PARTNERSHIPCUI Vault and Trout Software partner to extend the CUI boundary to the machine.CUI Vault partners with Trout Software.Read the announcement

The reform report is written. It is now moving through rooms you are not in.

The 60-day review is finished and recommendations are drafted, but the package now has to clear General Counsel, the small business office, OMB and the White House before anyone outside sees it. The estimate for a public release is the back half of October — at the earliest.

At the Cyber AB’s September 30 town hall, the sequence finally got specific: the 60-day review is finished, recommendations are drafted, and the package now has to clear General Counsel, the small business office, OMB and the White House before anyone outside sees it. The estimate for a public release is the back half of October — at the earliest.

For three months the honest answer to “what happens next with CMMC” has been a date that keeps moving. Last week the Cyber AB gave the clearest public account yet of why, and the explanation is more useful than another date would have been.

Cyber AB chief executive Matthew Travis described the mechanics: the Reform Task Force closed its 60-day review in mid-September and moved into a roughly 15-day window to draft recommendations. The draft then has to be coordinated with the Department’s CIO, its General Counsel, the small business office, the Office of Management and Budget, and the White House before it can be released publicly. Travis’s own estimate — offered with the caveat that no official timeline exists — was the back half of October at the earliest. Practitioner reporting indicates the report itself reached the Department’s CIO on or about September 11; everything since has been internal.

Read that chain of custody and one thing becomes clear: the stage where industry had a voice ended on August 14, when the request-for-information window closed with more than 1,100 responses and over 10,000 pages of feedback. What emerges in late October or beyond will not be a draft circulated for your comment. It will be a decision.

  • Aug 14, 2026
    RFI comment period closes. More than 1,100 responses, over 10,000 pages. This was industry’s formal input, and it is now closed.
  • Sep 11–12, 2026
    60-day review window closes and the report goes to the Department’s CIO. Nothing is released publicly.
  • Sep 30, 2026
    Cyber AB town hall describes the 15-day drafting window and the interagency coordination still ahead — CIO, General Counsel, small business, OMB, the White House.
  • Back half of Oct 2026 (earliest)
    Possible public release. An estimate from the Cyber AB, not a commitment from the Department. There is still no official date.
  • Nov 1 – Dec 31, 2026
    A date that is committed: the practitioner credential renewal window (see Quick Hits).

Meanwhile the machinery everyone assumes is switched off has been running the whole time. DFARS 252.204-7012 remains in force. C3PAOs are still conducting Level 2 assessments. CMMC eMASS and SPRS are still processing certifications. DIBCAC is still evaluating both C3PAOs and the organizations they assess. And the certification counts reported at the town hall are worth sitting with:

The ecosystem during a pause: final Level 2 certificates reached 2,362 — up 12% in a single month. Conditional certificates rose to 71. Assessments in progress fell 5%, to 151. There are now 117 authorized or accredited C3PAOs, four of them fully accredited to ISO/IEC 17020. Completions up and the queue down means the backlog is draining, not refilling — and the companies draining it decided the pause did not change their answer.

On what the recommendations might contain, the town hall’s speakers were explicit that they were speculating with no inside knowledge. The concepts raised — continuous monitoring and risk scoring, compliance expressed as code, a hybrid of third-party assessment and self-attestation, FedRAMP alignment, an expansion into operational technology, and preserving the value of certificates already earned — are the vocabulary of the debate, not policy. None of them removes a requirement that exists today.

So what: stop using the Task Force release as a planning milestone. It has now slipped through three signaled windows, it is governed by an interagency process with no published deadline, and when it arrives you will not get a comment period on it. Replace it with a date you control: pick the month you intend to be able to withstand an assessment, write it down, and work backward from it. Three months of waiting has already cost some organizations a quarter of readiness time — and 2,362 of your peers are not waiting.

Three in four subcontractors have heard nothing from their prime about the pause

A survey of defense contractors that handle CUI and federal contract information, fielded over the summer and published on October 1 by the C3PAO Redspin as Committed to the Mission: The State of the DIB with CMMC in Flux, puts a number on something a lot of suppliers have been quietly guessing about.

76.6% of subcontractors reported receiving no communication at all from their primes about the Phase 2 pause. Only 10.6% said a prime had actually told them CMMC requirements were paused. On the other side of the same relationship, 39.5% of primes said they were still deciding whether to relax Phase 2 expectations for subcontractors, and 23.3% said they were relaxing them.

Put those four figures in one sentence and the risk becomes obvious: the most common experience in the supply chain right now is silence, and silence is being read as permission by people whose primes have not decided anything yet. If you have concluded your prime relaxed its expectations, the odds are roughly nine in ten that nobody told you so.

It also matters what a prime can and cannot relax. A prime can defer its own expectation that you hold a third-party certificate by a given date. It cannot relax DFARS 252.204-7012, the NIST SP 800-171 implementation behind your SPRS score, or the annual affirmation you sign — those flow from the contract, not from a supplier policy. As Redspin vice president and Lead CCA Dr. Thomas Graham put it: “CMMC may be in flux, but DFARS and NIST obligations haven’t gone away.” On who sets the clock: “Primes will play a big role in determining when subs need certification timelines.”

Most of the industry appears to have worked this out already. 78.2% are continuing toward Level 2 certification or already hold it, against 21.9% delaying or slowing down, and between 75% and 84% report no change at all in cybersecurity spending. 75% see value in certification beyond simply being eligible to bid — citing independent validation (68.8%), commitment to protecting CUI (62.5%), and a genuinely improved security posture (58.3%).

So what: send one email this week. Ask your prime’s supply chain or supplier-risk contact, in writing, whether their CMMC and Phase 2 expectations have changed, and by what date they expect certification. File the reply with the contract. If the answer is “we’re still deciding” — which is what roughly four in ten primes would say today — you have just learned that your deadline is being set by someone else, on their schedule, and that being ready before they decide is the only position that costs you nothing.

The Pentagon just took the building off the list of things keeping you out of sensitive work

On September 3, the Department of War launched the Secure Space Network: roughly 50 mobile accredited secure facilities, run by the Office of Industrial Base Growth inside the Under Secretary of War for Acquisition and Sustainment, and placed at military installations, APEX Accelerators and other mission-relevant sites around the country. The stated purpose is to let more suppliers take part in classified development, collaboration and production by broadening regional access to accredited secure workspace.

For a small or mid-sized supplier that removes a barrier that has been decisive for decades: building and accrediting your own secure facility is a capital project most companies in this sector will never undertake, and a firm holding a non-possessing facility clearance can now reach classified work without one. (The clearance itself is unchanged — the network provides space, not eligibility.) It arrives alongside the Smaller War Plants Commission, stood up on August 25 by the Small Business Administration and the Department of War, named for a World War II-era predecessor and aimed squarely at pulling smaller firms into the defense industrial base.

Now notice which barrier did not move. The Secure Space Network addresses physical space for classified work. It does nothing about the unclassified-but-controlled technical data that makes up the overwhelming majority of what actually flows to suppliers — drawings, specifications, test results, requirements documents. That material arrives on your network, inside your boundary, under DFARS 252.204-7012 and the 110 requirements of NIST SP 800-171, with an affirmation signed in your own name. There is no shared facility to borrow for that.

The same part of the Department made the point itself. Keynoting CMMC CON 2026 in late September, James Mismash, the Pentagon’s deputy assistant secretary for industrial base growth, told a room of compliance practitioners: “Suspending one part of the implementation model is not the same as relaxing the cybersecurity mission.” That is the office whose job is to grow the industrial base saying the security bar is not what is being lowered.

So what: the Department is actively widening the pool of companies that can handle sensitive work — which means more competition for it, and a lower physical barrier to entry for your competitors too. The qualifying event is shifting from real estate to information handling, and information handling is the part you own. Name the two or three programs you want to be on in 2027, find out what controlled data they would send, and answer honestly whether you could receive and hold it today. If the answer is no, that gap is now the only thing between you and a growing set of opportunities.

What to do this week

The theme this issue: every date worth planning around right now is one you set yourself.

  • Retire the Task Force date as a planning input. Replace it with the month you intend to be assessment-ready, in writing, and work the schedule backward from there.
  • Ask your prime, in writing, whether its CMMC expectations have changed. One email to the supply chain or supplier-risk contact. File whatever comes back with the contract.
  • Check your practitioners’ credential dates against the November 1 renewal window. It closes December 31 and the grace period ends January 30 — the only hard deadline currently on the CMMC calendar.
  • Name the programs you want in 2027 and confirm you could receive their controlled data today. If you could not, that is your real growth constraint.
  • Decide by October 19 whether to comment on the FAR Overhaul’s second batch. The last open comment window on the near-term calendar. The CUI substance sits in the separate Part 40 rule, which lands final — no further comment period — whenever it lands.

Quick hits

  • Sep 30, 2026
    Credential renewal is the one hard deadline currently on the CMMC calendar.
    The renewal window opens November 1 and closes December 31, with processing on January 1 and the grace period expiring January 30, 2027. Certified CMMC Professionals need 20 continuing-education credits a year; assessors must keep an intermediate or advanced DoD 8140 certification. Meanwhile approved training providers have fallen from 53 to 49 and new training content is on hold until the first quarter of 2027. If your readiness plan depends on credentialed people, the supply side is tightening while the deadline is fixed.
  • Sep 30, 2026
    A Revision 3 transition plan already exists — it is sitting in a drawer.
    The Cyber AB confirmed a plan for moving from NIST SP 800-171 Revision 2 to Revision 3 was drafted before the pause and held in abeyance since; grace periods are anticipated but not guaranteed. Revision 3 is a question of when and how gently, not whether — and organizations that read it now will not be reading it under a deadline later.
  • Jun 8, 2026
    The 1260H list of Chinese military companies has grown to 188 names — and the second ban lands in 2027.
    June’s update added 55 entities and pushed the list beyond aerospace into cybersecurity, telecommunications, batteries and solar. Direct Pentagon procurement from listed companies has been barred since June 30, 2026; the ban on indirect procurement — buying from suppliers who buy from them — takes effect June 30, 2027. Screening your own supply chain against the current list is a twelve-month project that starts now, not next June.

Not sure where your organization stands?

CUI Vault gives you a live, always-audit-ready picture of your CUI environment and NIST 800-171 posture — so headlines like today’s are a footnote, not a fire drill. Reach out to your NtelSec team to talk through your current gaps.

This briefing is a general-information summary of publicly reported CMMC and CUI developments. It is not legal advice; consult your compliance counsel before making contractual or certification decisions.
Talk to us about CUI Vault All issues