In July 2026, the Department of Defense issued two memos suspending the Cybersecurity Maturity Model Certification (CMMC) Program, the result of five years of work to secure the U.S. defense industrial base. In a piece for Lawfare, Michael McLaughlin and CERL Executive Board Member Harvey Rishikof examine the haky legal ground underpinning the memos, and note that while their goal of removing administrative burdens on small firms has merit, the security costs of the current approach may outweigh any possible benefits.
Harvey Rishikof is a member of the CERL Executive Board member. He is former Director of Military Commissions and Convening Authority at DoD and former Dean of the National War College. Read his bio here.
The views expressed here are the author’s own and do not necessarily represent those of any organization or university.