DOD Suspends CMMC Phase 2 & the DOJ Issues a Billion-Dollar Trade-Fraud Warning (07/22/2026)
- › The Department of Defense immediately suspended CMMC Phase 2 requirements that were set to begin on November 10, 2026.
- › The DOJ and DHS signaled that the era of treating customs fraud as a manageable cost of doing business is over.
- › TriWest Healthcare Alliance disclosed a breach affecting almost 12,000 Tricare beneficiaries.
- › Clover Health notified the SEC of a cybersecurity incident it traced to social engineering.
- › The FTC imposed a record $12 million HSR penalty over a transaction it said was structured to avoid reporting.
Today’s compliance news is a set of moved goalposts, and the risk behind each one stayed exactly where it was. A cybersecurity certification deadline got pushed, a category of fraud that used to be tolerated is now a stated enforcement priority, and two more healthcare organizations are cleaning up breaches. The pattern for an operator is that a paused rule does not pause the threat it was written to address.
Top 5 Critical Compliance Alerts
1. DOD Suspends CMMC Phase 2
The Department of Defense announced it was immediately suspending the Cybersecurity Maturity Model Certification Phase 2 requirements, which were set to begin on November 10, 2026 (JD Supra). A suspended deadline is a reprieve on the paperwork, and it changes nothing about the adversary interest in the defense supply chain that the certification exists to counter.
Operator Note: Do not stand down your CMMC program because the enforcement date slipped. The controls it requires are the ones that keep controlled unclassified information out of an adversary’s hands, and the assessment will come. Keep building toward it on your own clock.
2. The DOJ and DHS Issue a Billion-Dollar Trade-Fraud Warning
The Department of Justice and Department of Homeland Security signaled clearly that the era of treating customs fraud as a manageable cost of doing business is over, raising the stakes for importers (JD Supra). Customs valuation and country-of-origin claims are the kind of paperwork that gets delegated and then forgotten, and a stated federal priority is the moment to pull those records back up and confirm they are accurate.
3. TriWest Discloses a Breach Affecting Tricare Beneficiaries
TriWest Healthcare Alliance announced a data breach affecting almost 12,000 Tricare beneficiaries, one of several healthcare breach notifications posted the same day (HIPAA Journal). Beneficiary data tied to a military health program is a sensitive category, and a breach at an administrator like this reaches the covered entities and the individuals who never chose the vendor themselves.
4. Clover Health Reports a Social Engineering Incident
Clover Health notified the SEC of a cybersecurity incident it first identified in July and traced to social engineering (HIPAA Journal). Social engineering is the reminder that the breach often walks in through a convincing phone call rather than a software flaw, and no certification protects an organization whose people can be talked into granting access.
Operator Note: Test your help desk against a pretext call the way an attacker would run it. The verification step that stops a social engineer is a procedure your staff practice, not a policy they signed.
5. The FTC Imposes a Record $12 Million HSR Penalty
The FTC levied its largest-ever Hart-Scott-Rodino penalty, $12 million, over a transaction it said was disguised as non-reportable to avoid premerger review (JD Supra). Structuring a deal around reporting thresholds is legal, and disguising a reportable deal as one that is not crosses the line the FTC just priced at eight figures.
Additional Compliance Alerts
Enforcement & Litigation
- $3 Million Settlement in Healthcare Services Group Breach: Healthcare Services Group agreed to pay $3 million to settle litigation arising from a September 2024 cybersecurity incident, another data-breach class action resolved with a seven-figure check. HIPAA Journal
- New NYC Sick and Safe Leave Rules Take Effect: Amended New York City Sick and Safe Leave rules become effective July 23, 2026, with practical changes employers operating in the city should review. JD Supra
The Axe Report is a daily briefing from Grab The Axe. Need help assessing your organization’s security posture? Take our free Human Attack Surface Score assessment.
A leader defined by a 'bias for action,' Dusten specializes in physical security assessments that impact profitability and facility resilience.
View Profile →Media Inquiries
For expert commentary, interview requests, or high-res assets regarding this announcement, initialize the terminal.