Mid-Q3 update — July 14, 2026. The headline of this briefing has been overtaken by events.
(1) CMMC Phase 2 is suspended. On July 13, 2026 the Department of War CIO suspended the November 2026 Phase 2 transition and held all pending and future CMMC implementation milestones in abeyance until further notice, pending a 60-day review by a new CMMC Reform Task Force. Program managers may designate only Level 1 (Self) or Level 2 (Self) assessments — not Level 2 (C3PAO) or Level 3 (DIBCAC) — solicitations and contracts carrying those requirements are directed to be amended or modified to remove them, and no waivers will be granted during the review. This supersedes the November 10, 2026 cliff that section 1 below is built around, and the timing advice in section 1 and Priority 1 is withdrawn. What did not change: DFARS 252.204-7012 safeguarding and 72-hour reporting are explicitly still in effect, NIST SP 800-171 Rev 2 remains the enforced baseline via self-assessment, and False Claims Act exposure still attaches to the SPRS score you affirmed. Primary-source read of both memos: CMMC Phase 2 is suspended. There is an open RFI — “Reforming CMMC and Reducing Compliance Burden for the Defense Industrial Base (DIB)” — with responses due August 14, 2026, 12:00 PM Eastern.
(2) FedRAMP released the Consolidated Rules for 2026 (CR26) on June 24, 2026. CR26 consolidates the 20x requirements into one versioned, machine-readable ruleset and resets how every submission — Rev 5 included — is reviewed. Optional early adoption opened July 4, 2026; it is mandatory for all stakeholders January 1, 2027; no new Rev 5 applications after June 11, 2027. It carries three component notices: NTC-0012 (incident communications), NTC-0013 (Rev 5 baseline rebuild), and NTC-0014 (VDR/VER vulnerability rules, mandatory December 7, 2026). Start here: the CR26 explainer. This closes out the “FedRAMP Phase 3 finalization” item promised below.
(3) NDAA Section 1513 — no confirmed submission. The June 16, 2026 deadline for DoD’s AI-security plan to Congress has passed. We can find no primary-source evidence that the report was actually delivered — no congressional record, no DoD CIO publication. We are not going to report a submission we cannot verify; the item stays open. Background: AI is coming to CMMC.
(4) A note on the readiness statistics below. Sections 1 and 3 cite “fewer than 1,100 certified as of February 2026.” The more current figure is ~1,042 of ~76,600 organizations (~1.4%) as of May 2026, cited in item (3) of the June 5 update. Both are approximately the same readiness rate, and that rate is a large part of why the program was just suspended — the capacity arithmetic never cleared.
Mid-Q2 update — June 5, 2026 — Four further developments worth flagging since the May 8 update:
(1) FedRAMP renamed “Authorization” to “Certification” (May 4, 2026) and replaced the Low/Moderate/High impact-level terminology with Classes A/B/C/D. The substantive control baselines are unchanged; this is a terminology overhaul. Every piece of FedRAMP marketing copy, every SSP cover sheet, and every customer-facing FedRAMP claim on the open web is now subtly out-of-date until refreshed. Our FedRAMP Moderate realistic timeline and the Rev 5 series carry a footnote on the rename.
(2) Executive Order “Promoting Advanced AI Innovation and Security” — signed June 2, 2026. Directs federal agencies, within 30 days (by July 2, 2026), to prepare federal and private-sector systems for advanced AI; Committee on National Security Systems prioritizes NSS cyber defense; Treasury must stand up an AI Cybersecurity Clearinghouse for voluntary industry / critical-infrastructure participation. Combined with NDAA FY26 Section 1513 — which requires DoD to deliver a CMMC-for-AI framework plan to Congress by June 16, 2026 — this is the first formal signal that AI/ML security obligations will become a CMMC scope expansion lane in 2027-2028.
(3) CMMC narrative shifts from “planning” to “enforcement.” June 2026 trade-press reporting (Federal News Network) now reframes the program: primes are flowing CMMC requirements down on tight deadlines, contracting officers signal at the solicitation stage, and the capacity arithmetic has hardened. ~103 authorized C3PAOs as of late Q1 2026 against a population of ~76,600 organizations needing Level 2; only ~1,042 organizations (1.4%) have completed certification as of May 2026. Industry reporting cites wait times exceeding 18 months for new clients by Q3 2026. The “C3PAO scarcity is the binding constraint” framing in our Realistic CMMC Level 2 Timeline is now the dominant practitioner narrative.
(4) DCSA system “under strain” + GAO follow-on. May 2026 Federal News Network reporting flagged that DoD’s classified-information protection regime for cleared contractors is buckling under resource constraints. Director Cattler retired Sept 30, 2025; Justin Overbaugh is acting; NBIS remains years behind schedule and over budget. Combined with the April 2026 GAO 815-violations report (covered in the May 8 update), the picture is one of accelerating enforcement expectations against a regulator that covers only 25-30% of cleared facilities annually. Our DCSA 815 analysis carries the GAO data; the strain narrative is a Q3 article in our pipeline.
(5) Correction — DFARS 7019/7020 were not deleted or renumbered. An earlier version of this briefing reported a “February 2026 Revolutionary FAR Overhaul” that deleted DFARS 252.204-7019 and renumbered 252.204-7020 to “252.240-7997.” That was incorrect: per acquisition.gov, both 252.204-7019 and 252.204-7020 remain active and in force, and no clause “252.240-7997” exists. The real change is the CMMC final rule (DFARS Case 2019-D041, September 10, 2025), which layers CMMC (252.204-7021) — and a new notice clause, 252.204-7025 — on top of the existing assessment clauses rather than replacing them. Section 3 below has been corrected.
(6) NIST 800-171 Rev 3 rulemaking window tightens. Practitioner consensus across April-May 2026 trade press is now “late 2026 to early 2027 rulemaking” — meaningfully tighter than the “timeline unknown” framing that held through Q1. CMMC Level 2 will remain Rev 2-assessed through at least the first wave of Phase 2 enforcement, but Tier-1 primes are increasingly asking subs about Rev 3 readiness in pre-award evaluations. Our how primes evaluate CMMC subs covers the operational pattern.
A Mid-Q3 update will follow in August 2026 covering: FedRAMP Phase 3 finalization (June 30 close-out), DoD’s response to the June 16 NDAA Section 1513 deadline, ISO 27017 second-edition publication (expected later 2026), and any new DOJ FCA settlements through July.
Updated May 8, 2026 — Two material developments since this briefing first published:
(1) GAO Report 26-107861 (April 24, 2026) documented 815 security violations across 4,600+ DCSA cleared-contractor security reviews in FY2025, plus 1,032 open security vulnerabilities. Distribution: data spills ~60%, improper storage 11.5%, unauthorized access 6.5%, physical losses 6.3%, improper transfers 5.6%. DCSA’s review capacity covers only 25-30% of the cleared industrial base in any fiscal year, and industrial security funding has remained “relatively flat” while personnel-vetting funding increased. Real annual industry violation count, extrapolated, is probably 2,500-3,300. Our DCSA 815 violations analysis walks through each category and the architectural patterns that prevent them.
(2) L3Harris insider-threat case (May 8, 2026) — Peter Williams, formerly head of L3Harris’s offensive cyber tooling division, ordered to pay $10M restitution for stealing surveillance and hacking tools and selling them for $1.3M to a Russian broker. Reinforces the personnel-security control family (NIST 800-171 3.9) as a real risk vector for cleared and CUI-handling contractors, not just a paper requirement.
Neither development changes the strategic conclusions below — but both are evidence that the policy direction (more enforcement, more visibility on contractor failures) is producing observable consequences month-over-month, not just at policy-cycle inflection points.
The first half of 2026 has been the most consequential compliance-landscape quarter since the original DFARS 252.204-7012 rollout in 2017. Multiple large-scale regulatory shifts have landed in a narrow window: a new CMMC enforcement posture, the CMMC final rule layering new clauses onto the DFARS framework that underpins CUI handling, a step-change in DoD cloud-provider requirements, the first major SCIF standard overhaul in fifteen years, an accelerating DOJ enforcement program with the first defense-subcontractor False Claims Act settlement, and the quiet staging of the NIST 800-171 Rev 3 transition.
This briefing is a practitioner’s view of what changed, what it means for each buyer profile (defense subcontractor, cloud SaaS, classified-work contractor, commercial vendor with federal exposure), and what to prioritize over the next two quarters. The article is built from primary rulemaking review, DoD and Cyber AB communications, and pattern-recognition across engagements we’ve run this year.
A single-sentence TL;DR for each reader:
- Defense subcontractors: Phase 2 was suspended on July 13, 2026 — but 7012, NIST 800-171 Rev 2, and the SPRS score you affirmed all still bind you, so the security work does not stop.
- Cloud SaaS: FedRAMP 20x is finally real, IL5 just got 40% harder, and IL6 now has government pentest rights.
- Classified-work contractors: ICD 705 2025 requires most SCIFs to be rebuilt or significantly remediated.
- Commercial SaaS with federal exposure: ISO 27001:2013 is dead, GSA added CUI requirements for civilian contractors, and DOJ is actively pursuing false SPRS scores under the FCA.
The rest of the article unpacks each, with citations to primary sources where useful.
1. CMMC Phase 2 — suspended July 13, 2026 (was November 10, 2026)
Superseded — read this first. This section was written around November 10, 2026 as the single most important date in DoD compliance this year. On July 13, 2026 that transition was suspended and all pending CMMC implementation milestones were held in abeyance pending a 60-day review. The capacity analysis below is left standing because it is essentially the reason the program was suspended — but the deadline framing and the timing advice are withdrawn. See CMMC Phase 2 is suspended for what still binds you.
The plan, until July 13, was this: on November 10, 2026, CMMC Phase 2 would activate, contracting officers would require C3PAO-assessed Level 2 certification by default for contracts involving CUI, and self-assessment would cease to satisfy the DFARS 252.204-7021 obligation for the majority of subcontractors handling CUI. During the suspension the reverse is true — program managers may designate only self-assessment (Level 1 or Level 2), and may not designate C3PAO or DIBCAC assessment at all.
The capacity math is the alarming part. DoD estimates 76,000+ organizations need Level 2 certification to continue serving defense primes. As of February 2026, fewer than 1,100 had completed it — roughly 1.4% readiness against a deadline now under six months out. C3PAO assessor capacity is the binding constraint. Our CMMC Level 2 timeline article lays out what a realistic engagement looks like month-by-month.
Phase 3 (November 10, 2027) extends the mandate to option exercises on existing contracts — there is no grandfathering for contracts awarded before Phase 2 if they contain option years extending past November 2027. Subcontractors who plan to ride existing contracts through 2027 without certifying need to re-check their option-year structure; most will need Level 2 before 2027’s option exercise.
What to prioritize (revised July 14, 2026): The deadline this section was organized around no longer exists, so the original “kick off by June 2026 or miss the window” arithmetic is withdrawn — it would be false advice today. The revised priority is narrower and, we think, more durable: keep implementing NIST SP 800-171 Rev 2, and make sure your SPRS score is actually supported by your implementation. Those obligations are explicitly unaffected by the suspension, the score carries False Claims Act exposure with or without an assessor, and the 60-day review is chartered to recommend a reformed framework rather than none at all. Pause the C3PAO booking; do not pause the engineering. The CMMC self-assessment vs C3PAO piece explains the assessment paths, and CMMC Phase 2 is suspended covers exactly what survived.
2. DOJ False Claims Act enforcement — the cybersecurity wave is real
The DOJ Cyber Fraud Initiative announced in 2021 is no longer theoretical. 2025 data:
- Eight DOJ cyber-fraud settlements in 2025 — the aggregate settlement value rose roughly 233% year-over-year (about $52M across the year)
- $875,000 — a university research institution settled in September 2025 for submitting a false SPRS score and failing to install anti-malware tools on CUI-handling lab systems
- $421,000 — an Illinois precision machining subcontractor settled in December 2025, reportedly the first cyber-fraud FCA settlement to reach the subcontractor tier rather than a prime
- Acquirer/successor-liability case — an acquirer (Raytheon/Nightwing, ~$8.4M, 2025) held liable for a target’s pre-acquisition cyber violations
The pattern to notice: FCA liability attaches to the certification, not the incident. You don’t need a breach to be actionable. An SPRS score self-asserted at 110 that an assessor would score at 87 is, in DOJ’s reading, a false claim to the government — prosecutable under 31 U.S.C. §§ 3729-3733 even if no data was exfiltrated.
This creates a specific asymmetric risk for subcontractors who told their prime “we’re fully compliant” to win the subcontract and aren’t. The whistleblower incentive (qui tam provisions pay up to 30% of recovery to the relator) creates disgruntled-employee risk that subcontractors historically didn’t have to model.
What to prioritize: Audit your SPRS score against a pre-engagement gap assessment. If the reported score is more than 5-10 points above what an honest third-party assessment would produce, the subcontract is both a contract performance risk and a potential FCA exposure. Remediating before the prime asks is cheaper than remediating after DOJ asks.
3. DFARS cyber clauses — what the CMMC final rule actually changed
The DFARS cybersecurity clauses were not deleted or renumbered in 2026. (An earlier version of this briefing incorrectly reported a “Revolutionary FAR Overhaul” that deleted 7019 and created a clause “252.240-7997” — that did not happen; see the correction in the mid-Q2 update above.) As of the current DFARS, all four clauses remain in force:
- DFARS 252.204-7012 — safeguarding covered defense information, 72-hour incident reporting, cloud computing. Unchanged.
- DFARS 252.204-7019 — Notice of NIST SP 800-171 DoD Assessment Requirements; offerors must have a current Basic self-assessment posted in SPRS. Active.
- DFARS 252.204-7020 — NIST SP 800-171 DoD Assessment Requirements; government access for Medium/High assessments. Active.
- DFARS 252.204-7021 — CMMC requirement. Active and phasing in.
The real regulatory motion is the CMMC final rule (DFARS Case 2019-D041, published September 10, 2025), which adds the CMMC clause (7021) and a new notice clause, 252.204-7025 (Notice of CMMC Level Requirements). It layers CMMC on top of the existing assessment regime rather than deleting the self-assessment clauses.
The strategic direction is unchanged: as Phase 2 (November 10, 2026) makes C3PAO-assessed Level 2 the default for CUI contracts, CMMC becomes the operative assessment mechanism for most CUI-handling subcontractors. But the parallel 7019/7020 self-assessment clauses still appear in contracts today and were not eliminated. Any subcontractor whose strategy was “hit the SPRS score via 7019 self-assessment and postpone CMMC” should re-read the flowdown in their subcontract — most CUI contracts now invoke 7021.
Our self-assessment vs C3PAO article covers which contracts still accept self-assessment and which require a C3PAO.
4. NIST 800-171 Rev 3 — DoD is staging the transition
NIST 800-171 Rev 3 was published in 2024. DoD has not yet transitioned CMMC Level 2 from Rev 2 to Rev 3 formally — the current 110-practice baseline is still Rev 2. But in April 2025, DoD published Organization-Defined Parameters for Rev 3, specifying values for Rev 3’s 88 ODP placeholders.
The DoD isn’t publishing ODPs for fun. Publishing the parameters before formal rulemaking is the clearest possible signal that Rev 3 transition is coming — probably on a 2028-2030 timeline, and Tier-1 primes are starting to ask subs about Rev 3 readiness in pre-award evaluations even where Rev 2 remains the contractual baseline. Our prime evaluation article covers how this shows up in practice.
Rev 3 structural changes worth knowing:
- Three new control families: Planning (PL), System and Services Acquisition (SA), and Supply Chain Risk Management (SR) — alignment with NIST 800-53 Rev 5
- 88 Organization-Defined Parameters allowing organizations to specify implementation details
- Tighter language on several existing controls (access control, audit, configuration management)
What to prioritize: Don’t redesign your control environment for Rev 3 yet — the rulemaking isn’t there, and Rev 2 is what C3PAOs will assess against through at least 2027. But do track the Rev 3 / Rev 2 delta for your own environment so when Rev 3 becomes formal, you’re not rediscovering it under deadline.
5. DoD Cloud Computing SRG v1r3 — IL5 just got 40% harder
On July 2, 2025, DISA published CSP SRG v1r3, the most consequential update to the DoD Cloud Computing Security Requirements Guide in years.
The headline change: Impact Level 5 Cloud Service Offerings must now implement National Security Systems controls from CNSSI 1253 — approximately 170 additional controls layered on top of FedRAMP High baseline. That’s a ~40% increase in control count from the prior IL5 baseline. (The NIST 800-53 Rev 4 → Rev 5 transition across all impact levels came with the earlier June 2024 SRG release, not v1r3.)
Separately, the June 2024 SRG release added language granting government the right to perform internal and external penetration testing on CSP IL6 hosting environments — prior guidance allowed government-led assessments but did not explicitly grant offensive-testing rights on production environments.
The consequence for cloud service providers: the IL5 and IL6 assessment scope just increased materially. CSPs currently authorized at IL5 under the pre-v1r3 baseline face additional control implementations at their next authorization renewal or reassessment. CSPs pursuing a fresh IL5 authorization in 2026 should plan for a longer and costlier assessment than 2024 industry averages suggest.
Our IL5 controls that burn CSPs article has been updated with the v1r3 delta — worth re-reading if IL5 is on your roadmap. For broader context on the IL4→IL5→IL6 upgrade path, the upgrade path article covers sequencing.
6. ICD 705 2025 overhaul — the first major SCIF standard update since 2010
This update has received less coverage than it should. Intelligence Community Directive 705 — the standard governing SCIF and SAPF construction, TEMPEST protection, and accreditation — received its first major overhaul since 2010 in the 2025 update.
Material changes:
- Minimum RF attenuation is now typically 60 dB on SCIF walls, ceilings, floors, and doors, structurally integrated rather than surface-applied. The prior regime set RF protection case-by-case through the Certified TEMPEST Technical Authority rather than a fixed attenuation figure, so many existing SCIFs were not built to a 60 dB structural standard.
- Enhanced TEMPEST countermeasures — including updated zoning requirements for emanation-security
- Tightened acoustic controls — intelligibility testing protocols and STC-rating minimums have moved up
- Accreditation posture shift — AOs and DSS expect earlier documentation at project initiation, design development, and preconstruction review. Late-stage compliance discovery is being flagged as higher risk.
The practical consequence is blunt: most existing SCIFs are now architecturally non-compliant with the updated technical specifications. Organizations with aging SCIFs need to plan for either significant renovation or new construction on a 4-5 year horizon. Organizations starting the accreditation process in 2026 have more flexibility than those who wait — accrediting authorities are still absorbing the updated standard and early applicants benefit from engagement bandwidth that will compress as 2028+ demand builds.
Our SCIF/SAPF accreditation playbook has been updated with the 2025 ICD 705 changes. The SCIF vs SAPF differences article still holds but picked up a 2025-update callout. For venture-backed defense startups, the first SCIF article incorporates the updated RF and acoustic requirements.
7. FedRAMP 20x — Phase 2 wrapped, Phase 3 active
FedRAMP 20x is GSA’s long-promised modernization of the FedRAMP authorization program. Phase 2 wrapped on March 31, 2026 with the targeted ~10 FedRAMP Moderate pilot authorizations completed. Phase 3 (FY26 H2) is now active, expanding 20x to broader adoption for Low and Moderate CSPs.
The structural difference: Key Security Indicators (KSIs). Instead of manual 3PAO attestation against every control, 20x defines machine-verifiable indicators (e.g., “data encrypted at rest with FIPS 140-validated algorithms”) that CSP environments can demonstrate automatically. The goal is faster, cheaper authorizations with less manual review overhead.
Phase 4 (FY27 H1) pilots FedRAMP High. DoD Cloud Computing SRG paths (IL4/IL5/IL6) are not yet in scope for 20x, though the underlying KSI automation direction foreshadows where those assessments will eventually move.
What to prioritize: If FedRAMP Moderate is on your 2026 roadmap, evaluate 20x against the traditional path. Pilot authorizations completed so far are running meaningfully faster than 2024 industry averages. The trade-off: 20x requires more automation tooling and instrumentation than a traditional 3PAO-driven path, so the time savings come with upfront engineering investment.
Our FedRAMP Moderate realistic timeline article still reflects the traditional path; our FedRAMP 20x deep-dive covers the KSI model, the phased rollout, and who should evaluate it.
8. ISO 27001:2013 — the deadline passed (October 31, 2025)
This is old news but the implications are still live. The international transition deadline from ISO/IEC 27001:2013 to ISO/IEC 27001:2022 passed on October 31, 2025. Every active ISO 27001 certification is now the 2022 edition. Any organization still operating on a 2013-era certificate has an invalid certificate — not a deprecated one, not a grace-period one, an invalid one.
If you missed the transition, the path back is a full Stage 1 / Stage 2 audit against the 2022 standard with a new certification body. No shortcut. Transition-audit pathways are no longer available from accredited certification bodies under IAF rules.
For organizations currently holding a valid 2022 certificate, the focus shifts to the four new Annex A themes (organizational, people, physical, technological) and the 11 new Annex A controls introduced in the 2022 edition. Our ISO 27001:2013 to 2022 transition article has been updated with the post-deadline status.
9. GSA CUI requirements for civilian contractors — the parallel track
In January 2026, GSA published new Controlled Unclassified Information security requirements for federal civilian contractors (CIO-IT Security-21-112, Rev 1). The practical effect: a CMMC-like regime is beginning to emerge for civilian agency contracts, parallel to DoD’s CMMC.
The GSA requirements draw from NIST 800-171 (same baseline as CMMC Level 2), with GSA-specific implementation parameters. Civilian-agency contractors handling CUI should expect a formalized assessment and attestation regime within 2-3 years, following a similar pattern to CMMC’s 2019-2026 rollout.
For cloud SaaS vendors whose addressable market includes both DoD and civilian agencies, the strategic implication is that NIST 800-171 compliance is becoming the default federal CUI baseline, not just a DoD obligation. Building toward it once and serving both markets is more efficient than the bifurcated posture most vendors currently run.
10. DoD Zero Trust — Target Level deadline September 30, 2027
The DoD Zero Trust Strategy, published in 2022, set a target-level capability deadline of September 30, 2027. The strategy defines 45 capabilities and 152 activities across seven pillars; the 91 Target Level activities must be demonstrated by the FY27 deadline, with 61 Advanced Level activities extending to a 2032 target.
Pentagon officials continue to publicly affirm the 2027 target, but the practical path is ambitious: 91 distinct Target Level activities across seven pillars (User, Device, Application, Data, Network, Automation, Visibility). A Zero Trust Strategy 2.0 update is expected from the Pentagon in early-to-mid 2026.
For defense contractors, the enforcement mechanism matters: organizations that miss Target Level by September 30, 2027 face contract ineligibility — not award withdrawal of existing contracts, but inability to receive new awards, exercise options, or extend contract periods of performance. Primes are increasingly flowing down Zero Trust readiness requirements into subcontracts ahead of the deadline.
The Zero Trust overlay intersects with CMMC — several CMMC Level 2 practices map to Zero Trust pillars, but the Zero Trust Target Level demands more than CMMC Level 2 requires. Defense contractors pursuing CMMC Level 2 certification in 2026 should design with Zero Trust Target Level in mind to avoid a second, larger remediation in 2027.
What this means for the next two quarters
Synthesizing across the ten changes above, four operating priorities fall out for compliance-affected organizations this year:
Priority 1 (revised July 14, 2026): Defense subcontractors should keep implementing 800-171 and correct their SPRS score — the certification deadline is gone, the obligations are not. This priority originally read “close your CMMC engagement gap this quarter or accept Phase 2 exposure,” on the arithmetic that a 6–9 month engagement had to start by June 2026 to clear the November 10 cliff. That cliff was suspended on July 13, 2026, so that advice is withdrawn. The exposure that remains is the one that always had teeth: DFARS 252.204-7012 safeguarding and 72-hour reporting are still in effect, NIST SP 800-171 Rev 2 is still enforced through self-assessment, and a false or unsupported SPRS score is a False Claims Act problem whether or not a C3PAO ever visits.
Priority 2: Cloud SaaS on an IL5 path should re-scope assessment work for the v1r3 delta. Approximately 170 additional controls layered on top of FedRAMP High is not marginal. Budget and timeline adjustments at next renewal are unavoidable for organizations holding authorizations issued before July 2025.
Priority 3: Organizations with SCIFs older than 2015 should commission a gap assessment against the 2025 ICD 705 update. Most will need renovation or replacement on a 4-5 year horizon. Early engagement with accrediting authorities produces better outcomes than late-stage remediation.
Priority 4: False Claims Act exposure on SPRS scores is a board-level risk, not a compliance-team housekeeping item. Any organization where the gap between reported and assessable SPRS score exceeds ten points should treat it as an active legal exposure.
For most organizations, the right operating response is not one engagement but a coordinated compliance posture review across the dimensions that changed: CMMC readiness, SPRS-score accuracy, cloud-assessment scope, SCIF architectural status, and Zero Trust Target Level gap. Running these in isolation produces duplicative work and misses the dependencies between them.
If you want an outside read on where your specific situation sits across these changes, book a 30-minute scoping call. If we can give you the view in thirty minutes without an engagement, we will. If the situation warrants an engagement, we’ll scope it honestly against a realistic timeline.
Related reading:
- CMMC Level 2 real cost breakdown — engagement, tooling, C3PAO, and year-2 costs with specific ranges
- How primes evaluate CMMC-certified subs — SPRS thresholds, SSP review, POA&M scrutiny, audit rights
- Why 30-day compliance claims are misleading — the positioning article this briefing complements
- DFARS 7012 incident reporting gap — the 72-hour reporting obligation and current DFARS clause state
- FedRAMP Moderate realistic timeline — traditional path; 20x-specific piece in the pipeline
- IL5 assessment controls that burn CSPs first — updated for CSP SRG v1r3
- SCIF/SAPF accreditation playbook — updated for 2025 ICD 705
This briefing is written as a reference document that Fortinetics will refresh quarterly. Next update: Q3 2026, reflecting Phase 2 activation evidence, FedRAMP 20x Phase 3 adoption, and the Pentagon’s Zero Trust Strategy 2.0 release.