CMMC Phase 2 third-party assessments put on hold
The Defense Department suspended the November 2026 ramp-up of CMMC Level 2 third-party assessments and opened a short review of the program. Phase 1 self-assessment rules stay in force.
The Defense Department suspended the November 2026 ramp-up of CMMC Level 2 third-party assessments and opened a short review of the program. Phase 1 self-assessment rules stay in force.
HHS OCR’s proposed Security Rule update is now a long-term action with a projected final action date of July 2027. The current Security Rule stays in force.
On October 15, 2024, DoD published the CMMC Program final rule. It took effect December 16, 2024 and is the current CMMC 2.0 program regulation.
On June 11, 2024, PCI SSC published PCI DSS v4.0.1, a limited revision of v4.0. Future-dated v4 requirements became mandatory on March 31, 2025.
In October 2022, AICPA revised the points of focus that support the 2017 Trust Services Criteria. The criteria themselves did not change. This remains the current SOC 2 basis.
On January 25, 2013, HHS published the HIPAA Omnibus Final Rule. It took effect March 26, 2013, with a compliance date of September 23, 2013, and remains the rule set in force today.