Find notable cyber news and cases, enriched with sources, timelines, and signals.

DoD final CMMC rule and ISACA credentialing rollout

Public Sector Action
First reported
Last updated
Happening score
H score 28
1 unique sources, 1 articles

Summary

Hide ▲

The US Department of Defense published the final CMMC rule, starting a three-year rollout of cybersecurity requirements across DoD contracts. The change matters because contractors handling FCI and CUI must meet stricter controls to keep working in the defense supply chain. ISACA's new role as global credentialing authority and CAICO formalizes how the program will train, test, and certify assessors through 2028.

Timeline

  1. 17.12.2025 16:05 1 articles · 5mo ago

    DoD publishes final CMMC rule

    Legal Policy Action Update

    The US Department of Defense published the final Cybersecurity Maturity Model Certification (CMMC) rule in the Federal Register, formalizing cybersecurity requirements for defense contractors that handle Federal Contract Information (FCI) and Controlled Unclassified Information (CUI).

    Show sources
  2. 17.12.2025 16:05 1 articles · 5mo ago

    CMMC rule takes effect and rollout begins

    Industry Or Public Sector Update

    The final CMMC rule took effect, launching a three-year rollout of cybersecurity requirements across DoD contracts through 2028 and requiring organizations supplying or working into the DoD to maintain a CMMC credential.

    Show sources
  3. 17.12.2025 16:05 2 articles · 5mo ago

    ISACA named global CMMC credentialing authority

    Initial Disclosure

    The US Department of Defense appointed ISACA as the global credentialing authority for the Cybersecurity Maturity Model Certification (CMMC) program and made it the exclusive CMMC Assessor and Instructor Certification Organization (CAICO), with ISACA saying the rollout will affect more than 200,000 organizations.

    Show sources