Skip to main content

🔔 Notifications Hub: See compliance updates in one place

CMMC News & Updates

Where CMMC stands right now

CMMC third-party assessments are paused. The underlying cybersecurity requirements are not.

On July 13, 2026, the Department of War paused the transition to CMMC Phase 2 and stood up a 60-day Reform Task Force to review the program. That review period closed September 11, 2026, and the Task Force report has not yet been released. Class Deviation 2026-O0025 Revision 3, issued September 3, carries the pause into DFARS Part 240 and FAR Overhaul Part 40 contract text: contracting officers are directed to accept Level 1 and Level 2 self-assessments and to remove Level 2 (C3PAO) and Level 3 (DIBCAC) assessment requirements from active solicitations and contracts at the next option or modification.

However, as stated in memo 26-P-1023, the Department will continue to enforce baseline compliance with NIST SP 800-171 Rev 2 through CMMC Level 1 and CMMC Level 2 self-assessment and select government-led assessments.

Here is what still applies to defense contractors and subcontractors:

The work that determines whether you can keep doing defense business is the same work it was on July 12: scope where CUI actually lives, keep NIST 800-171 Rev 2 implemented in the live environment, maintain an SPRS score a senior official can stand behind, and be ready for verification whenever it returns.

Not sure where you stand against the 110 requirements? Our CMMC Level 2 compliance checklist walks through what you need in place now, pause or no pause.

To help you stay current on your CMMC and other cybersecurity contractual obligations, we built the news tracker below. 

Latest CMMC news and updates

Last checked: September 18, 2026

Last updated: September 11, 2026

Every week we monitor DoW announcements, federal rulemaking dockets, Cyber AB and assessor ecosystem updates, False Claims Act enforcement actions, and congressional activity affecting the Defense Industrial Base (DIB).

Each entry below is a short, dated summary of what changed, with links to primary sources and to the full write-up in our 2026 news log.

September 11, 2026: As CMMC reform review period comes to close, DoW CIO emphasizes its focus areas

On September 11, 2026, the 60-day CMMC reform review launched by the July Phase 2 pause reached its close, with Department of War CIO Kirsten Davies confirming the Task Force report will be made public but setting no firm date. Speaking on September 9 at the Billington CyberSecurity Summit, Davies reiterated the reform focus areas she first raised at the DIBX conference: information security remains important and is federally mandated elsewhere, but the Reform Task Force and Department are now turning their focus to operational technology and the cyber resilience of the manufacturing base. She also signaled a move away from point-in-time evaluation, saying cybersecurity "needs to be contiguous and continuous, and it needs to be at … the pace of the threat in and of itself." However, Davies added that the third-party assessor base raised concerns over how to prove the DIB is following federal policies, saying "this is still something that we need to resolve for." Read the full entry on Davies's reform focus areas.

September 3, 2026: DoD carries CMMC Phase 2 pause into contract text with class deviation

On September 3, 2026, the Department of War issued Class Deviation 2026-O0025 Revision 3, which supersedes the July 16 Revision 2 and carries the CMMC Phase 2 pause forward into current DFARS Part 240 and FAR Overhaul Part 40 contract text department-wide. Like Revision 2, it directs contracting officers to accept CMMC Level 1 and Level 2 self-assessments and remove third-party assessment requirements from active solicitations and contracts at the next option or modification, while baseline NIST SP 800-171 Revision 2 obligations under DFARS 252.204-7012 remain in place. Read the full entry on the September 3 class deviation.

September 1, 2026: Honeywell Aerospace settles $2M cybersecurity False Claims Act case

Honeywell Aerospace agreed to pay $2,042,518 to resolve False Claims Act allegations that a Honeywell business unit failed to implement NIST SP 800-171 controls on one network under a Department of Defense contract between April 2020 and December 2023. The case came from a whistleblower suit filed by a former employee, who receives $375,823. The alleged conduct took place before CMMC Phase 1 began, showing that the government has verification layers for existing contractual cybersecurity requirements like DFARS 252.204-7012 and these are still in place while CMMC Phase 2 is on hold. Read the full entry on the Honeywell settlement.

August 26, 2026: Davies provides update on the CMMC task force and emphasizes OT security at DIBX

At her DIBX 2026 fireside chat in Philadelphia, DoW CIO Kirsten Davies put operational technology and performance, "not paperwork," at the center of how she is thinking about CMMC reform. She said protecting federal data is a requirement that never went away, and said the Reform Task Force is working through about 1,100 RFI responses to gather insights into making cybersecurity a dynamic process where contractors can continue to reduce risk and improve their cyber posture while still doing business with the Department. Read the full entry on the DIBX remarks.

August 19, 2026: Industry RFI responses flag unclear CUI marking

The CMMC Reform Task Force's RFI comment window closed August 14, and several industry groups flagged inconsistent, unclear, or improper CUI identification and marking as a top driver of CMMC cost and over-scoping. SBA Advocacy called CUI uncertainty the "most frequently cited concern" for small businesses. These are comments rather than decisions, but they signal likely focus areas for the Task Force, whose report to the DoW CIO is expected in late September or early October 2026. Read the full entry on the RFI responses.

August 7, 2026: Defense connector maker discloses phishing breach

IEH Corporation, which manufactures hyperboloid connectors used on THAAD, PATRIOT, and AMRAAM platforms, disclosed in an SEC Form 8-K that an attacker compromised an employee's Microsoft 365 mailbox and could access engineering documentation and potentially export-controlled technical information. The company reported no evidence of exfiltration. The incident changes no CMMC policy, but it is a reminder that DFARS 7012 incident reporting obligations did not pause when assessments did. Read the full entry on the IEH disclosure.

July 23, 2026: FAR CUI rule comment period closes

FAR Case 2017-016, the governmentwide CUI and NIST SP 800-171 Rev 3 proposal, closed comments. If finalized it would apply immediately, with no CMMC-style phased on-ramp. Contractors with both defense and civilian work should not read the Phase 2 pause as cover for this rule. Read the full entry on the FAR CUI rule.

July 22, 2026: House passes FY2027 NDAA with CMMC small business language

H.R. 8800 passed 216 to 212 and includes a provision directing a Pentagon briefing on CMMC's impact on small businesses. The Senate companion, S. 4784, stalled after a July 14 procedural vote and would create a CMMC Level 2 assessment grant program capped at $100,000 per award. Conference is expected after Congress returns in September. None of this is law yet. Read the full entry on the FY2027 NDAA.

July 16, 2026: Elbit tells suppliers to keep going during the pause

Most primes did not send new supplier notices in the week after the announcement. Elbit Systems of America did, urging suppliers to keep meeting existing cybersecurity requirements and to confirm the applicable requirement with their Elbit America buyer before scheduling or cancelling a C3PAO assessment. RTX makes a similar point on its supplier cybersecurity page. The pause is a pause in the Department's own designations, not a release from a prime's flowdown. Read the full entry on the prime notices.

July 15, 2026: Cyber AB confirms the assessment ecosystem stays open

The Cyber AB clarified that this was only "another momentary pause" to the rollout of the CMMC program, specifically to Phase 2. C3PAO assessments, training, and exams remain available to organizations that want them. Read the full entry on the Cyber AB statement.

What we are watching

  • The Reform Task Force report. The 60-day review closed September 11. Davies has said the report will be made public but has set no date. This is the next real beat in the story.
  • RIN 0790-AM01 in the Federal Register. Until it publishes, Rev 2 is the standard.
  • NDAA conference, expected after Congress returns in September.
  • Additional DIB incident disclosures. We add these only when a company filing or government source confirms a covered defense information nexus.

CMMC News 2026: Every Program Update, Rule Change & Enforcement Action

View a dated record of every major CMMC development in 2026, including the Phase 2 pause, Reform Task Force activity, enforcement actions, and rulemaking status of a NIST 800-171 Rev 3 amendment.

Explore Resource

CMMC 2.0 Timeline: Key Dates, Deadlines & the Current Phase

Phase 1 of CMMC enforcement began Nov 2025 and remains in effect today. Get the full CMMC timeline, key dates in its development, and what's coming next now that Phase 2 is on hold.

Explore Resource

The CMMC 2.0 Rulemaking Process + 32 CFR & 48 CFR Status

Learn how and when the 32 CFR CMMC Program rule and 48 CFR Acquisition rule were finalized, where each stands today, and what it would take to change the CMMC program.

Explore Resource
Loading...