Fortinetics Book a call →
Menu
Cross-cutting · · · 14 min read

What changed in compliance — Q2 2026 briefing: CMMC Phase 2, DOJ enforcement, ICD 705, FedRAMP 20x, and the DoD Zero Trust cliff

A practitioner briefing on the most consequential compliance-landscape changes heading into Q2 2026. Covers the CMMC Phase 2 transition originally set for November 10, 2026 and SUSPENDED on July 13, 2026, the DOJ False Claims Act enforcement wave against defense contractors, the CSP SRG releases that re-scoped IL5 to unclassified National Security Systems, why no ICD 705 revision date should be taken on trust, FedRAMP 20x Phase 2 pilots, the CMMC final rule's new DFARS clauses, NIST 800-171 Rev 3 organization-defined parameters, the expired ISO 27001:2013 certification baseline, GSA's new civilian-contractor CUI requirements, and DoD Zero Trust's September 30, 2027 Target Level deadline.

Mid-Q3 update — July 14, 2026. The headline of this briefing has been overtaken by events.

(1) CMMC Phase 2 is suspended. On July 13, 2026 the Department of War CIO suspended the November 2026 Phase 2 transition and held all pending and future CMMC implementation milestones in abeyance until further notice, pending a 60-day review by a new CMMC Reform Task Force. Program managers may designate only Level 1 (Self) or Level 2 (Self) assessments, not Level 2 (C3PAO) or Level 3 (DIBCAC). Solicitations and contracts carrying those requirements are directed to be amended or modified to remove them, and no waivers will be granted during the review. This supersedes the November 10, 2026 cliff that section 1 below is built around, and the timing advice in section 1 and Priority 1 is withdrawn. What did not change: DFARS 252.204-7012 safeguarding and 72-hour reporting are explicitly still in effect, NIST SP 800-171 Rev 2 remains the enforced baseline via self-assessment, and False Claims Act exposure still attaches to the SPRS score you affirmed. Primary-source read of both memos: CMMC Phase 2 is suspended. The associated RFI, “Reforming CMMC and Reducing Compliance Burden for the Defense Industrial Base (DIB),” closed to responses on August 14, 2026. What remains outstanding is the Task Force output itself; a 60-day clock from July 13 lands around mid-September 2026.

(2) FedRAMP released the Consolidated Rules for 2026 (CR26) on June 24, 2026. CR26 consolidates the 20x requirements into one versioned, machine-readable ruleset and resets how every submission, Rev 5 included, is reviewed. Optional early adoption opened July 4, 2026; it is mandatory for all stakeholders January 1, 2027; no new Rev 5 applications after June 11, 2027. It carries three component notices: NTC-0012 (incident communications), NTC-0013 (Rev 5 baseline rebuild), and NTC-0014 (VDR/VER vulnerability rules, mandatory December 7, 2026). Start here: the CR26 explainer. This closes out the “FedRAMP Phase 3 finalization” item promised below.

(3) NDAA Section 1513 — no confirmed submission. The June 16, 2026 deadline for DoD’s AI-security plan to Congress has passed. We can find no primary-source evidence that the report was actually delivered: no congressional record, no DoD CIO publication. We are not going to report a submission we cannot verify; the item stays open. Background: AI is coming to CMMC.

(4) A note on the readiness statistics below. Sections 1 and 3 cite “fewer than 1,100 certified as of February 2026.” The more current figure is ~1,042 of ~76,600 organizations (~1.4%) as of May 2026, cited in item (3) of the June 5 update. Both are approximately the same readiness rate, and that rate is a large part of why the program was just suspended. The capacity arithmetic never cleared.

Mid-Q2 update — June 5, 2026. Four further developments worth flagging since the May 8 update:

(1) FedRAMP renamed “Authorization” to “Certification” (May 4, 2026) and replaced the Low/Moderate/High impact-level terminology with Classes A/B/C/D. The substantive control baselines are unchanged; this is a terminology overhaul. Every piece of FedRAMP marketing copy, every SSP cover sheet, and every customer-facing FedRAMP claim on the open web is now subtly out-of-date until refreshed. Our FedRAMP Moderate realistic timeline and the Rev 5 series carry a footnote on the rename.

(2) Executive Order “Promoting Advanced AI Innovation and Security” — signed June 2, 2026. Directs federal agencies, within 30 days (by July 2, 2026), to prepare federal and private-sector systems for advanced AI; Committee on National Security Systems prioritizes NSS cyber defense; Treasury must stand up an AI Cybersecurity Clearinghouse for voluntary industry / critical-infrastructure participation. Combined with NDAA FY26 Section 1513, which requires DoD to deliver a CMMC-for-AI framework plan to Congress by June 16, 2026, this is the first formal signal that AI/ML security obligations will become a CMMC scope expansion lane in 2027-2028.

(3) CMMC narrative shifts from “planning” to “enforcement.” June 2026 trade-press reporting (Federal News Network) now reframes the program: primes are flowing CMMC requirements down on tight deadlines, contracting officers signal at the solicitation stage, and the capacity arithmetic has hardened. 92 authorized C3PAOs as of December 2025 per GAO, against a population of ~76,600 organizations needing Level 2; only ~1,042 organizations (1.4%) have completed certification as of May 2026. Industry reporting cites wait times exceeding 18 months for new clients by Q3 2026. The “C3PAO scarcity is the binding constraint” framing in our Realistic CMMC Level 2 Timeline is now the dominant practitioner narrative.

(4) DCSA system “under strain” + GAO follow-on. May 2026 Federal News Network reporting flagged that DoD’s classified-information protection regime for cleared contractors is buckling under resource constraints. Director Cattler retired Sept 30, 2025; Justin Overbaugh is acting; NBIS remains years behind schedule and over budget. Combined with the April 2026 GAO 815-violations report (covered in the May 8 update), the picture is one of accelerating enforcement expectations against a regulator that covers only 25-30% of cleared facilities annually. Our DCSA 815 analysis carries the GAO data; the strain narrative is a Q3 article in our pipeline.

(5) Correction — DFARS 7019/7020 were not deleted or renumbered. An earlier version of this briefing reported a “February 2026 Revolutionary FAR Overhaul” that deleted DFARS 252.204-7019 and renumbered 252.204-7020 to “252.240-7997.” That was incorrect: per acquisition.gov, both 252.204-7019 and 252.204-7020 remain active and in force, and no clause “252.240-7997” exists. The real change is the CMMC final rule (DFARS Case 2019-D041, September 10, 2025), which layers CMMC (252.204-7021) plus a new notice clause, 252.204-7025, on top of the existing assessment clauses rather than replacing them. Section 3 below has been corrected.

(6) NIST 800-171 Rev 3 rulemaking — trade-press expectation only. April-May 2026 trade press converged on a near-term rulemaking window. Do not plan against it. DoD has published no migration date: 32 CFR 170.2 still incorporates Rev 2, and the CMMC final rule says only that Rev 3 “is not currently applicable to this rule.” Rev 2 is the assessed baseline and stayed so through the July 13 suspension, which explicitly kept Rev 2 enforced via self-assessment. Tier-1 primes are nonetheless asking subs about Rev 3 readiness in pre-award evaluations. Our how primes evaluate CMMC subs covers the operational pattern.

(Written June 5, this block promised a Mid-Q3 update covering FedRAMP Phase 3 finalization, DoD’s response to the NDAA Section 1513 deadline, ISO 27017 second-edition publication, and new DOJ FCA settlements. The July 14 block above landed early and closed the first two — CR26 superseded the Phase 3 item, and Section 1513 remains unverified rather than unaddressed. ISO 27017 second edition and the FCA settlement count are still open.)

Updated May 8, 2026. Two material developments since this briefing first published:

(1) GAO Report 26-107861 (April 24, 2026) documented 815 security violations across 4,600+ DCSA cleared-contractor security reviews in FY2025, plus 1,032 open security vulnerabilities. Distribution: data spills ~60%, improper storage 11.5%, unauthorized access 6.5%, physical losses 6.3%, improper transfers 5.6%. DCSA’s review capacity covers only 25-30% of the cleared industrial base in any fiscal year, and industrial security funding has remained “relatively flat” while personnel-vetting funding increased. Real annual industry violation count, extrapolated, is probably 2,500-3,300. Our DCSA 815 violations analysis walks through each category and the architectural patterns that prevent them.

(2) L3Harris insider-threat case (May 8, 2026). Peter Williams, formerly head of L3Harris’s offensive cyber tooling division, ordered to pay $10M restitution for stealing surveillance and hacking tools and selling them for $1.3M to a Russian broker. Reinforces the personnel-security control family (NIST 800-171 3.9) as a real risk vector for cleared and CUI-handling contractors, not just a paper requirement.

Neither development changes the strategic conclusions below, but both are evidence that the policy direction (more enforcement, more visibility on contractor failures) is producing observable consequences month-over-month, not just at policy-cycle inflection points.

The first half of 2026 has been the most consequential compliance-landscape quarter since the original DFARS 252.204-7012 rollout in 2017. Multiple large-scale regulatory shifts have landed in a narrow window: a new CMMC enforcement posture, the CMMC final rule layering new clauses onto the DFARS framework that underpins CUI handling, a step-change in DoD cloud-provider requirements, an accelerating DOJ enforcement program with the first defense-subcontractor False Claims Act settlement, and the quiet staging of the NIST 800-171 Rev 3 transition.

This briefing is a practitioner’s view of what changed, what it means for each buyer profile (defense subcontractor, cloud SaaS, classified-work contractor, commercial vendor with federal exposure), and what to prioritize over the next two quarters. The article is built from primary rulemaking review, DoD and Cyber AB communications, and pattern-recognition across engagements we’ve run this year.

A single-sentence TL;DR for each reader:

  • Defense subcontractors: Phase 2 was suspended on July 13, 2026, but 7012, NIST 800-171 Rev 2, and the SPRS score you affirmed all still bind you, so the security work does not stop.
  • Cloud SaaS: FedRAMP 20x is finally real, IL5 is now an unclassified-NSS level built on a FedRAMP High floor, and the CSP SRG is at V1R7 — check which release your last assessment was against.
  • Classified-work contractors: ICD 705 Tech Specs are revised periodically; confirm the current revision with your Accrediting Official before scoping a renovation.
  • Commercial SaaS with federal exposure: ISO 27001:2013 is dead, GSA added CUI requirements for civilian contractors, and DOJ is actively pursuing false SPRS scores under the FCA.

The rest of the article unpacks each, with citations to primary sources where useful.

1. CMMC Phase 2 — suspended July 13, 2026 (was November 10, 2026)

Superseded — read this first. This section was written around November 10, 2026 as the single most important date in DoD compliance this year. On July 13, 2026 that transition was suspended and all pending CMMC implementation milestones were held in abeyance pending a 60-day review. The capacity analysis below is left standing because it is the reason the program was suspended, but the deadline framing and the timing advice are withdrawn. See CMMC Phase 2 is suspended for what still binds you.

The plan, until July 13, was this: on November 10, 2026, CMMC Phase 2 would activate, contracting officers would require C3PAO-assessed Level 2 certification by default for contracts involving CUI, and self-assessment would cease to satisfy the DFARS 252.204-7021 obligation for the majority of subcontractors handling CUI. During the suspension the reverse is true: program managers may designate only self-assessment (Level 1 or Level 2), and may not designate C3PAO or DIBCAC assessment at all.

The capacity math is the alarming part. DoD estimates 76,000+ organizations need Level 2 certification to continue serving defense primes. As of February 2026, fewer than 1,100 had completed it — roughly 1.4% readiness against a deadline now under six months out. C3PAO assessor capacity is the binding constraint. Our CMMC Level 2 timeline article lays out what a realistic engagement looks like month-by-month.

Under the same superseded schedule, Phase 3 (November 10, 2027) would have extended the mandate to option exercises on existing contracts, with no grandfathering for contracts awarded earlier that carried option years past November 2027. That milestone is held in abeyance along with everything else, so there is currently no date by which an option exercise requires a certificate. The underlying structural point survives the suspension and is worth keeping: option-year architecture is how a compliance requirement reaches a contract you already signed, and it is where a reinstated or reformed requirement would land first.

What to prioritize (revised July 14, 2026): The deadline this section was organized around no longer exists, so the original “kick off by June 2026 or miss the window” arithmetic is withdrawn. It would be false advice today. The revised priority is narrower and, we think, more durable: keep implementing NIST SP 800-171 Rev 2, and make sure your SPRS score is actually supported by your implementation. Those obligations are explicitly unaffected by the suspension, the score carries False Claims Act exposure with or without an assessor, and the 60-day review is chartered to recommend a reformed framework rather than none at all. Pause the C3PAO booking; do not pause the engineering. The CMMC self-assessment vs C3PAO piece explains the assessment paths, and CMMC Phase 2 is suspended covers exactly what survived.

2. DOJ False Claims Act enforcement — the cybersecurity wave is real

The DOJ Cyber Fraud Initiative announced in 2021 is no longer theoretical. 2025 data:

  • Eight DOJ cyber-fraud settlements in 2025 — the aggregate settlement value rose roughly 233% year-over-year (about $52M across the year)
  • $875,000 — a university research institution settled in September 2025 for submitting a false SPRS score and failing to install anti-malware tools on CUI-handling lab systems
  • $421,000 — an Illinois precision machining subcontractor settled in December 2025, reportedly the first cyber-fraud FCA settlement to reach the subcontractor tier rather than a prime
  • Acquirer/successor-liability case — an acquirer (Raytheon/Nightwing, ~$8.4M, 2025) held liable for a target’s pre-acquisition cyber violations

The pattern to notice: FCA liability attaches to the certification, not the incident. You don’t need a breach to be actionable. An SPRS score self-asserted at 110 that an assessor would score at 87 is, in DOJ’s reading, a false claim to the government — prosecutable under 31 U.S.C. §§ 3729-3733 even if no data was exfiltrated.

This creates a specific asymmetric risk for subcontractors who told their prime “we’re fully compliant” to win the subcontract and aren’t. The whistleblower incentive (qui tam provisions pay up to 30% of recovery to the relator) creates disgruntled-employee risk that subcontractors historically didn’t have to model.

What to prioritize: Audit your SPRS score against a pre-engagement gap assessment. If the reported score is more than 5-10 points above what an honest third-party assessment would produce, the subcontract is both a contract performance risk and a potential FCA exposure. Remediating before the prime asks is cheaper than remediating after DOJ asks.

3. DFARS cyber clauses — what the CMMC final rule actually changed

The DFARS cybersecurity clauses were not deleted or renumbered in 2026. (An earlier version of this briefing incorrectly reported a “Revolutionary FAR Overhaul” that deleted 7019 and created a clause “252.240-7997”; that did not happen. See the correction in the mid-Q2 update above.) As of the current DFARS, all four clauses remain in force:

  • DFARS 252.204-7012 — safeguarding covered defense information, 72-hour incident reporting, cloud computing. Unchanged.
  • DFARS 252.204-7019 — Notice of NIST SP 800-171 DoD Assessment Requirements; offerors must have a current Basic self-assessment posted in SPRS. Active.
  • DFARS 252.204-7020 — NIST SP 800-171 DoD Assessment Requirements; government access for Medium/High assessments. Active.
  • DFARS 252.204-7021 — CMMC requirement. Active and phasing in.

The real regulatory motion is the CMMC final rule (DFARS Case 2019-D041, published September 10, 2025), which adds the CMMC clause (7021) and a new notice clause, 252.204-7025 (Notice of CMMC Level Requirements). It layers CMMC on top of the existing assessment regime rather than deleting the self-assessment clauses.

The strategic direction is unchanged, though the schedule is not: Phase 2 would have made C3PAO-assessed Level 2 the default for CUI contracts from November 10, 2026, which would make CMMC the operative assessment mechanism for most CUI-handling subcontractors. That transition was suspended on July 13, 2026 pending a 60-day review, so the direction stands without a date attached to it. But the parallel 7019/7020 self-assessment clauses still appear in contracts today and were not eliminated. Any subcontractor whose strategy was “hit the SPRS score via 7019 self-assessment and postpone CMMC” should re-read the flowdown in their subcontract; most CUI contracts now invoke 7021.

Our self-assessment vs C3PAO article covers which contracts still accept self-assessment and which require a C3PAO.

4. NIST 800-171 Rev 3 — DoD is staging the transition

NIST 800-171 Rev 3 was published in 2024. DoD has not yet transitioned CMMC Level 2 from Rev 2 to Rev 3 formally. The current 110-practice baseline is still Rev 2. But in April 2025, DoD published Organization-Defined Parameters for Rev 3, specifying values for Rev 3’s 88 ODP placeholders.

The DoD isn’t publishing ODPs for fun. Publishing the parameters before formal rulemaking is the clearest available signal that a Rev 3 transition is intended. It is not a schedule: DoD has published no migration date, 32 CFR 170.2 still incorporates Rev 2, and the CMMC final rule says only that it will amend the rule to incorporate the current version “at that time.” Any specific year attached to this is someone’s forecast. Tier-1 primes are starting to ask subs about Rev 3 readiness in pre-award evaluations even where Rev 2 remains the contractual baseline. Our prime evaluation article covers how this shows up in practice.

Rev 3 structural changes worth knowing:

  • Three new control families: Planning (PL), System and Services Acquisition (SA), and Supply Chain Risk Management (SR), aligning with NIST 800-53 Rev 5
  • 88 Organization-Defined Parameters allowing organizations to specify implementation details
  • Tighter language on several existing controls (access control, audit, configuration management)

What to prioritize: Don’t redesign your control environment for Rev 3 yet. The rulemaking isn’t there, and Rev 2 is the baseline every assessment — self or third-party — is scored against. But do track the Rev 3 / Rev 2 delta for your own environment so when Rev 3 becomes formal, you’re not rediscovering it under deadline.

5. CSP SRG — IL5 is now an NSS level, and V1R7 is current

Correction, August 17, 2026. This section previously ran under the headline “IL5 just got 40% harder,” stated that V1R3 added “approximately 170 additional controls,” and treated V1R3 (2 July 2025) as the current release. The first two are unsourced and the third is four releases out of date.

What is verified, from DISA’s June 2026 SRG package: the current release is Cloud Service Provider SRG, Version 1, Release 7, dated 30 June 2026. The CSP SRG lineage runs V1R1 (14 Jun 2024), V1R2 (30 Jan 2025), V1R3 (2 Jul 2025), V1R4 (13 Aug 2025), V1R5 (3 Sep 2025), V1R6 (10 Dec 2025), V1R7 (30 Jun 2026).

One structural point that gets lost, and that changes which document you should be reading. June 2024 was a split, not a rename. The release memo states it plainly: “The Cloud Computing SRG consist of two parts, a Mission Owners (MO) document and a Cloud Service Provider (CSP) document.” The MO side is itself an Overview plus STIGs, and it carries “the MO responsibilities for DOD CAC/PKI, Active Directory, Endpoint Security, Cloud Storage, Data-at-Rest encryption, and contract requirements for cloud activities.” If you are a CSP, the CSP document is yours; if you are a DoD component consuming a cloud service, a good deal of what you owe is in the MO documents, not the one everyone cites.

The substantive V1R3 change was real and is what people are reaching for when they cite it: Impact Level 5 was re-scoped to Unclassified National Security System/National Security Information, with CUI no longer the defining category. IL5 still reaches CUI — V1R7 section 3.7.3 says it “includes CUI and/or other mission data that may require a higher level of protection than that afforded by Impact Level 4,” with the determination left to the AO — but the level is now built on NSS. The SRG states the baseline relationship as: “Per CNSSP 32, the minimum requirement for all unclassified NSS is equivalent to the FedRAMP High baseline with the additional overlays and NSS controls in CNSSI 1253 Appendix D.”

One thing V1R3 did not do, despite frequently being credited with it: the move from NIST 800-53 Rev 4 to Rev 5 came with the June 2024 release that created the CSP SRG, not with V1R3.

There is no control count in the SRG, at V1R3 or V1R7. The 170 figure and the 40% derived from it are withdrawn rather than replaced; if you need a number for planning it has to come from CNSSI 1253 Appendix D against your own categorization.

On penetration testing: the right is real but narrower than we described. Section 5.14 reads “The DoW will have the authority to perform internal and external penetration testing on all CSP IL6 hosting environments and service offerings at any time using DoW-approved methods in coordination with the CSP.” That is IL6, related control CA-8, and it is standing SRG text rather than an addition by any particular release.

The consequence for cloud service providers is a transition clock rather than a one-time scope jump, and the SRG spells it out at section 4.4: changes are effective immediately on publication; a CSP/CSO whose assessment starts within 30 days of a release is assessed against the previous requirements; a CSO in active assessment proceeds but transitions at its next annual assessment; and a CSO in continuous monitoring must provide a POA&M within 30 days of publication and comply no later than its next annual assessment — “as soon as practical but no longer than between six months and one year.” An existing DoW PA remains in effect for its duration provided those timelines are met.

Our IL5 controls that burn CSPs article carries the same corrections and the eight friction points, worth re-reading if IL5 is on your roadmap. For broader context on the IL4→IL5→IL6 upgrade path, the upgrade path article covers sequencing.

6. ICD 705 — confirm the current Tech Spec revision before you scope

Intelligence Community Directive 705 governs SCIF and SAPF construction, TEMPEST protection, and accreditation. It is implemented through the IC Technical Specifications, a versioned document that ODNI’s National Counterintelligence and Security Center revises periodically. This is the area of the briefing where secondary sources are least reliable, and where we got it wrong ourselves.

Correction, August 17, 2026. An earlier version of this section listed four “material changes” to the IC Tech Specs, including a claim that minimum RF attenuation is “now typically 60 dB… structurally integrated.” We have withdrawn all four. We could not substantiate any of them against a primary source, and the RF figure is affirmatively wrong: the IC Tech Specs contain no decibel figure of any value, and RF protection is not a default requirement at all. What the standard actually says, at Chapter 3, Section C, item 4 of version 1.5.1, is that “RF protection shall be installed at the direction of the CTTA when a SCIF utilizes electronic processing and does not provide adequate RF attenuation at the inspectable space boundary.” The determination sits with the Certified TEMPEST Technical Authority, case by case. The only numeric attenuation ratings anywhere in the document are acoustic Sound Group ratings (STC 45 and STC 50), which are a different physical quantity from RF shielding effectiveness and are the likely origin of the confusion.

We should not have published those four bullets, and we are recording the correction rather than quietly deleting them because the wrong version was live for months and is the kind of number that gets repeated.

What we can substantiate: ODNI’s National Counterintelligence and Security Center maintains the Technical Specifications for ICD/ICS 705 as a versioned document, and the most recent version we can evidence is 1.5.1, dated July 26, 2021, whose own change history records five prior revisions (1.2 in 2012, 1.3 in 2015, 1.4 in 2017, 1.5 in 2019, 1.5.1 in 2021). ICD 705 itself is dated May 26, 2010, with one technical amendment. We are not aware of a published revision after 1.5.1, and we are not going to assert one on the strength of secondary commentary.

The practical guidance is unchanged and does not depend on any of the above: revisions apply to new construction and major renovation rather than retroactively decertifying accredited space, and the revision your facility was accredited against may not be the one your next project is judged against. Confirm the governing revision, and any RF or TEMPEST determination, with your Accrediting Official and the CTTA at project initiation. That is the answer regardless of what any vendor page says the current standard requires.

Our SCIF/SAPF accreditation playbook carries the same correction. The SCIF vs SAPF differences article and, for venture-backed defense startups, the first SCIF article both hold.

7. FedRAMP 20x — Phase 2 wrapped, Phase 3 active

FedRAMP 20x is GSA’s long-promised modernization of the FedRAMP authorization program. Phase 2 wrapped on March 31, 2026 with the targeted ~10 FedRAMP Moderate pilot authorizations completed. Phase 3 (FY26 H2) is now active, expanding 20x to broader adoption for Low and Moderate CSPs.

The structural difference: Key Security Indicators (KSIs). Instead of manual 3PAO attestation against every control, 20x defines machine-verifiable indicators (e.g., “data encrypted at rest with FIPS 140-validated algorithms”) that CSP environments can demonstrate automatically. The goal is faster, cheaper authorizations with less manual review overhead.

Phase 4 (FY27 H1) pilots FedRAMP High. DoD Cloud Computing SRG paths (IL4/IL5/IL6) are not yet in scope for 20x, though the underlying KSI automation direction foreshadows where those assessments will eventually move.

What to prioritize: If FedRAMP Moderate is on your 2026 roadmap, evaluate 20x against the traditional path. Pilot authorizations completed so far are running meaningfully faster than 2024 industry averages. The trade-off: 20x requires more automation tooling and instrumentation than a traditional 3PAO-driven path, so the time savings come with upfront engineering investment.

Our FedRAMP Moderate realistic timeline article still reflects the traditional path; our FedRAMP 20x deep-dive covers the KSI model, the phased rollout, and who should evaluate it.

8. ISO 27001:2013 — the deadline passed (October 31, 2025)

This is old news but the implications are still live. The international transition deadline from ISO/IEC 27001:2013 to ISO/IEC 27001:2022 passed on October 31, 2025. Every active ISO 27001 certification is now the 2022 edition. Any organization still operating on a 2013-era certificate has an invalid certificate — not a deprecated one, not a grace-period one, an invalid one.

If you missed the transition, the path back is a full Stage 1 / Stage 2 audit against the 2022 standard with a new certification body. No shortcut. Transition-audit pathways are no longer available from accredited certification bodies under IAF rules.

For organizations currently holding a valid 2022 certificate, the focus shifts to the four new Annex A themes (organizational, people, physical, technological) and the 11 new Annex A controls introduced in the 2022 edition. Our ISO 27001:2013 to 2022 transition article has been updated with the post-deadline status.

9. GSA CUI requirements for civilian contractors — the parallel track

In January 2026, GSA published new Controlled Unclassified Information security requirements for federal civilian contractors (CIO-IT Security-21-112, Rev 1). The practical effect: a CMMC-like regime is beginning to emerge for civilian agency contracts, parallel to DoD’s CMMC.

The GSA requirements draw from NIST 800-171 (same baseline as CMMC Level 2), with GSA-specific implementation parameters. Civilian-agency contractors handling CUI should expect a formalized assessment and attestation regime within 2-3 years, following a similar pattern to CMMC’s 2019-2026 rollout.

For cloud SaaS vendors whose addressable market includes both DoD and civilian agencies, the strategic implication is that NIST 800-171 compliance is becoming the default federal CUI baseline, not just a DoD obligation. Building toward it once and serving both markets is more efficient than the bifurcated posture most vendors currently run.

10. DoD Zero Trust — Target Level deadline September 30, 2027

The DoD Zero Trust Strategy, published in 2022, set a target-level capability deadline of September 30, 2027. The strategy defines 45 capabilities and 152 activities across seven pillars; the 91 Target Level activities must be demonstrated by the FY27 deadline, with 61 Advanced Level activities extending to a 2032 target.

Pentagon officials continue to publicly affirm the 2027 target, but the practical path is ambitious: 91 distinct Target Level activities across seven pillars (User, Device, Application, Data, Network, Automation, Visibility). A Zero Trust Strategy 2.0 update is expected from the Pentagon in early-to-mid 2026.

For defense contractors, the enforcement mechanism matters: organizations that miss Target Level by September 30, 2027 face contract ineligibility: not award withdrawal of existing contracts, but inability to receive new awards, exercise options, or extend contract periods of performance. Primes are increasingly flowing down Zero Trust readiness requirements into subcontracts ahead of the deadline.

The Zero Trust overlay intersects with CMMC. Several CMMC Level 2 practices map to Zero Trust pillars, but the Zero Trust Target Level demands more than CMMC Level 2 requires. Defense contractors pursuing CMMC Level 2 certification in 2026 should design with Zero Trust Target Level in mind to avoid a second, larger remediation in 2027.

What this means for the next two quarters

Synthesizing across the ten changes above, four operating priorities fall out for compliance-affected organizations this year:

Priority 1 (revised July 14, 2026): Defense subcontractors should keep implementing 800-171 and correct their SPRS score. The certification deadline is gone; the obligations are not. This priority originally read “close your CMMC engagement gap this quarter or accept Phase 2 exposure,” on the arithmetic that a 6–9 month engagement had to start by June 2026 to clear the November 10 cliff. That cliff was suspended on July 13, 2026, so that advice is withdrawn. The exposure that remains is the one that always had teeth: DFARS 252.204-7012 safeguarding and 72-hour reporting are still in effect, NIST SP 800-171 Rev 2 is still enforced through self-assessment, and a false or unsupported SPRS score is a False Claims Act problem whether or not a C3PAO ever visits.

Priority 2: Cloud SaaS on an IL5 path should re-baseline against CSP SRG V1R7 and diary the section 4.4 clock. The CNSSI 1253 Appendix D overlay on top of FedRAMP High is not marginal, and four releases have landed since the V1R3 most published commentary still cites. If you are in continuous monitoring, the SRG gives you 30 days from a release to file a POA&M and no longer than your next annual assessment to comply.

Priority 3: Organizations with older SCIFs should confirm the current IC Tech Spec revision with their Accrediting Official before scoping any renovation. Tech Spec revisions apply to new construction and major renovation rather than retroactively decertifying accredited space, but the revision your facility was built to is not necessarily the one your next project is judged against. Early engagement with accrediting authorities produces better outcomes than late-stage remediation.

Priority 4: False Claims Act exposure on SPRS scores is a board-level risk, not a compliance-team housekeeping item. Any organization where the gap between reported and assessable SPRS score exceeds ten points should treat it as an active legal exposure.

For most organizations, the right operating response is not one engagement but a coordinated compliance posture review across the dimensions that changed: CMMC readiness, SPRS-score accuracy, cloud-assessment scope, SCIF architectural status, and Zero Trust Target Level gap. Running these in isolation produces duplicative work and misses the dependencies between them.

If you want an outside read on where your specific situation sits across these changes, book a 30-minute scoping call. If we can give you the view in thirty minutes without an engagement, we will. If the situation warrants an engagement, we’ll scope it honestly against a realistic timeline.


Primary sources for the items above. This briefing paraphrases a lot of rulemaking; here is where to check us.

Related reading:

This briefing is written as a reference document that we refresh quarterly. The next update is anchored to the CMMC Reform Task Force output, which a 60-day clock from July 13 puts around mid-September 2026 — that is the event that determines whether Phase 2 returns, returns reshaped, or is replaced. Also on the list: FedRAMP CR26 adoption ahead of the January 1, 2027 mandatory date and the December 7, 2026 VDR/VER deadline, ISO 27017 second-edition publication, the Pentagon’s Zero Trust Strategy 2.0 release, and any further DOJ cyber-fraud settlements.

Frequently asked

Common questions.

What's the single most important compliance change for defense contractors in 2026?
As of July 13, 2026, it is the suspension of CMMC Phase 2 itself. The Department of War CIO suspended the November 2026 transition to Phase 2 and held all pending and future CMMC implementation milestones in abeyance pending a 60-day review. Program managers may now designate only CMMC Level 1 (Self) or Level 2 (Self) assessments, not Level 2 (C3PAO) or Level 3 (DIBCAC), and solicitations and contracts already carrying those requirements are directed to be amended or modified to remove them. No waivers are granted during the review. This does not relieve the underlying obligations: DFARS 252.204-7012 safeguarding and 72-hour incident reporting remain explicitly in effect, NIST SP 800-171 Rev 2 is still enforced through self-assessment, and False Claims Act liability still attaches to the SPRS score you affirmed. The previous answer to this question was the November 10, 2026 Phase 2 cliff; that has been overtaken by events.
Is the DOJ actually enforcing cyber compliance under the False Claims Act?
Yes, and the pace is accelerating. DOJ resolved eight cyber-fraud settlements in 2025, with aggregate settlement value up roughly 233% over 2024. Settlements included an $875K resolution with a university research institution for a false SPRS score and missing anti-malware tools, and a $421K settlement (December 2025) with an Illinois precision machining subcontractor, reportedly the first cyber-fraud settlement to reach the subcontractor tier rather than a prime. FCA liability attaches to false certifications even without a cyberattack or data breach. Overstating an SPRS score is actionable on its own.
What changed in the DoD Cloud Computing SRG for IL5 cloud service providers?
CSP SRG V1R3 (2 July 2025) re-scoped Impact Level 5 to Unclassified National Security System/National Security Information, so IL5 Cloud Service Offerings implement the CNSSI 1253 Appendix D overlays and NSS controls on top of a FedRAMP High floor (per CNSSP 32). Two corrections to what we previously published here: the SRG contains no control count, so the 'approximately 170 new controls / 40%' figure we cited is withdrawn as unsourced; and the government right to perform internal and external penetration testing sits at section 5.14 and covers IL6 hosting environments, not IL5. Note also that V1R3 is four releases stale — V1R7 (30 June 2026) is current. Section 4.4 sets the transition rules: a CSO in continuous monitoring files a POA&M within 30 days of a release and complies no later than its next annual assessment.
Is ICD 705 still the SCIF construction standard?
Yes. ICD 705 (dated May 26, 2010) remains the governing directive, implemented through the IC Technical Specifications maintained by ODNI's National Counterintelligence and Security Center. The most recent version we can evidence from a primary source is 1.5.1, dated July 26, 2021. Three things are commonly misstated. First, revisions apply to new construction and major renovation; they do not retroactively decertify an accredited facility. Second, the revision your space was accredited against is not necessarily the one your next project will be judged by. Third, there is no fixed RF attenuation figure in the standard: RF protection is installed at the direction of the Certified TEMPEST Technical Authority when a SCIF uses electronic processing and does not already provide adequate attenuation at the inspectable space boundary. Any specific decibel number you see quoted as an ICD 705 requirement is not from the document. Confirm the governing revision and the CTTA determination at project initiation rather than assuming. Compliance risk sits in the design phase, not the inspection.
What's FedRAMP 20x and should my cloud SaaS care?
FedRAMP 20x is GSA's new cloud-native authorization path, designed to replace much of the manual 3PAO attestation workload with automated validation against Key Security Indicators (KSIs). Phase 2 wrapped on March 31, 2026 with the targeted ~10 FedRAMP Moderate pilot authorizations completed; **Phase 3 (H2 FY26) is now active** and expanding to broader Low and Moderate adoption. A Phase 4 pilot for FedRAMP High is slated for FY27 H1. If you're pursuing FedRAMP Moderate in 2026, 20x is worth evaluating because Phase 2 pilots ran materially faster than traditional paths. If you're pursuing FedRAMP High or DoD IL4/IL5/IL6, 20x doesn't apply yet, but the automation direction telegraphs where those assessments will eventually go.