2026-09-30UPDATE
Upcoming: CMMC Reform Task Force recommendations finalized (~late Sep 2026, approximate)
CMMC Reform Task Force recommendations finalized (~late September: 60 days of feedback + 15 days for recommendations, per DoD). Expected to reset every buyer's compliance timeline. [Revised 2026-07-20 from ~Sep 11 (initial 60-day read) after FNN reported the 60+15-day structure; id was ev-2026-09-11-taskforce-report.]
Source 1Source 2Source 3
2026-08-14UPDATE
Upcoming: CMMC reform RFI responses due (Aug 14 2026)
CMMC reform RFI responses due — last day for DIB stakeholders (and vendors) to shape the reformed program.
Source 1Source 2
2026-07-28UPDATE
Upcoming: Cyber AB July Town Hall addresses the Phase 2 pause (Jul 28, 6pm EDT)
Cyber AB July Town Hall (6:00 pm EDT) — expected to address the Phase 2 pause, the Reform Task Force, and ecosystem impacts.
Source
2026-07-20UPDATE
C3PAO channel under revenue pressure from the pause — 'when the mandate pauses, so does their revenue'
Industry fallout from the Phase 2 pause (National Defense, Jul 20): Pete Sfoglia (Pistos): 'The C3PAOs built their business on a mandate, and when the mandate pauses, so does their revenue.' Redspin warns pausing active work risks losing ground on a 12-18-month readiness timeline. Compliance estimates run to $600K per company. Watch the assessor channel for consolidation, pivots, or exits. Counterpoint (Eric Crusius via FNN, Jul 21): C3PAO assessment capacity actually exceeded initial DoD estimates — the 'assessor shortage' rationale is contested; cost benchmarks ~$150K-$500K control implementation, ~$20K-$40K small-business assessments.
Source 1Source 2
2026-07-17UPDATE
DoD plans nationwide CMMC listening sessions; Reform Task Force held first meeting Jul 16
DoD plans nationwide CMMC listening sessions; Reform Task Force held its first meeting Jul 16. Review timeline firmed up: 60 days of feedback then 15 days for recommendations — finalized by late September. RFI issued via SAM.gov. Davies: 'we want to hear back from the defense industrial base... even from Cyber [AB], from the assessors themselves.' Officials named: Kirsten Davies (DoD CIO), Kelly Loeffler (SBA Administrator), Michael Duffey (USD A&S). (Published Jul 17; missed by the Jul 19 catch-up sweep, captured Jul 20.)
Source 1Source 2
2026-07-15UPDATE
Cyber AB: 'surprised and disappointed' but all CMMC ecosystem elements remain operational
Cyber AB response (CEO Matthew Travis): 'surprised and disappointed' but all CMMC ecosystem elements remain operational — C3PAO L2 certification assessments, training, exams, RP services continue. Town hall Jul 28. Voluntary certification market stays open during the pause.
Source
2026-07-13UPDATE
CMMC vendors reposition within hours of the suspension — 'DFARS obligations endure'
Within hours of the suspension, CMMC vendors repositioned in unison — PreVeil, Kiteworks ('a redistribution of risk, not relief'), Summit 7, and A-LIGN all published keep-going guidance. The competitive narrative is now 'DFARS obligations endure'; expect pipeline-freeze pressure on every CMMC-adjacent seller.
Source 1Source 2Source 3Source 4
2026-07-13UPDATE
SBA commends the CMMC Phase 2 suspension for small defense contractors
SBA publicly commends the Phase 2 suspension for small defense contractors — political backing suggests the pause is durable, not cosmetic. Administrator Kelly Loeffler: 'CMMC compliance was becoming an untenable barrier'; SBA estimates third-party assessments could cost up to $600K (Washington Technology, Jul 16).
Source 1Source 2
2026-07-13UPDATE
CMMC reform RFI opened; responses due Aug 14 2026
CMMC reform RFI opened alongside the Phase 2 suspension — stakeholder responses due Aug 14 2026. Direct channel to shape whatever replaces the phased rollout. RFI asks industry about: cost drivers, administrative burdens, security controls that provide meaningful cyber uplift, commercial cybersecurity tools and managed services, Phase 1 self-assessment challenges, and policy reforms implementable within 60 days.
Source 1Source 2
2026-07-13UPDATE
DoD suspends CMMC Phase 2, freezes Phases 3-4, launches 60-day reform review
DoD (Dept. of War) SUSPENDS CMMC Phase 2 (was effective Nov 10 2026) and freezes Phases 3-4. CIO Kirsten Davies & USD(A&S) Michael Duffey cite $7B+/yr SMB cost and ~100 C3PAOs vs ~100k companies needing assessment. Cross-department CMMC Reform Task Force gets 60 days. Phase 1 self-assessments, DFARS 7012/7021 and NIST 800-171 Rev 2 obligations remain in force — pause, not repeal.
Source 1Source 2Source 3
2026-07-10UPDATE
DoD PQC Strategy mandates post-quantum crypto in CMMC; CMMC Revision 3 formally initiated July 2026
DoD's Post-Quantum Cryptography Strategy (published June 2026) mandates all DoD systems support PQC by end of 2030 and employ it by end of 2031, and explicitly requires updating CMMC with PQC-based requirements. CMMC Revision 3, formally initiated July 2026, would enable PQC via organizationally defined values in NIST baselines — quantum-resistant encryption could enter contracts without overhauling the framework. Experts (Thomas Graham/Redspin, Jacob Horne/Summit 7, Michael Gruden/Crowell) expect a multi-year implementation cycle, not a six-month adoption. (Published Jul 10, pre-suspension; missed by the Jul 19 catch-up sweep, captured Jul 22. The reform review may reshape this arc.)
Source
2026-06-30UPDATE
Senate FY2027 NDAA §1626 proposes $100K grants for small-business CMMC Level 2 assessments
Senate FY2027 NDAA Section 1626 proposes $100,000 grants for small businesses to offset CMMC Level 2 assessment costs (proposal stage; first reported by Federal News Network June 2026 — month precision; FNN original paywalled/403, sourced via National Defense Jul 20). First congressional money on the table for CMMC compliance — a lever that could survive the reform review in some form.
Source 1Source 2
2026-06-30UPDATE
Smithers announces authorized C3PAO status (June 2026)
Smithers announced authorized C3PAO status (June 2026 — month precision, exact day unsourced). Trade-press pickup in machining/manufacturing outlets suggests a manufacturing-OSC channel focus.
Source 1Source 2
2026-06-18ENFORCEMENT
LOGZONE pays $507K to settle FCA allegations on Navy NIST 800-171 work
LOGZONE pays $507K+ to settle FCA allegations of misrepresenting NIST 800-171 compliance on Navy work (DOJ CCFI). The failed controls are the foundation of CMMC L2. Later commentary: LOGZONE self-scored 110; DCMA assessed −170 — DIBCAC/DCMA score deltas now drive DOJ referrals without whistleblowers.
Source 1Source 2Source 3
2026-06-15ENFORCEMENT
FY2025 cyber-fraud recoveries topped $52M across 9 cases
FY2025 cyber-fraud recoveries topped $52M across 9 cases (5 whistleblower-initiated) — enforcement momentum heading into the Nov 2026 C3PAO phase.
Source
2026-06-01UPDATE
Phase 2 (C3PAO-issued Level 2 certificates) approaches — Nov 10 2026
Phase 2 (C3PAO-issued Level 2 certificates) approaches — effective Nov 10, 2026. [Superseded by the Jul 13 2026 suspension — see ev-2026-07-13-phase2-suspend.]
Source
2025-11-10UPDATE
48 CFR CMMC acquisition rule effective; DFARS 252.204-7021 enters contracts
48 CFR CMMC acquisition rule effective; DFARS 252.204-7021 in contracts.
Source
2025-07-30ENFORCEMENT
Illumina to pay $9.8M to resolve cybersecurity misrepresentation allegations
Illumina to pay $9.8M to resolve cybersecurity misrepresentation allegations.
Source
2025-05-01ENFORCEMENT
Raytheon/Nightwing pays $8.4M FCA settlement over NIST 800-171 non-compliance
Raytheon/Nightwing pays $8.4M over NIST 800-171 non-compliance (DOJ CCFI).
Source