
The Way Forward – TorchLight Blog
-

CMMC Phase II Suspended: What It Means and What to Do Next
On July 13, 2026, the Department of War suspended CMMC Phase II, removing the November 2026 third-party audit deadline. But DFARS 252.204-7012, NIST SP 800-171, and your SPRS self-attestation all still apply. This is schedule relief, not scope relief, and…
-

MSP vs MSSP: Which Does Your Business Actually Need? (2026)
Choosing between an MSP and an MSSP is becoming increasingly difficult as cyber threats grow more sophisticated and compliance requirements become more demanding. Many businesses invest in outsourced IT services expecting comprehensive protection, only to discover later that traditional IT…
-

What Is a Fractional vCISO? And Does a Credit Union Under $500M Actually Need One?
A fractional vCISO gives credit unions under $500 million the strategic security leadership of a full-time CISO, part-time and at a fraction of the cost. Here is what a vCISO actually does, how it differs from a vCIO, what NCUA…
Stay in the loop on Cyber Security and other important thoughts from TorchLight
