<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Cybersecurity Maturity Model Certification (CMMC) news from Infosec Standards</title>
    <link>https://infosecstandards.org/standards/cmmc</link>
    <description>News about Cybersecurity Maturity Model Certification (CMMC), including major updates to our page on it.</description>
    <language>en-us</language>
    <atom:link href="https://infosecstandards.org/standards/cmmc/feed.xml" rel="self" type="application/rss+xml"/>
    <item>
      <title>Standard pages now say who decides your obligation, and what to ask them</title>
      <link>https://infosecstandards.org/news/who-decides-what-to-ask</link>
      <guid>https://infosecstandards.org/news/who-decides-what-to-ask</guid>
      <pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate>
      <description>The HIPAA, PCI DSS, CMMC, and SOC 2 pages each gained a section naming the party that actually sets your obligation and the questions to put to them in writing. HIPAA and SOC 2 also gained a first-decision picker.</description>
    </item>
    <item>
      <title>Infosec Standards now has a free, browser-only risk assessment tool</title>
      <link>https://infosecstandards.org/news/risk-assessment-tool</link>
      <guid>https://infosecstandards.org/news/risk-assessment-tool</guid>
      <pubDate>Wed, 02 Sep 2026 00:00:00 GMT</pubDate>
      <description>Infosec Standards now has a guided, NIST SP 800-30 based risk assessment tool. Everything stays in your browser; you leave with a JSON file to resume from, a spreadsheet register, and a printable report.</description>
    </item>
    <item>
      <title>CMMC Phase 2 third-party assessments put on hold</title>
      <link>https://infosecstandards.org/news/cmmc-phase-2-suspended</link>
      <guid>https://infosecstandards.org/news/cmmc-phase-2-suspended</guid>
      <pubDate>Mon, 13 Jul 2026 00:00:00 GMT</pubDate>
      <description>The Defense Department suspended the November 2026 ramp-up of CMMC Level 2 third-party assessments and opened a short review of the program. Phase 1 self-assessment rules stay in force.</description>
    </item>
    <item>
      <title>CMMC Program rule published as 32 CFR Part 170</title>
      <link>https://infosecstandards.org/news/cmmc-final-rule</link>
      <guid>https://infosecstandards.org/news/cmmc-final-rule</guid>
      <pubDate>Tue, 15 Oct 2024 00:00:00 GMT</pubDate>
      <description>On October 15, 2024, DoD published the CMMC Program final rule. It took effect December 16, 2024 and is the current CMMC 2.0 program regulation.</description>
    </item>
  </channel>
</rss>
