CLASSIFICATION: UNCLASSIFIED

Intelligence & Briefings

Authoritative technical guidance on CMMC 2.0 compliance, NIST SP 800-171/172 implementation, Zero Trust architecture, and cybersecurity best practices for defense contractors operating in high-consequence environments.

Following the CMMC Reform

The Department suspended CMMC Phase II requirements on July 13, 2026 while a Reform Task Force reviews the program. We maintain a plain-language briefing on what changed, what remains binding, and what contractors should do now — updated as the Task Force acts.