CMMC Phase 1 requirements: what applies to defense contractors in 2026
Phase 1 of CMMC started on 10 November 2025 and is still in force after Phase 2 was suspended. Here is what contracting officers can require now and how to prove it.
Author · Content reviewer
Aishwarya reviews QULDEX blog guidance before publication, checking each article's dates, requirements and references against the primary sources it cites.
Articles
Phase 1 of CMMC started on 10 November 2025 and is still in force after Phase 2 was suspended. Here is what contracting officers can require now and how to prove it.
NIST SP 800-171 is the set of security requirements; CMMC is the Department of War program that checks you meet them. Here is how they relate and what the Phase 2 suspension means.
Both are EU cybersecurity laws with incident reporting and supplier rules. DORA is the sector law for finance; NIS2 covers 18 sectors through national laws. Here is how to tell which applies and how to run both.
FedRAMP 20x moves from long narrative packages to automated evidence and certification classes. Here is how it compares with the Rev5 path and what existing providers need to do.
ISO 31000 is the general risk management guideline; ISO/IEC 27005 applies it to information security for ISO 27001. Here is where they differ and how to use them together.
Saudi Arabia's National Cybersecurity Authority replaced ECC-1:2018 with ECC-2:2024. Here is the new structure, what changed and how to move an existing programme across.
Banks with broking or depository arms answer to both RBI and SEBI. Here is how the RBI Directions of 31 July 2026 compare with SEBI CSCRF, and how to run one control set for both.
A risk appetite statement tells managers how much risk the board will accept in pursuit of its objectives. Here are worked examples by risk category and the tolerances that make them measurable.
The Saudi Central Bank's Cyber Security Framework rates every control area from 0 to 5 and expects at least level 3. Here is what each level means and how to prove it.
If your SaaS product processes personal data of people in Saudi Arabia, the PDPL applies even if you are based abroad. Here is what it asks of SaaS providers and their customers.
ISO 31000:2018 clause 6 sets out one process for any kind of risk. Here is what each step asks for, what it produces and how it looks in a real risk register.
Boards want to know whether compliance is under control and getting better. These 12 metrics answer that, and they double as ISO 27001 clause 9.1 measurement.
A.5.15 asks for rules on who can access what, based on business and security needs. Here is how to set them, and the evidence that proves they work.
A.5.18 is where access control is most often tested, because every joiner, mover and leaver leaves a record. Here is how to run it and what auditors sample.
Backups only count if you can restore from them. A.8.13 asks for a backup policy, protected copies and regular testing. Here is how to evidence it.
A.8.15 asks for logs that record activities, exceptions and faults, kept safe and analysed. Here is what to log, and what auditors check.
A.8.8 asks you to find vulnerabilities, judge your exposure and act on time. Here is a workable process, sensible SLAs and the records that prove it runs.
A practical checklist for an ISO 27001:2022 project, in the order auditors expect to see the work. Tick it off as you go.
Clause 9.2 requires an internal audit programme before certification and every year after. Here is how to plan it, stay objective with a small team, and write findings that survive the certification audit.
Clause 6.1.2 doesn't prescribe a method, but it does prescribe what the method must do. Here is a practical approach, a worked example, and the records auditors ask for.
The SoA is the document auditors open first. Here is what clause 6.1.3 d requires, how to justify inclusions and exclusions, and the mistakes that become findings.
One is a certificate against an international standard, the other a CPA firm's attestation report. Here is how they differ, where they overlap and how to run both without doing the work twice.
AI teams in India need a lawful basis for every piece of personal data a model learns from. Public data, research and consent each work differently under the DPDP Act and Rules.
ISO 42001 asks you to assess how an AI system could affect people and society, not only your organisation. This worked example uses a CV-screening model.
Sample sizes for testing controls depend mainly on how often the control runs. Here are the sizes auditors commonly use, and how to handle an exception.
CERT-In's 2022 directions give most organisations in India six hours to report specified cyber incidents. That only works if the decision to report is made in the first hour.
India's DPDP Rules, 2025 phase in over 18 months. The Data Protection Board is already running; consent managers start in November 2026 and core obligations in May 2027.
The Digital Omnibus pushed the EU AI Act's high-risk rules to December 2027 and August 2028. Transparency duties did not move, and some already apply.
Since 11 September 2026, anyone placing software or connected products on the EU market must report exploited vulnerabilities and severe incidents within 24 hours. Here is the runbook.
Whether a finding is major or minor decides whether you get certified on schedule. The difference is about the management system, not the size of the mistake.
Every ISO 9001:2015 certificate must move to the 2026 edition by 30 September 2029. For certification bodies that means three years of transition audits to schedule, staff and evidence.
CSF 2.0 added Govern as a sixth function. It covers strategy, roles, policy, oversight and supply chain risk, and it is where most organisations have the least evidence.
Two PCI DSS v4 requirements target attacks that skim card data from payment pages in the browser. Here is what each asks for, who it applies to and what assessors want to see.
Under SEBI's Cybersecurity and Cyber Resilience Framework, regulated entities need cyber audits by CERT-In empanelled auditors, half-yearly or yearly depending on their category.
A bridge letter covers the gap between the end of your last SOC 2 period and your next report. Customers usually accept one for a few months, not longer.
ISO/IEC 42001 applies management-system discipline to AI. If you already run an ISO 27001 ISMS, most of the scaffolding exists.
Evidence that cannot be found, dated or traced to a control gets requested again. A five-part file name fixes most of that before any tool is involved.
Three, six or twelve months: the right first observation window depends on how long your controls have run, what your buyers will accept and when you need the report.
The 2022 revision regrouped Annex A into four themes and added 11 controls. Here is what that means for your Statement of Applicability and your next surveillance audit.
DORA requires financial entities to maintain a register of all contractual arrangements with ICT third-party service providers, in a standard format supervisors can collect.