CENTER FOR ETHICS AND THE RULE OF LAW​

Third-party security verification of defense contractors must be maintained

Share this Post

Related posts

CERL summer interns complete research on topics ranging from regulating AI in warfare to election interference in the midterms

In July 2026, the Department of Defense issued two memos suspending the Cybersecurity Maturity Model Certification (CMMC) Program, the result of five years of work to secure the U.S. defense industrial base. In a piece for Lawfare, Michael McLaughlin and CERL Executive Board Member Harvey Rishikof examine the haky legal ground underpinning the memos, and note that while their goal of removing administrative burdens on small firms has merit, the security costs of the current approach may outweigh any possible benefits.

Harvey Rishikof is a member of the CERL Executive Board member. He is former Director of Military Commissions and Convening Authority at DoD and former Dean of the National War College. Read his bio here.

The views expressed here are the author’s own and do not necessarily represent those of any organization or university.

Mailing List

Submissions

Submissions to The Rule of Law Post. Please refer to CERL’s submission guidelines for additional details on the blog post format. Should your submission be accepted, we ask that you please complete the Agreement to Transfer Copyright.

Please upload text in one document under 6 mb. Preferred format as a simple text file (.txt).

Share Third-party security verification of defense contractors must be maintained on:

LinkedIn
Twitter
Facebook
Reddit
Email
Print
Third-party security verification of defense contractors must be maintained