Watch hub·cmmc · dfars · cui · nist-800-171

CMMC

Rules, assessments, the C3PAO ecosystem, and the road to contract enforcement.

Updated ·RSS ↗

CMMC is the Department of Defense's certification regime for handling Controlled Unclassified Information across the Defense Industrial Base. This hub tracks rule milestones, C3PAO certifications, assessor body decisions, and DIBCAC activity as they happen.

What changed in the last 30 days

  • cmmc/trade-press

    CMMC's architects make the case for pressing on

    Stacy Bostjanick and Tara Lemieux, both central to CMMC's development and now at Cybersec Investment, published an opinion piece in Federal News Network arguing the Pentagon's July 2026 phase-two suspension shouldn't be read as permission to abandon compliance. They point to real DIB breach cases as the cost of inaction, cite $20,000, $50,000 in annual sunk compliance investment by small firms, and warn that contractors publicly posting on Reddit that they've halted spending are betting wrong on the direction of the review. The piece is advocacy from the compliance community, not a DoD signal, but with the 60-day review window launched July 13 now closing, the argument lands while the program's fate is genuinely unsettled.

  • cmmc/trade-press

    Normal workflows push CUI past CMMC enclave boundaries

    A Federal News Network commentary argues CMMC compliance programs share a blind spot: the assumption that CUI stays where you put it. In practice, controlled technical information propagates through Teams, email, cloud storage, and subcontractor correspondence as a byproduct of ordinary business. An organization can achieve certification and fall out of scope within days, not through policy failure, but through the normal velocity of project work.

  • enforcement/judicial

    Honeywell Aerospace Pays $2.04M to Settle DFARS Cyber FCA Case

    Honeywell Aerospace Inc. agreed to pay $2,042,518 to resolve False Claims Act allegations that it failed to comply with cybersecurity requirements in a Department of Defense contract. The DOJ press release does not specify which DFARS controls were at issue or what contract was involved. Honeywell Aerospace was a business segment of Honeywell International Inc. until June 29, when it became a standalone public company. The settlement follows a pattern of CCFI enforcement actions against defense contractors, including the $8.4M Raytheon/Nightwing settlement and the $4.6M MORSECORP settlement earlier this year.

  • ai-compliance/trade-press

    ChatGPT Mil goes live on Pentagon's GenAI.mil

    The Pentagon's GenAI.mil platform now includes ChatGPT Mil, an OpenAI deployment built to support more than 3 million defense personnel for work involving controlled unclassified information. The model had to be engineered into a separate environment from the commercial product, with security architecture designed to pass scrutiny from both the Defense Information Systems Agency and the National Security Agency. Deployment lands roughly a month after OpenAI's June projection of "early July."

  • cmmc/trade-press

    DOD to shift CMMC to NIST 800-171 Rev. 3 with expanded assessment scope

    DOD is planning an interim final rule to transition CMMC Level 2 compliance from NIST SP 800-171 Revision 2 to Revision 3, reducing controls from 110 to 97 while expanding assessment objectives from 320 to roughly 420 and adding supply-chain risk management requirements. Presenters at an Aug. 25 NDIA webinar warned that supply-chain risk management isn't an IT function and that contractors treating 800-171 compliance as a security-team problem will find Rev. 3 especially punishing. No effective date has been set; the CMMC Reform Task Force delivers recommendations in mid-September, and DOD must still issue guidance on organization-defined parameters before contractors can fully align.

  • cmmc/trade-press

    Sonu Shankar named Pentagon principal deputy CIO amid CMMC review

    Sonu Shankar was sworn in Aug. 24 as the Pentagon's principal deputy CIO, filling a post that's been vacant since Leslie Beavers departed last September. An industry veteran whose résumé includes Phosphorus Cybersecurity and Arctic Wolf, Shankar reached the role through the Pentagon's BOND program, which embeds private-sector executives in advisory positions. He arrives with the CMMC Reform Task Force roughly two weeks from its 60-day deadline, the group's recommendations will determine whether Phase 2 requirements, suspended in July, are revived, reworked, or scrapped.

  • procurement/trade-press

    Feinberg directs API supply-chain transparency for $10M+ contracts

    Deputy Defense Secretary Steve Feinberg's Aug. 18 memo directs contracting officers to obtain supply-chain cost transparency through APIs on commercial contracts over $10 million, and to establish fair profit margins by product line. Major system providers face stricter Cost and Software Data Reporting requirements. The memo is the latest in a sequence that industry says contradicts Defense Secretary Hegseth's pledge to cut bureaucracy and expand the defense industrial base. "These send a signal that DoD doesn't trust industry," said former acquisition executive David Berteau.

  • cmmc/trade-press

    ADI Urges DoD-Funded Enclaves to Ease CMMC Cost Burden

    The Alliance for Digital Innovation filed recommendations August 14 urging the Defense Department to sponsor a centrally funded, government-accredited enclave that small and nontraditional defense contractors could onboard into and inherit CMMC controls from. The filing, responding to DoD's July 13 RFI, also proposes a $500,000 contract-value threshold below which Level 2 third-party assessment costs would be recoverable. The recommendations arrive as the CMMC Reform Task Force prepares mid-September guidance that will shape the paused phase two rollout.

  • cmmc/trade-press

    ITI pushes DOD to accept FedRAMP controls under CMMC

    ITI urged DOD to establish formal FedRAMP-CMMC reciprocity in comments filed during the Phase Two pause, arguing that re-auditing controls already validated under FedRAMP produces "duplicative cost without a proportionate increase in security." The filing proposes a "commercial solutions equivalency" pathway where contractors inherit platform-level FedRAMP assurances rather than re-certifying per project. DOD already recognized FedRAMP Moderate equivalency for cloud providers handling CUI in a January 2024 memo, ITI wants that extended to commercial software platforms broadly and codified in a common control matrix.

  • cui/trade-press

    CUI rules keep fracturing because the government isn't a business

    Former GSA Administrator Emily Murphy told Federal News Network the government's push for commercial technology keeps colliding with the reality that agencies aren't commercial buyers. The fractured CUI landscape illustrates the problem: NIST publishes one standard, but DoD spent a decade building CMMC around it while GSA issued its own procedural guide and the FAR Council's government-wide rule remains unfinished. "We always say we want the government to act more like a business, but at the end of the day, the government isn't a business," Murphy said. The protest rights, cyber requirements, and socioeconomic rules that distinguish federal procurement aren't temporary.

  • cmmc/trade-press

    Contractor SPRS Confidence Falls from 89% to 65% in One Year

    Per Inside Cybersecurity, CyberSheath's annual survey of 302 defense contractors found 88% now report a positive SPRS score, but only 65% are confident in their accuracy, down from 89% last year and 94% in 2024. Average annual cybersecurity spend hit $155,204, yet median self-assessed CMMC readiness sits at 70%. Just 1% of respondents say they're completely ready. CyberSheath, a managed security provider that sells CMMC compliance services, commissioned the survey conducted by Merrill Research.

  • cmmc/trade-press

    PSC renews call for single cyber standard in CMMC reform comments

    The Professional Services Council filed comments on the latest CMMC reform proposal, reiterating three longstanding concerns: inconsistent cybersecurity standards across federal agencies, the cost of demonstrating compliance versus actually improving security, and what happens to companies that already earned certifications under prior versions of the program. The consistency argument is the sharpest, a contractor serving both DoD and DHS faces different rules for fundamentally the same work, and PSC has been raising it since CMMC's inception.

  • cmmc/trade-press

    PSC urges CMMC alignment with NIST 800-171 Rev. 3

    The Professional Services Council filed comments Aug. 14 on DoD's CMMC review, asking for alignment with NIST 800-171 Rev. 3, reciprocity with FedRAMP Moderate, and grandfathering of existing Level 2 certifications. The filing also recommends risk-tiered C3PAO assessments, then undercuts its own case, conceding that "sophisticated threat actors routinely target the least-protected organization in a supply chain" and "the sensitivity of CUI does not change based on company size."

  • dfars/independent

    TINA Threshold Hits $10M; FAR Still Shows $2.5M

    The Truthful Cost or Pricing Data threshold for DoD contracts rose from $2.5 million to $10 million on July 1, 2026, per FY 2026 NDAA Section 1804(c). The statute is operative on its own terms, but FAR 15.403-4 still recites $2.5 million and implementing DFARS rules haven't caught up. Because the change keys to contract date and is not retroactive, the two thresholds coexist for years. Primes and subs must segregate pre- and post-July 1 actions immediately: a modification to a legacy contract still triggers certification at $2.5 million, and misapplying the threshold on a $2.5 million to $10 million deal exposes contractors to downward price adjustment plus interest and potential False Claims Act risk.

  • cmmc/trade-press

    CMMC program operational despite phase-two pause, Cyber AB says

    CMMC's phase-two implementation timeline is on hold after DoD's July 13 pause and 60-day task-force review, but Cyber AB CEO Matthew Travis told a July 28 town hall that the program itself remains operational: C3PAOs are conducting level two certifications, DFARS 252.204-7012 compliance is still in force, and both CMMC portals remain open. Travis framed certification as "the best insurance policy against False Claims Act risk" and urged contractors to respond to DoD's RFI by the Aug. 14 deadline. The task force's authority to alter the rule's cost, scope, or timing remains undefined, and the Cyber AB hasn't been contacted for tier-four participation yet.

  • cmmc/trade-press

    BlueVoyant exec: use CMMC pause to build enterprise monitoring

    Former NSA chief technology officer Lonny Anderson, now president of BlueVoyant Government Solutions, published an open argument Wednesday urging the Defense Department to use the CMMC Phase 2 suspension to adopt an enterprise accountability model (independent assessment plus continuous external monitoring and shared remediation funding) rather than letting the pause lapse into pure self-attestation. The piece marks a public shift from CMMC skeptic to conditional supporter. Anderson's central claim: many NIST SP 800-171 failures, like expired TLS certificates and exposed misconfigured services, are visible from the outside right now, regardless of whether formal C3PAO assessments are running.

  • cmmc/trade-press

    NDIA: DoD's own CUI marking failures drive CMMC costs

    NDIA told DoD during the CMMC reform comment window that inconsistent Pentagon CUI marking is the root cause of compliance costs running $100K to $5M+ for individual contractors. Nearly half of NDIA's survey respondents spent over $100,000 implementing NIST 800-171, costs that can't be amortized across contracts for small firms. The filing names what contractors have said quietly for years: you can't protect information the government itself can't consistently label.

  • cmmc/trade-press

    CMMC architect wants AI to sharpen CUI targeting

    Katie Arrington, who built the CMMC program, argues in a NextGov op-ed that the framework's requirements shouldn't loosen, but its targeting needs sharpening. CUI determinations remain inconsistent across the defense industrial base: some small businesses get assessed for data that isn't really CUI, while others handling sensitive material slide through with lighter requirements. Her fix: use AI to do first-pass sorting of contract language and CUI flow-down, with a human contracting officer making the final call. She also calls for a dedicated SBA loan program to fund cybersecurity investment at small businesses outside the defense supply chain.

  • procurement/trade-press

    DoD seeks GAAP-aligned accounting to lower contractor barriers

    Acquisition chief Michael Duffey and acting comptroller Michael Powers issued an open letter asking industry for "common sense contract accounting changes" that would align DoD's data and audit requirements with GAAP and Sarbanes-Oxley internal controls companies already maintain. Stakeholders have until Aug. 15 to submit ideas. The request is the latest in a year-long CAS-to-GAAP conformance push (OMB and the Cost Accounting Standards Board eliminated 68 of 72 individual CAS requirements in a July final rule) but DoD's separate DFARS business-system audit framework hasn't yet been touched.

  • supply-chain/trade-press

    DoD’s Anthropic ban fractures across agencies mid-enforcement

    Five months after the Pentagon designated Anthropic a supply-chain risk, contractors are discovering that enforcement isn't uniform. Different DoD agencies (and even different offices within the same agency) are issuing conflicting certification requests. Some ask only what the active designation requires: no Claude on DoD contracts. Others demand contractors certify they aren't using Claude at all, including on commercial or civilian-agency work. Subcontractors face a compounding problem, with primes sometimes flowing down their own broader checklists rather than the government's actual request. The gap between what the order says and what contracting officers are demanding is now a live liability question.

Open questions

  • 01How will Joint Surveillance Voluntary Assessments transition to Level 2 certifications post-rule effective date?
  • 02When will DoD finalize the second tranche of CMMC contract clauses?
  • 03How are primes flowing CMMC requirements down to subs?

Sources we watch

Related from Deep Fathom

Earlier coverage