Insights · Program Status · Defense Wire

Plain-language guidance on CMMC, CUI, and the road to award.

Field notes, the compliance timeline, and the contracting developments that actually change what contractors need to do — written for the people who have to do the work.

Updated · Q3 2026South Florida · Palm Beach · Broward · Miami-Dade
(561) 887-5470
No. 11 — Resources

Primary sources — cited, current, clickable.

External · opens in new tab
Program Status · Under Review

CMMC Phase 2 — suspended, not repealed.

On 13 July 2026 DoD suspended the Phase 2 C3PAO certification requirement and all future implementation milestones, pending a 60-day Reform Task Force review. Phase 1 self-assessments, DFARS 252.204-7012, NIST SP 800-171, and SPRS obligations all remain in force. Each milestone below links to the authoritative source or to the engagement that handles it.

P1
In Force
·
P2
Suspended
·
P3
Held
·
P4
Held
StatusSuspended · Under Review
Since13 · JUL · 2026
ReviewReform Task Force · 60 days
Still in forcePhase 1 · DFARS 7012 · 800-171 · SPRS
13 JUL 26 · SUSPENDED
YOU ARE HERE
20242025202620272028
Oct 2024Q4 · 2024

CMMC 2.0 Final Rule

CFR 32 Part 170 finalized. The CMMC Program rule was published in the Federal Register, codifying Level 1 / 2 / 3.

Read on Federal Register
Dec 2024Q4 · 2024

CMMC Program Effective

The CMMC Program rule took effect, with phased rollout planned across DoD contracts.

DoD CIO program page
10 · NOV · 2025Phase 1 · IN FORCE

Phase 1 — Self-Assessment Required

DoD began requiring Level 1 and Level 2 self-assessments in applicable contracts. The implementing DFARS rule (DFARS 252.204-7021) took effect. Phase 1 obligations remain fully in force.

DoD CIO rollout overview
13 · JUL · 2026Program Review

DoD Suspends Phase 2 & Future Milestones

DoD suspended the Phase 2 C3PAO certification requirement and all future implementation milestones pending a 60-day Reform Task Force review. Phase 1 self-assessments, DFARS 252.204-7012, NIST SP 800-171, and SPRS obligations all remain in force.

DoD CIO announcement
10 · NOV · 2026Phase 2 · SUSPENDED

L2 Certification Assessments — Suspended

Originally the date C3PAO Level 2 certification assessments would begin appearing in applicable solicitations. Held in abeyance since 13 Jul 2026 pending the reform review — a reformed requirement is expected to return, and primes still flow down NIST 800-171 today.

Start with a gap assessment
10 · NOV · 2027 →Phases 3–4 · SUSPENDED

Level 3 & Full Implementation — Held in Abeyance

Phase 3 (government-led Level 3 assessments) and Phase 4 (full implementation across DoD solicitations) are likewise held in abeyance pending the Reform Task Force review and any subsequent rulemaking.

Browse all five engagements
Sources: 32 CFR Part 170 (CMMC Program), DoD Office of the CIO public guidance. Program status reflects the 13 July 2026 DoD announcement suspending Phase 2 and future milestones pending reform review; the requirements themselves have not gone away, and specific contract obligations vary by program office and prime contractor flow-down.
The Defense WireEditionVol. I · MMXXVI·Last update----

CMMC, NIST & cyber intelligence — filtered for the defense base.

Editorially curated from DoD CIO, NIST CSRC, Cyber-AB, CISA, and the Acquisition.gov DFARS catalog. Click any item to read the primary source.

CMMC/CRITICAL/DoD CIO2026-07-13

DoD suspends CMMC Phase 2 and future milestones pending 60-day reform review

DoD suspended the Phase 2 C3PAO certification requirement (originally 10 Nov 2026) and all future implementation milestones while a Reform Task Force conducts a 60-day review. Phase 1 self-assessments, DFARS 252.204-7012, NIST SP 800-171, and SPRS obligations remain in force — a suspension pending reform, not a repeal.

Feature · top wireRead primary source →
highCMMC2025-11-10

DFARS 252.204-7021 in effect — CMMC certification required prior to award

The DFARS contract clause requiring contractors to hold the required CMMC certification level before award (and primes to flow down the requirement to subcontractors handling CUI/FCI) became enforceable on 10 November 2025.

SRC · Acquisition.govRead →
highPOLICY2026-02-01

Revolutionary FAR Overhaul — DFARS Part 240 reorganization takes effect

Class deviations issued under the FAR Overhaul renumber DFARS 252.204-7020 to DFARS 252.240-7997 and eliminate 252.204-7019. Foundational clauses 252.204-7012 and 252.204-7021 remain in full force.

SRC · DoDRead →
mediumNIST2024-05-14

NIST SP 800-171 Rev. 3 published — Rev. 2 remains current CMMC basis

NIST published the final SP 800-171 Rev. 3 and the assessment guide SP 800-171A Rev. 3 on 14 May 2024. DoD continues to anchor CMMC Level 2 assessments to Rev. 2; Rev. 3 implementation is expected to be addressed in future rulemaking.

SRC · NISTRead →
criticalTHREAT2026-05-21

CISA adds Langflow and Trend Micro Apex One vulnerabilities to KEV catalog

CISA added CVE-2025-34291 (Langflow origin validation) and CVE-2026-34926 (Trend Micro Apex One directory traversal) to the Known Exploited Vulnerabilities catalog with binding remediation deadlines for federal agencies.

SRC · CISARead →
highTHREAT2026-05-20

Microsoft Defender vulnerabilities added to KEV — exploited in the wild

CISA added seven vulnerabilities to the KEV catalog including CVE-2026-41091 (Microsoft Defender elevation of privilege) and CVE-2026-45498 (Microsoft Defender denial of service). Federal civilian agencies have set remediation deadlines.

SRC · CISARead →
mediumPOLICY2025-12-01

CISA releases Cybersecurity Performance Goals 2.0 for critical infrastructure

CPG 2.0 updates CISA’s recommended practices to reflect the NIST Cybersecurity Framework 2.0. The goals apply to defense-relevant critical infrastructure and align well with CMMC Level 2 controls.

SRC · CISARead →
mediumC3PAO2026-05-01

C3PAO marketplace — accredited assessor count remains in the dozens

The Cyber AB’s C3PAO marketplace lists currently-authorized third-party assessor organizations. Limited assessor supply versus demand makes scheduling Level 2 certification slots a planning consideration.

SRC · Cyber-ABRead →
Disclaimer: The Defense Wire aggregates publicly-available developments. Summaries reflect the editors' reading and are not legal or contractual advice. Always verify specific requirements with your contracting officer or prime.Sources tracked: DoD CIO, NIST CSRC, Cyber-AB, CISA, FBI/IC3, GAO, Acquisition.gov DFARS, Federal Register
Defense Wire · Live
§ CMMC Phase 2 suspended 13 Jul 2026 — 60-day Reform Task Force review underway§ Phase 1 self-assessments + DFARS 7012 + NIST 800-171 + SPRS remain in force§ NIST SP 800-171 Rev. 2 remains the current CMMC Level 2 basis§ CISA KEV catalog — Langflow + Trend Micro Apex One added (May 2026)§ Microsoft Defender vulnerabilities exploited in the wild — patch ASAP§ Cyber-AB C3PAO marketplace — limited assessor capacity§ DFARS Part 240 reorganization effective 1 Feb 2026§ 110 controls · 14 families · NIST SP 800-171 Rev. 2§ CMMC Phase 2 suspended 13 Jul 2026 — 60-day Reform Task Force review underway§ Phase 1 self-assessments + DFARS 7012 + NIST 800-171 + SPRS remain in force§ NIST SP 800-171 Rev. 2 remains the current CMMC Level 2 basis§ CISA KEV catalog — Langflow + Trend Micro Apex One added (May 2026)§ Microsoft Defender vulnerabilities exploited in the wild — patch ASAP§ Cyber-AB C3PAO marketplace — limited assessor capacity§ DFARS Part 240 reorganization effective 1 Feb 2026§ 110 controls · 14 families · NIST SP 800-171 Rev. 2