Facebook  Linkedin  X

July 2026

NEWS & UPDATES

Welcome to the WPI Cyber Newsletter, a monthly publication from the Wisconsin Procurement Institute (WPI), Wisconsin's Apex Accelerator


If your organization needs assistance meeting Federal or Department of Defense cyber security requirements, contact Marc Violante, Director of Federal Market Strategies at marcv@wispro.org, or Matt Frost, Government Contract Specialist at mattf@wispro.org

NEWS & UPDATES

DoW pauses CMMC C3PAO requirements


On Monday, July 13, the Department of War issued guidance pausing the CMMC C3PAO assessment requirement for 60 days. DoW’s review and report is expected on September 11, 2026 or possibly sooner.


This action was taken in part due to the shrinking DIB and feedback concerning the time, cost, and difficulty in meeting CMMC requirements.


In response to these concerns, the DoW paused the C3PAO assessment requirement and posted a Request for Information to SAM.gov.


See: https://sam.gov/workspace/contract/opp/89ef9bfb0834473791e991c712698d94/view.


Responses are due by August 14, 2026 12:00 ET. An attachment to the RFI provides background and outlines the types of information being requested. Information being requested includes both what are the most costly and problematic requirements and what tools are being used that have made the journey easier. For details concerning both submission format and content please review the document titled - RFI - CMMC - FINAL 7-13-2026.docx.


During this period solicitations and contracts will not contain C3PAO requirement. Additionally, solicitations that have been published with a C3PAO requirement will be amended and contracts that have been awarded will be modified to remove the C3PAO requirement. Waivers will also not be granted.


All requirements of DFARS 252.204-7012 remain in effect. Companies are required to maintain their SSPs, perform self-assessments, update SPRS and post their annual Affirmation Letter.

Companies that would like to discuss current requirements should contact WPI.


WPI is Wisconsin’s Apex Accelerator and can provide assistance with understanding these requirements, determining a path forward as well as assisting with questions/requirements related to federal contracting.


WPI’s main number is 414-270-3600.

 

DoD Suspension of CMMC Phase II is a Mixed Bag for Defense Contractors


The Defense Department’s (DoD’s) decision to suspend the second phase of the CMMC program and take the next 60 days to study its merits will remove some financial pressures from small and midsize defense contractors but put a greater burden on the companies themselves to ensure they have the needed cybersecurity protections in place.

 

The DoD this week announced it is suspending the next step in the Cybersecurity Maturity Model Certification program, which was scheduled to go into effect November 10. In making the decision, government officials said the goal was to ensure that such programs align with the department’s Acquisition Transformation System (ATS) directives from last year that prioritize speed to capability, address regulations that create a barrier for smaller contractors, and make scalable and resilient security measures the deciding factor rather than “bureaucratic” compliance.


https://securityboulevard.com/2026/07/dod-suspension-of-cmmc-phase-ii-is-a-mixed-bag-for-defense-contractors/

 

How CMMC Solutions Strengthen Cybersecurity for Small Businesses


Small businesses are up against a cybersecurity threat landscape that just keeps getting nastier. Data breaches, ransomware, supply chain vulnerabilities: none of these are hypothetical anymore, and that's exactly why robust security frameworks have gone from nice-to-have to non-negotiable. For companies handling sensitive federal information, the Cybersecurity Maturity Model Certification (CMMC) has turned into both a compliance requirement and, honestly, a pretty solid defense strategy in its own right.


CMMC solutions give small businesses a real, structured way to protect controlled unclassified information (CUI) and federal contract data. But it's not just about satisfying a regulator. Done right, these frameworks help build a security posture that can actually take a hit from sophisticated threats and keep standing. So let's dig into how CMMC implementation actually strengthens cybersecurity and what business leaders really need to know before they get started.


https://www.analyticsinsight.net/cybersecurity/how-cmmc-solutions-strengthen-cybersecurity-for-small-businesses

 

What data do you have?


What data do you have, do you know where your data lives and how it moves through your information system? These are key issues with respect to CMMC scoping and are explored in the following article.

 

CMMC pressure is turning MSPs into part of the audit


CMMC (Cybersecurity Maturity Model Certification) is not just a tick in the compliance box. While it may sound like a topic only relevant for defense contractors, regulated industries, and the MSPs that serve them, if looked at closely, it speaks to a core problem of enterprises - data. Companies don't know where sensitive data lives, who has access to it, how it moves across the business, or whether they can prove the right controls are in place. And this is irrespective of whether the data is CUI, customer records, financial information, healthcare data, intellectual property, or anything else the business cannot afford to lose.


https://www.msspalert.com/news/cmmc-pressure-is-turning-msps-into-part-of-the-audit

 

FAR Council Proposes Revised CUI Safeguarding and Incident-Reporting Framework, While DoW Pauses CMMC Implementation


On June 23, 2026, the Federal Acquisition Regulatory Council (FAR Council) published a Proposed Rule that would establish a government-wide framework for safeguarding Controlled Unclassified Information (CUI) and reporting CUI incidents. These obligations traditionally have applied to defense contractors, but would now impact civilian-agency contractors as well. The proposal is one of a series of rules the FAR Council is issuing to implement Executive Order 14275, Restoring Common Sense to Federal Procurement, and the broader “Revolutionary FAR Overhaul.” Comments are due July 23, 2026.

 

Meanwhile, as discussed at the end of this Legal Update, on July 13, 2026, the Department of War (DoW) announced a suspension of the implementation of the Cybersecurity Maturity Model Certification (CMMC) program. Although defense contractors remain obligated to handle CUI and report incidents under DFARS clause 252.204-7012, the requirement to obtain a third-party assessment of their compliance with the controls of NIST SP 800-171 is being held in abeyance pending a “top-to-bottom” review of the CMMC program.


https://www.mayerbrown.com/en/insights/publications/2026/07/far-council-proposes-revised-cui-safeguarding-and-incident-reporting-framework-while-dow-pauses-cmmc-implementation

 

Defending the Digital Frontline: Enlisting AI to Neutralize Cyberattacks Before They Strike


The growing presence of artificial intelligence (AI) is a change that presents as many new challenges as solutions. Although AI seems friendly enough when it is summarizing articles or rewriting emails, not every AI model is trained for altruistic purposes—nor are the malicious actors that wield AI to accelerate digital attacks and hacking attempts. In this time of unprecedented and constantly evolving cybersecurity threats, Dr. Irfan Khan, Assistant Professor in the Department of Marine Engineering Technology at Texas A&M University at Galveston, offers an innovative solution: leveraging AI to stop cyberattacks before they can even happen.


https://news.galveston.tamu.edu/2026/06/16/defending-the-digital-frontline-enlisting-ai-to-neutralize-cyberattacks-before-they-strike/

 

10 signs that someone is monitoring or accessing your accounts - how to stop them


Learn how to spot the signs of account monitoring and compromise - and take back control.


ZDNET's key takeaways

  • Strange email or social activity could mean compromise.
  • There are common indicators you should be aware of.
  • But there are ways for you to take back control.


Account compromise or monitoring can be a quiet affair, and there may be no glaring or immediate signs that your accounts are no longer completely under your control.


https://www.zdnet.com/article/10-signs-online-accounts-monitored-compromised-guide/

 

Gathering Clouds: Building Digital Strategic Depth in the Compute Age


The wars in Ukraine and the Middle East have exposed a strategic reality that military planners are only beginning to confront: In a data-centric age, digital infrastructure has become part of the battlespace. Data centers and cloud regions are now the digital backbone of military power and economic prosperity. As such, they present attractive targets for rapidly proliferating long-range strike systems, drones, and cyber capabilities. As the protective value of physical distance erodes, strategic depth — once conceived in geographical terms — must now be measured in the resilience of data and compute.


https://warontherocks.com/cogs-of-war/gathering-clouds-building-digital-strategic-depth-in-the-compute-age/


Strategic Cargo Theft Now Accounts for Nearly a Third of All US Incidents, Report Finds


Organized criminal networks are increasingly using digital tools and impersonation tactics to steal high-value freight, according to BSI Consulting and Munich Re Specialty.


https://riskandinsurance.com/strategic-cargo-theft-now-accounts-for-nearly-a-third-of-all-us-incidents-report-finds/

 

This AI agent autonomously hacked a network, adapted on the fly, and demanded a ransom


JadePuffer exploited a vulnerable Langflow server, harvested credentials, moved laterally and encrypted more than 1,300 database records, marking what Sysdig describes as the first documented end-to-end agentic ransomware operation.


The paper (link in article) cited multiple instances where the AI agent diagnosed failures and generated corrected payloads without human intervention. In one case, it recovered from a failed attempt to create an administrator account in Alibaba’s Nacos platform within 31 seconds. Sysdig said the behavior, along with self-narrating code and contextual reasoning, supported its assessment that the operation was LLM-driven.


https://www.csoonline.com/article/4193195/this-ai-agent-autonomously-hacked-a-network-adapted-on-the-fly-and-demanded-a-ransom.html

 

The Shift Toward Business-Aligned Risk Management

 

Moving from isolated, technical data to a continuous risk lifecycle can help organizations align security controls with actual business consequences.

 

Periodic risk assessment cannot keep pace with a dynamic threat landscape, underpinned by a volatile geopolitical environment and emerging technologies such as AI and quantum computing. Information risk management must instead become an ongoing process that connects risks, how well controls are working, and the potential consequences for the business if the controls don’t work.


Different risks have varying levels of impact, available data, and stakeholder needs.; therefore, the depth of analysis also varies. There are two analysis tracks you can use for this purpose.


Qualitative analysis works when you need a fast decision with limited data, such as quickly rating the risk of a new SaaS vendor during procurement. Quantitative analysis fits when investment decisions need financial backing, e.g., deciding whether money spent on endpoint detection is justified given the projected cost of a ransomware incident. 


https://www.securityweek.com/the-shift-toward-business-aligned-risk-management

If your organization needs assistance meeting Federal or Department of Defense cyber security requirements, contact Marc Violante, Director of Federal Market Strategies at marcv@wispro.org, or Matt Frost, Government Contract Specialist at mattf@wispro.org

OTHER NEWS

If you are currently, or are planning to be, a contractor or subcontractor supporting the Defense Industrial Base (DIB) you are required to comply with the newly finalized CMMC requirements. 


  • August 27 – Determining Your Real CMMC Compliance Responsibilities


Registration and more information can be found at wispro.org/wpi-events/featured-webinars

  • Be sure to follow WPI on social media (Facebook, LinkedIn, X) for regular updates on events, news and opportunities.
WPI 10437 Innovation Dr. Suite 320, Milwaukee, WI 53226 414-270-3600
Newsletter Editor: Doug Clemons, dougc@wispro.org 
Facebook  Linkedin  X

Not currently a subscriber to WPI's Newsletters?

Click Here to Subscribe