CMMC Phase II Suspended, Bulk Data Deadlines Loom & Martyn's Law Lands (07/14/2026)
- › The Pentagon suspended CMMC Phase II requirements for defense contractors, changing near-term obligations but not the underlying need to secure controlled data.
- › Audit and certification deadlines under the DOJ's Bulk Data Transfer Rule are approaching for companies across many industries.
- › New guidance under the UK's Martyn's Law pushes counterterrorism preparedness into everyday event planning.
- › HHS data shows 61 healthcare breaches reported in May 2026.
- › Lucent Health Solutions agreed to pay up to $1.95 million to settle breach litigation.
Two of today’s items pull an obligation forward and one pushes one back, and all three land on someone’s operating plan. The Pentagon hit pause on CMMC Phase II, the Justice Department’s bulk data deadlines are coming up fast, and the UK is telling event organizers that counterterrorism is now part of the run of show. A suspended requirement is not the same as a lifted one, so read each of these for what it actually changes in the work.
Top 5 Critical Compliance Alerts
1. Pentagon Suspends CMMC Phase II for Defense Contractors
The Department of Defense suspended CMMC Phase II requirements for defense contractors, easing the near-term certification timeline (Byte Back Law). A suspension changes the deadline, not the exposure, because the controlled unclassified information the rule protects is still a target, and contractors who treat this as permission to stop hardening will regret it at the next audit or the next breach.
Operator Note: Do not stand down your CMMC work. Keep the controls you have built and the assessment evidence current, because a suspended requirement tends to come back with a shorter runway.
2. Bulk Data Transfer Rule Deadlines Are Approaching
Audit and certification deadlines under the US Department of Justice’s Bulk Data Transfer Rule are coming up for companies across a wide range of sizes and industries (JD Supra). This rule governs how sensitive US data can move to certain foreign parties, and any business with international data flows needs to know whether it is in scope well before the certification clock runs out.
3. Martyn’s Law Pushes Counterterror Into Event Planning
New guidance under the UK’s Martyn’s Law, ahead of the act’s expected entry into force next year, signals a cultural shift that embeds counterterrorism preparedness into everyday event planning (Corporate Compliance Insights). Any organization that gathers people at a venue now has a documented duty to plan for a physical threat, and the smart move is to build that assessment into the event process rather than bolt it on for the regulator.
4. HHS Logs 61 Healthcare Breaches in May 2026
HHS Office for Civil Rights data shows 61 healthcare data breaches reported in May 2026 (HIPAA Journal). The monthly report is a running reminder that healthcare remains one of the most breached sectors, and every entry is a covered entity that now faces notification duties and the litigation that tends to follow.
5. Lucent Health to Pay Up to $1.95M in Breach Settlement
Lucent Health Solutions, a Nashville-based health plan administrator, agreed to pay up to $1.95 million to settle class action litigation over a data breach (HIPAA Journal). The settlement is the reminder that the true cost of a breach is not the incident response, it is the years of legal exposure that follow a lapse in protecting the data.
Additional Compliance Alerts
Regulatory Updates
- Malaysia Consults on an AI Governance Bill: Malaysia opened consultation on an AI Governance Bill, another sign that AI-specific compliance obligations are arriving market by market. JD Supra
The Axe Report is a daily briefing from Grab The Axe. Need help assessing your organization’s security posture? Take our free Human Attack Surface Score assessment.
A leader defined by a 'bias for action,' Dusten specializes in physical security assessments that impact profitability and facility resilience.
View Profile →Media Inquiries
For expert commentary, interview requests, or high-res assets regarding this announcement, initialize the terminal.