{
	"version": "https://jsonfeed.org/version/1.1",
	"title": "Cybersecurity Maturity Model Certification (CMMC) news from Infosec Standards",
	"description": "News about Cybersecurity Maturity Model Certification (CMMC), including major updates to our page on it.",
	"home_page_url": "https://infosecstandards.org/standards/cmmc",
	"feed_url": "https://infosecstandards.org/standards/cmmc/feed.json",
	"authors": [
		{
			"name": "Infosec Standards",
			"url": "https://infosecstandards.org"
		}
	],
	"language": "en-US",
	"items": [
		{
			"id": "https://infosecstandards.org/news/who-decides-what-to-ask",
			"url": "https://infosecstandards.org/news/who-decides-what-to-ask",
			"title": "Standard pages now say who decides your obligation, and what to ask them",
			"summary": "The HIPAA, PCI DSS, CMMC, and SOC 2 pages each gained a section naming the party that actually sets your obligation and the questions to put to them in writing. HIPAA and SOC 2 also gained a first-decision picker.",
			"content_text": "The HIPAA, PCI DSS, CMMC, and SOC 2 pages each gained a section naming the party that actually sets your obligation and the questions to put to them in writing. HIPAA and SOC 2 also gained a first-decision picker.",
			"date_published": "2026-09-03T00:00:00.000Z",
			"tags": [
				"site-updates"
			]
		},
		{
			"id": "https://infosecstandards.org/news/risk-assessment-tool",
			"url": "https://infosecstandards.org/news/risk-assessment-tool",
			"title": "Infosec Standards now has a free, browser-only risk assessment tool",
			"summary": "Infosec Standards now has a guided, NIST SP 800-30 based risk assessment tool. Everything stays in your browser; you leave with a JSON file to resume from, a spreadsheet register, and a printable report.",
			"content_text": "Infosec Standards now has a guided, NIST SP 800-30 based risk assessment tool. Everything stays in your browser; you leave with a JSON file to resume from, a spreadsheet register, and a printable report.",
			"date_published": "2026-09-02T00:00:00.000Z",
			"tags": [
				"site-updates"
			]
		},
		{
			"id": "https://infosecstandards.org/news/cmmc-phase-2-suspended",
			"url": "https://infosecstandards.org/news/cmmc-phase-2-suspended",
			"title": "CMMC Phase 2 third-party assessments put on hold",
			"summary": "The Defense Department suspended the November 2026 ramp-up of CMMC Level 2 third-party assessments and opened a short review of the program. Phase 1 self-assessment rules stay in force.",
			"content_text": "The Defense Department suspended the November 2026 ramp-up of CMMC Level 2 third-party assessments and opened a short review of the program. Phase 1 self-assessment rules stay in force.",
			"date_published": "2026-07-13T00:00:00.000Z",
			"tags": [
				"program-changes",
				"version-updates",
				"email-standard"
			]
		},
		{
			"id": "https://infosecstandards.org/news/cmmc-final-rule",
			"url": "https://infosecstandards.org/news/cmmc-final-rule",
			"title": "CMMC Program rule published as 32 CFR Part 170",
			"summary": "On October 15, 2024, DoD published the CMMC Program final rule. It took effect December 16, 2024 and is the current CMMC 2.0 program regulation.",
			"content_text": "On October 15, 2024, DoD published the CMMC Program final rule. It took effect December 16, 2024 and is the current CMMC 2.0 program regulation.",
			"date_published": "2024-10-15T00:00:00.000Z",
			"tags": [
				"version-updates",
				"program-changes"
			]
		}
	]
}
