This page is the complete dated record of major CMMC news in 2026, starting with the latest developments first and updated weekly. It covers program and policy changes, Cyber AB ecosystem updates, False Claims Act enforcement, and congressional activity affecting the Defense Industrial Base (DIB), each verified against at least one primary source.
A note on naming: The Department is now commonly referred to by its official secondary title, the Department of War (DoW). Because existing CMMC rules, contract clauses, and source documents still read "Department of Defense (DoD)," we continue to use this statutory name or "the Department” as well as the secondary title.
CMMC News 2026: Final rule, enforcement, and DoW updates
We update this page weekly or when a primary source moves: a DoW or Cyber AB statement, a Federal Register or DOJ release, NDAA conference text, or a company filing that confirms a potential CUI incident or DFARS 7012 nexus.
August 26, 2026: Davies provides update on the CMMC task force and emphasizes OT security at DIBX
Six weeks after the CMMC Phase 2 pause, DoW CIO Kirsten Davies spent most of her fireside chat at the Department’s inaugural DIBX conference in Philadelphia talking about a threat that CMMC isn't built to address: operational technology attacks.
Davies drew a line between information security and OT security. Protecting federal data is already required and "that requirement never went away," she said. The shift that she wants the government and contractors to make now is toward protecting the controllers, workstations, and production systems that determine whether a supplier can actually produce what they need to for the Department and deliver on their contracts. That's OT security. Explaining that a key focus of the Task Force and potential CMMC reform is not only reducing cost but also improving operational resilience and performance, she said, “What we want is results, not red tape.”
On the review itself, she said the Reform Task Force’s RFI closed with about 1,100 responses, totaling more than 11,000 pages of feedback, and that the team is going offsite for three days before assembling recommendations for her and Under Secretary Michael Duffey. She did not give a new date for the report, but said this won't be a six- to twelve-month study. If the original 60-day review plus 15-day write-up holds, the report is still expected in late September or early October 2026.
None of that changes what contracts require now. DFARS 252.204-7012, NIST SP 800-171 Rev 2, CMMC Phase 1 self-assessments, SPRS scores, and annual affirmations remain in effect. Under current CMMC scoping, OT is a Specialized Asset: documented and managed, not assessed against all 110 requirements but spot checked. Davies' remarks signal that reform and the government's expectations may raise the bar for OT security. Contractors that want a competitive advantage when bidding on work should start assessing and implementing the Top 10 OT best practices from the DoW's Brilliant at the Basics campaign.
Source: CMMC.com, Aug 26, 2026
Recommended reading
OT Security Is Key to DIB Resilience: What the DoW CIO Signaled about CMMC Reform at DIBX 2026
Read MoreAugust 19, 2026: Industry RFI responses flag unclear CUI marking as a top CMMC cost driver
In comments submitted to the CMMC Reform Task Force through the DoW RFI, multiple industry groups including the SBA Office of Advocacy, the National Defense Industrial Association, the Professional Services Council, and the Alliance for Digital Innovation flagged inconsistent, unclear, or improper CUI identification and marking as one of the biggest drivers of CMMC cost and confusion.
SBA Advocacy called CUI uncertainty the "most frequently cited concern" for small businesses and said it "warrants focused, immediate attention," recommending DoD define anticipated CUI categories, markings, and data flows before imposing CMMC requirements.
According to several groups, inconsistent or improper marking leads both the Department and prime contractors to unnecessarily flow down or apply blanket CMMC requirements across subcontractors, some of which will not actually handle CUI. PSC framed the fix as a matter of execution, writing that the solution is "to improve execution, not to postpone or weaken the requirements."
These are industry comments and recommendations rather than decisions, but they indicate potential focus areas for the Task Force, which is expected to deliver a final report to the DoW CIO in late September or early October 2026.
August 14, 2026: CMMC reform RFI comment window closes
The Department of War's request for information, "Reforming CMMC and Reducing Compliance Burden for the Defense Industrial Base," closed at 12:00 p.m. Eastern on August 14, 2026. The notice asked seven questions, five of them about cost and administrative burden, and directed comments by email.
Those responses will be used by the CMMC Reform Task Force to make reform recommendations that “definitively reduce compliance and cost burdens on small, medium, and non-traditional companies.” The Task Force was given 60 days from July 13 to review the program and roughly two more weeks to write its report. That puts delivery to the DoW CIO and USD(A&S) sometime between mid-September and early October 2026.

Closing the comment window is a process milestone, not a policy change. Phase 1 self-assessments, DFARS 252.204-7012, NIST SP 800-171 Rev 2, and SPRS remain in force while the Department writes its recommendations.
Recommended reading
CMMC Phase 1 Self-Assessment Guide: Level 1 and Level 2 Requirements
Read MoreAugust 7, 2026: Defense connector maker discloses phishing breach
IEH Corporation, a publicly traded manufacturer of hyperboloid connectors used on defense and aerospace platforms including THAAD, PATRIOT, and AMRAAM, disclosed in an SEC Form 8-K filed August 7, 2026 that it discovered a phishing-driven compromise of an employee's Microsoft 365 mailbox on August 4. The company said the attacker could access emails, attachments, purchase orders, engineering documentation, and potentially export-controlled technical information, and that it found no evidence data was exfiltrated.
The incident is a timely reminder that the DoW’s Phase 2 pause did not change contractors' underlying duties. DFARS 252.204-7012 still requires safeguarding of covered defense information and 72-hour cyber incident reporting, and NIST SP 800-171 Rev 2, SPRS scoring, and annual affirmations remain fully in effect.
Contractors handling covered defense information should confirm their incident response and DIBNet reporting processes are current.
Recommended reading
Government Cyber Attacks: 10+ Examples, Trends & Tips for Prevention
Read MoreJuly 28, 2026: Cyber AB holds its first town hall since the pause
The Cyber AB's first public event after the pause emphasized that the CMMC program itself has not been paused. CEO Matt Travis's standing position has not changed from the CyberAB’s initial response: Level 2 certification remains available, and provides the highest level of assurance to primes and customers that are still asking for proof of cybersecurity.
July 23, 2026: FAR CUI rule comment period closes
The 30-day comment period on the re-proposed FAR CUI rule closed on July 23, 2026 with 96 comments received. The FAR Council has said it intends to finalize the Revolutionary FAR Overhaul rules, including the FAR CUI Rule, before the end of 2026.
If finalized, the rule applies as soon as the new Part 40 clauses appear in contracts. There is no CMMC-style phase-in period, which is the detail most likely to be missed. Contractors with both defense and civilian work should not read the Phase 2 pause as cover for a separate rule that reaches beyond DoD contracts.
Recommended reading
The FAR CUI Rule: What the June 2026 Proposed Rule Means for Federal Contractors
Read MoreJuly 22, 2026: House passes FY2027 NDAA with CMMC small business language
The House passed H.R. 8800, its FY2027 National Defense Authorization Act, on July 22. The bill includes a provision directing a Pentagon briefing on CMMC's impact on small businesses.
The Senate companion, S. 4784, remains stalled after a July 14 procedural vote failed 50 to 46. That bill's Section 1626 would create a CMMC Level 2 assessment grant program for small businesses and new entrants, capped at $100,000 per award and $50 million total, to be established by July 1, 2027 if enacted.
Conference is expected after Congress returns in September. None of this is law yet, and none of it changes DFARS 7012 or current SPRS obligations.
Source: Senate Armed Services Committee FY2027 NDAA executive summary
Recommended reading
CMMC for Small Business: Requirements, Costs, and How to Reduce Them
Read MoreJuly 16, 2026: Elbit tells suppliers to keep going during the pause
Most primes did not send new supplier notices in the week after the announcement. Elbit Systems of America did, urging suppliers to stay focused on meeting existing cybersecurity requirements and maturing their programs while the transition to Phase 2 is on hold. Elbit's framing is that suppliers who keep maturing their programs will be in a stronger position once a revised assessment timeline is announced, which signals an expectation that the phased rollout returns in some form, even if it differs from what the 32 CFR and 48 CFR rules codified.
The letter also indicates that existing third-party assessment requirements may still apply, directing suppliers to confirm the applicable requirement with their Elbit America buyer before scheduling or cancelling a C3PAO assessment.
Elbit closes by calling the pause "an opportunity to strengthen your program" rather than a reason to delay it.

RTX makes a similar point on its supplier cybersecurity page, telling suppliers to keep meeting every applicable contractual cybersecurity requirement, including NIST SP 800-171 Rev 2 and DFARS 252.204-7012, until they are formally directed otherwise through an authorized contract amendment or modification.
Recommended reading
Elbit America Tells Suppliers to Stay the Course: Why the CMMC Pause Doesn't Change Prime Flowdown Requirements
Read MoreJuly 15, 2026: Cyber AB confirms the assessment ecosystem stays open
The Cyber AB clarified that this was only "another momentary pause" to the rollout of the CMMC program, specifically to Phase 2. C3PAO assessments, training, and exams remain available to organizations that want them.
For contractors mid-way through readiness work, this is the practical takeaway: nothing stops you from completing a certification assessment, and organizations with prime flowdown requirements or near-term contract exposure have reason to.
Source: Cyber AB statement on the DoW’s suspension of CMMC Phase 2, July 15, 2026
July 13, 2026: DoW puts CMMC Phase 2 on hold and the program under review
DoW CIO Kirsten Davies paused the transition to CMMC Phase 2, which had been scheduled to take effect on November 10, 2026, and put later milestones on hold as well. The Department cited prohibitive cost and limited assessor capacity, pointing to Small Business Administration figures that put third-party certification cost near $593,800 against about $388,600 for a self-assessment, with more than 120,000 DIB small businesses affected and roughly 100 approved assessors.
Davies’ policy memo and USD(A&S) Michael Duffey's memo under public case 26-P-1023 implement the pause, directing contracting officers to allow only Level 1 (Self) or Level 2 (Self), grant no waivers, and strip C3PAO and DIBCAC requirements from active solicitations and from existing contracts at the next option exercise or administrative modification.
The Department was explicit that this does not eliminate the duty to protect federal data. During the review it continues to enforce NIST SP 800-171 Rev 2 through CMMC Level 1 and Level 2 self-assessments and select government-led assessments, and DFARS 252.204-7012 remains in every covered contract.

The Department also issued FAQ Revision 2.4 the same day, with minor updates to A-Q1 and D-Q1 to reflect the pause.
Source: DoW release on July 13, 2026
Recommended reading
CMMC Phase 2 on Hold: What the DoW and Primes Still Require
Read MoreJuly 4, 2026: Rev 3 transition rule appears on the Unified Agenda, still unpublished
The DoD's 2026 Unified Agenda, quietly released over the Fourth of July weekend, listed RIN 0790-AM01 as an interim final rule that would amend 32 CFR Part 170 (the CMMC program rule) to transition the requirement from the underlying requirement to comply with NIST SP 800-171 Revision 2 to Revision 3 and incorporate organization-defined parameters. The agenda used a placeholder date (07/00/2026), targeting sometime that same month (July 2026) as the publication date.
To date, that interim final rule has not appeared in the Federal Register, 32 CFR 170 has not been amended, and no DFARS class deviation has been issued. The Department's own latest FAQ states that it will incorporate Revision 3 through future rulemaking and that the existing class deviation holds Revision 2 in place until it does.
An agenda listing is not a requirement. Keep Rev 2 implementation current and watch the Federal Register rather than the agenda.
Recommended reading
The CMMC 2.0 Rulemaking Process + 32 CFR & 48 CFR Status
Read MoreJuly 2, 2026: Lockheed Martin makes Level 2 the shortcut past supplier risk review
Lockheed Martin reinstated its Cybersecurity Compliance and Risk Assessment (CCRA) as the primary cybersecurity form for all suppliers, completed in Exostar. Every active supplier must submit CMMC and cyber risk status. The interim Cybersecurity Compliance Attestation was renamed CCRA-Compliance on June 30, 2026, and existing responses carried over.
The mechanism is what makes this notable. Suppliers who attest to a CMMC Level 2 (Self or C3PAO) assessment or higher in SPRS skip the risk survey entirely and default to a Green rating. Suppliers who indicate DFARS 252.204-7012 applies, or that they handle sensitive information, without Level 2 get assigned the risk form.
Level 2 is not a gate here. It is the way out of additional scrutiny, which is a different lever than the certification deadline L3Harris set in April, and one more primes are likely to copy.
Source: Lockheed Martin, Cybersecurity Compliance and Risk Assessment, July 2, 2026
Recommended reading

CMMC Subcontractor Oversight: What Primes Are Requiring and How to Stay Contract-Eligible
Read MoreJune 30, 2026: Cyber AB town hall questions the November 10 framing
The Cyber AB's June 30 town hall addressed how the DIB was interpreting the November 10, 2026 Phase 2 date. The core clarification: the November 10 dates in the phased rollout marked when requirements could start appearing in new solicitations, not a cutoff by which every contractor had to be certified. CMMC is not retroactive, so existing contracts were not modified mid-performance.
Our writeup of that session argued the DIB should stop planning around November 10 as a deadline. The Department paused Phase 2 thirteen days later.

Source: Cyber AB Town Hall, June 2026
June 23, 2026: FAR CUI rule re-proposed under the Revolutionary FAR Overhaul
The FAR Council re-proposed the FAR CUI rule on June 23, 2026 as part of the Revolutionary FAR Overhaul (FAR Case 2026-001, 91 FR 37550). First proposed in January 2025, the rule would extend CUI safeguarding and incident reporting requirements to nearly every federal contractor and subcontractor, not just defense ones.
The revised version consolidates the requirements into an expanded FAR Part 40 and adds provision FAR 52.240-6 and clause FAR 52.240-7. Four changes matter most for defense contractors:
- The cybersecurity baseline moves from NIST SP 800-171 Revision 2 to Revision 3, with the DoW-defined organization-defined parameters applied. DFARS 252.204-7012 and CMMC still reference Revision 2.
- Incident reporting moves from 8 hours to 72 hours, aligning with DFARS 7012.
- Cloud services handling CUI must meet requirements equivalent to the FedRAMP Moderate baseline rather than holding a full authorization.
- Verification is by self-attestation validated through normal contract administration, with no third-party or government-led assessment layer.

Most of these changes ease specific burdens while one raises the bar. Contractors serving both defense and civilian customers may need to satisfy Revision 2 and Revision 3 at the same time until the frameworks align.
Recommended reading
NIST 800-171 Rev 2 vs Rev 3: What Changed and What It Means for CMMC
Read MoreJune 18, 2026: LOGZONE settles False Claims Act cybersecurity allegations
LOGZONE Inc. of Huntsville, Alabama agreed to pay $507,144 to resolve allegations that it knowingly submitted false claims on two Department of the Navy contracts while failing to comply with the contracts' cybersecurity requirements. From May 2021 to March 2025, LOGZONE allegedly failed to implement NIST SP 800-171 controls that, if left unimplemented, could lead to significant exploitation of the system or exfiltration of sensitive defense information.
The Defense Contract Management Agency's DIBCAC assessed LOGZONE's implementation and scored it at negative 170, near the bottom of the possible range of negative 203 to 110. DOJ's release names no relator, and the resolution came out of a coordinated effort between the Civil Division's Fraud Section, the U.S. Attorney's Office for the Northern District of Alabama, the Navy, NCIS, Army CID, and DIBCAC.
With self-assessment now the primary CMMC verification path, SPRS accuracy and the annual affirmation carry more weight, not less.
Source: DOJ press release, June 18, 2026
Recommended reading
SPRS Scoring: How to Get a Current CMMC Status and Stay Eligible for Defense Contracts
Read MoreMay 5, 2026: DoD FAQ Revision 2.3 adds a scoping section
The Department released Revision 2.3 of the CMMC FAQs (the document's revision history is dated April 29, reflecting when it was finalized rather than posted), the third update in under six months and the fifth since the program's 2024 rollout.
It added a standalone Section F devoted to scoping, moved four existing scoping FAQs into it from Sections C and E, and added three new questions:
- whether a joint venture needs its own CMMC Status
- what qualifies as a significant change requiring reassessment
- how to handle system changes while maintaining compliance
The FAQs have become the Department's primary vehicle for guidance between formal rulemaking. That scoping needed its own section this late in the rollout says the same misunderstandings keep surfacing during readiness reviews and assessments, where they cost organizations time, money, and sometimes the assessment.
Source: CMMC FAQs, Office of the DoW CIO (see Document Revision History since v2.4 is only unbroken link currently)
Recommended reading
New CMMC FAQ Revision from DoD Shows Scoping Is Still Misunderstood
Read MoreApril 6, 2026: L3Harris Missile Solutions sets a July 30 certification deadline for suppliers
L3Harris Missile Solutions notified subcontractors that all suppliers on DoD programs who receive CUI at any tier must be certified where the DoD prime contract requires it, including small businesses and foreign suppliers. The notice stated that certification may be needed to submit a proposal and prior to contract award, and that suppliers who do not qualify for Level 2 certification will be precluded from the program. It asked applicable suppliers to submit proof of certification by July 30, 2026.
This made L3Harris Missile Solutions the first major prime business unit to attach a specific date to supplier status rather than a general requirement.
Since nothing in the July 13 memo directs a prime to drop a requirement it set for its own risk reasons, existing deadlines like this one may still be in place. Monitor communications from your primes, and reach out for clarification if you have an existing contract or an open bid.
Note: L3Harris did not publish the notice publicly. The details above come from a copy of the memo published online and included below.

Recommended reading
Why Prime Contractors Are Enforcing CMMC Level 2 Ahead of DoD
Read MoreMarch 30, 2026: Cyber AB town hall shows requirements reaching real solicitations
The March 30 town hall moved past timelines into execution. CMMC requirements were appearing in active solicitations across NAVSEA, the Air Force, USACE, and NAVAIR, spanning Level 1 and Level 2 and mixing self-assessment and C3PAO pathways depending on the program. Different parts of the Department were adopting enforcement at different speeds.
Level 2 certifications reached 1,074, passing 1,000 for the first time. Authorized C3PAOs reached 103, with steady growth in Certified CMMC Professionals and Lead Certified CMMC Assessors. A GAO report discussed at the session focused on execution risk rather than program intent, flagging the structural dependency on private-sector assessors to meet demand. The CAICO transition to ISACA completed in December 2025.
Set against a DIB of 200,000 to 300,000 organizations, 1,074 certifications is the number that explains the assessor-capacity concern the Department cited three months later when it paused Phase 2.
February 1, 2026: DFARS cybersecurity clauses restructured under the FAR Overhaul
Regulatory changes took effect on February 1, 2026 as part of the Revolutionary FAR Overhaul, implemented through DoW Class Deviation 2026-O0025, which consolidated cybersecurity and supply chain requirements into a new DFARS Part 240.
Three changes affect CMMC:
- DFARS 252.204-7019 was eliminated. The standalone requirement to perform a Basic NIST SP 800-171 self-assessment no longer exists as a separate provision, because it became redundant of DFARS 252.204-7021, the CMMC clause. Assessment obligations are now fulfilled through CMMC.
- DFARS 252.204-7020 was renumbered to DFARS 252.240-7997 and revised to remove all references to Basic assessments. The clause now defines only Medium and High assessments, both government-performed, and both still in force despite the Phase 2 pause.
- FAR 52.204-21 was renumbered to FAR 52.240-93 under the new FAR Part 40. The 15 basic safeguarding requirements are unchanged.
DFARS 252.204-7012 and 252.204-7021 are unchanged. This is a renumbering and consolidation, not a change in what contractors must do, but it matters for anyone citing clause numbers in an SSP, a contract review, or a flowdown notice. Solicitations issued after February 1, 2026 use the new numbering, while older contracts still reference the legacy numbers, so expect to see both during the transition.
Source: DoW Class Deviation 2026-O0025
Recommended reading
A Guide to the DFARS Clauses Behind CMMC
Read MoreJanuary 16, 2026: DOJ reports record False Claims Act recoveries for FY2025
The Justice Department announced that False Claims Act settlements and judgments exceeded $6.8 billion in the fiscal year ending September 30, 2025, the highest single-year total in the statute's history. Whistleblowers filed 1,297 qui tam suits, also a record, and the government opened 401 new investigations. Health care accounted for more than $5.7 billion of the total.
Defense contractors should read past the headline number. The record qui tam volume is the part that matters for the DIB, because it signals a pipeline of cases that will surface over the next several years. The pattern in DIB cyber cases is consistent: exposure begins with a score or an affirmation that does not match the environment, and the whistleblower is usually an insider who knew.
That risk did not change when the assessment schedule did. If anything, a verification model resting on self-attestation puts more weight on the accuracy of what you submit.
Recommended reading
What Is the False Claims Act? The Cybersecurity Misrepresentation Cases DIB Contractors Should Know
Read MoreWhat contractors should do now
The work that determines whether you can keep doing defense business is the same work it was on July 12.
- Scope where CUI actually lives and document that boundary in your SSP.
- Keep NIST 800-171 Rev 2 implemented in the live environment, not just on paper.
- Maintain an accurate SPRS score and an annual affirmation a senior official can stand behind.
- Confirm DFARS 7012 incident reporting through DIBNet within 72 hours still works in practice.
- Ask your prime, in writing, whether any flowdown they set for their own risk reasons still applies. The Department paused its own Phase 2 designations. It did not order primes to drop supplier requirements they imposed independently.
- Watch three calendars: the Task Force report, Federal Register publication of RIN 0790-AM01, and NDAA conference when Congress returns.
Not sure where you stand against the 110 requirements? Our CMMC Level 2 compliance checklist walks through what you need in place now, pause or no pause.
2026 CMMC news at a glance
| Date | Event | Status |
|---|---|---|
| Jan 16, 2026 | DOJ reports record FY2025 FCA recoveries | Announced |
| Feb 1, 2026 | DFARS 7019 eliminated, 7020 renumbered to 7997, FAR 52.204-21 renumbered to 52.240-93 | In effect |
| Mar 30, 2026 | Cyber AB town hall: 1,074 Level 2 certifications, 103 C3PAOs | Recapped |
| Apr 6, 2026 | L3Harris Missile Solutions supplier notice, July 30 deadline | Deadline passed, status unconfirmed |
| May 5, 2026 | DoD CMMC FAQ Rev 2.3 adds Section F on scoping | Current guidance |
| Jun 18, 2026 | LOGZONE FCA settlement | Still the latest DOJ cyber-FCA action |
| Jun 23, 2026 | FAR CUI rule re-proposed | Comments closed Jul 23 |
| Jun 30, 2026 | Cyber AB town hall on the November 10 framing | Recapped |
| Jul 2, 2026 | Lockheed Martin reinstates CCRA in Exostar | In effect |
| Jul 13, 2026 | Phase 2 put on hold, Reform Task Force stood up; FAQ Rev 2.4 issued | In effect |
| Jul 13–14, 2026 | Reform RFI posted | Closed Aug 14, noon ET |
| Jul 15, 2026 | Cyber AB: only Phase 2 paused, ecosystem operational | Standing statement |
| Jul 16, 2026 | Elbit Systems of America open letter to suppliers | Confirmed |
| Jul 22, 2026 | House passes FY2027 NDAA (H.R. 8800) | Awaiting Senate conference |
| Jul 23, 2026 | FAR CUI comment period closed, 96 comments | Final rule pending |
| Jul 28, 2026 | Cyber AB town hall | Recaps published, no new official statement |
| Aug 4 and Aug 7, 2026 | IEH incident discovered, 8-K filed | Confirmed, company-disclosed |
| Aug 14, 2026 | Reform RFI comments due | Closed on schedule |
| Aug 26, 2026 | Davies DIBX fireside chat on OT and CMMC reform | Recapped, no new memo |
| Mid-Sep to early Oct 2026 | Task Force report due to DoW CIO | Watch |
| Sep 2026 | NDAA conference expected | Watch |
| TBD | RIN 0790-AM01 (Rev 3 IFR) in the Federal Register | Not yet published |
| Before end of 2026 | FAR CUI final rule targeted | Watch |
Secureframe Defense was built for the work required in defense contracts today: a CMMC-ready GCC High or Google Workspace environment, guided NIST 800-171 Rev 2 implementation, and continuous monitoring so the score in SPRS matches the secure environment you actually run.
Talk to a CMMC expert. No sales pitch, just answers about where your program stands. Request a demo.