CMMC Ready Now
← CMMC Intelligence|July 2026

CMMC Intelligence Report: July 2026

On July 13, DoD suspended CMMC Phase 2, the third-party C3PAO certification requirement, and froze Phases 3 and 4 alongside it. The November 10 deadline that has driven every conversation in this report since April is no longer an active enforcement date. That is not the same as the bar disappearing: Phase 1 self-assessment remains fully enforceable, and with third-party verification paused, an inaccurate SPRS score is now a bigger liability, not a smaller one. This month’s report covers what the suspension actually changes, what it doesn’t, and a new executive order reshaping supply-chain requirements regardless of how the CMMC review concludes.

Phase 2 SuspendedReform Task ForceSupply Chain EOSelf-Attestation Risk

CMMC Program Status: Phase 2 Suspended

On July 13, DoD Chief Information Officer Kirsten Davies signed a memo suspending CMMC Phase 2, the requirement that contractors handling CUI obtain third-party (C3PAO) assessment at Level 2, and froze Phases 3 and 4 alongside it. The memo cites prohibitive compliance costs, a severe shortage of accredited third-party assessors, and complex regulatory timelines pushing small businesses and non-traditional entrants out of DoD contracting.

The suspension was issued via internal DoD memo, not a Federal Register rule change: 32 C.F.R. Part 170 remains formally unamended. In practice, that means the November 10, 2026 deadline that has anchored every conversation in this report since April is no longer an active enforcement date. DoD has stood up a CMMC Reform Task Force to conduct a 60-day review, with a public Request for Information due August 14, 2026 and a report expected around mid-September.

What’s unchanged is arguably more important than what’s paused. Phase 1 obligations remain fully enforceable: contractors handling CUI still must self-assess against all 110 NIST SP 800-171 Revision 2 controls, maintain a current SPRS score with a named senior official affirming its accuracy, and report cyber incidents to DIBNet within 72 hours. With third-party verification on hold, self-certification carries more exposure, not less. False attestations remain an explicit target of the Department of Justice’s Civil Cyber-Fraud Initiative, with False Claims Act liability including treble damages. An inaccurate SPRS score is a bigger liability now than it was in June, because there is no longer a scheduled third-party assessment that would have caught the gap before it became a legal problem.

What Actually Changed vs. What Didn’t

  • Suspended: Phase 2 (C3PAO Level 2 certification), and Phases 3 & 4
  • No longer active: The November 10, 2026 enforcement deadline
  • Unchanged: Phase 1 self-assessment against all 110 NIST SP 800-171 Rev 2 controls
  • Unchanged: SPRS score submission with senior official affirmation
  • Unchanged: 72-hour DIBNet incident reporting under DFARS 252.204-7012
  • Higher stakes, not lower: False attestation liability under the DOJ Civil Cyber-Fraud Initiative

Assessment Pipeline: What Happens to Booked C3PAO Work

The most common question this report is getting since July 13: what do I do with an assessment I already booked? DoD’s guidance is not to cancel it. Converting a scheduled C3PAO engagement to a readiness assessment or mock assessment preserves the value of the work: you still get an independent, methodical review of your control implementation, documentation, and evidence, without the certification outcome being contingent on a program that is currently under review.

For contractors who had not yet engaged a C3PAO, the suspension removes the hard calendar pressure this report spent April through June documenting, but it does not remove the underlying requirement. NIST 800-171 Rev 2 remediation should continue on its own timeline, independent of when or how Phase 2 resumes. Contractors who use this pause to stop work entirely will be starting from behind again whenever third-party assessment restarts, and self-assessment liability under Phase 1 is running the entire time regardless.

The practical shift is this: the forcing function for CMMC work is no longer a government enforcement date. It is now (1) prime contractor flow-down requirements, which several primes began enforcing ahead of DoD’s own timeline earlier this year, and (2) the exposure sitting behind your own SPRS self-certification. Neither of those paused on July 13.

CMMC Gap Assessment Grants Available

100 grants valued at $5,000 each for small and mid-sized defense contractors. Administered by Cyber Grants Alliance. First come, first served.

Apply for a CMMC Gap Assessment Grant →

New Executive Order on Defense Supply Chain Security

A July 20 executive order, published in the Federal Register on July 23, directs the Secretary of War to develop a regulatory process requiring covered contractors and subcontractors, at any tier, to map their supply chains back to raw-material origin and implement due-diligence screening to identify and mitigate sourcing risk. Implementation guidance is due within 180 days.

Combined with expanded Foreign Ownership, Control, or Influence (FOCI) disclosure requirements moving through rulemaking this year, the direction of travel is clear even as CMMC’s specific mechanics are under review: supply chain visibility and ownership transparency are becoming standing requirements, not optional documentation. Contractors at any tier of a defense supply chain should expect sourcing and provenance questions to become a standard part of both prime due-diligence and eventual regulatory review, independent of the CMMC Reform Task Force’s outcome.

DIB Threat Landscape

PTC Windchill / FlexPLM: Mass Extortion Campaign Hits the Defense Supply Chain Directly

Clop-affiliated threat actors exploited CVE-2026-12569 (CVSS 9.8), an unauthenticated remote code execution flaw in PTC’s Windchill and FlexPLM product lifecycle management software, likely as a zero-day starting in early June. PTC patched on June 17 and CISA added the flaw to its Known Exploited Vulnerabilities catalog on June 25, but the active extortion campaign (threatening to leak data under the subject line “Windchill PDMLink module serious data leak”) didn’t begin until July 20, confirmed hitting organizations across aerospace, automotive, and manufacturing.

The data at risk is exactly what CMMC exists to protect: product designs, bills of materials, and supplier records. PTC’s customer base includes defense contractors, energy suppliers, and electronics manufacturers, making this the single most relevant incident of the month for a CUI-handling readership. If your organization runs Windchill or FlexPLM, confirm patch status against the June 17 release immediately if you have not already. This is not a theoretical exposure, it is an active campaign.

Ransomware Groups Continue Targeting Defense-Adjacent Organizations

The Gentlemen ransomware group claimed an attack on a subsidiary of Indra Group, a Spanish defense, aerospace, and air-traffic-management technology company and NATO cyber coalition member, with an initial ransom deadline later extended to July 9. Indra says the incident was contained to a non-critical environment with no operational disruption. Whatever the ultimate outcome, it is a current, concrete example of a top-tier ransomware group directly targeting a defense-adjacent, NATO-affiliated organization, the same threat category that any CMMC-scoped contractor sits in.

Regulatory Watch

CMMC Reform Task Force RFI: Due August 14

DoD’s CMMC Reform Task Force has opened a public Request for Information as part of its 60-day review of the suspended program, due August 14, 2026, with a report expected around mid-September. Contractors, C3PAOs, and industry associations with a position on how third-party assessment should be restructured have a narrow window to submit input before the review concludes.

NIST SP 800-171 Revision 3: Still Not the Enforced Standard

Revision 2 remains the enforced standard under DFARS 252.204-7012, and DoD’s own suspension memo explicitly reaffirms that self-assessments will continue against Rev 2 during the review period. Revision 3 was finalized in 2024 but is not expected to become the mandatory baseline via formal rulemaking until sometime between late 2026 and late 2027. Don’t let a vendor’s Rev 3 tooling rollout be mistaken for a new compliance deadline.

What changes in NIST 800-171 Rev 3

DOJ Civil Cyber-Fraud Initiative: Self-Attestation Under Sharper Scrutiny

With third-party verification paused, self-certified SPRS scores are the only check standing between a contractor’s stated posture and the government’s. The Department of Justice’s Civil Cyber-Fraud Initiative continues pursuing False Claims Act cases (including treble damages) against contractors who misrepresent their cybersecurity compliance. An SPRS score you cannot defend under audit is a materially larger legal exposure this quarter than it was before July 13.

Cyber Grants Alliance: Grants Remain Available

CMMC gap assessment grants through Cyber Grants Alliance remain available. Applications are reviewed on a rolling basis. With Phase 2 suspended, a gap assessment is still the most actionable step for contractors who have not started: it establishes a defensible SPRS score and documents your remediation priorities regardless of when third-party assessment resumes.

Apply for a CMMC Gap Assessment Grant

August Action Items

August is a month to re-baseline, not to stand down. The items below reflect what actually changed on July 13, and what didn’t.

Immediate

Do not cancel a booked C3PAO engagement

Convert it to a readiness or mock assessment instead. You keep the independent review of your control implementation without a certification outcome contingent on a program under active reform.

Immediate

Patch or confirm patch status on PTC Windchill / FlexPLM

CVE-2026-12569 is under active exploitation with a live extortion campaign targeting the exact CUI-adjacent data (product designs, BOMs, supplier records) CMMC exists to protect. If you run this software, verify the June 17 patch is applied today.

This Month

Continue NIST 800-171 Rev 2 remediation on its own timeline

Phase 1 self-assessment obligations did not pause. Treat remediation as independent of when or how Phase 2 resumes: stopping now just means restarting from behind later, while your self-certification exposure runs the entire time.

This Month

Stress-test your SPRS score before someone else does

With third-party verification paused, your self-certification is under sharper legal scrutiny, not less. If you could not defend your current SPRS score under a DOJ Civil Cyber-Fraud Initiative inquiry, that is the gap to close first.

This Quarter

Submit input to the CMMC Reform Task Force RFI if you have a position

The public comment window closes August 14, ahead of a report expected around mid-September. This is the narrow window to influence how third-party assessment gets restructured.

CMMC Gap Assessment Grants Available

100 grants valued at $5,000 each for small and mid-sized defense contractors. Administered by Cyber Grants Alliance. First come, first served.

Apply for a CMMC Gap Assessment Grant →