CMMC Intelligence Report: August 2026
The CMMC Reform Task Force’s public comment window closed August 14 as scheduled, and DoD has said nothing about what it received or which direction it’s leaning. The mid-September report date from July’s suspension memo still stands. While the federal review sits quiet, prime contractors are not waiting: flow-down clauses requiring CMMC Level 2 are showing up in more subcontracts than they were in July. This month also covers a new actively-exploited flaw in supply-chain software and a real change to how Cyber Grants Alliance structures its gap assessment grant.
CMMC Program Status: RFI Closed, No Ruling Yet
The CMMC Reform Task Force’s public Request for Information closed August 14, on schedule with the timeline set in July’s suspension memo. DoD has not disclosed comment volume, published a summary, or signaled a direction. The report the task force owes is still expected “around mid-September” per the original memo — that date has not moved, but it also has not been confirmed since.
Nothing here requires action yet. What it means practically: contractors have roughly the same window they had at the start of August to prepare for either outcome — a reformed third-party assessment program restarting on new terms, or an extended pause. Waiting for certainty before continuing Phase 1 remediation was the wrong call in July and remains the wrong call now, for the same reason: Phase 1 self-assessment obligations were never part of the suspension.
Assessment Pipeline: Prime Flow-Down Keeps Tightening
June’s report first flagged prime contractors enforcing CMMC flow-down requirements ahead of DoD’s own timeline. That trend continued through August: more subcontract templates are now carrying CMMC Level 2 flow-down language as a standard clause, not a special case. For subcontractors, this means the forcing function for CMMC work is increasingly contractual, not federal — a prime’s own deadline can be earlier and stricter than anything DoD currently has active.
If you have not reviewed your active and pending subcontracts specifically for CMMC flow-down clauses since July, that is the single most concrete thing to check this month. A subcontractor who is only tracking the paused federal deadline may be missing a nearer, contractually binding one.
CMMC Gap Assessment Grants Available
Level 1 and Level 2 tracks now available through Cyber Grants Alliance. First come, first served.
CGA Grant Program Update: Gap Assessment Grants Now Split by Level
Cyber Grants Alliance has restructured its CMMC Gap Assessment Grant into two separate tracks: a CMMC Level 1 Gap Assessment Grant and a CMMC Level 2 Gap Assessment Grant, replacing the single combined grant that existed through July. The prior generic grant URL now redirects to the Level 2 track.
For applicants, the practical change is matching your application to your actual CMMC scope rather than a one-size assessment: contractors who only handle FCI (Level 1 scope) and contractors handling CUI (Level 2 scope) now apply through separate, level-specific tracks. If you started a CGA application before this change, confirm which track your organization now falls under before submitting.
DIB Threat Landscape
CVE-2026-41207 (Kiteworks Secure File Gateway, CVSS 9.6): Active Exploitation Against Defense Supply Chain Data Transfer
A pre-authentication remote code execution flaw in Kiteworks’ Secure File Gateway — software widely used by defense contractors and primes to exchange large CAD files, BOMs, and CUI-adjacent engineering data with suppliers — was disclosed August 6 and confirmed under active exploitation by August 11. Kiteworks shipped a patch August 8; CISA added the flaw to its Known Exploited Vulnerabilities catalog on August 12 with an August 26 federal remediation deadline. Unlike the July Windchill campaign, which was extortion-driven, early reporting on this campaign points to data staging and exfiltration rather than a ransom demand, consistent with espionage-motivated activity rather than a criminal group. Any organization using Kiteworks for supplier file exchange should confirm the August 8 patch is applied and review transfer logs for the exploitation window.
Ransomware Activity Holds Near July’s Elevated Level
Comparitech’s monthly tracker recorded 761 claimed ransomware attacks in August, down modestly from July’s 799 but still the third-highest month of 2026. The Gentlemen and Qilin again led the leaderboard, together accounting for roughly a third of claimed activity — the same concentration pattern as July. No new defense-adjacent or NATO-affiliated victim on the scale of July’s Indra Group incident was confirmed this month, but manufacturing and logistics remained represented in the mid-tier of targeted sectors across every tracker reviewed.
Regulatory Watch
CMMC Reform Task Force: RFI Closed, Report Still Due Mid-September
The public comment window closed August 14. DoD has given no interim signal on findings or direction. Contractors should treat the mid-September date as the next real checkpoint, not before.
Prime Flow-Down Requirements: The Nearer Deadline for Many Subs
More subcontract templates now carry CMMC Level 2 flow-down clauses as standard language. For subcontractors, a prime’s own contractual deadline can now be earlier than anything currently active at the federal level.
NIST SP 800-171 Revision 3: Still Not the Enforced Standard
No change from July: Revision 2 remains the enforced standard under DFARS 252.204-7012. Revision 3 is not expected to become the mandatory baseline via formal rulemaking until sometime between late 2026 and late 2027.
What changes in NIST 800-171 Rev 3Cyber Grants Alliance: Gap Assessment Grants Now Split by CMMC Level
The combined CMMC Gap Assessment Grant is now two tracks, Level 1 and Level 2, matched to actual scope. Applications continue to be reviewed on a rolling basis.
Apply for a CMMC Gap Assessment GrantSeptember Action Items
September is when the task force report is due. Until it lands, the checklist stays the same as August’s, plus one new patch item.
Patch or confirm patch status on Kiteworks Secure File Gateway
CVE-2026-41207 is under active exploitation targeting defense supply-chain file transfer data. Confirm the August 8 patch is applied and review transfer logs for the exploitation window if you run this software.
Review active and pending subcontracts for CMMC flow-down clauses
Prime-set deadlines are increasingly the real forcing function, not the paused federal date. Check your own subcontracts specifically rather than assuming the November date still applies.
Confirm which CGA grant track matches your scope
If you started a gap assessment grant application before the Level 1/Level 2 split, confirm which track now applies to your organization before submitting.
Continue NIST 800-171 Rev 2 remediation independent of the task force timeline
Phase 1 self-assessment obligations were never part of the suspension. Treat remediation as running on its own clock regardless of when the mid-September report lands.
Watch for the CMMC Reform Task Force report, expected mid-September
This is the next scheduled checkpoint that could actually change the program’s direction. Nothing to act on until it publishes, but worth tracking closely once September begins.
CMMC Gap Assessment Grants Available
Level 1 and Level 2 tracks now available through Cyber Grants Alliance. First come, first served.
