In July 2026, the Department of War suspended Phase II of its Cybersecurity Maturity Model Certification (CMMC) program, a requirement that would have forced more than 100,000 defense contractors into costly third-party cybersecurity assessments starting this November. The program stalled under its own weight: compliance costs approaching $600,000 per organization and a severe shortage of qualified assessors to conduct the certifications. Accounting and tax firms don’t fall under CMMC. But the pattern deserves attention from anyone advising clients on compliance and risk. A federal deadline was delayed, and it’s tempting to read that as license to delay related work elsewhere. For firms managing client financial and tax records, that instinct is worth resisting. Obligations under the FTC Safeguards Rule and GLBA don’t move just because a different program’s timeline did, and client financial data remains a high-value target for cybercriminals regardless of what happens in the defense sector. The Real Lesson Behind the Suspension Government compliance programs get delayed, revised, or scrapped with some regularity. The underlying risk they were designed to address rarely follows suit. For firms serving clients who depend on the confidentiality of tax records, banking details, and payroll information, a documented, consistently enforced security policy isn’t a box to check when a regulator demands it. It’s a baseline expectation clients increasingly assume is already in place. Firms that treat cybersecurity policy as an ongoing practice, rather than a reaction to the next compliance deadline, tend to identify gaps before they become incidents. That distinction matters most during filing season, when client data volume peaks and downtime carries the highest cost. Practical Steps Firms Can Take Now - Formalize a written information security policy (WISP). This is already an expectation under the FTC Safeguards Rule, and having it documented protects both the firm and its clients. -