Mid-Q3 update — July 14, 2026. The headline of this briefing has been overtaken by events.
(1) CMMC Phase 2 is suspended. On July 13, 2026 the Department of War CIO suspended the November 2026 Phase 2 transition and held all pending and future CMMC implementation milestones in abeyance until further notice, pending a 60-day review by a new CMMC Reform Task Force. Program managers may designate only Level 1 (Self) or Level 2 (Self) assessments, not Level 2 (C3PAO) or Level 3 (DIBCAC). Solicitations and contracts carrying those requirements are directed to be amended or modified to remove them, and no waivers will be granted during the review. This supersedes the November 10, 2026 cliff that section 1 below is built around, and the timing advice in section 1 and Priority 1 is withdrawn. What did not change: DFARS 252.204-7012 safeguarding and 72-hour reporting are explicitly still in effect, NIST SP 800-171 Rev 2 remains the enforced baseline via self-assessment, and False Claims Act exposure still attaches to the SPRS score you affirmed. Primary-source read of both memos: CMMC Phase 2 is suspended. The associated RFI, “Reforming CMMC and Reducing Compliance Burden for the Defense Industrial Base (DIB),” closed to responses on August 14, 2026. What remains outstanding is the Task Force output itself; a 60-day clock from July 13 lands around mid-September 2026.
(2) FedRAMP released the Consolidated Rules for 2026 (CR26) on June 24, 2026. CR26 consolidates the 20x requirements into one versioned, machine-readable ruleset and resets how every submission, Rev 5 included, is reviewed. Optional early adoption opened July 4, 2026; it is mandatory for all stakeholders January 1, 2027; no new Rev 5 applications after June 11, 2027. It carries three component notices: NTC-0012 (incident communications), NTC-0013 (Rev 5 baseline rebuild), and NTC-0014 (VDR/VER vulnerability rules, mandatory December 7, 2026). Start here: the CR26 explainer. This closes out the “FedRAMP Phase 3 finalization” item promised below.
(3) NDAA Section 1513 — no confirmed submission. The June 16, 2026 deadline for DoD’s AI-security plan to Congress has passed. We can find no primary-source evidence that the report was actually delivered: no congressional record, no DoD CIO publication. We are not going to report a submission we cannot verify; the item stays open. Background: AI is coming to CMMC.
(4) A note on the readiness statistics below. Sections 1 and 3 cite “fewer than 1,100 certified as of February 2026.” The more current figure is ~1,042 of ~76,600 organizations (~1.4%) as of May 2026, cited in item (3) of the June 5 update. Both are approximately the same readiness rate, and that rate is a large part of why the program was just suspended. The capacity arithmetic never cleared.
Mid-Q2 update — June 5, 2026. Four further developments worth flagging since the May 8 update:
(1) FedRAMP renamed “Authorization” to “Certification” (May 4, 2026) and replaced the Low/Moderate/High impact-level terminology with Classes A/B/C/D. The substantive control baselines are unchanged; this is a terminology overhaul. Every piece of FedRAMP marketing copy, every SSP cover sheet, and every customer-facing FedRAMP claim on the open web is now subtly out-of-date until refreshed. Our FedRAMP Moderate realistic timeline and the Rev 5 series carry a footnote on the rename.
(2) Executive Order “Promoting Advanced AI Innovation and Security” — signed June 2, 2026. Directs federal agencies, within 30 days (by July 2, 2026), to prepare federal and private-sector systems for advanced AI; Committee on National Security Systems prioritizes NSS cyber defense; Treasury must stand up an AI Cybersecurity Clearinghouse for voluntary industry / critical-infrastructure participation. Combined with NDAA FY26 Section 1513, which requires DoD to deliver a CMMC-for-AI framework plan to Congress by June 16, 2026, this is the first formal signal that AI/ML security obligations will become a CMMC scope expansion lane in 2027-2028.
(3) CMMC narrative shifts from “planning” to “enforcement.” June 2026 trade-press reporting (Federal News Network) now reframes the program: primes are flowing CMMC requirements down on tight deadlines, contracting officers signal at the solicitation stage, and the capacity arithmetic has hardened. 92 authorized C3PAOs as of December 2025 per GAO, against a population of ~76,600 organizations needing Level 2; only ~1,042 organizations (1.4%) have completed certification as of May 2026. Industry reporting cites wait times exceeding 18 months for new clients by Q3 2026. The “C3PAO scarcity is the binding constraint” framing in our Realistic CMMC Level 2 Timeline is now the dominant practitioner narrative.
(4) DCSA system “under strain” + GAO follow-on. May 2026 Federal News Network reporting flagged that DoD’s classified-information protection regime for cleared contractors is buckling under resource constraints. Director Cattler retired Sept 30, 2025; Justin Overbaugh is acting; NBIS remains years behind schedule and over budget. Combined with the April 2026 GAO 815-violations report (covered in the May 8 update), the picture is one of accelerating enforcement expectations against a regulator that covers only 25-30% of cleared facilities annually. Our DCSA 815 analysis carries the GAO data; the strain narrative is a Q3 article in our pipeline.
(5) Correction — DFARS 7019/7020 were not deleted or renumbered. An earlier version of this briefing reported a “February 2026 Revolutionary FAR Overhaul” that deleted DFARS 252.204-7019 and renumbered 252.204-7020 to “252.240-7997.” That was incorrect: per acquisition.gov, both 252.204-7019 and 252.204-7020 remain active and in force, and no clause “252.240-7997” exists. The real change is the CMMC final rule (DFARS Case 2019-D041, September 10, 2025), which layers CMMC (252.204-7021) plus a new notice clause, 252.204-7025, on top of the existing assessment clauses rather than replacing them. Section 3 below has been corrected.
(6) NIST 800-171 Rev 3 rulemaking — trade-press expectation only. April-May 2026 trade press converged on a near-term rulemaking window. Do not plan against it. DoD has published no migration date: 32 CFR 170.2 still incorporates Rev 2, and the CMMC final rule says only that Rev 3 “is not currently applicable to this rule.” Rev 2 is the assessed baseline and stayed so through the July 13 suspension, which explicitly kept Rev 2 enforced via self-assessment. Tier-1 primes are nonetheless asking subs about Rev 3 readiness in pre-award evaluations. Our how primes evaluate CMMC subs covers the operational pattern.
(Written June 5, this block promised a Mid-Q3 update covering FedRAMP Phase 3 finalization, DoD’s response to the NDAA Section 1513 deadline, ISO 27017 second-edition publication, and new DOJ FCA settlements. The July 14 block above landed early and closed the first two — CR26 superseded the Phase 3 item, and Section 1513 remains unverified rather than unaddressed. ISO 27017 second edition and the FCA settlement count are still open.)
Updated May 8, 2026. Two material developments since this briefing first published:
(1) GAO Report 26-107861 (April 24, 2026) documented 815 security violations across 4,600+ DCSA cleared-contractor security reviews in FY2025, plus 1,032 open security vulnerabilities. Distribution: data spills ~60%, improper storage 11.5%, unauthorized access 6.5%, physical losses 6.3%, improper transfers 5.6%. DCSA’s review capacity covers only 25-30% of the cleared industrial base in any fiscal year, and industrial security funding has remained “relatively flat” while personnel-vetting funding increased. Real annual industry violation count, extrapolated, is probably 2,500-3,300. Our DCSA 815 violations analysis walks through each category and the architectural patterns that prevent them.
(2) L3Harris insider-threat case (May 8, 2026). Peter Williams, formerly head of L3Harris’s offensive cyber tooling division, ordered to pay $10M restitution for stealing surveillance and hacking tools and selling them for $1.3M to a Russian broker. Reinforces the personnel-security control family (NIST 800-171 3.9) as a real risk vector for cleared and CUI-handling contractors, not just a paper requirement.
Neither development changes the strategic conclusions below, but both are evidence that the policy direction (more enforcement, more visibility on contractor failures) is producing observable consequences month-over-month, not just at policy-cycle inflection points.
The first half of 2026 has been the most consequential compliance-landscape quarter since the original DFARS 252.204-7012 rollout in 2017. Multiple large-scale regulatory shifts have landed in a narrow window: a new CMMC enforcement posture, the CMMC final rule layering new clauses onto the DFARS framework that underpins CUI handling, a step-change in DoD cloud-provider requirements, an accelerating DOJ enforcement program with the first defense-subcontractor False Claims Act settlement, and the quiet staging of the NIST 800-171 Rev 3 transition.
This briefing is a practitioner’s view of what changed, what it means for each buyer profile (defense subcontractor, cloud SaaS, classified-work contractor, commercial vendor with federal exposure), and what to prioritize over the next two quarters. The article is built from primary rulemaking review, DoD and Cyber AB communications, and pattern-recognition across engagements we’ve run this year.
A single-sentence TL;DR for each reader:
- Defense subcontractors: Phase 2 was suspended on July 13, 2026, but 7012, NIST 800-171 Rev 2, and the SPRS score you affirmed all still bind you, so the security work does not stop.
- Cloud SaaS: FedRAMP 20x is finally real, IL5 is now an unclassified-NSS level built on a FedRAMP High floor, and the CSP SRG is at V1R7 — check which release your last assessment was against.
- Classified-work contractors: ICD 705 Tech Specs are revised periodically; confirm the current revision with your Accrediting Official before scoping a renovation.
- Commercial SaaS with federal exposure: ISO 27001:2013 is dead, GSA added CUI requirements for civilian contractors, and DOJ is actively pursuing false SPRS scores under the FCA.
The rest of the article unpacks each, with citations to primary sources where useful.
1. CMMC Phase 2 — suspended July 13, 2026 (was November 10, 2026)
Superseded — read this first. This section was written around November 10, 2026 as the single most important date in DoD compliance this year. On July 13, 2026 that transition was suspended and all pending CMMC implementation milestones were held in abeyance pending a 60-day review. The capacity analysis below is left standing because it is the reason the program was suspended, but the deadline framing and the timing advice are withdrawn. See CMMC Phase 2 is suspended for what still binds you.
The plan, until July 13, was this: on November 10, 2026, CMMC Phase 2 would activate, contracting officers would require C3PAO-assessed Level 2 certification by default for contracts involving CUI, and self-assessment would cease to satisfy the DFARS 252.204-7021 obligation for the majority of subcontractors handling CUI. During the suspension the reverse is true: program managers may designate only self-assessment (Level 1 or Level 2), and may not designate C3PAO or DIBCAC assessment at all.
The capacity math is the alarming part. DoD estimates 76,000+ organizations need Level 2 certification to continue serving defense primes. As of February 2026, fewer than 1,100 had completed it — roughly 1.4% readiness against a deadline now under six months out. C3PAO assessor capacity is the binding constraint. Our CMMC Level 2 timeline article lays out what a realistic engagement looks like month-by-month.
Under the same superseded schedule, Phase 3 (November 10, 2027) would have extended the mandate to option exercises on existing contracts, with no grandfathering for contracts awarded earlier that carried option years past November 2027. That milestone is held in abeyance along with everything else, so there is currently no date by which an option exercise requires a certificate. The underlying structural point survives the suspension and is worth keeping: option-year architecture is how a compliance requirement reaches a contract you already signed, and it is where a reinstated or reformed requirement would land first.
What to prioritize (revised July 14, 2026): The deadline this section was organized around no longer exists, so the original “kick off by June 2026 or miss the window” arithmetic is withdrawn. It would be false advice today. The revised priority is narrower and, we think, more durable: keep implementing NIST SP 800-171 Rev 2, and make sure your SPRS score is actually supported by your implementation. Those obligations are explicitly unaffected by the suspension, the score carries False Claims Act exposure with or without an assessor, and the 60-day review is chartered to recommend a reformed framework rather than none at all. Pause the C3PAO booking; do not pause the engineering. The CMMC self-assessment vs C3PAO piece explains the assessment paths, and CMMC Phase 2 is suspended covers exactly what survived.
2. DOJ False Claims Act enforcement — the cybersecurity wave is real
The DOJ Cyber Fraud Initiative announced in 2021 is no longer theoretical. 2025 data:
- Eight DOJ cyber-fraud settlements in 2025 — the aggregate settlement value rose roughly 233% year-over-year (about $52M across the year)
- $875,000 — a university research institution settled in September 2025 for submitting a false SPRS score and failing to install anti-malware tools on CUI-handling lab systems
- $421,000 — an Illinois precision machining subcontractor settled in December 2025, reportedly the first cyber-fraud FCA settlement to reach the subcontractor tier rather than a prime
- Acquirer/successor-liability case — an acquirer (Raytheon/Nightwing, ~$8.4M, 2025) held liable for a target’s pre-acquisition cyber violations
The pattern to notice: FCA liability attaches to the certification, not the incident. You don’t need a breach to be actionable. An SPRS score self-asserted at 110 that an assessor would score at 87 is, in DOJ’s reading, a false claim to the government — prosecutable under 31 U.S.C. §§ 3729-3733 even if no data was exfiltrated.
This creates a specific asymmetric risk for subcontractors who told their prime “we’re fully compliant” to win the subcontract and aren’t. The whistleblower incentive (qui tam provisions pay up to 30% of recovery to the relator) creates disgruntled-employee risk that subcontractors historically didn’t have to model.
What to prioritize: Audit your SPRS score against a pre-engagement gap assessment. If the reported score is more than 5-10 points above what an honest third-party assessment would produce, the subcontract is both a contract performance risk and a potential FCA exposure. Remediating before the prime asks is cheaper than remediating after DOJ asks.
3. DFARS cyber clauses — what the CMMC final rule actually changed
The DFARS cybersecurity clauses were not deleted or renumbered in 2026. (An earlier version of this briefing incorrectly reported a “Revolutionary FAR Overhaul” that deleted 7019 and created a clause “252.240-7997”; that did not happen. See the correction in the mid-Q2 update above.) As of the current DFARS, all four clauses remain in force:
- DFARS 252.204-7012 — safeguarding covered defense information, 72-hour incident reporting, cloud computing. Unchanged.
- DFARS 252.204-7019 — Notice of NIST SP 800-171 DoD Assessment Requirements; offerors must have a current Basic self-assessment posted in SPRS. Active.
- DFARS 252.204-7020 — NIST SP 800-171 DoD Assessment Requirements; government access for Medium/High assessments. Active.
- DFARS 252.204-7021 — CMMC requirement. Active and phasing in.
The real regulatory motion is the CMMC final rule (DFARS Case 2019-D041, published September 10, 2025), which adds the CMMC clause (7021) and a new notice clause, 252.204-7025 (Notice of CMMC Level Requirements). It layers CMMC on top of the existing assessment regime rather than deleting the self-assessment clauses.
The strategic direction is unchanged, though the schedule is not: Phase 2 would have made C3PAO-assessed Level 2 the default for CUI contracts from November 10, 2026, which would make CMMC the operative assessment mechanism for most CUI-handling subcontractors. That transition was suspended on July 13, 2026 pending a 60-day review, so the direction stands without a date attached to it. But the parallel 7019/7020 self-assessment clauses still appear in contracts today and were not eliminated. Any subcontractor whose strategy was “hit the SPRS score via 7019 self-assessment and postpone CMMC” should re-read the flowdown in their subcontract; most CUI contracts now invoke 7021.
Our self-assessment vs C3PAO article covers which contracts still accept self-assessment and which require a C3PAO.
4. NIST 800-171 Rev 3 — DoD is staging the transition
NIST 800-171 Rev 3 was published in 2024. DoD has not yet transitioned CMMC Level 2 from Rev 2 to Rev 3 formally. The current 110-practice baseline is still Rev 2. But in April 2025, DoD published Organization-Defined Parameters for Rev 3, specifying values for Rev 3’s 88 ODP placeholders.
The DoD isn’t publishing ODPs for fun. Publishing the parameters before formal rulemaking is the clearest available signal that a Rev 3 transition is intended. It is not a schedule: DoD has published no migration date, 32 CFR 170.2 still incorporates Rev 2, and the CMMC final rule says only that it will amend the rule to incorporate the current version “at that time.” Any specific year attached to this is someone’s forecast. Tier-1 primes are starting to ask subs about Rev 3 readiness in pre-award evaluations even where Rev 2 remains the contractual baseline. Our prime evaluation article covers how this shows up in practice.
Rev 3 structural changes worth knowing:
- Three new control families: Planning (PL), System and Services Acquisition (SA), and Supply Chain Risk Management (SR), aligning with NIST 800-53 Rev 5
- 88 Organization-Defined Parameters allowing organizations to specify implementation details
- Tighter language on several existing controls (access control, audit, configuration management)
What to prioritize: Don’t redesign your control environment for Rev 3 yet. The rulemaking isn’t there, and Rev 2 is the baseline every assessment — self or third-party — is scored against. But do track the Rev 3 / Rev 2 delta for your own environment so when Rev 3 becomes formal, you’re not rediscovering it under deadline.
5. CSP SRG — IL5 is now an NSS level, and V1R7 is current
Correction, August 17, 2026. This section previously ran under the headline “IL5 just got 40% harder,” stated that V1R3 added “approximately 170 additional controls,” and treated V1R3 (2 July 2025) as the current release. The first two are unsourced and the third is four releases out of date.
What is verified, from DISA’s June 2026 SRG package: the current release is Cloud Service Provider SRG, Version 1, Release 7, dated 30 June 2026. The CSP SRG lineage runs V1R1 (14 Jun 2024), V1R2 (30 Jan 2025), V1R3 (2 Jul 2025), V1R4 (13 Aug 2025), V1R5 (3 Sep 2025), V1R6 (10 Dec 2025), V1R7 (30 Jun 2026).
One structural point that gets lost, and that changes which document you should be reading. June 2024 was a split, not a rename. The release memo states it plainly: “The Cloud Computing SRG consist of two parts, a Mission Owners (MO) document and a Cloud Service Provider (CSP) document.” The MO side is itself an Overview plus STIGs, and it carries “the MO responsibilities for DOD CAC/PKI, Active Directory, Endpoint Security, Cloud Storage, Data-at-Rest encryption, and contract requirements for cloud activities.” If you are a CSP, the CSP document is yours; if you are a DoD component consuming a cloud service, a good deal of what you owe is in the MO documents, not the one everyone cites.
The substantive V1R3 change was real and is what people are reaching for when they cite it: Impact Level 5 was re-scoped to Unclassified National Security System/National Security Information, with CUI no longer the defining category. IL5 still reaches CUI — V1R7 section 3.7.3 says it “includes CUI and/or other mission data that may require a higher level of protection than that afforded by Impact Level 4,” with the determination left to the AO — but the level is now built on NSS. The SRG states the baseline relationship as: “Per CNSSP 32, the minimum requirement for all unclassified NSS is equivalent to the FedRAMP High baseline with the additional overlays and NSS controls in CNSSI 1253 Appendix D.”
One thing V1R3 did not do, despite frequently being credited with it: the move from NIST 800-53 Rev 4 to Rev 5 came with the June 2024 release that created the CSP SRG, not with V1R3.
There is no control count in the SRG, at V1R3 or V1R7. The 170 figure and the 40% derived from it are withdrawn rather than replaced; if you need a number for planning it has to come from CNSSI 1253 Appendix D against your own categorization.
On penetration testing: the right is real but narrower than we described. Section 5.14 reads “The DoW will have the authority to perform internal and external penetration testing on all CSP IL6 hosting environments and service offerings at any time using DoW-approved methods in coordination with the CSP.” That is IL6, related control CA-8, and it is standing SRG text rather than an addition by any particular release.
The consequence for cloud service providers is a transition clock rather than a one-time scope jump, and the SRG spells it out at section 4.4: changes are effective immediately on publication; a CSP/CSO whose assessment starts within 30 days of a release is assessed against the previous requirements; a CSO in active assessment proceeds but transitions at its next annual assessment; and a CSO in continuous monitoring must provide a POA&M within 30 days of publication and comply no later than its next annual assessment — “as soon as practical but no longer than between six months and one year.” An existing DoW PA remains in effect for its duration provided those timelines are met.
Our IL5 controls that burn CSPs article carries the same corrections and the eight friction points, worth re-reading if IL5 is on your roadmap. For broader context on the IL4→IL5→IL6 upgrade path, the upgrade path article covers sequencing.
6. ICD 705 — confirm the current Tech Spec revision before you scope
Intelligence Community Directive 705 governs SCIF and SAPF construction, TEMPEST protection, and accreditation. It is implemented through the IC Technical Specifications, a versioned document that ODNI’s National Counterintelligence and Security Center revises periodically. This is the area of the briefing where secondary sources are least reliable, and where we got it wrong ourselves.
Correction, August 17, 2026. An earlier version of this section listed four “material changes” to the IC Tech Specs, including a claim that minimum RF attenuation is “now typically 60 dB… structurally integrated.” We have withdrawn all four. We could not substantiate any of them against a primary source, and the RF figure is affirmatively wrong: the IC Tech Specs contain no decibel figure of any value, and RF protection is not a default requirement at all. What the standard actually says, at Chapter 3, Section C, item 4 of version 1.5.1, is that “RF protection shall be installed at the direction of the CTTA when a SCIF utilizes electronic processing and does not provide adequate RF attenuation at the inspectable space boundary.” The determination sits with the Certified TEMPEST Technical Authority, case by case. The only numeric attenuation ratings anywhere in the document are acoustic Sound Group ratings (STC 45 and STC 50), which are a different physical quantity from RF shielding effectiveness and are the likely origin of the confusion.
We should not have published those four bullets, and we are recording the correction rather than quietly deleting them because the wrong version was live for months and is the kind of number that gets repeated.
What we can substantiate: ODNI’s National Counterintelligence and Security Center maintains the Technical Specifications for ICD/ICS 705 as a versioned document, and the most recent version we can evidence is 1.5.1, dated July 26, 2021, whose own change history records five prior revisions (1.2 in 2012, 1.3 in 2015, 1.4 in 2017, 1.5 in 2019, 1.5.1 in 2021). ICD 705 itself is dated May 26, 2010, with one technical amendment. We are not aware of a published revision after 1.5.1, and we are not going to assert one on the strength of secondary commentary.
The practical guidance is unchanged and does not depend on any of the above: revisions apply to new construction and major renovation rather than retroactively decertifying accredited space, and the revision your facility was accredited against may not be the one your next project is judged against. Confirm the governing revision, and any RF or TEMPEST determination, with your Accrediting Official and the CTTA at project initiation. That is the answer regardless of what any vendor page says the current standard requires.
Our SCIF/SAPF accreditation playbook carries the same correction. The SCIF vs SAPF differences article and, for venture-backed defense startups, the first SCIF article both hold.
7. FedRAMP 20x — Phase 2 wrapped, Phase 3 active
FedRAMP 20x is GSA’s long-promised modernization of the FedRAMP authorization program. Phase 2 wrapped on March 31, 2026 with the targeted ~10 FedRAMP Moderate pilot authorizations completed. Phase 3 (FY26 H2) is now active, expanding 20x to broader adoption for Low and Moderate CSPs.
The structural difference: Key Security Indicators (KSIs). Instead of manual 3PAO attestation against every control, 20x defines machine-verifiable indicators (e.g., “data encrypted at rest with FIPS 140-validated algorithms”) that CSP environments can demonstrate automatically. The goal is faster, cheaper authorizations with less manual review overhead.
Phase 4 (FY27 H1) pilots FedRAMP High. DoD Cloud Computing SRG paths (IL4/IL5/IL6) are not yet in scope for 20x, though the underlying KSI automation direction foreshadows where those assessments will eventually move.
What to prioritize: If FedRAMP Moderate is on your 2026 roadmap, evaluate 20x against the traditional path. Pilot authorizations completed so far are running meaningfully faster than 2024 industry averages. The trade-off: 20x requires more automation tooling and instrumentation than a traditional 3PAO-driven path, so the time savings come with upfront engineering investment.
Our FedRAMP Moderate realistic timeline article still reflects the traditional path; our FedRAMP 20x deep-dive covers the KSI model, the phased rollout, and who should evaluate it.
8. ISO 27001:2013 — the deadline passed (October 31, 2025)
This is old news but the implications are still live. The international transition deadline from ISO/IEC 27001:2013 to ISO/IEC 27001:2022 passed on October 31, 2025. Every active ISO 27001 certification is now the 2022 edition. Any organization still operating on a 2013-era certificate has an invalid certificate — not a deprecated one, not a grace-period one, an invalid one.
If you missed the transition, the path back is a full Stage 1 / Stage 2 audit against the 2022 standard with a new certification body. No shortcut. Transition-audit pathways are no longer available from accredited certification bodies under IAF rules.
For organizations currently holding a valid 2022 certificate, the focus shifts to the four new Annex A themes (organizational, people, physical, technological) and the 11 new Annex A controls introduced in the 2022 edition. Our ISO 27001:2013 to 2022 transition article has been updated with the post-deadline status.
9. GSA CUI requirements for civilian contractors — the parallel track
In January 2026, GSA published new Controlled Unclassified Information security requirements for federal civilian contractors (CIO-IT Security-21-112, Rev 1). The practical effect: a CMMC-like regime is beginning to emerge for civilian agency contracts, parallel to DoD’s CMMC.
The GSA requirements draw from NIST 800-171 (same baseline as CMMC Level 2), with GSA-specific implementation parameters. Civilian-agency contractors handling CUI should expect a formalized assessment and attestation regime within 2-3 years, following a similar pattern to CMMC’s 2019-2026 rollout.
For cloud SaaS vendors whose addressable market includes both DoD and civilian agencies, the strategic implication is that NIST 800-171 compliance is becoming the default federal CUI baseline, not just a DoD obligation. Building toward it once and serving both markets is more efficient than the bifurcated posture most vendors currently run.
10. DoD Zero Trust — Target Level deadline September 30, 2027
The DoD Zero Trust Strategy, published in 2022, set a target-level capability deadline of September 30, 2027. The strategy defines 45 capabilities and 152 activities across seven pillars; the 91 Target Level activities must be demonstrated by the FY27 deadline, with 61 Advanced Level activities extending to a 2032 target.
Pentagon officials continue to publicly affirm the 2027 target, but the practical path is ambitious: 91 distinct Target Level activities across seven pillars (User, Device, Application, Data, Network, Automation, Visibility). A Zero Trust Strategy 2.0 update is expected from the Pentagon in early-to-mid 2026.
For defense contractors, the enforcement mechanism matters: organizations that miss Target Level by September 30, 2027 face contract ineligibility: not award withdrawal of existing contracts, but inability to receive new awards, exercise options, or extend contract periods of performance. Primes are increasingly flowing down Zero Trust readiness requirements into subcontracts ahead of the deadline.
The Zero Trust overlay intersects with CMMC. Several CMMC Level 2 practices map to Zero Trust pillars, but the Zero Trust Target Level demands more than CMMC Level 2 requires. Defense contractors pursuing CMMC Level 2 certification in 2026 should design with Zero Trust Target Level in mind to avoid a second, larger remediation in 2027.
What this means for the next two quarters
Synthesizing across the ten changes above, four operating priorities fall out for compliance-affected organizations this year:
Priority 1 (revised July 14, 2026): Defense subcontractors should keep implementing 800-171 and correct their SPRS score. The certification deadline is gone; the obligations are not. This priority originally read “close your CMMC engagement gap this quarter or accept Phase 2 exposure,” on the arithmetic that a 6–9 month engagement had to start by June 2026 to clear the November 10 cliff. That cliff was suspended on July 13, 2026, so that advice is withdrawn. The exposure that remains is the one that always had teeth: DFARS 252.204-7012 safeguarding and 72-hour reporting are still in effect, NIST SP 800-171 Rev 2 is still enforced through self-assessment, and a false or unsupported SPRS score is a False Claims Act problem whether or not a C3PAO ever visits.
Priority 2: Cloud SaaS on an IL5 path should re-baseline against CSP SRG V1R7 and diary the section 4.4 clock. The CNSSI 1253 Appendix D overlay on top of FedRAMP High is not marginal, and four releases have landed since the V1R3 most published commentary still cites. If you are in continuous monitoring, the SRG gives you 30 days from a release to file a POA&M and no longer than your next annual assessment to comply.
Priority 3: Organizations with older SCIFs should confirm the current IC Tech Spec revision with their Accrediting Official before scoping any renovation. Tech Spec revisions apply to new construction and major renovation rather than retroactively decertifying accredited space, but the revision your facility was built to is not necessarily the one your next project is judged against. Early engagement with accrediting authorities produces better outcomes than late-stage remediation.
Priority 4: False Claims Act exposure on SPRS scores is a board-level risk, not a compliance-team housekeeping item. Any organization where the gap between reported and assessable SPRS score exceeds ten points should treat it as an active legal exposure.
For most organizations, the right operating response is not one engagement but a coordinated compliance posture review across the dimensions that changed: CMMC readiness, SPRS-score accuracy, cloud-assessment scope, SCIF architectural status, and Zero Trust Target Level gap. Running these in isolation produces duplicative work and misses the dependencies between them.
If you want an outside read on where your specific situation sits across these changes, book a 30-minute scoping call. If we can give you the view in thirty minutes without an engagement, we will. If the situation warrants an engagement, we’ll scope it honestly against a realistic timeline.
Primary sources for the items above. This briefing paraphrases a lot of rulemaking; here is where to check us.
- CMMC. 32 CFR Part 170 (not rescinded), 170.2 (incorporates NIST SP 800-171 Rev 2), 170.21 (conditional status and POA&M limits), 170.22 (annual affirmation), 170.24 (scoring). Population estimates: Table 5 of the CMMC final rule, 89 FR 83176. The July 13, 2026 suspension memoranda (case 26-P-1023) are quoted at length in our primary-source read because they are not at a stable public URL we can link.
- DFARS clauses. 252.204-7012, -7019, -7020 — all three still live, which is the point of the correction in the June 5 block above.
- DCSA / cleared contractors. GAO-26-107861, April 24, 2026, is the source of every figure in section 1 of the May 8 update. The program it audits is 32 CFR Part 117.
- FedRAMP. Consolidated Rules for 2026 and its Important Dates; Certification Classes (read this before believing anyone who tells you a class is a renamed impact level); notices NTC-0012, NTC-0013, NTC-0014. The Joint Authorization Board’s replacement by the FedRAMP Board is documented at FedRAMP Governance.
- CISA. BOD 26-04 and the KEV catalog.
- ICD 705. Deliberately not linked to a summary. See the correction in section 6; take the governing revision from your Accrediting Official.
Related reading:
- CMMC Level 2 real cost breakdown — engagement, tooling, C3PAO, and year-2 costs with specific ranges
- How primes evaluate CMMC-certified subs — SPRS thresholds, SSP review, POA&M scrutiny, audit rights
- Why 30-day compliance claims are misleading — the positioning article this briefing complements
- DFARS 7012 incident reporting gap — the 72-hour reporting obligation and current DFARS clause state
- FedRAMP Moderate realistic timeline — traditional path; 20x-specific piece in the pipeline
- IL5 assessment controls that burn CSPs first — the eight friction points, corrected against CSP SRG V1R7
- SCIF/SAPF accreditation playbook — the design-through-accreditation arc, and what the IC Tech Specs do and do not specify
This briefing is written as a reference document that we refresh quarterly. The next update is anchored to the CMMC Reform Task Force output, which a 60-day clock from July 13 puts around mid-September 2026 — that is the event that determines whether Phase 2 returns, returns reshaped, or is replaced. Also on the list: FedRAMP CR26 adoption ahead of the January 1, 2027 mandatory date and the December 7, 2026 VDR/VER deadline, ISO 27017 second-edition publication, the Pentagon’s Zero Trust Strategy 2.0 release, and any further DOJ cyber-fraud settlements.