CMMC News Feed

Tracked developments in CMMC reform, DIB cybersecurity policy, and False Claims Act enforcement. Curated by Blue Heron Defense; every item links to its public source.

Last updated 2026-07-22

2026-09-30UPDATE

Upcoming: CMMC Reform Task Force recommendations finalized (~late Sep 2026, approximate)

CMMC Reform Task Force recommendations finalized (~late September: 60 days of feedback + 15 days for recommendations, per DoD). Expected to reset every buyer's compliance timeline. [Revised 2026-07-20 from ~Sep 11 (initial 60-day read) after FNN reported the 60+15-day structure; id was ev-2026-09-11-taskforce-report.]

Source 1Source 2Source 3

2026-08-14UPDATE

Upcoming: CMMC reform RFI responses due (Aug 14 2026)

CMMC reform RFI responses due — last day for DIB stakeholders (and vendors) to shape the reformed program.

Source 1Source 2

2026-07-28UPDATE

Upcoming: Cyber AB July Town Hall addresses the Phase 2 pause (Jul 28, 6pm EDT)

Cyber AB July Town Hall (6:00 pm EDT) — expected to address the Phase 2 pause, the Reform Task Force, and ecosystem impacts.

Source

2026-07-20UPDATE

C3PAO channel under revenue pressure from the pause — 'when the mandate pauses, so does their revenue'

Industry fallout from the Phase 2 pause (National Defense, Jul 20): Pete Sfoglia (Pistos): 'The C3PAOs built their business on a mandate, and when the mandate pauses, so does their revenue.' Redspin warns pausing active work risks losing ground on a 12-18-month readiness timeline. Compliance estimates run to $600K per company. Watch the assessor channel for consolidation, pivots, or exits. Counterpoint (Eric Crusius via FNN, Jul 21): C3PAO assessment capacity actually exceeded initial DoD estimates — the 'assessor shortage' rationale is contested; cost benchmarks ~$150K-$500K control implementation, ~$20K-$40K small-business assessments.

Source 1Source 2

2026-07-17UPDATE

DoD plans nationwide CMMC listening sessions; Reform Task Force held first meeting Jul 16

DoD plans nationwide CMMC listening sessions; Reform Task Force held its first meeting Jul 16. Review timeline firmed up: 60 days of feedback then 15 days for recommendations — finalized by late September. RFI issued via SAM.gov. Davies: 'we want to hear back from the defense industrial base... even from Cyber [AB], from the assessors themselves.' Officials named: Kirsten Davies (DoD CIO), Kelly Loeffler (SBA Administrator), Michael Duffey (USD A&S). (Published Jul 17; missed by the Jul 19 catch-up sweep, captured Jul 20.)

Source 1Source 2

2026-07-15UPDATE

Cyber AB: 'surprised and disappointed' but all CMMC ecosystem elements remain operational

Cyber AB response (CEO Matthew Travis): 'surprised and disappointed' but all CMMC ecosystem elements remain operational — C3PAO L2 certification assessments, training, exams, RP services continue. Town hall Jul 28. Voluntary certification market stays open during the pause.

Source

2026-07-13UPDATE

CMMC vendors reposition within hours of the suspension — 'DFARS obligations endure'

Within hours of the suspension, CMMC vendors repositioned in unison — PreVeil, Kiteworks ('a redistribution of risk, not relief'), Summit 7, and A-LIGN all published keep-going guidance. The competitive narrative is now 'DFARS obligations endure'; expect pipeline-freeze pressure on every CMMC-adjacent seller.

Source 1Source 2Source 3Source 4

2026-07-13UPDATE

SBA commends the CMMC Phase 2 suspension for small defense contractors

SBA publicly commends the Phase 2 suspension for small defense contractors — political backing suggests the pause is durable, not cosmetic. Administrator Kelly Loeffler: 'CMMC compliance was becoming an untenable barrier'; SBA estimates third-party assessments could cost up to $600K (Washington Technology, Jul 16).

Source 1Source 2

2026-07-13UPDATE

CMMC reform RFI opened; responses due Aug 14 2026

CMMC reform RFI opened alongside the Phase 2 suspension — stakeholder responses due Aug 14 2026. Direct channel to shape whatever replaces the phased rollout. RFI asks industry about: cost drivers, administrative burdens, security controls that provide meaningful cyber uplift, commercial cybersecurity tools and managed services, Phase 1 self-assessment challenges, and policy reforms implementable within 60 days.

Source 1Source 2

2026-07-13UPDATE

DoD suspends CMMC Phase 2, freezes Phases 3-4, launches 60-day reform review

DoD (Dept. of War) SUSPENDS CMMC Phase 2 (was effective Nov 10 2026) and freezes Phases 3-4. CIO Kirsten Davies & USD(A&S) Michael Duffey cite $7B+/yr SMB cost and ~100 C3PAOs vs ~100k companies needing assessment. Cross-department CMMC Reform Task Force gets 60 days. Phase 1 self-assessments, DFARS 7012/7021 and NIST 800-171 Rev 2 obligations remain in force — pause, not repeal.

Source 1Source 2Source 3

2026-07-10UPDATE

DoD PQC Strategy mandates post-quantum crypto in CMMC; CMMC Revision 3 formally initiated July 2026

DoD's Post-Quantum Cryptography Strategy (published June 2026) mandates all DoD systems support PQC by end of 2030 and employ it by end of 2031, and explicitly requires updating CMMC with PQC-based requirements. CMMC Revision 3, formally initiated July 2026, would enable PQC via organizationally defined values in NIST baselines — quantum-resistant encryption could enter contracts without overhauling the framework. Experts (Thomas Graham/Redspin, Jacob Horne/Summit 7, Michael Gruden/Crowell) expect a multi-year implementation cycle, not a six-month adoption. (Published Jul 10, pre-suspension; missed by the Jul 19 catch-up sweep, captured Jul 22. The reform review may reshape this arc.)

Source

2026-06-30UPDATE

Senate FY2027 NDAA §1626 proposes $100K grants for small-business CMMC Level 2 assessments

Senate FY2027 NDAA Section 1626 proposes $100,000 grants for small businesses to offset CMMC Level 2 assessment costs (proposal stage; first reported by Federal News Network June 2026 — month precision; FNN original paywalled/403, sourced via National Defense Jul 20). First congressional money on the table for CMMC compliance — a lever that could survive the reform review in some form.

Source 1Source 2

2026-06-30UPDATE

Smithers announces authorized C3PAO status (June 2026)

Smithers announced authorized C3PAO status (June 2026 — month precision, exact day unsourced). Trade-press pickup in machining/manufacturing outlets suggests a manufacturing-OSC channel focus.

Source 1Source 2

2026-06-18ENFORCEMENT

LOGZONE pays $507K to settle FCA allegations on Navy NIST 800-171 work

LOGZONE pays $507K+ to settle FCA allegations of misrepresenting NIST 800-171 compliance on Navy work (DOJ CCFI). The failed controls are the foundation of CMMC L2. Later commentary: LOGZONE self-scored 110; DCMA assessed −170 — DIBCAC/DCMA score deltas now drive DOJ referrals without whistleblowers.

Source 1Source 2Source 3

2026-06-15ENFORCEMENT

FY2025 cyber-fraud recoveries topped $52M across 9 cases

FY2025 cyber-fraud recoveries topped $52M across 9 cases (5 whistleblower-initiated) — enforcement momentum heading into the Nov 2026 C3PAO phase.

Source

2026-06-01UPDATE

Phase 2 (C3PAO-issued Level 2 certificates) approaches — Nov 10 2026

Phase 2 (C3PAO-issued Level 2 certificates) approaches — effective Nov 10, 2026. [Superseded by the Jul 13 2026 suspension — see ev-2026-07-13-phase2-suspend.]

Source

2025-11-10UPDATE

48 CFR CMMC acquisition rule effective; DFARS 252.204-7021 enters contracts

48 CFR CMMC acquisition rule effective; DFARS 252.204-7021 in contracts.

Source

2025-07-30ENFORCEMENT

Illumina to pay $9.8M to resolve cybersecurity misrepresentation allegations

Illumina to pay $9.8M to resolve cybersecurity misrepresentation allegations.

Source

2025-05-01ENFORCEMENT

Raytheon/Nightwing pays $8.4M FCA settlement over NIST 800-171 non-compliance

Raytheon/Nightwing pays $8.4M over NIST 800-171 non-compliance (DOJ CCFI).

Source

Get updates by email

We send an update when the CMMC picture actually changes — no noise in between. Start with the context: what the suspension changed and what it didn't.