Watch hub·cmmc · dfars · cui · nist-800-171

CMMC

Rules, assessments, the C3PAO ecosystem, and the road to contract enforcement.

Updated ·RSS ↗

CMMC is the Department of Defense's certification regime for handling Controlled Unclassified Information across the Defense Industrial Base. This hub tracks rule milestones, C3PAO certifications, assessor body decisions, and DIBCAC activity as they happen.

What changed in the last 30 days

  • cui/trade-press

    Chamber Challenges Immediate 800-171 Rev. 3 Mandate in FAR CUI Rule

    The U.S. Chamber of Commerce filed comments opposing the FAR Council's proposed CUI rule, which would require contractors to comply with NIST SP 800-171 Rev. 3 immediately upon contract insertion with no phase-in period. The filing argues this is operationally infeasible for roughly 67,000 unique entities and more than 2 million private-sector employees, most of whom have never been subject to the 800-171 framework. The Chamber warns the absence of a phase-in period may render the rule vulnerable under the Administrative Procedure Act if the FAR Council cannot demonstrate that immediate compliance is feasible across the entire civilian contractor base.

  • supply-chain/trade-press

    Software sovereignty isn't in any DFARS clause

    A Federal News Network opinion piece by a Coder strategic advisor argues that America-first industrial policy has a blind spot: software supply chains. The piece defines software sovereignty as four requirements, code written on U.S.-controlled infrastructure, government-operated servers, U.S.-sourced toolchains, and no foreign-reachable SaaS dependencies. These requirements don't exist in current DFARS supply-chain clauses (252.239-7018 covers IT supply chain risk broadly; Subpart 239.73 addresses covered systems) or in CMMC or FedRAMP. No proposed rulemaking or draft standard from CISA or DoD yet formalizes software-sovereignty mandates. The commentary flags that the SHIPS Act reauthorization defines sovereignty in maritime terms (shipyards, labor, materials) and is silent on where the software that runs a modern destroyer gets developed.

  • executive-order/trade-press

    House NDAA mandates vulnerability disclosure, extends CISA 2015

    The House passed its fiscal 2027 NDAA 216-212 on July 22, packing in a nine-year CISA 2015 extension through 2035 and a first-of-its-kind mandate requiring federal contractors to adopt vulnerability disclosure policies. The bill also directs the Pentagon to brief Congress on CMMC's impact on small businesses. CISA 2015's current authorization expires September 30, leaving the Senate and reconciliation between now and then. The vulnerability disclosure mandate, carried by Rep. Nancy Mace's Federal Contractor Vulnerability Disclosure Act, shifts the practice from encouraged best practice to a condition of doing business with the federal government.

  • nist/trade-press

    NIST opens public comment on first storage-infrastructure security guide update since 2020

    NIST released an initial public draft of SP 800-209 Revision 1, updating its storage infrastructure security guidelines for the first time since 2020. The revision adds new security control families and expands threat modeling to address platform compromise and data resilience risks specific to storage systems. Assessors, C3PAOs, contractors, and MSPs that manage storage infrastructure will need to evaluate revised criteria. Comments close September 8.

  • dfars/independent

    DFARS Consultant-Lobbyist Ban Takes Effect With Rules Unresolved

    The Section 851 prohibition on defense contractors using consultants who lobby for covered foreign entities took effect June 30 via a DFARS class deviation, not formal rulemaking, after DoD abandoned DFARS Case 2025-D0007. The deviation tracks the statutory text and provides no guidance on the safe harbor for legal, audit, and tax compliance services. Contractors must now self-certify under 252.209-7012 without knowing which consultant arrangements qualify.

  • cmmc/trade-press

    Contractors continue CMMC assessments through DoD pause

    Federal News Network reports that Professional Services Council President Stephanie Kostro says PSC members already midway through Cybersecurity Maturity Model Certification (CMMC) assessments are staying with Certified Third Party Assessment Organizations (C3PAOs) despite DoD’s suspension. PSC has 400 member companies, about 40% with Defense Department work. The lesson is operational: companies have sunk assessment costs, protected government information to secure and no evidence that contractor cybersecurity requirements are disappearing.

  • cmmc/trade-press

    DoD CMMC pause leaves NIST SP 800-171 burden intact

    Federal News Network reports DoD paused Phase 2 third-party Cybersecurity Maturity Model Certification reviews, but defense contractors still must implement NIST SP 800-171 under DFARS 252.204-7012 and provide senior-official affirmations. Primes, subs and certified third-party assessment organizations get timeline uncertainty, not a compliance holiday. The expensive work remains the 110-plus controls, with False Claims Act and whistleblower exposure waiting for contractors that read “pause” as “stop.”

  • executive-order/trade-press

    Trump EO tightens foreign-supplier waivers for defense contractors

    Defense News reports Trump signed an executive order removing ease of sourcing and cost as grounds for foreign-supplier waivers tied to critical minerals and other prohibited inputs. Primes, subs and other defense contractors seeking waivers must document alternative searches, provenance and domestic transition plans, and risk contract loss if they cannot show progress. The hard part starts where the order stops: the Pentagon has not issued mapping rules, review timelines or a definition of critical systems and materials.

  • cmmc/trade-press

    DoD freezes third-party CMMC assessments for 60-day review

    DoD suspended all Cybersecurity Maturity Model Certification third-party assessment requirements while it runs a 60-day review, Federal News Network reports. The review includes a request for information and listening sessions aimed at small business cost concerns. Contractors, subcontractors, C3PAOs and assessors now have stalled certification timelines, plus the more useful problem: DoD has finally stopped treating implementation pain as a communications issue.

  • cmmc/trade-press

    DoD suspends CMMC third-party assessments indefinitely

    Federal News Network reports that DoD has suspended Cybersecurity Maturity Model Certification (CMMC) third-party assessment requirements indefinitely and opened a 60-day program review, with recommendations expected by late September. Primes and subcontractors face frozen certification pathways, while CMMC Third-Party Assessment Organizations (C3PAOs) lose near-term assessment revenue. DoD is reopening the verification model it built because contractor self-attestation did not work.

  • cmmc/trade-press

    CMMC Phase II pause leaves audits likely to return

    Breaking Defense reports that Katie Arrington and other industry voices expect DoD’s CMMC Phase II pause to be temporary, with cybersecurity audits likely to return. Defense contractors preparing for assessments get schedule relief, but no exit from compliance. The hard part remains verification: DoD still needs a way to know whether suppliers actually meet the requirements.

  • cmmc/trade-press

    DoD pauses CMMC Phase II, seeks burden-cutting input

    Federal News Network sponsored commentary from Avatara CEO Rob McCormick says DoD suspended Cybersecurity Maturity Model Certification Phase II and posted a SAM.gov request for information on reducing compliance costs, administrative burden and operational complexity. Defense Industrial Base contractors still face existing covered defense information obligations. The vendor pitch is predictable, but the useful point is concrete: screenshots and evidence collection are not the same thing as resilient systems.

  • dfars/independent

    War Department pushes FOCI onto CUI contractors over $5M

    The Department of War’s proposed Defense Federal Acquisition Regulation Supplement (DFARS) rule on foreign ownership, control, or influence (FOCI) closed for comment July 6. It would require primes and subs on covered unclassified sensitive work, including controlled unclassified information (CUI), over $5 million to disclose and mitigate FOCI, with award blocked for noncompliance and nearly 40,000 entities affected by DoW’s estimate. Congress is moving in parallel: the Senate Fiscal Year 2027 National Defense Authorization Act would drop the threshold to $500,000, while an undefined commercial-contract national-security override stays loose enough to slow deals.

  • cmmc/trade-press

    DoD suspends CMMC Phase 2 for 60-day review

    DoD said it suspended Cybersecurity Maturity Model Certification (CMMC) Phase 2 immediately, stopping the third-party certification launch set for Nov. 10 and halting Phases 3 and 4 during a 60-day reform review. Contractors, primes and subs keep Phase 1 self-assessments, with select government-led assessments. Small and mid-sized suppliers get breathing room; the defense industrial base now has an undefined compliance target.

  • far/independent

    FAR Council consolidates supply-chain, CUI rules in Part 40 proposal

    The FAR Council's June 23, 2026 Part 40 proposal would pull supply-chain security restrictions from FAR Parts 4, 25 and 40 into one structure, add FAR-wide Controlled Unclassified Information obligations, impose a uniform reasonable-inquiry standard, and set a 72-hour reporting window for supply-chain violations. Primes, subs and counsel get a central hub, but not yet a settled answer on how agency-specific CUI clauses will run alongside it.

  • cmmc/trade-press

    DoD fast-tracks CMMC shift to NIST 800-171 Rev. 3

    Inside Cybersecurity reports that the Defense Department’s 2026 unified agenda, published July 3, places an interim final rule in motion to move the Cybersecurity Maturity Model Certification program from National Institute of Standards and Technology Special Publication 800-171 Revision 2 to Revision 3 for controlled unclassified information. Primes, subcontractors and certified third-party assessment organizations get the practical problem: Rev. 2 assessments and contract planning now have an approaching shelf life, but DoD has not said when the clock starts or what happens after it expires.

  • circia/trade-press

    CIRCIA, FAR cyber rules crowd September compliance calendar

    Federal News Network reports that the 2026 Unified Agenda puts the Cybersecurity and Infrastructure Security Agency’s final Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) rule in September: 72-hour incident reports and 24-hour ransomware-payment reports across 16 critical infrastructure sectors. The same agenda targets September for two Federal Acquisition Regulation (FAR) cyber rules, while third-party Cybersecurity Maturity Model Certification (CMMC) assessments are expected to become standard in applicable DoD contracts in November. For primes, contractors and managed service providers, the open issue is whether CISA narrows the 2024 draft’s 300,000-entity scope and clarifies its ambiguous incident trigger.

  • dfars/regulator

    DoD seeks input on DFARS printed circuit board restrictions

    DoD is seeking information for a Defense Federal Acquisition Regulation Supplement revision to implement fiscal 2021 and 2022 National Defense Authorization Act sections on prohibiting acquisition of covered printed circuit boards from a covered nation. The immediate audience is the DoD acquisition and supplier community tied to PCB procurement. The notice starts the DFARS drafting work; it does not supply the final clause text.

  • far/trade-press

    FAR Council proposes civilian CUI rule after 15-year gap

    Federal News Network reports the FAR Council has proposed a government-wide controlled unclassified information (CUI) rule for civilian agencies, built around a standard form and contracting officer directions for identifying and marking CUI. Contractors, primes and subs would get one baseline for scope and flowdown; Cybersecurity Maturity Model Certification (CMMC) third-party assessment organizations (C3PAOs) will have to track the NIST SP 800-171 Revision 3 split from CMMC’s Revision 2 work. The rule still arrives inside the larger FAR overhaul with 30 days for comment, and its effective date and existing-contract treatment remain unresolved.

  • ai-compliance/trade-press

    DoD plans classified GenAI.mil expansion as users near 1.7M

    Nextgov reports the Department of Defense’s GenAI.mil platform has reached almost 1.7 million users and more than 100,000 custom agents. Cameron Stanley, DoD’s chief digital and artificial intelligence officer, said the department plans more models and higher classification levels; OpenAI has said ChatGPT will be eligible for controlled unclassified information (CUI) through GenAI.mil in July. For security and procurement teams, the meaningful shift is commercial models moving deeper into protected DoD workflows.

  • dfars/trade-press

    Section 851 bars DoD contractors retaining 1260H lobbyists

    Federal News Network reports that Section 851 of the fiscal 2025 National Defense Authorization Act is now in force, requiring DoD contractors to certify they do not retain lobbyists or consultants representing companies on the Pentagon’s Section 1260H Chinese military-company list. Primes, contractors and counsel face loss of current and future DoD eligibility, including debarment, while DoD has not issued the DFARS clauses, audit process, reporting timelines or retroactive diligence rules.

  • cui/trade-press

    FAR rewrite leaves CUI confusion intact

    Government Executive says the Federal Acquisition Regulation rewrite has not solved contractors’ recurring problem with controlled unclassified information: inconsistent agency implementation and unclear triggering facts. The FAR overhaul may consolidate information security and supply-chain provisions, but Executive Order 13556, National Archives and Records Administration CUI rules, NIST SP 800-171 and Cybersecurity Maturity Model Certification still sit outside that cleanup. The affected reader is not the policy shop. It is the bidder pricing cyber work before the solicitation tells them what data they will actually touch.

  • dfars/regulator

    DoD proposes DFARS certification for recruitment advertising contracts

    DoD proposed a Defense Federal Acquisition Regulation Supplement amendment for certain military recruitment advertising contracts, implementing National Defense Authorization Act provisions from fiscal years 2024, 2025 and 2026. Affected offerors and contractors would need to certify compliance to compete for covered work. The proposal leaves the operative details, including the triggering NDAA provisions, compliance content, sunset date and treatment of existing contracts, unresolved.

Open questions

  • 01How will Joint Surveillance Voluntary Assessments transition to Level 2 certifications post-rule effective date?
  • 02When will DoD finalize the second tranche of CMMC contract clauses?
  • 03How are primes flowing CMMC requirements down to subs?

Sources we watch

Related from Deep Fathom

Earlier coverage