Ammolite Insights: July 23, 2026

CYBERSECURITY NEWS, INSIGHTS & ANALYSIS


 
Graphic illustrating the U.S. Capitol and a CMMC certification checklist highlighting that while CMMC Phase II assessments are paused, organizations must continue meeting cybersecurity requirements.

Recent changes to the U.S. Department of Defense’s Cybersecurity Maturity Model Certification (CMMC) program have created uncertainty across the Defence Industrial Base. As announced by the Department of Defense CIO on July 13, 2026, CMMC Phase II third-party assessments have been temporarily suspended while the program is under review. Organizations handling Controlled Unclassified Information (CUI) are still required to protect that information in accordance with DFARS 252.204-7012 and NIST SP 800-171 Rev. 2. You can read the official announcement here.

What Does This Mean for Your Organization?

For organizations operating in Canada, it’s important to distinguish between the U.S. CMMC program and Canada’s Canadian Program for Cyber Security Certification (CPCSC). 

The recent announcement affects businesses pursuing U.S. Department of Defense contracts that require CMMC certification. Although third-party assessments have been temporarily paused, organizations that currently support, or plan to expand into, the U.S. defence supply chain are still expected to meet applicable cybersecurity requirements and protect Controlled Unclassified Information (CUI). 

Canada’s CPCSC program remains unchanged. Organizations preparing for CPCSC should continue working toward compliance, including completing required Level 1 self-assessments where applicable. 

Whether you’re preparing for CPCSC or CMMC, now is the time to strengthen your cybersecurity program. Building strong security practices today can reduce future compliance challenges, improve resilience against cyber threats, and position your organization for future certification requirements. 

At Ammolite Security, we help organizations prepare for both CPCSC and CMMC by identifying security gaps, conducting readiness assessments, and developing practical compliance roadmaps. We also provide advisory services to support organizations through the CPCSC process.

Eligible Canadian small and medium-sized businesses preparing for CPCSC may be able to access support through the National Research Council of Canada’s Industrial Research Assistance Program (NRC IRAP). If you’re preparing for CPCSC, contact Ammolite Security to learn whether your organization may be eligible and how we can help you navigate the CPCSC readiness and funding process.

 

In The News

 

Microsoft SharePoint Vulnerabilities Actively Exploited for RCE, Web Shells, and IIS Key Theft

Microsoft SharePoint Server flaws are being actively exploited to gain remote code execution, install persistent web shells, and steal cryptographic keys from exposed systems.

Improve Router Hygiene to Protect Against State-Sponsored Cyber Threats

CISA is urging organizations to strengthen router security after identifying ongoing exploitation of poorly configured and vulnerable networking devices by Russian state-sponsored threat actors targeting critical infrastructure worldwide.

'Frustrated and stressed': Thousands impacted by cyber attack at Calgary University 

Students and staff at Mount Royal University are concerned and frustrated after a cyber attack targeting the school last month compromised thousands of people’s sensitive information.


 
 

Your Employees Are Your First Line of Defence

Technology alone can’t stop every cyberattack. Every day, your employees make decisions that can either strengthen your organization’s security or create opportunities for attackers.

With practical, engaging cybersecurity awareness training, your team will learn how to recognize phishing attempts, handle sensitive information securely, and respond confidently to today’s evolving threats. Ammolite Security delivers customized training tailored to your organization’s industry, workforce, and risk profile, helping you reduce risk and build a stronger culture of cybersecurity.


Next
Next

Ammolite Insights: June 25, 2026