, BitSight, UpGuard, Archer) are built to solve. For the CISO on the other side of that demand, the same fragmentation is a standing tax: a large share of budget and staff goes to satisfying overlapping regimes — much of it attestation and documentation — rather than to controls that measurably cut breach risk.

No federal center — four overlapping layers manufacture compliance demand The fragmentation itself is the demand engine for GRC, TPRM & compliance automation Federal sectoral HIPAA · GLBA · FERPA · FTC §5 industry-specific Cross-cutting cyber SEC disclosure · CIRCIA (pending) · TSA directives Defense / nat-sec CMMC · DFARS · FedRAMP · ITAR / EAR State quilt CCPA/CPRA + ~20 state laws · NYDFS 500 Non-discretionary compliance spend GRC · TPRM · compliance automation · attestation · vCISO the most reliable demand in cyber Source: statutes/rules as cited. Exhibit: The Business of Cyber Security.
The US has no single privacy or cyber law; the overlap of four regimes is precisely why multi-regime compliance tooling is a structural growth market. See [GRC & TPRM](03i-grc-tprm.md) and [Regulatory Calendar](16c-regulatory-calendar-catalyst.md).

The SEC disclosure regime and the enforcement recalibration

The SEC adopted its cybersecurity disclosure rules on Jul 26, 2023. They created two obligations for public companies: a Form 8-K Item 1.05 filing within four business days of determining a cybersecurity incident is material, and annual Item 106 disclosure of cyber risk-management processes and board governance. The rules put the CISO function inside the federal securities-disclosure framework for the first time, and the SolarWinds complaint (Oct 2023) — naming CISO Tim Brown personally — was widely read as a signal that security leaders now carried securities-law exposure.

That reading has been substantially walked back. The SDNY dismissed most of the SEC's SolarWinds claims on Jul 18, 2024, finding that "perspective and context are critical" and that the company's filings were not materially misleading; the SEC dismissed the rest with prejudice on Nov 20, 2025. In parallel, the SEC reorganized its enforcement apparatus, launching the Cyber and Emerging Technologies Unit (CETU) on Feb 20, 2025 (≈30 specialists, led by Laura D'Allaird, repurposed from the former Crypto Assets and Cyber Unit) with a stated focus on fraud against retail investors rather than technical-controls theories. US public-company cyber liability has narrowed to knowingly false disclosure rather than honest judgment calls — a contrast with the EU's strengthening of management-body liability under NIS2 (16b). (The SEC did extract settlements from four issuers — Unisys, Avaya, Check Point, Mimecast — on Oct 22, 2024 for understating SolarWinds-related exposure, so disclosure accuracy still has teeth.)

CIRCIA — the federal incident-reporting rule

The Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) was enacted in Mar 2022 and would require covered critical-infrastructure entities to report substantial cyber incidents within 72 hours and ransomware payments within 24 hours. CISA issued the proposed rule in Apr 2024, but the final rule has still not been published as of Jun 2026: the statutory Oct 2025 finalization deadline was pushed to May 2026, and a partial government shutdown forced CISA to postpone its CIRCIA town halls (originally Mar 9–Apr 2, 2026). Per a May 26, 2026 Federal Register notice, CISA reconvened the public town-hall meetings June 15–18, 2026 (general sessions + critical-infrastructure-sector groupings), with more than 1,200 stakeholders participating across the four days, and CISA has indicated it is examining options to streamline the NPRM (criticized for sweeping ~300,000 entities).

A target date has since appeared. A July 2026 preview of the updated Unified Agenda of Federal Regulatory and Deregulatory Actions indicates CISA expects to issue the final rule in September 2026 — the third date the rule has carried, after the statutory October 2025 deadline and the internal May 2026 target. The distinction matters for anyone underwriting the date: the Unified Agenda records an agency's own projection, not a commitment, and no final rule has been published. The core 72-hour/24-hour obligations are not expected to change, and CISA's streamlining work goes to who is covered rather than to the reporting clocks. Whenever CIRCIA finalizes, it would pull forward incident-response, detection, and reporting-automation demand across the 16 critical-infrastructure sectors, and the compressed timelines make it a demand driver for asset visibility and forensic readiness as much as for reporting workflow — an organization cannot report inside 72 hours what it cannot see. (Hunton, Jul 17 2026 · Exterro)

CISA 2015 — the sharing statute and its sunset

The Cybersecurity Information Sharing Act of 2015 (CISA 2015) supplies the legal basis on which US firms share cyber threat indicators and defensive measures with the federal government and with each other. It grants three protections: limits on liability for sharing, an exemption from Freedom of Information Act disclosure, and safeguards against waiver of legal privilege. The statute carried a ten-year sunset. Its information-sharing provisions were scheduled to expire on September 30, 2026 and now run to December 11, 2026, extended by H.R. 6500, the Continuing Appropriations and Extensions Act, 2027, signed September 2, 2026 (White House · Nextgov/FCW, Sep 1 2026). The same measure extended the Technology Modernization Fund and the Federal Cybersecurity Enhancement Act, which authorizes the National Cybersecurity Protection System for federal network intrusion detection.

That date is the fifth in a sequence rather than a first deadline, and the sequence is the material fact. The law sunset on September 30, 2025 during an extended government shutdown and stayed lapsed until November 12, 2025 — 43 days — when Congress passed a renewal running only to January 30, 2026, a window of 79 days. It lapsed a second time for four days during a partial shutdown before the spending bill signed February 3, 2026 renewed it to September 30, 2026, a 239-day extension. In the twelve months to that date the statute was inoperative for 47 days, or 12.9% of the period, across two separate lapses (Davis Wright Tremaine, Feb 5 2026 · Covington, Feb 2026). The September 2026 renewal runs 72 days and is the third short extension since the original sunset; the three average 130 days against an original authorization of ten years, of which the longest post-sunset extension represents 6.5%.

The September 2026 renewal differs from its two predecessors in one respect that bears on how the risk should be read. Both earlier renewals arrived after the statute had already lapsed — 43 days and four days respectively. This one was enacted 28 days before expiry, so the protections ran continuously and no third gap opened. The pattern of short extensions is unchanged, but the record now contains one instance of the deadline being met rather than missed, which is the relevant precedent for an entity assessing whether to plan around a lapse at each expiry.

Two features distinguish this item from everything else on the US calendar. First, it withdraws a protection rather than imposing an obligation. Every other dated item — CIRCIA, CMMC, the state privacy regimes — creates compliance spend by mandating an activity. A CISA 2015 lapse instead creates legal exposure around an activity firms already perform, so its effect runs to the terms and volume of voluntary sharing — ISAC participation, threat-intelligence exchange, and the telemetry pooling on which managed detection and threat-intelligence vendors depend (04b, 15) — rather than to a compliance budget line. Counsel guidance during the 2025 lapse was to identify alternative legal bases for sharing and to revisit existing sharing agreements, which is a legal-review cost rather than a tooling purchase (Morrison Foerster, Oct 2025).

Second, its renewal risk is not independent of appropriations risk, and the September 2026 extension states that relationship in its strongest available form. Both lapses occurred during government shutdowns, and all three renewals arrived attached to spending bills. The new expiry, December 11, 2026, is the date federal appropriations themselves run out under the same continuing resolution — the statute and the budget now share a single deadline rather than adjacent ones. The statute's continuity is therefore governed by the budget calendar rather than decided on its own merits, which is why short renewals keep recurring and why a lapse is a live possibility on any expiry that coincides with an appropriations impasse.

A long-term fix exists in legislative text but has not been enacted. The House-passed fiscal 2027 National Defense Authorization Act carries a ten-year CISA 2015 renewal derived from the WIMWIG proposal; the Senate path has not cleared, with Senate Homeland Security and Governmental Affairs Committee chairman Rand Paul having repeatedly declined to advance clean extensions (Nextgov/FCW · The Record). Until a long-term measure passes, each expiry is settled inside a spending negotiation, and the interval between renewals is set by the length of the prevailing continuing resolution rather than by the statute's own merits.

CMMC — certification as a contracting gate

For the defense industrial base, compliance functions as a license to bid rather than a fine. The Cybersecurity Maturity Model Certification (CMMC) program rule (32 CFR Part 170) became effective Dec 16, 2024, and the DFARS contract clause (48 CFR final rule) took effect Nov 10, 2025, beginning a three-year phase-in that was to insert Level 1/Level 2 requirements into DoD solicitations and ramp to full application by 2028. On July 13, 2026, the Defense Department reversed course: two memoranda suspended the phased implementation — including the planned Nov 10, 2026 transition to Phase II, which would have required contractors and subcontractors handling controlled unclassified information (CUI) to pass Level 2 third-party (C3PAO) assessments — and placed all pending and future CMMC milestones "in abeyance until further notice." The Department opened a 60-day CMMC Reform Task Force review, framed around lowering barriers for small and non-traditional contractors and evaluating alternatives to the third-party assessment model, and issued a Request for Information whose comment window closed Aug 14, 2026 (noon ET), with Task Force recommendations expected around mid-September 2026 (Greenberg Traurig, Jul 15 2026). The 60-day window that opened with the July 13 memorandum closed on September 11, 2026; recommendations run to the Department's Chief Information Officer, and no public report has been issued. A Task Force report is advisory in any case — the obligations set by 32 CFR Part 170 and the DFARS clauses remain in force unless and until they are amended, so the recommendations are a signal of direction rather than a change in requirement (Latham & Watkins, Jul 30 2026). Baseline obligations are unchanged: contractors must still meet NIST SP 800-171 Rev. 2 controls via self-assessment, and FAR 52.204-21 and DFARS 252.204-7012 remain in force; program managers may still require Level 1 or Level 2 self-assessments, while solicitations carrying Level 2 (C3PAO) or Level 3 requirements are to be amended to remove them, and no CMMC waivers are granted during the review.

The suspension does not repeal the underlying demand — CUI-protection obligations persist — but it removes the near-term, deadline-driven catalyst that had been pulling third-party-assessment (C3PAO) and managed-compliance revenue forward toward the November 2026 cliff, replacing a fixed compliance clock with policy uncertainty for the tens of thousands of contractors and subcontractors in the defense supply chain. For the deal record the compliance-automation logic still holds: Fortreum (Gryphon-backed) acquired Kovr.AI (announced Apr 13, 2026), a compliance platform spanning FedRAMP, CMMC 2.0, DoD SRG and NIST CSF 2.0 that had itself achieved FedRAMP Moderate authorization — a tuck-in that buys a portable certification stack rather than rebuilding it — though the pace of CMMC-specific demand now depends on how the reform review resolves (16c). A second print landed a month into the suspension: Datavault AI agreed to acquire CyberCatch Holdings (announced Aug 14, 2026, US$94.5M all cash), a continuous-compliance and control-validation platform whose assessments map to NIST CSF 2.0, NIST SP 800-171, CMMC, ISO 27001, HIPAA and PCI DSS and whose customer base runs through the US defense supply chain. That a CMMC-mapped compliance asset changed hands while the Phase II clock was stopped indicates buyers are underwriting the durable multi-framework control-validation capability rather than the certification deadline alone (11).

The scale of the suspended requirement is quantified in the Small Business Administration's supporting analysis, and the figures locate the constraint on the supply side rather than the demand side. SBA estimates total compliance cost at approximately $593,800 per certification for a small firm requiring third-party assessment and approximately $388,600 for a firm eligible for self-assessment — a $205,200 difference, or a 52.8% premium, that prices the third-party assessment requirement itself rather than the underlying controls, since both paths require the same NIST SP 800-171 Rev. 2 baseline. Phase II would have brought more than 120,000 defense industrial base small businesses into scope against approximately 100 approved assessors, a ratio of roughly 1,200 firms per assessor. Both figures are SBA estimates rather than audited costs, and the split between firms needing third-party assessment and firms eligible for self-assessment is not disclosed, so the aggregate market the suspension removed cannot be derived from them (SBA, Jul 13 2026).

Read against the assessor count, the binding constraint was capacity rather than willingness to pay: the C3PAO population could not have certified the in-scope cohort on the announced schedule at any price, which is consistent with the Department's stated concern about "severe shortages in third-party assessment capacity" alongside cost. That distinction matters for how the suspended demand is classified. A cost barrier suppresses demand and returns if costs fall; a capacity barrier defers demand and returns only as assessor supply is built. It also identifies which businesses the reform outcome bears on most directly — assessment-services firms and the C3PAO accreditation channel (04d, 04g) carry more exposure to the decision than the compliance-automation vendors whose products serve the self-assessment path that remains in force.

Compliance posture of the defense industrial base

Two contractor surveys published in August 2026 bracket the Phase II suspension, and read together they separate what the pause changed from what was already changing. The 2026 State of the DIB Report (CyberSheath, fielded by Merrill Research) surveyed 302 US defense contractors in May 2026, roughly two months before the suspension; the sample comprises 195 prime contractors and 118 subcontractors, with 11 organizations identifying as both and therefore counted in each category. Kiteworks surveyed 273 contractors in the days after the July memoranda.

The pre-suspension survey records self-assessed scores rising while confidence in them falls. The average SPRS score reached a five-year high of +51, 18 points above the +33 recorded in 2025 — the first positive average in the report's history — against a maximum possible score of 110. Over the same period the share of contractors extremely or very confident that their score was accurate fell to 65%, from 89% in 2025 and 94% in 2024, a 24-point drop in a single year. 1% described themselves as completely prepared for CMMC certification, unchanged from the prior year. Average annual DFARS compliance budgets rose to $155,204, and cost was not identified as the binding constraint: 53% of contractors called that budget "just right" and a further 24% called it more than enough. Adoption of individual controls rose — multi-factor authentication 63%, secure backup 48%, data-leakage protection and vulnerability management 44% each, endpoint detection 40%.

The post-suspension survey measures the same gap directly. 96% of Kiteworks respondents said they were confident their self-attested SPRS score would withstand review, but 29% could support the claim with both a current SPRS submission and a FedRAMP-authorized platform. Kiteworks combined its two readiness measures — one tracking compliance maturity, the other tracking the response to the suspension itself — by multiplying rather than averaging them, producing a combined score of 60 out of 100 against roughly 77 on a simple average. The method matters for how the number reads: because the product of two fractions below one is never greater than the lower of them, a multiplicative score reports the weaker of a contractor's two positions rather than a midpoint, and a combined 60 is consistent with a simple average no lower than about 77.5. Just under a third of respondents scored low on both measures at once, the largest single grouping in the sample.

Legal exposure did not pause with the assessment mandate. The DFARS obligation to attest accurately remained in force throughout; 84% of contractors reported concern about False Claims Act liability tied to an inaccurate score, and 92% had already engaged legal or compliance review. Close to half of respondents were unaware that Phase 1 self-assessment obligations continued during the pause, and self-described confidence in understanding the changes did not track performance on a factual test of them.

Bidding behaviour moved quickly once the Level 2 gate lifted. 55% of contractors said they were bidding on work they had previously avoided because of Level 2 requirements; 52% had withdrawn from a Department of War bid and 38% had lost or been disqualified from a contract over the same requirement. The effect fell unevenly by tier: Tier 2 and lower subcontractors reported bid losses at 55%, against 31% among prime contractors — the pattern the buyer-tier analysis on 01e would predict, since the smaller supplier absorbs the same fixed control cost against a much smaller contract base.

Both samples asked for verification to survive the reform rather than lapse with it. 93% of Kiteworks respondents said independent third-party authorization would be essential or important in future vendor selection, 93% intended to comment on the Department of War's request for information, and 58% expected Phase II to return in modified form. In the CyberSheath sample, 90% wanted the government to mandate minimum cybersecurity standards across all federal contractors and 77% said DFARS compliance meaningfully improves national security, while 74% wanted implementation made easier and 70% wanted more vendor options (SecurityWeek, Aug 21 2026 · Infosecurity, Aug 20 2026 · CyberSheath — 2026 State of the DIB Report · Kiteworks — 2026 CMMC 2.0 DIB Readiness).

The 60-day Reform Task Force review opened by the July 13 memoranda runs to Sep 11, 2026. What is delivered on that date is a set of recommendations to the department's chief information officer, not a public document: practitioner guidance expects the report and its recommendations to become public between late September and early October 2026, so the resolution of the Phase II question arrives in two steps separated by several weeks rather than one. The distinction matters for anyone pricing a managed-compliance or assessment business, because the first date produces no observable information and the second may.

A further limitation constrains what any of it can change on its own. A task force report is advice. The obligations that actually bind a defense contractor — DFARS 252.204-7012, NIST SP 800-171 Rev 2, SPRS scoring and the annual affirmation — remain in force until a class deviation, a DFARS rule change or an amendment to 32 CFR Part 170 is issued. Phase II was suspended; the underlying CUI-protection regime was not. The commercially operative consequence is that the compliance spend tied to the standing clauses continues regardless of the report's content, and only the certification-and-assessment layer — the C3PAO revenue and the deadline-driven pull-forward behind it — is genuinely contingent on the outcome.

The state quilt — 20 regimes and rising enforcement

In the federal vacuum, the states have built the privacy regime. As of 2026, 20 states have comprehensive consumer-privacy laws in effect (California's CCPA/CPRA plus, most recently, Indiana, Kentucky and Rhode Island joining in 2026), each with its own definitions, thresholds and AG enforcement. The compliance burden is multiplicative, not additive — a national business must reconcile 20 rulebooks at once. Two 2025–2026 shifts matter for demand:

The result is the same as at the federal level, only sharper: fragmentation is the demand engine. Each new state law and each headline penalty pushes more enterprises toward consent/DSAR automation and multi-state compliance platforms.

Contracting the private sector into offensive operations

A fifth instrument appeared in August 2026, and it creates demand by procurement rather than by compliance. A National Security Presidential Memorandum, Expanding Capabilities to Combat Transnational Cyber-Enabled Crime, signed Aug 12, 2026, directs the National Coordination Center to establish a federal program under which vetted US cybersecurity companies may conduct government-approved cyber surveillance and cyber effects operations against cyber-enabled transnational criminal organizations. It builds on Executive Order 14390 (Mar 6, 2026), Combating Cybercrime, Fraud, and Predatory Schemes Against American Citizens, and cites more than $20.8B in 2025 losses to cyber-enabled crime against Americans.

The mechanism is contractual: participating companies sign agreements with the Department of Justice or the Department of Homeland Security, executive directors from those departments approve every operations package in writing, participants post a bond or escrow of at least $1M forfeitable for non-compliance, and a classified annex governs deconfliction across law enforcement, State, the Treasury, War, Justice and the intelligence community. Because authority runs only through government direction and supervision, legal analyses of the memorandum have read it as stopping short of authorizing private-sector "hack back," with the approval process supplying the authorization for access that the Computer Fraud and Abuse Act otherwise withholds. Targets exclude criminal groups that are an institutional part of, or wholly operated under the direction of, a foreign government. In structure the review-and-approval design echoes NSPM-13 (Aug 2018), United States Cyber Operations Policy, which delegated authority for offensive operations conducted by the military.

Operating procedures, vetting requirements and approval processes are due within 60 days of signing — approximately Oct 11, 2026. Until those land, the eligibility criteria, indemnification and liability terms, and the definition of the non-compliance that triggers bond forfeiture are undefined, and the reauthorization status of the Cybersecurity Information Sharing Act of 2015, whose information-sharing provisions expire Sep 30, 2026 (above), remains an open variable for prospective participants. The segment consequences are covered on Offensive Security & PTaaS; the milestone is tracked on 16c. (White House memorandum, Aug 12, 2026 · Wiley alert, Aug 14, 2026 · Cybersecurity Dive, Aug 13, 2026)

Supply-chain exclusion — the bulk-power emergency

A sixth instrument arrived on Aug 26, 2026, and it works by neither compliance nor procurement but by exclusion. An Executive Order, Declaring a National Emergency to Secure the United States Bulk-Power System, invokes the International Emergency Economic Powers Act and the National Emergencies Act against foreign-produced bulk-power system electric equipment. It generally prohibits the purchase or installation in the United States of covered foreign-produced equipment — including the associated critical software and digital capabilities — where a transaction involves foreign nationals posing an undue risk of sabotage, unauthorised access or other disruption, and permits conditions to be imposed instead of an outright bar. The order excludes facilities used for local distribution of electric energy, so its reach is transmission and generation rather than the last mile. It restates an approach first taken in Executive Order 13920 (May 2020), which was revoked in 2021.

Two clauses carry the commercial weight. The first is that the prohibition extends to software and digital capability rather than to hardware alone, which puts firmware, embedded control software and remote-management channels inside the scope of a trade instrument. The second, and the more consequential, is that the Secretary of Energy may impose conditions on the continued use and operation of equipment already installed, weighing reliability, safety, replacement availability and continuity of service. That reaches the installed base, not only the order book. A utility cannot satisfy a condition on continued use without knowing what equipment it operates, whose firmware it runs and where that firmware came from — which is the capability set sold by the OT asset-inventory, firmware and component-provenance cohort (OT / ICS Security). The order directs the Department of Energy to publish implementing rules and to identify equipment posing the specified risks; until those rules land, the covered-equipment list, the designated-entity criteria and the conditions regime are all undefined, so the demand is dated but not yet sized. Tracked on Regulatory Calendar as Deal Catalyst (White House fact sheet, Aug 26, 2026 · Executive Order, Aug 26, 2026 · Utility Dive, Aug 27, 2026).

→ M&A implications

US fragmentation produces three durable deal patterns. (1) Category creation: GRC, TPRM, compliance automation, data-residency and attestation all exist because the US never centralized — and each remains structurally fragmented enough to roll up. (2) Certification-as-moat M&A: FedRAMP, CMMC and StateRAMP authorizations are slow, expensive barriers to entry, so a certified target is acquisition-attractive to a platform that wants instant federal access — the strategic logic behind compliance-platform tuck-ins like Fortreum–Kovr.AI. (3) Enforcement-timed demand: a finalized CIRCIA rule, a new state law's effective date, or a marquee penalty each pull demand forward into a nameable sub-segment, lifting target revenue and multiples on a knowable clock (16c).

Sources: SEC — dismisses SolarWinds/CISO case (Perkins Coie, Nov 2025) · Harvard Corp Gov — SolarWinds dismissed, what the U-turn signals · SEC — CETU launch (press release 2025-42) · Hunton — SEC fines four companies (Oct 2024) · CyberScoop — CISA pushes CIRCIA final rule to May 2026 · Federal Register — CIRCIA town halls (Feb 2026) · White & Case — CMMC final DFARS rule · EDUCAUSE — DFARS/CMMC effective Nov 10, 2025 · MultiState — 20 state privacy laws in effect 2026 · Smith Anderson — data privacy 2026: state enforcement · Solganick — cybersecurity services M&A update (Fortreum–Kovr.AI) · BusinessWire — Fortreum acquires Kovr.AI (Apr 13, 2026) · SBA — news release 26-73 on CMMC Phase II suspension (Jul 13, 2026) · Latham & Watkins — what the CMMC Phase 2 suspension does and does not change (Jul 30, 2026) · Federal News Network — Pentagon suspends CMMC phase two requirements


Updated 2026-10-04 19:34 UTC · © El Dorado Capital · el-doradocapital.com · Market intelligence for informational purposes only; not investment advice.