This page is the complete dated record of major CMMC news in 2026, starting with the latest developments first and updated weekly. It covers program and policy changes, Cyber AB ecosystem updates, False Claims Act enforcement, and congressional activity affecting the Defense Industrial Base (DIB), each verified against at least one primary source.
A note on naming: The Department is now commonly referred to by its official secondary title, the Department of War (DoW). Because existing CMMC rules, contract clauses, and source documents still read "Department of Defense (DoD)," we continue to use this statutory name or "the Department” as well as the secondary title.
CMMC News 2026: Final rule, enforcement, and DoW updates
August 14, 2026: CMMC reform RFI comment window closes
The Department of War's request for information, "Reforming CMMC and Reducing Compliance Burden for the Defense Industrial Base," closed at 12:00 p.m. Eastern on August 14, 2026. The notice asked seven questions, five of them about cost and administrative burden, and directed comments by email.
Those responses will be used by the CMMC Reform Task Force to make reform recommendations that “definitively reduce compliance and cost burdens on small, medium, and non-traditional companies.” The Task Force was given 60 days from July 13 to review the program and roughly two more weeks to write its report. That puts delivery to the DoW CIO and USD(A&S) sometime between mid-September and early October 2026.
Closing the comment window is a process milestone, not a policy change. Phase 1 self-assessments, DFARS 252.204-7012, NIST SP 800-171 Rev 2, and SPRS remain in force while the Department writes its recommendations.
August 7, 2026: Defense connector maker discloses phishing breach
IEH Corporation, a publicly traded manufacturer of hyperboloid connectors used on defense and aerospace platforms including THAAD, PATRIOT, and AMRAAM, disclosed in an SEC Form 8-K filed August 7, 2026 that it discovered a phishing-driven compromise of an employee's Microsoft 365 mailbox on August 4. The company said the attacker could access emails, attachments, purchase orders, engineering documentation, and potentially export-controlled technical information, and that it found no evidence data was exfiltrated.
The incident is a timely reminder that the DoW’s Phase 2 pause did not change contractors' underlying duties. DFARS 252.204-7012 still requires safeguarding of covered defense information and 72-hour cyber incident reporting, and NIST SP 800-171 Rev 2, SPRS scoring, and annual affirmations remain fully in effect.
Contractors handling covered defense information should confirm their incident response and DIBNet reporting processes are current.
July 28, 2026: Cyber AB holds its first town hall since the pause
The Cyber AB's first public event after the pause emphasized that the CMMC program itself has not been paused. CEO Matt Travis's standing position has not changed from the CyberAB’s initial response: Level 2 certification remains available, and provides the highest level of assurance to primes and customers that are still asking for proof of cybersecurity.
July 23, 2026: FAR CUI rule comment period closes
The 30-day comment period on the re-proposed FAR CUI rule closed on July 23, 2026 with 96 comments received. The FAR Council has said it intends to finalize the Revolutionary FAR Overhaul rules, including the FAR CUI Rule, before the end of 2026.
If finalized, the rule applies as soon as the new Part 40 clauses appear in contracts. There is no CMMC-style phase-in period, which is the detail most likely to be missed. Contractors with both defense and civilian work should not read the Phase 2 pause as cover for a separate rule that reaches beyond DoD contracts.
July 22, 2026: House passes FY2027 NDAA with CMMC small business language
The House passed H.R. 8800, its FY2027 National Defense Authorization Act, on July 22. The bill includes a provision directing a Pentagon briefing on CMMC's impact on small businesses.
The Senate companion, S. 4784, remains stalled after a July 14 procedural vote failed 50 to 46. That bill's Section 1626 would create a CMMC Level 2 assessment grant program for small businesses and new entrants, capped at $100,000 per award and $50 million total, to be established by July 1, 2027 if enacted.
Conference is expected after Congress returns in September. None of this is law yet, and none of it changes DFARS 7012 or current SPRS obligations.
Source: Senate Armed Services Committee FY2027 NDAA executive summary
July 16, 2026: Elbit tells suppliers to keep going during the pause
Most primes did not send new supplier notices in the week after the announcement. Elbit Systems of America did, urging suppliers to stay focused on meeting existing cybersecurity requirements and maturing their programs while the transition to Phase 2 is on hold. Elbit's framing is that suppliers who keep maturing their programs will be in a stronger position once a revised assessment timeline is announced, which signals an expectation that the phased rollout returns in some form, even if it differs from what the 32 CFR and 48 CFR rules codified.
The letter also indicates that existing third-party assessment requirements may still apply, directing suppliers to confirm the applicable requirement with their Elbit America buyer before scheduling or cancelling a C3PAO assessment.
Elbit closes by calling the pause "an opportunity to strengthen your program" rather than a reason to delay it.
RTX makes a similar point on its supplier cybersecurity page, telling suppliers to keep meeting every applicable contractual cybersecurity requirement, including NIST SP 800-171 Rev 2 and DFARS 252.204-7012, until they are formally directed otherwise through an authorized contract amendment or modification.
July 15, 2026: Cyber AB confirms the assessment ecosystem stays open
The Cyber AB clarified that this was only "another momentary pause" to the rollout of the CMMC program, specifically to Phase 2. C3PAO assessments, training, and exams remain available to organizations that want them.
For contractors mid-way through readiness work, this is the practical takeaway: nothing stops you from completing a certification assessment, and organizations with prime flowdown requirements or near-term contract exposure have reason to.
Source: Cyber AB statement on the DoW’s suspension of CMMC Phase 2, July 15, 2026
July 13, 2026: DoW puts CMMC Phase 2 on hold and the program under review
DoW CIO Kirsten Davies paused the transition to CMMC Phase 2, which had been scheduled to take effect on November 10, 2026, and put later milestones on hold as well. The Department cited prohibitive cost and limited assessor capacity, pointing to Small Business Administration figures that put third-party certification cost near $593,800 against about $388,600 for a self-assessment, with more than 120,000 DIB small businesses affected and roughly 100 approved assessors.
Davies’ policy memo and USD(A&S) Michael Duffey's memo under public case 26-P-1023 implement the pause, directing contracting officers to allow only Level 1 (Self) or Level 2 (Self), grant no waivers, and strip C3PAO and DIBCAC requirements from active solicitations and from existing contracts at the next option exercise or administrative modification.
The Department was explicit that this does not eliminate the duty to protect federal data. During the review it continues to enforce NIST SP 800-171 Rev 2 through CMMC Level 1 and Level 2 self-assessments and select government-led assessments, and DFARS 252.204-7012 remains in every covered contract.
The Department also issued FAQ Revision 2.4 the same day, with minor updates to A-Q1 and D-Q1 to reflect the pause.
Source: DoW release on July 13, 2026
Recommended reading: CMMC Phase 2 on Hold: What the DoW and Primes Still Require
July 4, 2026: Rev 3 transition rule appears on the Unified Agenda, still unpublished
The DoD's 2026 Unified Agenda, quietly released over the Fourth of July weekend, listed RIN 0790-AM01 as an interim final rule that would amend 32 CFR Part 170 (the CMMC program rule) to transition the requirement from the underlying requirement to comply with NIST SP 800-171 Revision 2 to Revision 3 and incorporate organization-defined parameters. The agenda used a placeholder date (07/00/2026), targeting sometime that same month (July 2026) as the publication date.
To date, that interim final rule has not appeared in the Federal Register, 32 CFR 170 has not been amended, and no DFARS class deviation has been issued. The Department's own latest FAQ states that it will incorporate Revision 3 through future rulemaking and that the existing class deviation holds Revision 2 in place until it does.
An agenda listing is not a requirement. Keep Rev 2 implementation current and watch the Federal Register rather than the agenda.
Source: Reginfo.gov amendment RIN 0790-AM01
Recommended reading: The CMMC 2.0 Rulemaking Process + 32 CFR & 48 CFR Status
July 2, 2026: Lockheed Martin makes Level 2 the shortcut past supplier risk review
Lockheed Martin reinstated its Cybersecurity Compliance and Risk Assessment (CCRA) as the primary cybersecurity form for all suppliers, completed in Exostar. Every active supplier must submit CMMC and cyber risk status. The interim Cybersecurity Compliance Attestation was renamed CCRA-Compliance on June 30, 2026, and existing responses carried over.
The mechanism is what makes this notable. Suppliers who attest to a CMMC Level 2 (Self or C3PAO) assessment or higher in SPRS skip the risk survey entirely and default to a Green rating. Suppliers who indicate DFARS 252.204-7012 applies, or that they handle sensitive information, without Level 2 get assigned the risk form.
Level 2 is not a gate here. It is the way out of additional scrutiny, which is a different lever than the certification deadline L3Harris set in April, and one more primes are likely to copy.
Source: Lockheed Martin, Cybersecurity Compliance and Risk Assessment, July 2, 2026
June 30, 2026: Cyber AB town hall questions the November 10 framing
The Cyber AB's June 30 town hall addressed how the DIB was interpreting the November 10, 2026 Phase 2 date. The core clarification: the November 10 dates in the phased rollout marked when requirements could start appearing in new solicitations, not a cutoff by which every contractor had to be certified. CMMC is not retroactive, so existing contracts were not modified mid-performance.
Our writeup of that session argued the DIB should stop planning around November 10 as a deadline. The Department paused Phase 2 thirteen days later.
Source: Cyber AB Town Hall, June 2026
June 23, 2026: FAR CUI rule re-proposed under the Revolutionary FAR Overhaul
The FAR Council re-proposed the FAR CUI rule on June 23, 2026 as part of the Revolutionary FAR Overhaul (FAR Case 2026-001, 91 FR 37550). First proposed in January 2025, the rule would extend CUI safeguarding and incident reporting requirements to nearly every federal contractor and subcontractor, not just defense ones.
The revised version consolidates the requirements into an expanded FAR Part 40 and adds provision FAR 52.240-6 and clause FAR 52.240-7. Four changes matter most for defense contractors:
- The cybersecurity baseline moves from NIST SP 800-171 Revision 2 to Revision 3, with the DoW-defined organization-defined parameters applied. DFARS 252.204-7012 and CMMC still reference Revision 2.
- Incident reporting moves from 8 hours to 72 hours, aligning with DFARS 7012.
- Cloud services handling CUI must meet requirements equivalent to the FedRAMP Moderate baseline rather than holding a full authorization.
- Verification is by self-attestation validated through normal contract administration, with no third-party or government-led assessment layer.
Most of these changes ease specific burdens while one raises the bar. Contractors serving both defense and civilian customers may need to satisfy Revision 2 and Revision 3 at the same time until the frameworks align.
Source: Federal Register FAR Case 2026-001
Recommended reading: NIST 800-171 Rev 2 vs Rev 3: What Changed and What It Means for CMMC
June 18, 2026: LOGZONE settles False Claims Act cybersecurity allegations
LOGZONE Inc. of Huntsville, Alabama agreed to pay $507,144 to resolve allegations that it knowingly submitted false claims on two Department of the Navy contracts while failing to comply with the contracts' cybersecurity requirements. From May 2021 to March 2025, LOGZONE allegedly failed to implement NIST SP 800-171 controls that, if left unimplemented, could lead to significant exploitation of the system or exfiltration of sensitive defense information.
The Defense Contract Management Agency's DIBCAC assessed LOGZONE's implementation and scored it at negative 170, near the bottom of the possible range of negative 203 to 110. DOJ's release names no relator, and the resolution came out of a coordinated effort between the Civil Division's Fraud Section, the U.S. Attorney's Office for the Northern District of Alabama, the Navy, NCIS, Army CID, and DIBCAC.
With self-assessment now the primary CMMC verification path, SPRS accuracy and the annual affirmation carry more weight, not less.
Source: DOJ press release, June 18, 2026
Recommended reading: What Is the False Claims Act?
May 5, 2026: DoD FAQ Revision 2.3 adds a scoping section
The Department released Revision 2.3 of the CMMC FAQs (the document's revision history is dated April 29, reflecting when it was finalized rather than posted), the third update in under six months and the fifth since the program's 2024 rollout.
It added a standalone Section F devoted to scoping, moved four existing scoping FAQs into it from Sections C and E, and added three new questions:
- whether a joint venture needs its own CMMC Status
- what qualifies as a significant change requiring reassessment
- how to handle system changes while maintaining compliance
The FAQs have become the Department's primary vehicle for guidance between formal rulemaking. That scoping needed its own section this late in the rollout says the same misunderstandings keep surfacing during readiness reviews and assessments, where they cost organizations time, money, and sometimes the assessment.
Source: CMMC FAQs, Office of the DoW CIO (see Document Revision History since v2.4 is only unbroken link currently)
Recommended reading: New CMMC FAQ Revision from DoD Shows Scoping Is Still Misunderstood
April 6, 2026: L3Harris Missile Solutions sets a July 30 certification deadline for suppliers
L3Harris Missile Solutions notified subcontractors that all suppliers on DoD programs who receive CUI at any tier must be certified where the DoD prime contract requires it, including small businesses and foreign suppliers. The notice stated that certification may be needed to submit a proposal and prior to contract award, and that suppliers who do not qualify for Level 2 certification will be precluded from the program. It asked applicable suppliers to submit proof of certification by July 30, 2026.
This made L3Harris Missile Solutions the first major prime business unit to attach a specific date to supplier status rather than a general requirement.
Since nothing in the July 13 memo directs a prime to drop a requirement it set for its own risk reasons, existing deadlines like this one may still be in place. Monitor communications from your primes, and reach out for clarification if you have an existing contract or an open bid.
Note: L3Harris did not publish the notice publicly. The details above come from a copy of the memo published online.
Recommended reading: Why Prime Contractors Are Enforcing CMMC Level 2 Ahead of DoD
March 30, 2026: Cyber AB town hall shows requirements reaching real solicitations
The March 30 town hall moved past timelines into execution. CMMC requirements were appearing in active solicitations across NAVSEA, the Air Force, USACE, and NAVAIR, spanning Level 1 and Level 2 and mixing self-assessment and C3PAO pathways depending on the program. Different parts of the Department were adopting enforcement at different speeds.
Level 2 certifications reached 1,074, passing 1,000 for the first time. Authorized C3PAOs reached 103, with steady growth in Certified CMMC Professionals and Lead Certified CMMC Assessors. A GAO report discussed at the session focused on execution risk rather than program intent, flagging the structural dependency on private-sector assessors to meet demand. The CAICO transition to ISACA completed in December 2025.
Set against a DIB of 200,000 to 300,000 organizations, 1,074 certifications is the number that explains the assessor-capacity concern the Department cited three months later when it paused Phase 2.
February 1, 2026: DFARS cybersecurity clauses restructured under the FAR Overhaul
Regulatory changes took effect on February 1, 2026 as part of the Revolutionary FAR Overhaul, implemented through DoW Class Deviation 2026-O0025, which consolidated cybersecurity and supply chain requirements into a new DFARS Part 240.
Three changes affect CMMC:
- DFARS 252.204-7019 was eliminated. The standalone requirement to perform a Basic NIST SP 800-171 self-assessment no longer exists as a separate provision, because it became redundant of DFARS 252.204-7021, the CMMC clause. Assessment obligations are now fulfilled through CMMC.
- DFARS 252.204-7020 was renumbered to DFARS 252.240-7997 and revised to remove all references to Basic assessments. The clause now defines only Medium and High assessments, both government-performed, and both still in force despite the Phase 2 pause.
- FAR 52.204-21 was renumbered to FAR 52.240-93 under the new FAR Part 40. The 15 basic safeguarding requirements are unchanged.
DFARS 252.204-7012 and 252.204-7021 are unchanged. This is a renumbering and consolidation, not a change in what contractors must do, but it matters for anyone citing clause numbers in an SSP, a contract review, or a flowdown notice. Solicitations issued after February 1, 2026 use the new numbering, while older contracts still reference the legacy numbers, so expect to see both during the transition.
Source: DoW Class Deviation 2026-O0025
Recommended reading: A Guide to the DFARS Clauses Behind CMMC
January 16, 2026: DOJ reports record False Claims Act recoveries for FY2025
The Justice Department announced that False Claims Act settlements and judgments exceeded $6.8 billion in the fiscal year ending September 30, 2025, the highest single-year total in the statute's history. Whistleblowers filed 1,297 qui tam suits, also a record, and the government opened 401 new investigations. Health care accounted for more than $5.7 billion of the total.
Defense contractors should read past the headline number. The record qui tam volume is the part that matters for the DIB, because it signals a pipeline of cases that will surface over the next several years. The pattern in DIB cyber cases is consistent: exposure begins with a score or an affirmation that does not match the environment, and the whistleblower is usually an insider who knew.
That risk did not change when the assessment schedule did. If anything, a verification model resting on self-attestation puts more weight on the accuracy of what you submit.
Source: DOJ press release, January 16, 2026
Recommended reading: What Is the False Claims Act?
What contractors should do now
The work that determines whether you can keep doing defense business is the same work it was on July 12.
- Scope where CUI actually lives and document that boundary in your SSP.
- Keep NIST 800-171 Rev 2 implemented in the live environment, not just on paper.
- Maintain an accurate SPRS score and an annual affirmation a senior official can stand behind.
- Confirm DFARS 7012 incident reporting through DIBNet within 72 hours still works in practice.
- Ask your prime, in writing, whether any flowdown they set for their own risk reasons still applies. The Department paused its own Phase 2 designations. It did not order primes to drop supplier requirements they imposed independently.
- Watch three calendars: the Task Force report, Federal Register publication of RIN 0790-AM01, and NDAA conference when Congress returns.
Not sure where you stand against the 110 requirements? Our CMMC Level 2 compliance checklist walks through what you need in place now, pause or no pause.
2026 CMMC news at a glance
| Date | Event | Status |
|---|---|---|
| Jan 16, 2026 | DOJ reports record FY2025 FCA recoveries | Announced |
| Feb 1, 2026 | DFARS 7019 eliminated, 7020 renumbered to 7997, FAR 52.204-21 renumbered to 52.240-93 | In effect |
| Mar 30, 2026 | Cyber AB town hall: 1,074 Level 2 certifications, 103 C3PAOs | Recapped |
| Apr 6, 2026 | L3Harris Missile Solutions supplier notice, July 30 deadline | Deadline passed, status unconfirmed |
| May 5, 2026 | DoD CMMC FAQ Rev 2.3 adds Section F on scoping | Current guidance |
| Jun 18, 2026 | LOGZONE FCA settlement | Still the latest DOJ cyber-FCA action |
| Jun 23, 2026 | FAR CUI rule re-proposed | Comments closed Jul 23 |
| Jun 30, 2026 | Cyber AB town hall on the November 10 framing | Recapped |
| Jul 2, 2026 | Lockheed Martin reinstates CCRA in Exostar | In effect |
| Jul 13, 2026 | Phase 2 put on hold, Reform Task Force stood up; FAQ Rev 2.4 issued | In effect |
| Jul 13–14, 2026 | Reform RFI posted | Closed Aug 14, noon ET |
| Jul 15, 2026 | Cyber AB: only Phase 2 paused, ecosystem operational | Standing statement |
| Jul 16, 2026 | Elbit Systems of America open letter to suppliers | Confirmed |
| Jul 22, 2026 | House passes FY2027 NDAA (H.R. 8800) | Awaiting Senate conference |
| Jul 23, 2026 | FAR CUI comment period closed, 96 comments | Final rule pending |
| Jul 28, 2026 | Cyber AB town hall | Recaps published, no new official statement |
| Aug 4 and Aug 7, 2026 | IEH incident discovered, 8-K filed | Confirmed, company-disclosed |
| Aug 14, 2026 | Reform RFI comments due | Closed on schedule |
| Mid-Sep to early Oct 2026 | Task Force report due to DoW CIO | Watch |
| Sep 2026 | NDAA conference expected | Watch |
| TBD | RIN 0790-AM01 (Rev 3 IFR) in the Federal Register | Not yet published |
| Before end of 2026 | FAR CUI final rule targeted | Watch |
We update this page when a primary source moves: a DoW or Cyber AB statement, a Federal Register or DOJ release, NDAA conference text, or a company filing that confirms a CUI or DFARS 7012 nexus.
Secureframe Defense was built for the work that remains: a CMMC-ready GCC High or Google Workspace environment, guided NIST 800-171 implementation, and continuous evidence so the score in SPRS matches the environment you actually run.
Talk to a CMMC expert. No sales pitch, just answers about where your program stands. Request a demo.