# CMMC News & Updates: Latest CMMC Changes for Defense Contractors

> The latest CMMC news, explained for defense contractors. Weekly updates on DoW announcements, rulemaking, enforcement actions, and what each change means for your cybersecurity program.

canonical: https://secureframe.com/hub/cmmc/news

## Where CMMC stands right now

CMMC third-party assessments are paused. The underlying cybersecurity requirements are not.

On July 13, 2026, the Department of War paused the transition to [CMMC Phase 2](https://secureframe.com/blog/cmmc-phase-2-preparation) and stood up a 60-day Reform Task Force to review the program. During this period, DoW Program Managers cannot write Level 2 ([C3PAO](https://secureframe.com/hub/cmmc/c3pao)) and Level 3 (DIBCAC) assessments into new solicitations as a condition of award, and existing requirements are being stripped at the next option exercise or modification. 

However, as stated in memo [26-P-1023](https://dodcio.defense.gov/Portals/0/Documents/Library/ImplementingSuspensionCMMC-PhaseII.pdf), the Department will continue to enforce baseline compliance with NIST SP 800-171 Rev 2 through CMMC Level 1 and CMMC Level 2 self-assessment and select government-led assessments.

Here is what still applies to defense contractors and subcontractors:

- [DFARS 252.204-7012](https://secureframe.com/blog/dfars-7012-vs-cmmc) safeguarding and 72-hour incident reporting requirements
- [NIST SP 800-171 Rev 2](https://secureframe.com/hub/cmmc/vs-nist-800-171), all 110 requirements and 320 assessment objectives, as required under DFARS 7012 since 2017
- [Phase 1 CMMC Level 1 (Self) and Level 2 (Self) requirements](https://secureframe.com/blog/cmmc-self-assessment) remain in force, as they have since November 10, 2025
- [Primes will still flow down CMMC requirements](https://secureframe.com/blog/prime-contractor-cmmc-compliance) and ask suppliers for assurance of NIST 800-171 Rev 2 compliance
- A current [SPRS score](https://secureframe.com/blog/cmmc-sprs) and an annual affirmation from a senior official, both of which carry [False Claims Act exposure](https://secureframe.com/blog/false-claims-act) if they do not match your environment

The work that determines whether you can keep doing defense business is the same work it was on July 12: [scope](https://secureframe.com/blog/cmmc-scope) where CUI actually lives, keep NIST 800-171 Rev 2 implemented in the live environment, maintain an SPRS score a senior official can stand behind, and be ready for verification whenever it returns.


Not sure where you stand against the 110 requirements? Our [CMMC Level 2 compliance checklist](https://secureframe.com/compliance-resources/cmmc-level-2-compliance-checklist) walks through what you need in place now, pause or no pause.


To help you stay current on your CMMC and other cybersecurity contractual obligations, we built the news tracker below. 

## Latest CMMC news and updates

**Last updated or checked:** September 4, 2026

Every week we monitor DoW announcements, federal rulemaking dockets, Cyber AB and assessor ecosystem updates, False Claims Act enforcement actions, and congressional activity affecting the Defense Industrial Base (DIB).

Each entry below is a short, dated summary of what changed, with links to primary sources and to the full write-up in our [2026 news log](https://secureframe.com/hub/cmmc/news-updates-2026). 

### September 1, 2026: Honeywell Aerospace settles $2M cybersecurity False Claims Act case

Honeywell Aerospace agreed to pay $2,042,518 to resolve False Claims Act allegations that a Honeywell business unit failed to implement NIST SP 800-171 controls on one network under a Department of Defense contract between April 2020 and December 2023. The case came from a whistleblower suit filed by a former employee, who receives $375,823. The alleged conduct took place before CMMC Phase 1 began, showing that the government has verification layers for existing contractual cybersecurity requirements like DFARS 252.204-7012 and these are still in place while CMMC Phase 2 is on hold. [Read the full entry on the Honeywell settlement](https://secureframe.com/hub/cmmc/news-updates-2026#2026-09-01-honeywell-fca).

### August 26, 2026: Davies provides update on the CMMC task force and emphasizes OT security at DIBX

At her DIBX 2026 fireside chat in Philadelphia, DoW CIO Kirsten Davies put operational technology and performance, "not paperwork," at the center of how she is thinking about CMMC reform. She said protecting federal data is a requirement that never went away, and said the Reform Task Force is working through about 1,100 RFI responses to gather insights into making cybersecurity a dynamic process where contractors can continue to reduce risk and improve their cyber posture while still doing business with the Department. [Read the full entry on the DIBX remarks.](https://secureframe.com/hub/cmmc/news-updates-2026#2026-08-26-davies-dibx-ot)

### August 19, 2026: Industry RFI responses flag unclear CUI marking

The CMMC Reform Task Force's RFI comment window closed August 14, and several industry groups flagged inconsistent, unclear, or improper CUI identification and marking as a top driver of CMMC cost and over-scoping. SBA Advocacy called CUI uncertainty the "most frequently cited concern" for small businesses. These are comments rather than decisions, but they signal likely focus areas for the Task Force, whose report to the DoW CIO is expected in late September or early October 2026. [Read the full entry on the RFI responses.](https://secureframe.com/hub/cmmc/news-updates-2026#2026-08-19-industry-rfi-responses-cui-marking)

### August 7, 2026: Defense connector maker discloses phishing breach

IEH Corporation, which manufactures hyperboloid connectors used on THAAD, PATRIOT, and AMRAAM platforms, disclosed in an SEC Form 8-K that an attacker compromised an employee's Microsoft 365 mailbox and could access engineering documentation and potentially export-controlled technical information. The company reported no evidence of exfiltration. The incident changes no CMMC policy, but it is a reminder that DFARS 7012 incident reporting obligations did not pause when assessments did. [Read the full entry on the IEH disclosure](https://secureframe.com/hub/cmmc/news-updates-2026#2026-08-07-ieh-breach).

### July 23, 2026: FAR CUI rule comment period closes

FAR Case 2017-016, the governmentwide [CUI](https://secureframe.com/blog/controlled-unclassified-information-cui) and NIST SP 800-171 Rev 3 proposal, closed comments. If finalized it would apply immediately, with no CMMC-style phased on-ramp. Contractors with both defense and civilian work should not read the Phase 2 pause as cover for this rule. [Read the full entry on the FAR CUI rule](https://secureframe.com/hub/cmmc/news-updates-2026#2026-07-23-far-cui-comments-close).

### July 22, 2026: House passes FY2027 NDAA with CMMC small business language

H.R. 8800 passed 216 to 212 and includes a provision directing a Pentagon briefing on CMMC's impact on small businesses. The Senate companion, S. 4784, stalled after a July 14 procedural vote and would create a CMMC Level 2 assessment grant program capped at $100,000 per award. Conference is expected after Congress returns in September. None of this is law yet. [Read the full entry on the FY2027 NDAA](https://secureframe.com/hub/cmmc/news-updates-2026#2026-07-22-house-ndaa).

### July 16, 2026: Elbit tells suppliers to keep going during the pause

Most primes did not send new supplier notices in the week after the announcement. Elbit Systems of America did, urging suppliers to keep meeting existing cybersecurity requirements and to confirm the applicable requirement with their Elbit America buyer before scheduling or cancelling a C3PAO assessment. RTX makes a similar point on its supplier cybersecurity page. The pause is a pause in the Department's own designations, not a release from a prime's flowdown. [Read the full entry on the prime notices](https://secureframe.com/hub/cmmc/news-updates-2026#2026-07-16-elbit-notice).

### July 15, 2026: Cyber AB confirms the assessment ecosystem stays open

The Cyber AB clarified that this was only "another momentary pause" to the rollout of the CMMC program, specifically to Phase 2. C3PAO [assessments](https://secureframe.com/hub/cmmc/assessments), training, and exams remain available to organizations that want them. [Read the full entry on the Cyber AB statement](https://secureframe.com/hub/cmmc/news-updates-2026#2026-07-15-cyber-ab-statement).

### July 13, 2026: DoW puts CMMC Phase 2 on hold and program under review

DoW CIO Kirsten Davies paused the transition to Phase 2, scheduled to take effect November 10, 2026, and put the program under a 60-day review as well. The Department cited [cost](https://secureframe.com/hub/cmmc/certification-cost) and assessor capacity, pointing to Small Business Administration figures of roughly $593,800 for third-party certification against about $388,600 for a self-assessment, with more than 120,000 DIB small businesses affected and roughly 100 approved assessors. Two memoranda under public case 26-P-1023 implement the pause. For the full breakdown of what changed and what primes still require, see [CMMC Phase 2 on Hold](https://secureframe.com/blog/cmmc-news-2026-phase-2-pause), or [read the full entry on the suspension](https://secureframe.com/hub/cmmc/news-updates-2026#2026-07-13-phase-2-paused).

### July 4, 2026: Rev 3 transition rule appears on the Unified Agenda, still unpublished

The Fall 2025 Unified Agenda listed RIN 0790-AM01 as an interim final rule that would amend 32 CFR Part 170 to move CMMC from NIST SP 800-171 Rev 2 to Rev 3. As of August 14, 2026 it has not appeared in the Federal Register, 32 CFR 170 has not been amended, and no DFARS class deviation has been issued. Rev 2 remains the enforced standard. For why an agenda listing is not a requirement, see [what it would take to change CMMC](https://secureframe.com/hub/cmmc/rulemaking-process), or [read the full entry on RIN 0790-AM01](https://secureframe.com/hub/cmmc/news-updates-2026#2026-07-rev-3-unified-agenda).

## What we are watching

- **The Reform Task Force report**, due to the DoW CIO and USD(A&S) between mid-September and early October 2026. This is the next real beat in the story.
- **RIN 0790-AM01** in the Federal Register. Until it publishes, Rev 2 is the standard.
- **NDAA conference**, expected after Congress returns in September.
- **Additional DIB incident disclosures.** We add these only when a company filing or government source confirms a covered defense information nexus.
