CMMC Ready Now
← CMMC Intelligence|August 2026

CMMC Intelligence Report: August 2026

The CMMC Reform Task Force’s public comment window closed August 14 as scheduled, and DoD has said nothing about what it received or which direction it’s leaning. The mid-September report date from July’s suspension memo still stands. While the federal review sits quiet, prime contractors are not waiting: flow-down clauses requiring CMMC Level 2 are showing up in more subcontracts than they were in July. This month also covers a new actively-exploited flaw in supply-chain software and a real change to how Cyber Grants Alliance structures its gap assessment grant.

RFI ClosedFlow-Down TightensStill WaitingGrant Program Update

CMMC Program Status: RFI Closed, No Ruling Yet

The CMMC Reform Task Force’s public Request for Information closed August 14, on schedule with the timeline set in July’s suspension memo. DoD has not disclosed comment volume, published a summary, or signaled a direction. The report the task force owes is still expected “around mid-September” per the original memo — that date has not moved, but it also has not been confirmed since.

Nothing here requires action yet. What it means practically: contractors have roughly the same window they had at the start of August to prepare for either outcome — a reformed third-party assessment program restarting on new terms, or an extended pause. Waiting for certainty before continuing Phase 1 remediation was the wrong call in July and remains the wrong call now, for the same reason: Phase 1 self-assessment obligations were never part of the suspension.

Assessment Pipeline: Prime Flow-Down Keeps Tightening

June’s report first flagged prime contractors enforcing CMMC flow-down requirements ahead of DoD’s own timeline. That trend continued through August: more subcontract templates are now carrying CMMC Level 2 flow-down language as a standard clause, not a special case. For subcontractors, this means the forcing function for CMMC work is increasingly contractual, not federal — a prime’s own deadline can be earlier and stricter than anything DoD currently has active.

If you have not reviewed your active and pending subcontracts specifically for CMMC flow-down clauses since July, that is the single most concrete thing to check this month. A subcontractor who is only tracking the paused federal deadline may be missing a nearer, contractually binding one.

CMMC Gap Assessment Grants Available

Level 1 and Level 2 tracks now available through Cyber Grants Alliance. First come, first served.

Apply for a CMMC Gap Assessment Grant →

CGA Grant Program Update: Gap Assessment Grants Now Split by Level

Cyber Grants Alliance has restructured its CMMC Gap Assessment Grant into two separate tracks: a CMMC Level 1 Gap Assessment Grant and a CMMC Level 2 Gap Assessment Grant, replacing the single combined grant that existed through July. The prior generic grant URL now redirects to the Level 2 track.

For applicants, the practical change is matching your application to your actual CMMC scope rather than a one-size assessment: contractors who only handle FCI (Level 1 scope) and contractors handling CUI (Level 2 scope) now apply through separate, level-specific tracks. If you started a CGA application before this change, confirm which track your organization now falls under before submitting.

DIB Threat Landscape

CVE-2026-41207 (Kiteworks Secure File Gateway, CVSS 9.6): Active Exploitation Against Defense Supply Chain Data Transfer

A pre-authentication remote code execution flaw in Kiteworks’ Secure File Gateway — software widely used by defense contractors and primes to exchange large CAD files, BOMs, and CUI-adjacent engineering data with suppliers — was disclosed August 6 and confirmed under active exploitation by August 11. Kiteworks shipped a patch August 8; CISA added the flaw to its Known Exploited Vulnerabilities catalog on August 12 with an August 26 federal remediation deadline. Unlike the July Windchill campaign, which was extortion-driven, early reporting on this campaign points to data staging and exfiltration rather than a ransom demand, consistent with espionage-motivated activity rather than a criminal group. Any organization using Kiteworks for supplier file exchange should confirm the August 8 patch is applied and review transfer logs for the exploitation window.

Ransomware Activity Holds Near July’s Elevated Level

Comparitech’s monthly tracker recorded 761 claimed ransomware attacks in August, down modestly from July’s 799 but still the third-highest month of 2026. The Gentlemen and Qilin again led the leaderboard, together accounting for roughly a third of claimed activity — the same concentration pattern as July. No new defense-adjacent or NATO-affiliated victim on the scale of July’s Indra Group incident was confirmed this month, but manufacturing and logistics remained represented in the mid-tier of targeted sectors across every tracker reviewed.

Regulatory Watch

CMMC Reform Task Force: RFI Closed, Report Still Due Mid-September

The public comment window closed August 14. DoD has given no interim signal on findings or direction. Contractors should treat the mid-September date as the next real checkpoint, not before.

Prime Flow-Down Requirements: The Nearer Deadline for Many Subs

More subcontract templates now carry CMMC Level 2 flow-down clauses as standard language. For subcontractors, a prime’s own contractual deadline can now be earlier than anything currently active at the federal level.

NIST SP 800-171 Revision 3: Still Not the Enforced Standard

No change from July: Revision 2 remains the enforced standard under DFARS 252.204-7012. Revision 3 is not expected to become the mandatory baseline via formal rulemaking until sometime between late 2026 and late 2027.

What changes in NIST 800-171 Rev 3

Cyber Grants Alliance: Gap Assessment Grants Now Split by CMMC Level

The combined CMMC Gap Assessment Grant is now two tracks, Level 1 and Level 2, matched to actual scope. Applications continue to be reviewed on a rolling basis.

Apply for a CMMC Gap Assessment Grant

September Action Items

September is when the task force report is due. Until it lands, the checklist stays the same as August’s, plus one new patch item.

Immediate

Patch or confirm patch status on Kiteworks Secure File Gateway

CVE-2026-41207 is under active exploitation targeting defense supply-chain file transfer data. Confirm the August 8 patch is applied and review transfer logs for the exploitation window if you run this software.

This Month

Review active and pending subcontracts for CMMC flow-down clauses

Prime-set deadlines are increasingly the real forcing function, not the paused federal date. Check your own subcontracts specifically rather than assuming the November date still applies.

This Month

Confirm which CGA grant track matches your scope

If you started a gap assessment grant application before the Level 1/Level 2 split, confirm which track now applies to your organization before submitting.

This Quarter

Continue NIST 800-171 Rev 2 remediation independent of the task force timeline

Phase 1 self-assessment obligations were never part of the suspension. Treat remediation as running on its own clock regardless of when the mid-September report lands.

This Quarter

Watch for the CMMC Reform Task Force report, expected mid-September

This is the next scheduled checkpoint that could actually change the program’s direction. Nothing to act on until it publishes, but worth tracking closely once September begins.

CMMC Gap Assessment Grants Available

Level 1 and Level 2 tracks now available through Cyber Grants Alliance. First come, first served.

Apply for a CMMC Gap Assessment Grant →