CMMC Ready Now
← CMMC Intelligence|June 2026

CMMC Intelligence Report: June 2026

The runway is gone. FIPS 140-2 has three months left. C3PAO queues are booked through September. Primes are now enforcing CMMC flow-down requirements without waiting for DoD. And the math on November has turned unworkable for contractors who have not yet started. This month’s report covers what changed in June and what contractors must execute on in July.

FIPS Final StretchFlow-Down WaveQueue CrisisNo More RunwayJuly Actions

CMMC Program Status: The Window Has Closed

In May, we said June was the last month where a contractor starting from scratch could build a credible path to November. That window is now closed. Contractors who have not yet engaged a C3PAO and completed at least a gap assessment are now facing a calendar that does not work — not with standard assessment timelines, not with remediation buffers, not with the re-verification step that most assessments require.

This is not a reason to stop. Contractors who miss November enforcement on one contract will face it again on every subsequent contract. The cost of continuing to delay compounds with each award cycle. The right response to missing the November window is to compress the preparation timeline as aggressively as possible, understand which controls require the most lead time, and get on the C3PAO schedule immediately even if the timeline runs into early 2027.

For contractors already in their assessment process, June was generally a productive month. C3PAO firms reported steady assessment completions, and several smaller contractors received their first Letters of Assessment Findings. The post-findings remediation period is critical — do not treat a finding as a bureaucratic note. It is a documented gap that must be closed before your final certification can be issued.

4

Months to November

Broader Level 2 enforcement

3

Months to FIPS Sunset

September 21, 2026

6–12 wk

New C3PAO Wait Time

First availability for new clients

The November Math Has Broken

C3PAO wait time (8 wk) + assessment duration (7 wk) + findings remediation (4 wk) + re-verification (2 wk) = 21 weeks minimum. 21 weeks from July 1 lands on November 18 — after the enforcement window opens. Contractors beginning outreach now face a structural calendar problem, not a scheduling problem.

Prime Contractor Flow-Down: The Private Enforcement Wave

One of the most significant developments in June was not a DoD announcement — it was the acceleration of prime contractor flow-down enforcement. Major defense primes, including Tier 1 aerospace and defense systems integrators, have been inserting CMMC flow-down clauses into subcontractor agreements ahead of the government’s November timeline. Several primes began requiring proof of C3PAO engagement or active gap assessment completion as a condition for 2027 subcontract renewals.

This represents a meaningful shift. The CMMC enforcement mechanism that most contractors were watching was the government contracting officer at award. What is now emerging is a parallel enforcement layer: primes protecting their own prime contract compliance by pushing requirements down the supply chain before DoD formally mandates it.

For small and mid-sized subcontractors, this creates a dual-track pressure. They must satisfy both the government requirement (assessed against DFARS 252.204-7021) and any prime-specific cybersecurity requirements, which may be more stringent or have earlier deadlines. Subcontractors should review every teaming agreement and subcontract from this year for CMMC or NIST 800-171 language — some of these clauses are now carrying liquidated damages provisions for non-compliance.

For more on what prime enforcement looks like in practice, see the CMMC flow-down requirements analysis.

What to Look for in Your Subcontracts

  • DFARS 252.204-7012, 7019, 7020, or 7021 flow-down clauses
  • Prime-specific cybersecurity addenda or rider documents
  • Certification or attestation deadlines that predate November 2026
  • Liquidated damages provisions for cybersecurity non-compliance
  • Right-to-audit or right-to-inspect language covering your IT environment

CMMC Gap Assessment Grants Available

100 grants valued at $5,000 each for small and mid-sized defense contractors. Administered by Cyber Grants Alliance. First come, first served.

Apply for a CMMC Gap Assessment Grant →

FIPS 140-2 Sunset: Three Months Out

September 21, 2026 is now three months away. NIST will move all FIPS 140-2 validated modules to historical status under the Cryptographic Module Validation Program, and the practical implications for defense contractors are becoming harder to ignore.

In June, several major security vendors published FIPS 140-3 upgrade timelines and in some cases pushed emergency releases to meet the September deadline. Contractors should not assume their vendors will automatically upgrade their products in time. You need to know the specific FIPS status of every product in your CUI environment, and you need to know your vendor’s plan before your next C3PAO assessment.

Products to check immediately include VPN gateways, endpoint encryption tools, secure email systems, file transfer clients, and any hardware security module in your environment. Some vendors have already published FIPS 140-3 validated versions. Others are still in the NIST CMVP queue, which can take months. If your vendor is still in queue on September 21, their FIPS 140-2 module becomes historical — and an assessor reviewing your environment after that date will see a historical-status certificate.

The full transition guide, including how to use the NIST CMVP search tool to verify your products, is at FIPS 140-2 Sunset: How to Transition to FIPS 140-3.

~82

Days to FIPS 140-2 Historical Status

September 21, 2026

3–9 mo

CMVP Review Queue (typical)

New 140-3 module submissions

DIB Threat Landscape

Workforce-Targeted Social Engineering Increasing

Threat activity against the DIB workforce — rather than the infrastructure — increased in June. Social engineering attacks targeting employees with access to CUI are up, with techniques ranging from spear-phishing campaigns impersonating contracting officers to voice phishing (vishing) attacks targeting help desks and IT staff. Several incidents involved attackers successfully resetting MFA credentials by impersonating employees to IT departments.

This has direct CMMC implications. CMMC control AT.2.056 requires organizations to train personnel on cybersecurity awareness, with AT.2.057 specifically calling out insider threat awareness. But more practically, these incidents illustrate that technical controls alone are insufficient. A contractor with a well-configured IT environment but an undertrained workforce is still a soft target. The CMMC workforce training and cybersecurity culture guide covers what assessors look for in the AT domain.

Continuous Monitoring Gaps Exposed in Incident Reviews

Post-incident reviews from Q1 and Q2 2026 breaches in the DIB have consistently found the same gap: contractors lacked the monitoring capability to detect unauthorized access in real time. In several cases, threat actors maintained persistent access for weeks before the intrusion was discovered. CMMC control AU.2.041 (audit logging) and AU.2.042 (log review) are straightforward requirements, but many small contractors implement logging without implementing review — which satisfies the letter of the control but fails the spirit.

C3PAO assessors are increasingly asking for evidence of log review activity, not just log collection. If your SIEM generates alerts that go unread, or your log review process is manual and monthly, be prepared to discuss that during your assessment. For a deeper look at what a real-time security posture requires, see CMMC Continuous Monitoring: Building a Real-Time Security Posture.

Post-Quantum Threat Horizon: CNSA 2.0 Deadlines Approaching

The NSA’s Commercial National Security Algorithm Suite 2.0 (CNSA 2.0) establishes timelines for national security systems to migrate to quantum-resistant cryptography. While CMMC Level 2 does not yet require CNSA 2.0 compliance, contractors working on classified or sensitive programs should understand these timelines are not hypothetical. NIST finalized FIPS 203, 204, and 205 in August 2024. Vendors supplying equipment to national security programs will face CNSA 2.0 mandates beginning in the 2026–2030 timeframe depending on system type.

For contractors whose roadmap includes higher-sensitivity defense programs, beginning post-quantum readiness planning now — even informally — is a risk management decision, not a compliance checkbox. The post-quantum readiness guide covers what FIPS 203/204/205 mean for your CMMC program.

Regulatory Watch

FAR CUI Rule: Still Pending, Comment Review Ongoing

The proposed FAR rule requiring NIST 800-171 compliance for all federal contractors handling CUI has not yet produced a final rule as of July 1. The FAR Council continues reviewing comments received during the comment period. Industry observers had expected a final rule by mid-2026; the delay likely reflects the volume of comments and the scope of the proposed rule. Contractors with civilian agency work should continue building toward NIST 800-171 regardless — the rule will land, and the timeline will be compressed.

Full FAR CUI rule analysis

NIST SP 800-171 Rev 3: DoD Transition Timeline Still TBD

DoD has not announced a transition date for CMMC Level 2 assessments to move from the 110 practices of Rev 2 to the expanded controls in Rev 3. Current C3PAO assessments remain against Rev 2. The scope changes in Rev 3 — particularly in the Access Control, System and Communications Protection, and Supply Chain Risk Management families — are significant enough that contractors should begin gap-mapping against Rev 3 controls now rather than waiting for an announcement.

What changes in NIST 800-171 Rev 3

DoD Contractor Reporting: DIBNET Usage Expanding

DoD has been encouraging expanded use of DIBNET for incident reporting and cybersecurity information sharing. Contractors required to report cyber incidents under DFARS 252.204-7012 should verify their DIBNET registration is current and that their incident response procedures reference DIBNET as the reporting channel. An incident response plan that routes reports to the wrong destination will be flagged during a C3PAO assessment.

Cyber Grants Alliance: Grants Remain Available

CMMC gap assessment grants through Cyber Grants Alliance are still available as of July 1. Applications are reviewed on a rolling basis. With the assessment queue at critical levels, a gap assessment remains the most actionable first step for contractors who have not yet started their CMMC program — it establishes your SPRS score, identifies your highest-priority remediation items, and creates the documentation foundation your C3PAO will need.

Apply for a CMMC Gap Assessment Grant

July Action Items

July is not a month for new planning. It is a month for executing on whatever plan already exists. The items below are organized by urgency, not complexity.

Immediate

If you have not engaged a C3PAO: do it today

The November math no longer works for contractors who start now. That does not mean you stop. Get on the C3PAO schedule, understand your realistic completion timeline, and begin building your case for any interim attestation or contract bridge strategy your contracting officer may accept.

Immediate

Review subcontracts for prime-inserted CMMC clauses

Pull every active subcontract and teaming agreement from 2026. Look for DFARS flow-down clauses, cybersecurity riders, and certification deadline language. Prime enforcement is now ahead of government enforcement in many supply chains.

Immediate

FIPS 140-2: Contact vendors with outstanding 140-3 timelines

You have roughly 82 days before the September 21 sunset. For every product in your CUI environment without an active FIPS 140-3 certificate, contact the vendor this week. If they cannot confirm a validated version before September 21, escalate to procurement.

This Month

Verify DIBNET registration is current

If your organization is required to report cyber incidents under DFARS 252.204-7012, confirm your DIBNET portal access is working and your incident response procedures reference it as the reporting channel. Test the process before you need it.

This Month

Run a workforce phishing simulation

June incident data showed workforce targeting on the rise. A tabletop or simulated phishing campaign surfaces training gaps before an assessor or an attacker does. Document the results as evidence for the AT domain controls.

This Quarter

Begin NIST 800-171 Rev 3 gap mapping

DoD has not announced the Rev 3 transition date, but it is coming. Organizations that start mapping their Rev 3 gaps now will not be caught flat-footed when the announcement arrives. Focus first on the Access Control and Supply Chain Risk Management families, which have the largest scope increases.

CMMC Gap Assessment Grants Available

100 grants valued at $5,000 each for small and mid-sized defense contractors. Administered by Cyber Grants Alliance. First come, first served.

Apply for a CMMC Gap Assessment Grant →