Vigilant Cybersecurity

Every Monday

CMMC Weekly Briefing

The past week's CMMC rule changes, Cyber AB news and enforcement actions, in plain English for Alaska defense contractors. Each briefing links to its primary sources.

  1. Sep 21–25, 2026

    Task force report still pending as the Rev. 3 deviation sinks in

    No new CMMC actions surfaced September 21–25, but the Rev. 3 class deviation signed September 3 reaches well beyond CMMC. The task force report is still pending.

    Published September 28, 2026

  2. Sep 14–18, 2026

    "Not the death knell of CMMC" as the wait for the report begins

    The task force's review window has closed, but no report has been released. PSC's Stephanie Kostro said the class deviation doesn't kill CMMC, and the FAR Council published three more overhaul proposals.

  3. Sep 7–11, 2026

    Davies says CMMC hit small businesses "inappropriately hard"

    At the Billington CyberSecurity Summit on September 9, DoW CIO Kirsten Davies said the task force received more than 1,100 RFI responses and signaled a move away from point-in-time compliance. The 60-day review window closed September 11.

  4. Aug 31–Sep 4, 2026

    Rev. 3 deviation signed, and Honeywell settles a cyber FCA case

    DFARS Class Deviation 2026-O0025, Revision 3, signed September 3, supersedes Revision 2 and directs contracting officers to remove or revise CMMC requirements. On September 1 Honeywell Aerospace agreed to pay $2,042,518 to settle NIST SP 800-171 False Claims Act allegations.

  5. Aug 24–28, 2026

    About 1,100 RFI responses, and a new principal deputy CIO

    DoW CIO Kirsten Davies told the DIB Accelerator audience that the task force received about 1,100 RFI responses. Sonu Shankar was sworn in as principal deputy CIO, and the Cyber AB reported more than 2,000 Level 2 certifications issued.

  6. Aug 17–21, 2026

    CUI marking emerges as the reform issue everyone agrees on

    SBA Advocacy published its RFI comments, and trade groups and law firms told Federal News Network that inconsistent CUI marking is the program's core problem. The DoW CIO's "Brilliant at the Basics" lists hint at where reform may land.

  7. Aug 10–14, 2026

    RFI closes; SBA Advocacy asks DoW to fix CUI first

    The Reform Task Force RFI closed at noon ET on August 14. SBA's Office of Advocacy filed comments the same day, asking DoW to identify CUI clearly before imposing CMMC and to create a graduated path to Level 2.

  8. Aug 3–7, 2026

    A quiet week, and a phishing breach at a defense supplier

    No new CMMC rules, memos or Cyber AB announcements surfaced August 3–7. A defense supplier's SEC filing about a phished Microsoft 365 account shows why the pause doesn't pause the threat.

  9. Jul 27–31, 2026

    The Cyber AB says the program isn't paused, only Phase 2

    The Cyber AB's July town hall made the point that CMMC itself continues while Phase 2 contract requirements are on hold. Its education arm announced a rebuild of the practitioner programs through mid-2027.

  10. Jul 20–24, 2026

    Task force opens its RFI as the House passes its NDAA

    The CMMC Reform Task Force asked industry for input, with responses due August 14. The House passed its FY2027 NDAA 216–212, while the Senate bill with a proposed CMMC grant program stayed stalled.

  11. Jul 13–17, 2026

    DoW suspends CMMC Phase 2 and launches a 60-day review

    On July 13 the Department of War suspended the CMMC Phase 2 requirements scheduled for November 10, 2026, and stood up a Reform Task Force. By Friday a class deviation had told contracting officers how to carry it out.