Skip to content

Cybersecurity

The CMMC suspension is an organizational knowledge test

Cybersecurity certification was never going to be just another audit for the companies that build and support U.S. defense systems. Preparing for it changed budgets, architectures, hiring plans, subcontractor relationships, and the everyday work connecting cyber teams with engineers, contracts staff, and program leaders.

Then, on July 13, 2026, the Department of Defense (DoD) suspended the planned transition to Phase II of the Cybersecurity Maturity Model Certification (CMMC) program. The Department also halted later implementation milestones and opened a 60-day review of the program.

The announcement brought meaningful relief from the coming expansion of third-party assessments. It did not, however, abolish CMMC or erase the contractual duty to protect defense information. Phase I continues, and the underlying safeguarding and reporting requirements remain in force.

That leaves defense organizations with a harder question than whether to keep preparing for an assessment: Which parts of the CMMC effort were merely certification overhead, and which parts became necessary organizational capability?

The distinction matters because a compliance program leaves behind more than policies and evidence. It also changes who talks to whom, how work moves between teams, where decisions are recorded, and whether an organization can accurately explain the security of its systems. Those capabilities are slow to build and surprisingly easy to lose.

Capability gating is a cybersecurity control

OpenAI has introduced Trusted Access for Cyber, an approach intended to expand advanced cybersecurity capabilities for legitimate defenders while placing additional controls around uses that could create harm.

The initiative highlights a problem that every organization deploying powerful artificial intelligence now faces: access control cannot stop at whether somebody may use a model. It has to consider which capabilities they may invoke, under what conditions, with what evidence, and through which escalation path.

Agentic cyber threats collapse the distance between intent and action

Anthropic's August 27 threat-intelligence report describes artificial intelligence (AI) in use across multiple stages of cybercrime, including an extortion operation in which an agentic coding tool provides active operational support. The report also describes a low-skill actor using AI to develop and sell ransomware.

The change is not simply that attackers have a better advisor. It is that advice, tool use, adaptation, and execution can now be chained together inside a much shorter loop.

AI security overlays can connect two professions

The National Institute of Standards and Technology's (NIST) August 14 concept paper proposes security-control overlays tailored to artificial intelligence (AI) systems. The work adapts controls from NIST Special Publication 800-53 to generative, predictive, single-agent, multi-agent, and developer use cases.

The practical promise is not a new checklist. It is a better conversation between two professions that too often approach the same system with different maps.

The AI Cyber Challenge makes evaluation operational

The Defense Advanced Research Projects Agency's (DARPA) August 8 announcement reports the results of its Artificial Intelligence (AI) Cyber Challenge (AIxCC). In the final scored round, competing cyber reasoning systems have analyzed more than 54 million lines of code, identified 86 percent of the synthetic vulnerabilities, and patched 68 percent of those identified.

Those figures are impressive. The design of the evaluation may be more important.

Semiconductor security is a coordination problem

The National Institute of Standards and Technology's (NIST) June 30 framework for analyzing collusion threats in the semiconductor supply chain provides a way to compare threats involving adversaries at different stages of the chain and to reason about security-cost tradeoffs.

Its deeper value is a reminder that supply-chain assurance cannot be reduced to evaluating one supplier at a time.

AI threat intelligence should change the product backlog

Anthropic's April 23 report documents case studies on the malicious use of Claude. The cases include influence operations, credential-related activity, recruitment fraud, and a novice actor using artificial intelligence to advance malware development.

The details matter, but the report's most important feature is the loop it implies: observe abuse, interpret the pattern, change defenses, and share what others can use.

READER-NEUTRAL SUBSCRIPTION

Follow Field Notes via RSS.

Copy this address into the RSS reader you already use. New notes will appear there automatically—no account, email address, or tracking required.